A QR code is just a link you can't read. That's the whole problem. When a flyer on a coffee-shop bulletin board says "📷 Scan to enter our $500 giveaway," you're pointing your phone at a black-and-white box and trusting whatever it does next. Scammers noticed. The tactic even has a name — "quishing" (QR phishing) — and the FBI, FTC, and Better Business Bureau have all issued warnings about it. The dangerous twist for sweepers is that the code lives in the physical world, where a con artist doesn't need to hack anything. They just need a sticker.

The tampered-sticker trick

The nastiest version isn't a fake flyer at all — it's a real one with a sticker slapped over the original code. A legitimate business posts a genuine "scan to win" sign, and someone covers the printed QR with a printed-over version that points to their own phishing page. You scan what looks like an official promotion, and the destination is a lookalike login or a form harvesting your name, address, and card number "to ship your prize." Parking meters have been a favorite target: cities from Austin to San Antonio to Boston have found fraudulent QR stickers on public meters, and the same move works on any restaurant table tent, event poster, or gym bulletin board.

Before you scan anything physical, run a thumbnail over the code. A sticker has an edge you can feel, and a code applied on top of existing print will sit slightly raised or misaligned with the surrounding graphics. If the QR looks like a separate square pasted onto an otherwise professionally printed flyer — different paper sheen, a white border that doesn't match, a corner peeling up — treat it as hostile. When a real business is running the giveaway, you can almost always find the same promotion on its posted website or social account, so skip the mystery code and go straight to the source you can verify.

Preview the URL before you open it

Your phone is on your side here, and most people never use the one feature that matters. When you point the camera at a QR code, iOS and Android show the destination URL as a preview banner before loading it — do not tap until you've actually read that link. Scammers count on you scanning and tapping in one reflex. The tells are the same as any phishing link: a URL shortener hiding the real domain (bit.ly, tinyurl), a misspelled brand (arnazon, coca-colla), a .top/.xyz/.zip domain where you'd expect a .com, or a lookalike that buries the real host deep in a long string like giveaway-official.claim-prize.ru.

Two more habits close the gap. First, if the preview link doesn't clearly match the brand you think is running the contest, close it — a real Target or Starbucks promotion lives on that company's own domain, not a random one. Second, if you do land on a page, never enter a password, and never provide payment details to "release" a free prize — a legit giveaway does not ask you to log in through a QR code or pay to claim winnings. Turn OFF any phone setting that auto-opens scanned links, and consider a scanner app that displays the full expanded URL for shortened codes so nothing loads until you say so.

Bottom line: treat every physical QR code as an unverified link — feel for a sticker, read the URL, and when in doubt, type the brand's address yourself.