Scam entry · Wallet security · Scan-to-approve

Fake QR codes: scanning is harmless — the approval your wallet pops up isn't

You scan an unknown QR code, your wallet throws up a window asking you to "confirm" or "sign" — stop right there. Scanning doesn't move your coins. What actually touches your assets is the approval or signature you tap next. The question isn't "what did I scan," it's "what is it asking me to approve." Here's how fake payment, airdrop and support QR codes and WalletConnect hijacks pull it off, how to tell an approval from a signature, how to stop mid-way, and what to do if you already signed.

Fake QR code approval scam illustration: a phone scanning a malicious QR code as a wallet token-approval confirmation window pops up
Chain Scam Index · Scan-to-approve scam specimen

Here's the one line to keep up front: after you scan an unknown QR code and your wallet pops up a window asking you to "confirm" or "sign," don't tap it yet. Scanning by itself doesn't move your coins — it only connects you to some web page or starts a wallet connection. What lets your assets leave is the approval or signature you press inside that window. So the thing to guard isn't whether you scan, it's whether you sign. If you can't tell what it's asking you to approve, close it and start over.

Can scanning a single QR code really drain your wallet?

A QR code is just a chunk of text turned into a scannable grid of squares, and that text is usually a URL or a wallet-connection request. Scanning it "opens a link" or "starts a connection." That step alone doesn't move your coins — nothing goes on-chain.

The danger sits in what comes after: the page routes you to something that looks like a claim page, a payment screen, or a support console; your wallet then pops up an approval or signature request; you tap "confirm," and that is the moment your assets actually leave. The scam simply welds those two steps together — scan and confirm — so you believe scanning equals claiming a reward, receiving a payment, or reaching support. Scanning only opens the door; the theft happens the instant you press confirm. Separate the two and you know where to keep your guard: not on the image, on the window asking you to sign.

Where do these "just scan this" QR codes turn up?

Same logic, but it comes wrapped in a handful of familiar forms. Recognise them and you'll buy yourself a second of hesitation in the moment:

  • Fake payment QR codes. In person-to-person deals, resale, or "pay with this," someone hands you a code. A real payment only needs an address and an amount, but a malicious QR sends you to a web page that, once connected, asks you to "approve" rather than simply send once — and after you sign, what they can move is often more than the amount in front of you.
  • Fake airdrop and claim QR codes. Posted in comment sections, DMs, even printed on physical flyers and stickers: "scan to claim your airdrop." The site you land on asks you to sign an approval first to "unlock" the reward, and that approval hands the right to move your tokens to them. Some go further and ask you to scan to download a fake wallet app, where the wallet itself belongs to them.
  • Fake support telling you to scan. Someone posing as exchange or wallet support says they need to "verify your wallet," "sync your assets," or "lift a restriction," and sends a QR or link to scan. Real support does not ask you to scan something in order to sign an approval — you can treat that as close to a hard rule.
  • Hijacked WalletConnect sessions. This one is the most hidden. WalletConnect is a legitimate protocol that connects a mobile wallet to a web dApp by scanning a QR. The problem isn't the protocol; it's whether the site you connect to is the one you think it is. A phishing site clones a real one's look, you scan its WalletConnect QR, and the connection genuinely goes through — just to the scammer's contract, so the approval that follows is fed to them.
What these share: the QR code only "connects you up." What empties the wallet is the approval or signature after you're connected. So when you see "scan to claim / receive / unlock," assume the destination is a window asking for your signature, not money falling from the sky.

Is the pop-up an "approval" or a "signature" — and how do you tell?

After you scan, the window your wallet shows falls into a few categories, and each carries a different level of risk and a different way to read it. Being able to name which one you're looking at is the single most useful skill here. The table below lays out the ones you'll meet most:

Pop-up type How it looks in your wallet What it actually does Risk
approve / setApprovalForAll
(approval)
Shows a token name plus "Approve / grant use," usually with an amount — or the word "unlimited" Gives a contract the right to move that token of yours; setApprovalForAll opens an entire NFT collection at once High
eth_sign
(blind-sign gibberish)
A window showing an unreadable long hex string, asking you to "sign a signature" You're signing a message whose contents you can't read — potentially an authorisation to move your assets Very high
permit / Permit2
(off-chain approval)
Looks like "just a signature," no gas to pay — but the content is an approval Replaces an approve transaction with a signature, still handing over the right to move your tokens — and free, so your guard is lower High
Login / connect signature "Sign in" / "verify you own this wallet," with readable text Only proves the wallet is yours; moves no assets Low

The one-line rule: any time the window shows "Approve / setApprovalForAll," or asks you to sign an unreadable string, treat it as "I'm about to hand over the power to move my assets." Only a readable request that merely proves your identity is relatively safe. If you genuinely can't tell, treat it as the high-risk kind — refusing costs nothing, signing wrong can cost the whole wallet.

You scanned, something feels off — how do you stop right now?

The good news: while the approval or signature window is up and you haven't pressed confirm, nothing has happened yet. That gap is your brake, and holding it is all it takes.

  • Close the window and reject the request. Without a "confirm," nothing goes on-chain, and closing costs you nothing. When it feels off, the first move is always to reject — not "sign now and look into it later."
  • Disconnect the wallet session. Go to your wallet's "connected sites / WalletConnect" list and disconnect the site you just joined. Disconnecting is free and cuts off the channel they use to keep pushing pop-ups at you.
  • Decide by reading, not by feel. Does the window show token-approval wording? Is the amount marked "unlimited"? Can you actually read what you're signing? If those don't pass, it doesn't pass.
  • Start over from a clean route. If you really do need to receive or claim something, close the unknown QR and go again from your own saved official bookmark or the app's built-in entry — not by following the code someone handed you.

If you've already signed, can it be undone?

Start with the hard part: if what you signed was an approval handing over the right to move your tokens, the scammer may already have moved them, and once an on-chain transfer confirms it can't be reversed — no support desk can pull it back. But as long as you haven't been cleaned out, or there are other assets in the same wallet, the one thing you can and should do now is close any approval still open, so they aren't left with a door they can walk back through at will.

How to check exactly which approvals you've granted and revoke them one by one is laid out step by step in our wallet approval review and revoke guide. That's the place for damage control after a malicious approval — shutting the open doors one at a time. Move quickly, because until you revoke, they can act again at any moment.

One more warning up front: at this point, if an "I can recover your funds" DM or support account appears, it's almost always a second layer of the scam, using your panic to charge you another fee or "deposit." What you should actually do is keep your transaction records, close the approvals, and report it where reporting is warranted — not pay another stranger.

Editorial verification notes

We followed the public flow and connected a test wallet to a WalletConnect demo page. The most direct takeaway: from scanning to the pop-up, it's fast enough that you barely have time to react, and it's easy to confirm on reflex. What saves you isn't being clever before you scan — it's whether you pause and read when the window appears. We also put an approve window next to an ordinary login signature: the difference is visible — the former carries a token name and amount, the latter is just readable text. Recognising that difference beats memorising a pile of jargon.

When it happens to you, watch three things: who gave you this QR and where it's taking you (unknown source, don't scan); whether the pop-up is an approval or a plain login (token-approval wording or a request to sign gibberish means high risk); and whether you pause before pressing confirm. Pass all three and scan-to-approve theft basically can't reach you.

FAQ

I only scanned a QR code and haven't tapped anything. Can my wallet still be drained?

Scanning usually just opens a link or starts a wallet connection; it doesn't move your coins on its own. What actually touches your assets is the approval or signature you confirm afterwards. So as long as you haven't tapped confirm or sign in the pop-up, your coins are still there. The trap is that many people scan, see the pop-up, and confirm on reflex. The step to guard is whether you sign, not whether you scan. With an unknown QR the safest move is not to scan it at all; if you did scan, read the pop-up carefully before anything else.

Is WalletConnect safe? Can scanning its QR code be a problem?

WalletConnect itself is a legitimate connection protocol; the problem isn't the protocol but whether the site you connect to is the one you think it is. A phishing site copies a real site's look, you scan its WalletConnect QR, and the connection genuinely goes through — but it goes through to the scammer's contract, so the approval that pops up next is fed straight to them. Before scanning a WalletConnect QR, confirm the site's URL is really the official one; and if it then asks you to approve a token or sign an unreadable string, stop.

My wallet asks me to sign, and it's free with no gas fee. That's safe, right?

A gas-free signature is exactly the thing that lowers people's guard. Off-chain signatures like permit and Permit2 replace a gas-paying approve transaction, but the effect is the same: you hand over the right to move your tokens, just without paying a fee. So 'no fee means safe' is the wrong test. Read the content: if what you're signing involves a token approval, an allowance, or anything you don't understand, don't sign — it's as dangerous as an approval you'd pay for.

I signed an approval by mistake. What's the first thing to do?

Move fast. First, stop tapping anything and disconnect the site from your wallet so it can't keep throwing pop-ups at you. Then check which approvals this wallet has granted and revoke the suspicious ones one by one — the detailed steps are in our wallet approval review and revoke guide. During this time, if someone messages offering to 'recover' your funds, ignore them; that's almost always a second layer of the scam.

2026-07-12 · Entry created.