What to Do If a QR Code Asked for a One-Time Code
A one-time code can be the final approval step for a login, account recovery, authenticator enrollment, payment, or device change. Do not type it into a page opened by an unexpected QR code.
If you did not enter the code
- Close the QR page and do not share the code with a person in chat or on the phone.
- Open the account from the official app, bookmark, or typed domain.
- Check recent sign-ins, password reset requests, payments, and device approvals.
- Report the QR code to the business, school, venue, or support team that appears to be copied.
If the page looked like account recovery, compare What to Do If a QR Code Opened a Password Reset Page.
If you entered the one-time code
- Login code: review sessions and sign out unknown devices.
- Password reset code: change the password from the real service and check recovery methods.
- Payment code: contact the bank, card issuer, or payment app tied to the transaction.
- Backup code: generate new backup codes from the official account settings if supported.
For two-factor bypass patterns, read Can a QR Code Bypass Two-Factor Authentication? and I Scanned a QR Code and It Sent Me to a Fake Login Page.
One-time-code red flags
- The QR code appeared on an unexpected sign, flyer, email, invoice, or support page.
- A caller or chat agent asks you to read the code aloud.
- The code message says not to share it, but the page tells you to enter it anyway.
- The domain does not match the company, bank, school, or account provider.
If the QR page tried to add an authenticator or device, see What to Do If a QR Code Opened an Authenticator Enrollment Page.
Frequently asked questions
Is sharing a one-time code after scanning a QR code dangerous?
It can be. A one-time code can approve a sign-in, password reset, device enrollment, payment, or account recovery action. Treat it as sensitive even if the page looks familiar.
What if I only saw the code request but did not enter it?
Close the page and open the account from the official app or typed website. Review sign-in activity if the scan was unexpected, but the risk is lower if you did not submit a code or password.
What if I entered the one-time code?
Open the real account, change the password if needed, review recent sign-ins, remove unknown sessions or devices, and contact the provider if you see activity you do not recognize.
Can QRsafer stop one-time-code scams?
QRsafer helps preview QR destinations before login, payment, account recovery, and device approval pages open.
Preview code-request QR destinations first
QRsafer helps preview QR destinations before login, payment, account recovery, and device approval pages open.
