What to Do If a QR Code Asked for a One-Time Code

A one-time code can be the final approval step for a login, account recovery, authenticator enrollment, payment, or device change. Do not type it into a page opened by an unexpected QR code.

If you did not enter the code

  1. Close the QR page and do not share the code with a person in chat or on the phone.
  2. Open the account from the official app, bookmark, or typed domain.
  3. Check recent sign-ins, password reset requests, payments, and device approvals.
  4. Report the QR code to the business, school, venue, or support team that appears to be copied.

If the page looked like account recovery, compare What to Do If a QR Code Opened a Password Reset Page.

If you entered the one-time code

  • Login code: review sessions and sign out unknown devices.
  • Password reset code: change the password from the real service and check recovery methods.
  • Payment code: contact the bank, card issuer, or payment app tied to the transaction.
  • Backup code: generate new backup codes from the official account settings if supported.

For two-factor bypass patterns, read Can a QR Code Bypass Two-Factor Authentication? and I Scanned a QR Code and It Sent Me to a Fake Login Page.

One-time-code red flags

  • The QR code appeared on an unexpected sign, flyer, email, invoice, or support page.
  • A caller or chat agent asks you to read the code aloud.
  • The code message says not to share it, but the page tells you to enter it anyway.
  • The domain does not match the company, bank, school, or account provider.

If the QR page tried to add an authenticator or device, see What to Do If a QR Code Opened an Authenticator Enrollment Page.

Frequently asked questions

Is sharing a one-time code after scanning a QR code dangerous?

It can be. A one-time code can approve a sign-in, password reset, device enrollment, payment, or account recovery action. Treat it as sensitive even if the page looks familiar.

What if I only saw the code request but did not enter it?

Close the page and open the account from the official app or typed website. Review sign-in activity if the scan was unexpected, but the risk is lower if you did not submit a code or password.

What if I entered the one-time code?

Open the real account, change the password if needed, review recent sign-ins, remove unknown sessions or devices, and contact the provider if you see activity you do not recognize.

Can QRsafer stop one-time-code scams?

QRsafer helps preview QR destinations before login, payment, account recovery, and device approval pages open.

Preview code-request QR destinations first

QRsafer helps preview QR destinations before login, payment, account recovery, and device approval pages open.