Simple Base SwapSimple Base SwapOpen app
← All articles
Sep 13, 2026·5 min read

QR Codes in Crypto: What They Encode and How to Scan Them Safely

basewallet-safetysecurity
base

Scan a QR code to receive a payment. Scan a QR code to connect your wallet to a website. Scan a QR code someone shows you at a meetup to trade contact details. QR codes are everywhere in crypto because they turn a long, error prone string of characters into something a camera can read in an instant. That convenience is exactly why it is worth understanding what a QR code actually contains before you point your camera at one.

A QR code is just a container

A QR code is not magic and it is not inherently tied to crypto at all. It is a way of encoding text as a small grid of black and white squares that a camera and some software can decode back into the original text. Whether that text is a website address, a phone number, or a wallet address is entirely up to whoever generated the code. Your phone's camera or your wallet app reads the pattern, converts it back to text, and then decides what to do with that text based on its format.

This matters because scanning a QR code is not an action with a single predictable outcome. It is more like pasting a string of text that you cannot read in advance. The QR code itself is neutral. What it decodes into, and what your app does with that result, is what determines whether scanning it is safe.

What a wallet QR code usually contains

In most self custody wallets, including on Base, QR codes you encounter fall into a few common categories.

A plain address. The simplest case is a QR code that decodes to nothing more than a wallet address, the same 0x string you would otherwise copy and paste. Scanning one just fills in the recipient field for you. This is the lowest risk case, since all it does is save you from typing or copying a long string, and a good wallet will still show you the full address to confirm before you send anything.

A payment request. Many wallets support a standardized format called ERC-681, sometimes referred to by its earlier name EIP-681, which encodes not just an address but also details like the amount, the token, and which network the payment is meant for. A merchant checkout screen or a payment request page often uses this format so that scanning the code pre-fills the entire transaction rather than just the address. This is convenient, but it also means the QR code is now dictating more of what your wallet is about to do, so the confirmation screen deserves an extra look.

A connection request. Some QR codes are not about payments at all. Protocols like WalletConnect use a QR code to pair your wallet with a website or app running on a different device, for example scanning a code on your laptop screen with your phone's wallet. This kind of code establishes a session that can request signatures and transactions afterward, so it is worth reading the earlier discussion of WalletConnect pairing and session review if this is new to you.

Where the risk actually comes from

The QR code format itself is not the vulnerability. The risk comes from where the code came from and what you assume it means without checking.

A few patterns show up repeatedly:

  • Swapped payment codes. At in person events, printed QR codes on stickers or signs have occasionally been swapped or covered by an attacker's own sticker, redirecting scans to an address the attacker controls. This is the QR equivalent of a skimmer placed over a card reader.
  • QR codes sent through chat or social media. A QR code shared in a direct message or a comment is just as easy to fake as a typed address, and arguably easier to trust blindly, since most people do not double check a decoded address the way they would double check typed text. Treat an unsolicited QR code from a stranger the same way you would treat an unsolicited link.
  • Fake connection prompts. A malicious website can display a QR code that looks like a normal WalletConnect pairing request but is actually designed to trigger a signature request for something harmful once paired. The code itself connects fine. The danger is in what gets requested after that connection is live.
  • Screenshots and image uploads. Some wallets let you scan a QR code from a saved image instead of your live camera. This is useful for scanning a code sent as a file, but it also means you should be just as careful about the source of that image as you would be about a link in the same message.

How to scan without giving up control

None of this means QR codes should be avoided. It means the same habits that apply to typed addresses and links apply here too.

Always read your wallet's confirmation screen after scanning, not before. A decoded QR code should show you the resulting address, amount, and network in plain text, and that screen is your real chance to catch a problem. If your wallet jumps straight to a signature request without a clear summary of what was decoded, that is worth treating as a red flag on its own.

For anything involving meaningful value, especially at a physical location like a store, ATM, or event booth, glance at whether a printed code looks tampered with, such as a sticker on top of a sticker, before scanning it. When in doubt, ask the recipient to read the address aloud from their own screen so you can compare it to what your wallet decoded.

Treat a QR code from an unknown sender exactly like you would treat an unknown link: something to verify through a second channel before acting on it, not something to trust because it happens to be a picture instead of text. The format changed, but the underlying rule from earlier in self custody has not: your wallet's confirmation screen is the last line of defense, and it is only useful if you actually read it.

Ready to try it yourself?

Create a non-custodial wallet on Base in seconds. No account, no sign-up.

Open the web app