Static QR codes never expire

QR & barcode guide

QR Code Payment Safety for Customers and Merchants

A payment QR code is not proof that a payment request is legitimate. Customers should verify the merchant name and amount inside the trusted banking or wallet app before confirming, while merchants should protect printed codes from replacement and rely on real-time account confirmation rather than a customer screenshot.

Updated 2 September 2026 · By EasyQR Kit

Checks customers should make before paying

Open the bank or wallet app yourself instead of installing an app from a QR landing page. After scanning, read the recipient name, merchant identity, amount and transaction details shown by the trusted payment app. Stop if the name is unexpected, the amount changed or the scan opens an unfamiliar website asking for credentials.

Do not let urgency replace verification. The FTC warns that malicious QR codes can lead to phishing pages or malware, especially when received unexpectedly by email, text, packaging or public signage. Navigate through a known official app or website when a message claims an account problem.

Controls merchants should use

Display the business name beside a static payment code and use a tamper-evident holder or an indoor location supervised by staff. Check stickers for overlays at the start of each shift. For a dynamic code produced by a point-of-sale system, confirm that the amount and order reference match the sale before showing it to the customer.

Confirm payment from the merchant's own bank, wallet or POS notification. A screenshot, animation or sound on the customer's phone can be copied or altered. Bank of Thailand guidance for standardized Thai QR payments emphasizes current transaction status, recipient or merchant verification and real-time notification.

Separate general QR generation from payment issuance

A general QR generator can encode text or a URL, but it does not create a registered merchant account, validate ownership of a payment identifier or guarantee that a banking network will accept the payload. Payment QR codes should be obtained through an authorized bank, wallet, acquirer or payment provider that supports the required local standard.

EasyQR Kit should be used for general QR utilities and educational layouts, not as evidence that a payment request is approved. Never place secret keys, account passwords or private customer data inside a normal QR code because anyone with a compatible reader can inspect its contents.

Respond when a code may have been replaced

Stop accepting scans from the affected sign, preserve the suspicious label and compare it with the approved artwork. Contact the bank or payment provider through a known channel, review recent transactions and replace the display only after verifying the destination.

If credentials were entered on a suspicious page, change the password from the official service, enable stronger authentication and report the incident through the relevant financial institution or national fraud-reporting channel. Acting through known contact details is safer than following instructions embedded in the suspicious message.

Payment QR verification responsibilities

Payment QR verification responsibilities
MomentCustomer checkMerchant control
Before scanningUse a trusted banking or wallet appInspect the printed holder for overlays
Before confirmingRead recipient name, amount and detailsEnsure the POS amount and order match
After confirmingKeep the in-app receiptVerify the merchant-side real-time notification
If suspiciousStop and contact the provider directlyDisable the sign and review transactions

Pre-production checklist

  • Verify recipient or merchant name in the trusted app
  • Check the amount before confirmation
  • Never trust a payment screenshot alone
  • Inspect public codes for replacement labels
  • Issue payment codes through an authorized provider
  • Keep sensitive credentials out of ordinary QR codes

Frequently asked questions

Can EasyQR Kit issue an official payment QR code?

No. Official payment issuance and merchant verification must come from an authorized bank, wallet, acquirer or payment provider. EasyQR Kit is a general static QR utility.

Is a QR payment receipt screenshot enough for a merchant?

No. Confirm the transaction in the merchant's own bank, wallet or POS system because screenshots and interface animations can be copied or altered.

What should I check after scanning a payment QR?

Check the recipient or merchant name, amount and transaction details inside the trusted payment app before you authorize the payment.

Continue with related guides

Primary sources

Your privacy, your choice

Essential storage keeps the site working. With your permission, analytics helps us improve tools and advertising keeps them free.