Where the four seconds went
Scanning is fast, and that is the whole attack. Here is what your phone gave you, and where it slipped past.
- 0.0s The camera picks up the code and shows a small grey banner with the destination in it.
- 0.4s You read the first few characters and stop. The banner truncates long addresses, so the part that matters is often the part you never see.
- 1.1s You tap. There is no confirmation step and no way to hover over a QR code the way you would a link in an email.
- 2.6s A page loads over HTTPS with a padlock. The padlock only means the connection is encrypted. Anyone can get one, including whoever printed the sticker.
- 4.0s The page invents a deadline — an expiring session, a fine, a missed delivery — so you type before you think.
Why stickers work so well
Email filters read links. Nobody filters a physical object. A printed square costs nothing, takes two seconds to stick over a real one, and inherits all the trust of whatever it is stuck to — a parking meter, an EV charger, a restaurant table, a parcel locker, a poster in a lobby, a badge at a conference.
And unlike a phishing email, the victim comes to it voluntarily, already intending to pay for something.
What actually helps
- Read the domain from the right-hand end backwards. The last two labels before the first slash are the real owner. Everything to the left of them is decoration the attacker chose.
- Treat any code that asks for payment, login or personal details as untrusted, whatever it is stuck to. Type the address yourself or use the app you already have.
- Feel the edges of the code in the physical world. A sticker over a sticker, a curled corner, a code that doesn't match the printing around it.
- Urgency is the tell that survives every redesign. A countdown on a page you reached by camera is a reason to stop, not to hurry.
- If you did enter card details, call the number on the back of your card — not any number shown on the page you just left.