Do Not Scan That WhatsApp QR Code

A QR code can look like an ordinary shortcut to vote for someone, claim a promotion or open a WhatsApp link. But a malicious code can instead connect another device to your WhatsApp account or redirect you to a convincing phishing page. Before scanning, make sure you understand exactly what the code is asking you to open or authorise.

Do not scan a WhatsApp-related QR code simply because someone you know sent it.

Before scanning, ask:

  • Why am I being asked to scan this?
  • Am I deliberately trying to connect WhatsApp to my own computer, tablet or second device?
  • Did I reach this screen through WhatsApp's official Linked Devices feature?
  • Is somebody promising a prize, vote, verification, job or giveaway in exchange for scanning?
  • Is WhatsApp showing a warning about an unfamiliar device or location?
  • If the QR code opens a website, does the web address actually belong to the organisation it claims to represent?

Meta confirmed in March 2026 that scammers have been trying to trick WhatsApp users into scanning QR codes that link the victim's account to the scammer's device. WhatsApp consequently introduced additional warnings when its systems detect suspicious device-linking activity.

Verification: Meta's official explanation of WhatsApp device-linking scams

A QR code is not automatically dangerous

QR codes are everywhere. Restaurants use them for menus. Airlines use them for boarding passes. Event organisers use them for tickets. Shops use them for payments. WhatsApp itself legitimately uses QR codes to connect your account to additional devices.

The technology is not the problem.

A QR code is essentially a machine-readable way of telling your phone to perform an action or open information.

The danger is that you cannot easily see what that action is just by looking at the black-and-white squares.

A familiar-looking QR code could direct you to a legitimate website.

Another could open a fake login page.

And in the specific case of WhatsApp, a QR code shown during the device-linking process can authorise another device to use your account.

That is why the question should never be: “Does this QR code look genuine?”

Most QR codes look virtually identical.

Ask instead: “What will happen after I scan it?”

The WhatsApp trick users need to understand

whatsapp
whatsapp

WhatsApp legitimately allows one account to work across additional devices.

According to WhatsApp's official guidance, users can connect compatible additional devices to their primary account through the Linked Devices feature. The QR code displayed on the device being added is scanned using WhatsApp on the primary phone.

That is useful when you are connecting your laptop or tablet. The security problem begins when somebody persuades you to perform essentially the same approval for a device that is not yours.

Meta says scammers have used false stories to persuade people to scan a QR code or approve a device-linking code. One example involves fake competitions asking people to vote before guiding them towards a linking process. Once an unauthorised device is successfully linked, the scammer may be able to use your WhatsApp account from that device. And because your primary phone can continue working normally, you may not immediately realise what has happened.

TechView takeaway: If you are not intentionally connecting your own computer, tablet or second device to WhatsApp, there is usually no reason for somebody else to instruct you to use Linked Devices.

The scam may come from somebody you trust

This is what makes messaging scams particularly effective. A strange message from an unknown international number is easy to question. A request apparently coming from:

  • Your friend
  • A family member
  • Your church or community group
  • A colleague
  • Your school's WhatsApp group
  • A business you regularly deal with

Feels safer. But the sender's account may itself have been compromised. A scammer who gains access to one account can use the victim's existing relationships to approach other people. The message may say something simple:

“Please vote for me.”

“Can you help my niece win this competition?”

“Scan this to join the group.”

“Your account needs verification.”

The story can change. The underlying principle does not:

Trust the action not merely the name appearing above the message, If a request is unusual, confirm it with the person through another channel before proceeding.

WhatsApp is now warning users about suspicious linking attempts

The problem has become significant enough for WhatsApp to add another protective layer. In March 2026, Meta announced that WhatsApp would show warnings when behavioural signals suggest a device-linking request could be suspicious. The warning can provide additional information about where the linking request is coming from and encourage the user to reconsider before approving it.

That is useful. But it should not become another button people tap without reading. If WhatsApp suddenly warns you while somebody is telling you: “Just ignore that and continue,” stop. The warning is there for a reason. No legitimate friend, employer, school, competition organiser or customer-support representative should need you to bypass a security warning so they can access something.

There is another QR-code danger: phishing

Not every malicious QR code is trying to link a WhatsApp device. Some work like ordinary phishing links. The US Federal Trade Commission has warned that fraudulent QR codes can direct people to spoofed websites designed to steal usernames, passwords or financial information. Some malicious QR-code campaigns may also attempt to deliver harmful software.

Verification: FTC guidance on malicious QR codes

This means you need to distinguish two situations.

A WhatsApp device-linking QR code: Scanning it may authorise another device to use your WhatsApp account.

A web QR code: Scanning it may open a website, including potentially a fake one.

In both cases, the safest habit is the same: Do not rush.

Nigeria is not outside the phishing problem

Nigeria's national Computer Emergency Response Team has repeatedly warned about phishing activity targeting Nigerian internet users. In January 2025, ngCERT specifically identified WhatsApp, email, SMS and other social platforms as channels being used to distribute fraudulent messages designed to steal personal information and financial details. It warned that successful phishing attacks could result in account compromise, identity theft, financial loss and reputational damage. In April 2026, ngCERT again warned about escalating cybersecurity incidents affecting Nigerian organisations, with phishing among the major attack methods being observed.

The practical implication is simple. A QR code circulating through a Nigerian WhatsApp group deserves the same caution as a suspicious link received anywhere else.

Check these things before scanning

1. Ask why a QR code is necessary

If somebody says you need to scan a code to vote, claim a reward or verify your WhatsApp account, question the process. Do not allow urgency to replace common sense.

2. Know which device you are linking

A legitimate WhatsApp linking process should involve a device you recognise and intend to use. If you cannot identify the device being added, cancel.

3. Read every WhatsApp warning

Do not let another person coach you through a warning screen. Read it yourself.

4. Preview web addresses

Many phones show the destination before opening a QR-code web link. Look carefully for misspellings, unusual domains or web addresses that have nothing to do with the organisation supposedly contacting you. The FTC specifically recommends inspecting URLs before opening unexpected QR-code links.

5. Verify unusual requests separately

If your friend sends an unexpected QR code, call them. If a bank supposedly sends one, use the bank's official app or contact details you already trust. Do not use the suspicious message itself as proof that the suspicious message is genuine.

What if you already scanned it?

Do not panic but do check what happened. If the QR code was connected to WhatsApp device linking, inspect your linked devices immediately.

On Android, WhatsApp's official guidance directs users through the menu to Linked devices. On iPhone, it is available through WhatsApp Settings → Linked Devices.

Look through the devices associated with your account. If you see one you do not recognise, log it out. Then review recent conversations for messages you did not send, particularly requests for money, verification codes or suspicious links. If you entered a password into a website after scanning a QR code, change that password through the genuine service and enable multi-factor authentication where available. If financial details were entered, contact the relevant bank or payment provider using official contact information. And if suspicious messages were sent from your WhatsApp account, tell your contacts quickly so they do not trust those messages.

Turn on WhatsApp two-step verification

WhatsApp provides an optional two-step verification feature that adds a personalised PIN to the account-registration process. WhatsApp's official instructions place the option under:

Settings → Account → Two-step verification → Enable.

Users can also add an email address for PIN recovery.

Verification:

Two-step verification does not mean you can safely approve suspicious linking requests. Think of it as another layer not permission to become less careful.

High-risk users have another option

In January 2026, WhatsApp introduced Strict Account Settings, a lockdown-style security mode aimed particularly at people who may face sophisticated attacks, including journalists and public figures. Meta says the feature can apply more restrictive protections, including blocking some attachments from unknown senders and silencing calls from unfamiliar numbers. It is available through WhatsApp Settings → Privacy → Advanced where supported.

Verification: Meta's Strict Account Settings announcement

Most ordinary users may never need the strongest mode, but people managing public-facing accounts or dealing with persistent targeting should know it exists.

Our Recommendation

The most dangerous thing about a malicious QR code is how ordinary it looks. There may be no misspelled link to notice. No suspicious attachment. No complicated technical trick. Just a square image and somebody saying: “Scan this.” That simplicity is exactly why you should slow down.

WhatsApp's own 2026 anti scam update confirms that criminals have attempted to exploit device linking by persuading victims to scan QR codes under false pretences. So remember one rule: If you are scanning a WhatsApp device-linking QR code, you should know exactly which device you are adding and it should be yours. For every other QR code, know where it came from and preview where it is taking you.

A five-second check may feel inconvenient. Recovering a compromised account, explaining fake messages to your contacts or dealing with stolen financial information is considerably more inconvenient. Do not scan first and investigate later. Check first. Then scan.

Sources & Verification

Meta's official explanation of WhatsApp device-linking scams

FTC guidance on malicious QR codes

Read ngCERT's phishing advisory for Nigerian users

WhatsApp's official two-step verification guide

Meta's Strict Account Settings announcement

Frequently asked questions

Can a QR code install malware by itself?

A QR code usually opens a link or begins an action; the risk depends on what you are directed to approve, download or share.

What if I already approved the link?

Open Linked devices, remove the unknown session, secure the account and contact official support if access has changed.

Should I pay someone to recover my account?

Be wary of unofficial recovery agents. Use the platform’s official recovery process.

Reader discussion

Leave a comment

Comments cannot be edited or deleted after posting. Please review your comment before submitting.

No comments yet. Start the conversation.

Found an error, outdated step or safety concern? Contact the desk.