Nepal's digital payments revolution is real — QR-code transactions worth hundreds of billions of rupees flow through eSewa, Khalti, and Fonepay every year. But that growth has attracted an equally fast-growing wave of fraud. Scammers have stickered fake QR codes over legitimate merchant displays, impersonated support agents from fintech companies, and drained lakhs of rupees from Nepalis in Kathmandu, Pokhara, Chitwan, and beyond. Before you scan that code on the tea stall counter or the parking meter, read these seven red flags — they could save your money.
How Big Is the Problem?
The Platforms Scammers Exploit Most
How a QR Payment Scam Typically Works
The Setup — Physical or Digital Placement
A scammer places a fake QR sticker over a legitimate merchant's Fonepay/eSewa code, or shares a QR image via WhatsApp, Facebook, or Telegram with an offer too good to be true (huge discounts, free recharges, lottery winnings).
The Scan — Victim Reads the Code
The victim scans the QR code. Instead of routing to a registered merchant account under the NepalQR standard, the code redirects to a phishing site that mirrors the eSewa or Khalti login page exactly.
The Credential Harvest — OTP & PIN Theft
The fake page asks for the victim's wallet PIN or OTP. Scammers send alarming SMS alerts using look-alike shortcodes ("AT Alert", "The Alert") claiming the account will be suspended unless the user verifies immediately.
The Drain — Money Transferred Out
Once the OTP is entered, scammers gain instant access to the wallet and transfer the entire balance. Accounts registered with fake citizenships make recovery nearly impossible through standard channels.
The Disappearance — Untraceable Withdrawal
Funds are quickly withdrawn or transferred through multiple wallet accounts registered using stolen citizenship documents. The Cyber Bureau notes scammers often operate from outside Nepal via Telegram, making tracing extremely difficult.
What to Check Before You Scan Any QR Code
๐ท️ The QR code looks stickered or layered over another code
Legitimate merchant QR codes are printed and laminated by registered acquirers (banks, Fonepay, eSewa Merchant). If you see a QR sticker that appears to be placed on top of another code, or the edges lift at the corners, do not scan it. Scammers physically overlay their own code on merchants' counters — especially on ATMs, fuel stations, and restaurant tables.
๐ช The merchant name shown in your app doesn't match the shop
When you scan a legitimate NepalQR code, your eSewa or Khalti app displays the registered merchant name before you confirm. If the name shown is a random personal name, a number, or an unrelated business, stop immediately and do not proceed with the payment. A local tea stall's QR should show the stall's registered business name — not "Ramesh Kumar" or a blank field.
๐ Scanning opens a browser link instead of your wallet app
A genuine payment QR code opens directly inside your eSewa or Khalti app in payment mode — it does not redirect you to a website. If scanning a code opens a browser and asks you to "log in" or "verify your account," you are on a phishing site. Fraudsters use look-alike domains such as esewa-support.com or khalti.app.login.com — always check the URL bar carefully and close immediately.
๐ You're asked to enter your OTP, PIN, or password
This is the most critical rule: no legitimate QR payment process ever asks for your OTP, PIN, or password. Scanning a merchant QR and entering your amount is all that's required. If any step asks for your credentials after scanning, the process has been compromised. Nepal Rastra Bank has issued repeated public warnings on this. Neither eSewa, Khalti, Fonepay, nor any NRB-licensed institution will ever request your OTP through a QR flow or phone call.
๐ The QR promises a reward, refund, discount, or prize
QR codes that offer instant cashback, surprise gifts, lottery winnings, or exclusive discounts when scanned are a major red flag. Scammers advertise on Facebook, TikTok, and WhatsApp with offers like "Scan this QR and get Rs. 5,000 cashback instantly." Legitimate wallet promotions are always run through the official app interface — never through an external QR code shared on social media.
⏱️ You're being pressured to scan right now
Urgency is a classic manipulation tactic. Phrases like "scan immediately or your account will be blocked," "this offer expires in 2 minutes," or "customs will confiscate the parcel if you don't pay via eSewa now" are all engineered to prevent you from thinking clearly. Legitimate merchants never pressure you to scan quickly. If you feel rushed, walk away — the offer is almost certainly fraudulent.
๐ The QR code is in an unusual location or appears unofficial
Be suspicious of QR codes placed on ATM machines, parking meters, public bulletin boards, inside taxis, or taped to walls in public spaces. Nepal's NepalQR standard requires merchant QR codes to be issued by registered acquirers with the merchant's verified business details embedded in the code. A random QR in an unusual location has not gone through this verification process and should not be trusted.
10 Rules to Never Lose Money to a QR Scam
Always check the merchant name
Before confirming any payment, verify that the merchant name in your app matches the actual business you are paying.
Never share your OTP
No legitimate bank, eSewa, Khalti, or Fonepay agent will ever ask for your OTP, PIN, or password over a call or QR code.
Use only official apps
Download eSewa and Khalti exclusively from the Google Play Store or Apple App Store. Verify the developer name carefully.
Inspect the QR before scanning
Check for signs of tampering — peeling edges, bubbles, or an obvious sticker placed over another code. Ask the merchant to confirm.
Check the URL if a browser opens
The official eSewa domain is esewa.com.np. Khalti is khalti.com. Any variation — especially with extra words or hyphens — is a phishing site.
Enable transaction alerts
Set up SMS alerts for every transaction so you're notified immediately of any unauthorized payment from your wallet or bank account.
Enable two-factor authentication
Turn on 2FA in your eSewa, Khalti, and mobile banking apps. This makes it much harder for scammers to access your account even with your password.
Report immediately if scammed
Contact Nepal Police Cyber Bureau instantly. Time is critical — early reporting can help freeze accounts before funds are withdrawn.
Verify via official channels
If you receive a suspicious call claiming to be from eSewa or Khalti, hang up and call the official number found on the app or website directly.
Educate those around you
Rural and first-time digital payment users are the most vulnerable. Share these red flags with family, neighbors, and your community.
If you've already been scammed: Call Nepal Police Cyber Bureau immediately at 01-4247255 or visit nepalpolice.gov.np. Also notify your bank and digital wallet provider within hours — fast action is your best chance of fund recovery. Under Nepal's Electronic Transaction Act 2063 (ETA), financial cyber fraud is a prosecutable offense with penalties including imprisonment.
⚖️ Legal Protection: What Nepal Law Says About QR Fraud
QR payment scams in Nepal are prosecuted under the Electronic Transaction Act 2063 (ETA) and the Banking Offence Act. Specifically:
- →Section 51 (computer fraud) covers fake QR codes, phishing links, and digital payment deception.
- →Section 47 covers identity impersonation and unauthorized use of personal credentials.
- →The Banking Offence Act applies to fraudulent access of bank and digital wallet accounts.
- →Victims can file complaints at the Nepal Police Cyber Bureau or through the NRB financial fraud reporting system.
- →Scammers using fake citizenships to open wallet accounts face additional charges under the Muluki Criminal Code.
๐ Official Fraud Reporting Contacts
QR Payment Scam FAQs for Nepal
The Bottom Line
Nepal's shift toward digital payments is overwhelmingly positive — QR transactions grew from Rs. 2.5 billion in 2020-21 to hundreds of billions today. But speed of adoption has outpaced digital literacy, and scammers are exploiting that gap aggressively. The good news is that almost every QR payment scam can be stopped before it starts if you know what to look for.
Remember the seven red flags: tampered codes, unknown merchant names, browser redirects, OTP requests, reward promises, urgency pressure, and suspicious QR placement. None of these appear in a legitimate payment flow. If you see even one, walk away.
Share this guide with your family, your community, and especially older relatives or first-time digital payment users — they are the most vulnerable. Nepal's cybercrime complaints have increased six-fold in five years. Awareness is the most effective defense we have.
Discussion