Over the past few weeks, readers have sent in a steady stream of questions about a "won a reward" call, a suspicious QR code, or a text message that looked just a little too official. So this post pulls together the most common questions we've received about digital payment safety in Nepal, answered plainly, with real reporting steps — not just a generic "be careful online."
Reader Q&A
No — and this is, by a wide margin, the most common scam pattern reported in Nepal right now. This exact script has appeared in real, documented cases: a caller identifies themselves as an eSewa or Khalti representative, announces a surprise reward, then asks the victim to read out an OTP that arrives moments later — an OTP that is actually authorizing a transaction out of the victim's own account, not "releasing a reward" into it. In one widely reported case, a victim in Solukhumbu lost roughly Rs 2.4 million this way after sharing a single OTP. eSewa, Khalti, and every legitimate bank in Nepal will never call you asking for your OTP, PIN, or password — full stop. If a call like this happens, hang up immediately.
Never scan a QR code from someone who says it will send you money — that's backwards from how QR payments actually work. Scanning a "receive money" QR code from a scammer typically opens a payment confirmation screen that sends money out of your account, not into it, and in the moment of confusion or excitement, many people confirm the transaction without reading it carefully. The only safe rule: only scan a QR code when you are the one paying for something, and always double-check the merchant name and amount shown on your screen before confirming.
Two different tricks are at play here, and both have been documented by Nepal's Cyber Bureau. On calls, scammers can set a misleading name on caller-ID apps like Truecaller — since you likely don't have the fraudster's real number saved, the fake display name is what shows up, creating false trust. On SMS, a technique called sender-ID spoofing lets a fraudulent message carry the same alphanumeric sender name — like "eSewa-Alert" or a bank's short code — that legitimate messages use, so the fake text can even land in the same conversation thread as real ones on your phone. Neither trick is something you can spot from the caller ID or sender name alone — the only reliable defense is to never act on urgent instructions from an inbound call or text, and instead verify independently through the official app or a number you look up yourself.
The scam script varies, but the tell is almost always the same: urgency plus a request for your OTP.
Treat any unsolicited message with a link and an urgency trigger — "your account will be suspended," "suspicious activity detected," "verify now" — as suspicious by default, regardless of how official the sender name looks. Nepal's Cyber Bureau has specifically flagged cases where fraudulent messages misused emergency-style alert codes to appear more credible, and some phishing sites are sophisticated enough to capture your password, trigger a real OTP on the legitimate platform in the background, and then harvest that OTP too when you enter it on the fake page — completing a full account takeover without ever calling you. The safest habit is simple: never tap a link in an unexpected SMS. Open the official app directly, or type the known website address yourself, to check your account status.
Be very cautious. Nepal's Cyber Bureau has specifically traced a rising wave of phishing links — often shared through WhatsApp and disguised as helpful financial tools — that lead to malicious installer files (.apk for phones, .exe for computers). Once installed, these can give an attacker full access to your device, including anything typed into your banking or wallet apps afterward. Only install financial apps from the official Google Play Store or Apple App Store, never from a link sent directly to you, and be skeptical of any "app" that arrives via a messaging platform rather than an app store search.
Nepal Rastra Bank has set specific ceilings on digital wallet transactions, partly as a consumer-protection measure that caps how much damage a single compromised account can suffer. As currently structured, transfers from a bank account into a wallet are capped at Rs 200,000 per day and Rs 1,000,000 per month; wallet-to-bank transfers follow the same daily and monthly caps; wallet-to-wallet transfers are capped lower, at Rs 50,000 daily and Rs 500,000 monthly; and a wallet's maximum balance at any time is capped at Rs 50,000. Beyond fraud protection, these limits also serve broader anti-money-laundering and financial transparency goals. Practically speaking, they mean that even in a worst-case scam scenario, the amount exposed in a single wallet is inherently bounded — one more reason to treat your bank account (which doesn't carry the same low balance cap) with even more caution around OTP-sharing than your wallet.
Move fast — speed genuinely affects recovery chances. Immediately open your wallet or banking app and change your PIN and password. Check your recent transaction history and screenshot anything unauthorized. Call your wallet or bank's official support line directly — for eSewa, that's 01-5970016 — and report the fraudulent transaction along with any transaction IDs, so they can attempt to flag the receiving account. Do not call back any number that contacted you first; always use the number printed on your card or listed on the provider's official website. Then file a complaint with the Nepal Police Cyber Bureau as soon as possible, since a fast report meaningfully improves the odds of freezing funds before they're moved further.
You can file a complaint directly with the Nepal Police Cyber Bureau, either in person at their office in Bhotahity, Kathmandu, or through nepalpolice.gov.np, and separately report the specific fraudulent transaction to your wallet or bank's fraud line. It's worth knowing the scale of what the Bureau is currently handling: in a recent fiscal year, it received over 13,000 cybercrime complaints in total, with several hundred specifically involving eSewa, Khalti, or bank account fraud. Investigators have acknowledged that tracing funds is genuinely difficult when scammers operate from abroad, but they've had more success identifying and prosecuting Nepal-based individuals who rent out their own bank accounts to receive stolen funds — which is itself a crime, not just a facilitation service, so never lend your account to someone else's transaction for a fee.
The wallets and the underlying payment infrastructure — NepalQR, Fonepay, connectIPS — are built on legitimate, regulated technical standards, and the vast majority of digital payments in Nepal complete without incident. The risk isn't in the technology itself; it's almost entirely in social engineering — tricking a person into voluntarily handing over an OTP or PIN, which no amount of platform-side security can fully prevent if the account holder gives the key away themselves. That's genuinely good news in one sense: it means the single habit of never sharing an OTP or PIN with anyone, for any reason, closes off the overwhelming majority of the fraud patterns currently circulating in Nepal.
Treat any inbound call, SMS, or QR code that creates urgency and asks you to act immediately as a red flag by default — reward notifications, account-suspension warnings, "verify now" links, "scan to receive" QR codes. Legitimate institutions overwhelmingly communicate through their official app, not through a surprise phone call demanding your OTP in the next sixty seconds. When in doubt, hang up, close the message, and go check directly in the app yourself.
Save these numbers: Nepal Police Cyber Bureau — report via nepalpolice.gov.np or visit their Bhotahity office in Kathmandu. eSewa fraud support — 01-5970016. For Khalti, IME Pay, or your bank, use the number printed on your card or listed on their official website — never a number given to you over an unexpected call.
๐ก The pattern behind nearly every scam
Almost every documented digital payment scam in Nepal — the reward call, the fake SMS, the "scan to receive" QR — follows the same underlying structure: create urgency, impersonate a trusted brand, and get you to hand over an OTP or click a link before you've had time to think it through. Recognizing that pattern matters more than memorizing every specific scam script, because new variations appear constantly while the underlying trick stays the same.
Final Thoughts
None of this means digital payments in Nepal are inherently risky — millions of transactions complete safely every day across eSewa, Khalti, connectIPS, and bank apps. What these reader questions really point to is how consistently the same handful of social-engineering tricks keep working, simply because they exploit trust and urgency rather than any technical weakness in the platforms themselves. Keep the OTP rule in your back pocket, verify independently rather than reacting to an inbound call or text, and share this post with the person in your life most likely to pick up an unexpected "you've won a reward" call.
Discussion