Resource icon

Reject a Discord login QR code sent by a stranger

Discord's QR login is designed for a code displayed on your own desktop or browser login screen. Your signed-in mobile app scans it, then asks you to approve the new session. A scammer can display their login code in a message and persuade you to scan it, turning your approval into access for their device. Discord says the code expires after two minutes, but that short life does not make an unsolicited code safe. The approval screen is the real security boundary.

Before you start​

If a person claims a QR scan is needed for a giveaway, moderator check, age verification, game reward or support ticket, stop before opening the camera. Verify the request through a separately known server channel or official Discord help page. A genuine login QR is generated by the desktop or browser you are personally trying to sign into, not delivered to you by another user.

Do it step by step​

  1. Look at where the code originated. If it is inside a DM, image attachment, website or shared screen controlled by someone else, do not scan it. A familiar friend's account can also be compromised.
  2. If you accidentally scan it and Discord opens a confirmation screen, choose Cancel. Read the destination and device information shown there; do not approve merely because you recognize the Discord branding.
  3. For a login you initiated yourself, open the Discord app or browser on your own computer and inspect the code there. In the already signed-in mobile app, use User Settings and Scan QR Code as Discord describes. Keep both devices in your possession.
  4. After scanning your own screen, approve only the login you expect. The computer should then show your account. If the code expires, refresh the code on that computer and start again instead of accepting a newly sent image from a stranger.
  5. If you approved a suspicious code, immediately change your Discord password from a trusted device. Discord says changing it logs out all devices. Then review MFA methods and Authorized Apps, and alert friends if the account sent suspicious messages.
  6. Preserve the scam message and report it using Discord's native reporting controls. Do not follow links to a supposed reversal service or share backup codes with a helper.

Check the result​

No unrequested login is approved. A legitimate QR login ends with the intended device signed in, while an accidental scan ends at Cancel. If compromise occurred, the password was changed and account access, apps and contacts were reviewed.

If something goes wrong​

If Cancel does not appear, close the flow without confirming, reopen Discord from its normal icon and check account sessions or security notices. If access is lost, use Discord's official compromised-account path; do not trust recovery offers in DMs. Save evidence before deleting scam messages.

Know the limit​

A QR code can be legitimate for many purposes, but the Discord login approval is specifically an account-access grant. QR expiration does not reverse an approval, and MFA cannot save you if you authorize the attacker's session yourself. Never approve a login you did not initiate on a device you control. Discord QR login and safety
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack