
The image above was captured mid-stream on YouTube, where a sports broadcast gave way to what looked like a presidential address and a banner telling viewers to “scan or regret.” Whether footage like this is fully synthetic or real footage with a cloned voice, the goal is the same: get you to pick up your phone and scan before you think.
Streams like this are cheap to make, quick to relaunch and close to impossible to enforce against. Here is how the scam works, what responsible QR design looks like, and how to spot the fake behind it.
Why the QR code is the scammer’s favorite link
A QR code is a link you cannot read, which is why the US Federal Trade Commission has warned consumers that scammers hide harmful links inside them. Three properties do most of the work:
You can’t inspect it. There is no hover and no visible URL, and email filters that check text links often miss one hidden in an image.
It moves you to your phone. The stream plays on a TV, but the scan happens where your wallet lives, behind a small screen and a truncated address bar.
It borrows authority, and enforcement lags. A code on a broadcast looks official. Channels get renamed, domains rotate within hours, and the stream is gone before a report is read.
What happens after the scan
Most funnels end one of three ways: a “send to receive” giveaway that never sends anything back, a wallet drainer that gets you to sign an approval letting its contract move your tokens, or a fake support form that asks for your seed phrase. On-chain transfers are final, so there is no chargeback.
No public figure, exchange or protocol will ever ask you to scan, connect and sign to receive free crypto. That request is the scam, whatever face is attached to it.
QR codes are not the problem
QR codes are genuinely useful. They carry boarding passes and menus, and in crypto, scanning an address is safer than typing one, because a single wrong character can lose funds for good. A QR code is just a container for a web address. The risk lives in where it sends you and what that page asks you to do.
A responsibly designed QR code points to a domain you can verify and asks for nothing that can move your money on its own.
How we use QR codes at Soulbound Finance
Soulbound Finance uses QR codes in two places, and both follow one rule: no QR code we generate leads to a wallet connection, a signature, a token approval or an on-chain transaction. Both open one page on our own domain, soulbound.finance/redeem.
Transfer cards. A member can download a Soulbound Transfer as a card for offline delivery or secure messaging. Its QR code opens the redemption page with the code filled in, so treat the card like a password. Redeeming needs no wallet, account or gas, and the page warns that redemption is irreversible before anything is submitted. Getting Started walks through it.
Request pages. Members publish request pages to collect Soulbound Transfers for a charity, a personal cause or a pooled purchase, like our launch Mission 22 page. The request QR prefills the destination address, and the donor types it again before redeeming. The page is built to resist abuse:
Published and frozen. Each page shows the Soulbound ID that published it, and its title, address and links can’t be edited, so nobody can earn trust and then swap the address.
Recorded at publication. An ENS name or wallet-linked domain is stored with the address it resolved to and when, and social links are validated against their platforms.
Cancelled, never erased. Cancelling removes the QR code and stops new transfers, but the page stays public as a permanent record.
Contract addresses sit in the footer of every page, verified on Arbiscan, with the protocol source on GitHub. More in our Security and Privacy Overview.
What design can’t do. Immutability proves a page hasn’t changed, not that its creator is the organization named on it, so confirm the address on the organization’s own site first. And because our redemption page asks for a code, a copycat would want exactly that. If a scan opens anything other than soulbound.finance/redeem, or any page asks you to connect a wallet to redeem a Soulbound Transfer, close it.
Spotting deepfakes, and why the tells won’t last
Today’s fakes still leave marks, and knowing them buys you time:
Video: lips out of sync on “p” and “b” sounds, hands that loop or stay out of frame, hairlines that shimmer, set pieces that look cloned, and a “live” stream with comments off and a QR code pinned the whole time.
Audio: flat pitch and pace, no breaths or mouth sounds, an even metronome rhythm, and a studio-clean voice in a room that should echo.
Those tells fade with every model release, which makes detection an arms race defenders can’t win. Our VoiceKey research at the AI Integrity Alliance flips the question: instead of hunting for what AI adds, it measures what only biology produces. A human voice carries micro-tremors and chaotic variation that a smooth generator can’t reproduce, however much noise is layered on top.
Our open-source proof of concept measures two complexity statistics, Higuchi fractal dimension and detrended fluctuation analysis. Synthetic voices scored higher on both, meaning more self-similar and more predictable than real speech. Human voices were messier, and the mess is the signal. The sample is small and the work is early, so the code is MIT-licensed for others to test and try to break.
The durable defense isn’t spotting the fake. It’s never letting a video be what authorizes you to move money. Go to the official site or verified account directly, never through anything shown in the stream.
The five-second checklist
Before you scan: free crypto from a public figure is always a scam, and “scan or regret” urgency is pressure, not information.
Before you open: read the full domain in the preview, and skip anything you can’t confirm from an independent source.
Before you connect or sign: never enter a seed phrase, reject any signature you can’t read, and keep savings in a wallet that never touches new sites.
If it already happened: revoke token approvals, move what’s left to a new wallet, and report the stream, the domain and the loss.
The one-sentence test
Any platform that puts a QR code in front of you should be able to say in one sentence what that code can and cannot do.
Ours opens soulbound.finance/redeem and nothing else, and nothing moves until a person has checked the address and confirmed.
Further reading: Getting Started with Soulbound Finance, Security and Privacy Overview, Where Privacy Actually Lives and VoiceKey: Proving You’re Human.
Spotted a scam using our name? Report it to security@soulboundsecurity.io.
Soulbound Security is a blockchain security and technology company. The AI Integrity Alliance builds open-source verification infrastructure for trustworthy AI and proof of humanity.





