It’s a reasonable thing to wonder about. QR codes look like black-and-white noise — how do you know what’s actually encoded in one? Could someone tamper with it? Could a bug in the app redirect your customer’s payment to a different wallet?
These are good questions, and the answers are reassuring. Here’s exactly how OrangeTill’s QR codes work — from the moment you tap “Generate” to the moment a payment lands in your wallet.
What a QR code actually is
A QR code is not a link to a server. It’s not a live request that gets processed somewhere in the cloud. It’s simply a visual encoding of a text string — like a barcode, but two-dimensional and capable of holding more information.
When OrangeTill generates a Bitcoin QR code for a $10.00 payment, the QR code encodes a string that looks exactly like this:
bitcoin:bc1qYOURADDRESS?amount=0.00014165
This is called a BIP21 payment URI — a standard format that every Bitcoin wallet app understands. It tells the customer’s wallet: here is the address to send to, here is the amount. The customer’s wallet reads it, pre-fills the send screen, and the customer confirms.
For Ethereum and other coins, similar URI standards exist. For Lightning Network, the Lightning address or LNURL is encoded directly. All of them follow open, publicly documented standards.
Where does the address in the QR code come from?
This is the most important part. The wallet address encoded in every OrangeTill QR code comes from one place only: your Settings.
When you save your wallet address in OrangeTill Settings, it is stored locally on your device — in your browser’s localStorage, which is private to your device and your account. When you tap “Generate QR Code,” OrangeTill reads that saved address and encodes it directly into the QR image. The entire process happens on your device. No address travels to a server to be “processed” or “approved.” No third party touches it.
There is no OrangeTill wallet that sits between you and your customer. There is no address substitution. What you saved is what gets encoded. What gets encoded is what the customer’s wallet sees. What the customer’s wallet sees is where the payment goes.
Can the QR code be tampered with?
For a QR code generated by OrangeTill to contain the wrong address, one of the following would have to be true:
- You saved the wrong address in Settings. This is the most common real-world cause of payment errors. Always double-check your wallet address when setting up OrangeTill — paste it directly from your wallet app rather than typing it manually.
- Someone with physical access to your logged-in device changed your Settings. OrangeTill requires login — but if someone had your unlocked device in their hands and knew what they were doing, they could theoretically change the wallet address. This is a general device security concern, not specific to OrangeTill. Lock your device when not in use.
- Your device was compromised by malware that modified the app’s code. This is a very serious, very rare scenario that would affect far more than OrangeTill. Keep your device updated and avoid installing software from untrusted sources.
What cannot happen: a random person intercepts the QR code generation process and substitutes their address. There is no network request during QR generation that could be intercepted. The code is built entirely on your device from your locally stored data.
How to verify a QR code yourself
You don’t have to take our word for it. You can verify exactly what any QR code encodes using any free QR scanner app — just point it at the code and read the text. It will show you the exact URI that the customer’s wallet will receive.
For extra confidence when setting up OrangeTill for the first time:
- Save your wallet address in Settings
- Generate a test QR code for a small amount — $0.01 works
- Scan the QR code yourself with a separate QR reader app
- Confirm the address in the decoded text matches your wallet address exactly
If it matches — and it will — you have independently verified that OrangeTill is encoding your address correctly. This one-time check takes about 60 seconds and gives you complete confidence going forward.
What about QR code scams in general?
QR code fraud does exist in the wild — but it works very differently from what most people imagine. The common attack is called QR code replacement: a bad actor physically sticks a printed QR code sticker over a legitimate one in a public place — a parking meter, a restaurant table, a poster. The fake QR code points to a phishing site or a fraudulent wallet address.
This has nothing to do with the software generating the QR code — it’s a physical attack on a printed or displayed code. The defense is the same as it is for OrangeTill: look at the wallet address displayed alongside the code. If the address is visible and matches what you expect, the code is legitimate.
For OrangeTill specifically, this attack vector doesn’t apply because:
- The QR code is generated live on screen every time — it’s not a printed static image that can be covered
- The wallet address is always displayed as readable text alongside the QR code
- The merchant controls the screen — the customer is scanning from the merchant’s device
“The address is always visible. If it looks right, it is right.”
The bottom line
OrangeTill QR codes are generated locally on your device, from your saved wallet address, with no server in the middle. The address encoded in the QR code is the address in your Settings — nothing more, nothing less. The wallet address is always displayed in plain text alongside the code so you and your customer can verify it at a glance.
The risk of an erroneous QR code is not zero — but the risks that exist are the same ones that apply to any digital tool: saving the wrong address in the first place, or having a compromised device. Both of those risks are fully within your control, and both have simple mitigations.
Common questions
Simple, transparent, secure.
OrangeTill never touches your funds. Your wallet address, your Bitcoin, your business.
Try OrangeTill Free →