Why a QR code deserves a second look
A QR code is just a picture that contains a link or payment string. It does not carry a guarantee, a receipt, or proof that a gaming site is legitimate. Anyone can generate one, print it on a tarpaulin, paste it into a chat, or overlay it on top of a real code at a counter.
In the Philippines, digital payment use has grown quickly, and the Bangko Sentral ng Pilipinas has repeatedly noted that while e-payment adoption is rising, the supported methods, recipients, fees and records of any destination still need to be checked directly. That is the practical principle behind QR verification: the code is only the beginning of the check, not the end of it.
For gaming deposits specifically, the risk is higher because the money leaves your wallet before you can confirm that anything was credited to your account. Once you press confirm and enter your MPIN, the transfer is generally final. Your best protection is a short, consistent routine you repeat every single time.
A simple rule helps: never scan a code you did not expect. Treat an unexpected QR code the same way you would treat an unexpected payment request message.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Step 1: Prepare your phone and wallet before scanning
Most QR mistakes happen before the scan itself, because the phone is not ready and the user is rushing.
Check these items first:
1. Use your own device and your own registered wallet account. Do not scan a deposit code using a friend's phone or a shared device. 2. Open your wallet app from the official app icon, not from a link inside a chat message. 3. Make sure your app is updated through your phone's official app store, and that your phone screen lock and biometric lock are active. 4. Keep your screen brightness moderate. Very dim screens cause failed scans, and repeated failed scans tempt people to accept whatever link pops up. 5. Have a stable mobile data or Wi-Fi connection so the confirmation screen can load fully before you act. 6. Set a personal deposit ceiling for the session before you start, so the amount is a decision you made earlier rather than in the moment.
If your wallet app shows a warning banner, an unusual login prompt, or a request to re-verify your account through a link, stop. Deal with the wallet concern first through the provider's own help center before doing anything related to a gaming deposit.
Never share an OTP, MPIN, or password with anyone who says they are helping you verify a QR code. Legitimate support processes do not require you to read out your one-time code.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Step 2: Read the code before you confirm the payment
Scanning is not confirming. Your wallet app will normally show you a preview screen first. That preview is where the real verification happens.
Check each of the following on the preview screen:
- Payee name. Does the name match what you expect for this deposit? If the app shows only an account number or a masked name, treat that as a reason to pause. - Destination details. Confirm the receiving account belongs to the destination you intended to fund. If the receiving name is unrelated to the site or service you meant to pay, stop and check again. - Amount and currency. Confirm the figure is in Philippine pesos and matches what you intended. A changed amount is a strong signal to cancel. - Fees. If a fee appears, decide whether it is acceptable before you continue. - Reference field. If there is a reference or note field, check that what is typed there matches the instructions on the page you came from. Keep the exact reference for your records. - Device prompt. If the app asks you to confirm on a web page rather than inside the app, be extra careful. A deposit should normally be completed inside the wallet experience you already trust.
If anything looks different from what you expected, cancel the transaction, close the app, and restart the process from the destination's page. Do not accept a 'maybe it's fine' feeling just because the scan succeeded.
The fact that a QR code opens a payment screen only proves the code is readable. It does not prove the recipient is the entity you intended to pay.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Step 3: Confirm the destination before you send
Before a deposit is confirmed, it helps to confirm the destination itself, not only the payment details.
On your mobile browser or app, check where you actually are:
- Read the address bar carefully. Look for the exact domain, including the ending. Misspellings, extra hyphens, and swapped letters are common tricks. - Confirm the connection is secure. A padlock and HTTPS indicate an encrypted connection, but they do not prove the operator is legitimate on their own. - PAGCOR provides a public page where the public can check whether an online gaming site appears on a list of licensed internet gaming platforms. Use it as one reference point, and remember that a listing is a check you perform yourself, not something a QR code or a chat agent can assert for you. - If you arrived at a payment page through a link in a message, close it and navigate to the destination manually the next time. - Keep one bookmarked address for the destination you use, so you are not guessing between similar-looking links.
For a deposit specifically, ask yourself one question: if this money leaves my wallet right now, can I name exactly who receives it? If the answer is vague, do not confirm. Go back and verify the destination first.
This extra minute is the single most useful habit in the whole process.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Step 4: Handle the amount, reference and receipt properly
Once you have decided to proceed, the goal is a clean record you can refer to later.
Before confirming:
1. Re-read the amount one final time and compare it to your planned deposit. 2. Type or verify the reference number exactly as instructed, if the destination uses one. A wrong reference can make your deposit hard to match to your account. 3. Take a screenshot of the preview screen before you enter your MPIN. This is not paranoia; it is your own record of what you approved.
After confirming:
4. Save the confirmation screen and any reference number. Screenshot or note the date, time, amount, payee name, and reference. 5. Check your wallet's transaction history to confirm the entry appears with the details you expect. 6. Check the destination's own deposit or transaction history, if it provides one, and confirm the credit appears with the amount you sent. 7. If the deposit does not appear within the timeframe stated by the destination, contact the destination's support through its own published channel, not through a random number that messaged you first.
Keep these records for at least the duration of the promotion or activity you joined. Disputes are far easier to resolve when you can show exactly what you approved and when.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Red flags that should stop a QR deposit immediately
Some situations are clear enough that the best step is simply to stop.
- The QR code arrived in a private message from someone you do not know, with pressure to pay quickly. - The code was sent as an image file rather than shown on the destination's own page. - The payee name does not match the destination you intended to fund. - The amount or reference in the preview differs from the instructions you were following. - The page or message asks for your OTP, MPIN, or a screenshot of your wallet balance. - A person offers to 'process' your deposit for you, or asks you to send to a personal account instead. - You are told the deposit will not appear unless you pay an additional 'activation' or 'release' amount. - The destination's page shows gambling-style ads or claims that feel exaggerated, such as promises about outcomes. Gambling advertising in the Philippines is subject to review standards that require it to avoid misleading content and target adults only, so overblown claims are a warning sign, not a selling point.
When any of these appear, cancel, close, and start again from a route you trust. If money has already left your wallet and something feels wrong, contact your wallet provider through its official help center and the destination's support right away, and keep all records.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
A short pre-deposit checklist for mobile users
Run through this list before every QR deposit. It takes under a minute once it becomes routine.
- [ ] I opened my wallet app from the official icon, not from a chat link. - [ ] My app is updated and my screen lock is on. - [ ] The QR code came from the destination's own page or app, not a private message. - [ ] I read the payee name and it matches the destination I intended. - [ ] The amount and currency match what I planned to send. - [ ] The reference number, if any, matches the instructions exactly. - [ ] I checked the domain in the address bar, including the ending. - [ ] I reviewed the destination against a public verification reference before paying. - [ ] I saved a screenshot of the preview and the confirmation. - [ ] I will check both the wallet record and the destination record after the deposit. - [ ] No one has asked me for an OTP, MPIN, or password. - [ ] I set my spending and time limits for this session before I started.
If a single box cannot be ticked honestly, the correct action is to pause, not to proceed and hope.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
If something goes wrong after you confirm
Act quickly and keep everything written down.
1. Do not send more money to 'fix' the first deposit. Additional payments made under pressure are a common pattern in deposit disputes. 2. Take screenshots of the destination's page, the payment instructions, your wallet confirmation, and your transaction history entry. 3. Contact your wallet provider through its official help center and report the transaction details. Follow their process for questions about records or unauthorized activity. 4. Contact the destination's published support channel and ask for a written status of your deposit reference. 5. If the destination keeps asking for more verification payments, stop communicating and preserve the conversation as evidence. 6. Report suspicious activity to the appropriate authorities and, for concerns about an online gaming operator's status, use official public verification tools rather than social media claims.
Being calm and organized matters more than being fast. Support teams respond better to clear references, timestamps, and screenshots than to repeated messages without details.
Sources for this section: BSP electronic payments measurement report, GCash official help center, Maya official support, PAGCOR platform verification guidance, PAGCOR and ASC advertising standards
Sources checked
- BSP electronic payments measurement reportChecked 2026-09-12
- GCash official help centerChecked 2026-09-12
- Maya official supportChecked 2026-09-12
- PAGCOR platform verification guidanceChecked 2026-09-09
- PAGCOR and ASC advertising standardsChecked 2026-09-09