OpenAI 2026 hackathon

fake qr code detector

scan a qr code. show the destination before opening detect suspicious domains warn users about phishing

Team of 4 · 0 likes · 0 comments

Archive position — measured, not model output

0 likes on Devpost

2,264 of the 7,856 archived projects have more likes, and 5,592 share exactly 0 — so this project's #4,043 place in the like-ranked listing is a tie-break inside that group, not a ranking.

Projects (log scale)

1
10
100
1k
10k
05,592
11,758
2285
3–4132
5–975
10+14

Likes on Devpost. ▲ marks this project's group.

Show the figures
LikesProjectsShare of archive
05,59271.2%
11,75822.4%
22853.6%
3–41321.7%
5–9751.0%
10+140.2%
Devpost like counts for all 7,856 archived projects, captured when this archive was built.

Executive Summary

The description states that "Fake QR Code Detector" is a web-based tool designed to scan QR codes and reveal their destination before users click on them, with the goal of preventing phishing and fraud. The author claims it uses browser APIs for camera access and QR decoding, performs local analysis of URLs for risk signals, and stores scan history locally. It was built as part of a hackathon project.

The single most important open question is: What is the actual commercial viability or scalability of this tool beyond a prototype? The description does not provide evidence of any revenue model, customer base, or adoption metrics — only self-reported claims about functionality and future plans.

This analysis is based entirely on the author's own write-up. No third-party verification or historical data exists for this project.

Back to contents

What The Product Actually Is

The description states that "Fake QR Code Detector" is a responsive web application built with HTML, CSS, and JavaScript. It scans QR codes via camera, uploaded image, or pasted link using the browser's MediaDevices API and BarcodeDetector API (with jsQR as fallback). It analyzes decoded URLs locally for risk signals such as insecure HTTP links, IP-address destinations, risky domain endings, phishing keywords, unusually long URLs, and look-alike brand domains. The tool assigns a safety score and displays warnings about suspicious signals.

The product stores scan history and demo reports in the browser using local storage. It includes features like safe domain preview, multi-language safety explanations, and local scam-report counts.

Back to contents

Positioning & Claim Evolution

The description states that the project was inspired by the lack of visibility into QR code destinations, aiming to provide a "simple safety layer" that helps users check QR codes before opening potentially harmful links or phishing websites. The author claims it combines practical QR scanning with understandable scam warnings and look-alike domain detection.

The positioning appears to be as a consumer-facing tool for personal digital safety, particularly in contexts where QR codes are used for payments or sensitive information sharing. The claim evolution shows an intent to expand into community reporting, threat intelligence integration, multilingual voice warnings, and mobile app development.

Back to contents

Target Customer & ICP

The description does not state specific target customers or ideal customer profiles (ICP). It implies a general audience concerned with digital safety and QR code security, particularly those who use QR codes for financial transactions or sensitive data entry. The tool is described as accessible via web browser, suggesting broad accessibility but no defined segment.

Back to contents

Business Model & Pricing Evidence

The description does not provide evidence of any business model or pricing structure. It describes the tool as a prototype built for a hackathon and mentions future plans to add backend features like community reporting and threat-intelligence APIs, but no commercialization strategy is outlined.

Back to contents

Technical & Delivery Signals

The description states that the product was built using HTML, CSS, JavaScript, and browser APIs including MediaDevices API and BarcodeDetector API (with jsQR fallback). It uses rule-based checks for URL analysis and stores data locally in the browser. The team notes challenges with cross-browser camera support and chose local processing over server-side analysis to balance security and privacy.

Back to contents

Traction & Maturity Signals

The description does not provide evidence of traction or maturity beyond a hackathon prototype. There is no mention of users, customers, revenue, or adoption metrics. The project is described as a proof-of-concept with future expansion plans, but no data on usage or impact is included.

Back to contents

Competitive Context

The description does not provide information about competitive landscape or existing solutions in the QR code scanning and phishing detection space. It does not mention competitors or how this tool would differ from them in terms of features or market positioning.

Back to contents

Key Risks & Red Flags

  • The tool is described as a prototype built for a hackathon, with no evidence of commercial viability or scalability.
  • No revenue model, customer base, or traction data are provided.
  • The description implies that the tool only works locally and does not integrate with broader threat intelligence or community reporting systems.
  • The author states they want to add backend features like threat-intelligence APIs and Android app support, suggesting current limitations in functionality.
  • The tool's effectiveness may be limited by its rule-based approach rather than machine learning or AI-driven analysis.

Back to contents

Diligence Questions To Ask The Founders

  1. What is the actual user base or adoption rate for this tool?
  2. How does the local-only analysis approach scale to real-world threats?
  3. What are the specific plans for monetization and commercialization?
  4. How will the tool integrate with existing security infrastructure or platforms?
  5. What are the technical limitations of the current implementation that prevent broader deployment?

Back to contents

Investment/Partnership Verdict

Not evidenced.

The description provides no evidence of revenue, customers, traction, or business model. The project is described as a hackathon prototype with future expansion plans, but no commercial viability or scalability indicators are present. Without data on market demand, user adoption, or financial performance, it's not possible to assess investment or partnership potential. The tool's current functionality appears limited to local analysis and lacks integration with broader threat intelligence systems. Any value proposition beyond the prototype remains unproven.

Back to contents

Source

Submitted to the OpenAI 2026 hackathon on Devpost. Project home on DevPost.

The analysis above was generated by a language model from the project's own one-line description. It is not independent research and contains no verified traction, revenue or customer data.