Fake bKash Screenshots and Fake TrxIDs: How to Protect Your Shop
A payment screenshot or a typed TrxID is not proof that you were paid. Both can be edited, copied from an old payment or simply invented. The safe rule for online sellers is to confirm every payment on your own phone or wallet app, match the exact amount, and never ship on a screenshot alone.
Why screenshots and typed TrxIDs are weak proof
A screenshot is an image the customer controls. Any picture can be edited with a free app, and a real screenshot from another payment can be reused. A TrxID typed into a chat or form is only text. Neither of them comes from your wallet. What you need is evidence that comes from your own side: the payment SMS on your phone, the transaction history in your wallet app, or your balance.
Common tricks sellers run into
These are generic patterns, not figures. Any shop that takes wallet payments by hand can meet them.
- Edited screenshot: the amount, name or time in a real payment screen is changed before sending it to you.
- Old TrxID reused: the customer gives the TrxID of an earlier, genuine payment, hoping you will not notice it already belongs to another order.
- Wrong amount: the customer pays less than the order total, or pays an older amount, and sends a screenshot that looks fine at a glance.
- Payment to a different number: the money went to a wrong or similar number, and the screenshot shows a successful transfer, just not to you.
- Invented TrxID: a random code that matches no payment at all, offered with confidence and pressure to hurry.
- Pending or failed payment: a screenshot taken before the transfer completed.
Often there is no bad intent. People mistype codes, pay the wrong number or pay late. The checklist below protects you in both cases.
A practical checklist for sellers
- Verify in your own app or SMS. Open your inbox or wallet statement and find the payment yourself.
- Match the exact amount. Close is not enough. A different amount is a different payment.
- Check the time. A payment from last week cannot be this order's payment.
- Allow one TrxID for one order only. Write it next to the order and search for it before you accept a new one.
- Confirm it went to your number. The message should show your wallet receiving it.
- Never trust a screenshot alone. Use it at most as a hint about where to look.
- Use an order reference. Ask customers to type a unique code, such as an order number, in the wallet app's Reference field if it has one, so each payment carries its own label.
- For large orders, check your balance. Do this in the app, not from a message someone forwarded to you.
If the customer is rushing you, that is a reason to slow down, not speed up. A real payment will still be there in ten minutes.
Habits that make your shop a harder target
- Tell customers in advance how you confirm payments, for example 'orders ship after we see the payment in our wallet, not after a screenshot'. A clear rule avoids arguments later.
- Show the exact amount and the wallet number on the order page, so mistakes are less likely.
- Keep a simple list of TrxIDs already used, even a spreadsheet, so a reused code stands out.
- Be extra careful with first-time customers, large orders and items that are hard to take back, such as digital goods or custom work.
How automatic SMS matching helps
Automatic matching applies the same rules without tiredness. With QRPayBD, a payment is confirmed only when a payment SMS actually arrives on your shop's phone and matches the order. The Collector app reads the message, and QRPayBD checks the order reference or the TrxID the customer entered, together with the exact amount. A TrxID can confirm only one order, so a reused code is refused. A wrong amount is not accepted automatically. A made-up TrxID cannot confirm anything, because no message with that code arrives.
The order reference helps in particular. When the customer types the QP-XXXX reference in the wallet's Reference field, it appears in the SMS and the match does not depend on anything the customer types on your site.
The limits: forged SMS and missing messages
SMS confirmation is stronger than a screenshot, but it is not perfect. A forged SMS is possible, because the sender name of a text message can be faked. Real wallet messages usually arrive from a named sender and not from an ordinary phone number, and the Collector app only reads payment-style messages from such senders. Still, do not treat that as a guarantee.
- Messages can be delayed or missed. A payment may be real but not yet confirmed.
- Message wording can change, and a changed format may not be recognised until it is updated.
- The phone must be on and online. If it is off, confirmations wait.
- The message readers for bKash, Nagad and Upay have been verified on real payments; Rocket and banks are planned.
So the rule stays: for large or hard-to-reverse orders, also look at your wallet balance in the app before you hand over goods. QRPayBD is not an official wallet API.
What to do when something does not match
Do not mark the order paid. Tell the customer politely what you see: amount too low, code not found, or payment not yet arrived. Ask them for the exact time and amount, and check again. Payments that QRPayBD cannot match automatically go to an inbox in your dashboard, where you can match them by hand once you have checked the wallet.
Read: what a TrxID is and why it is not proof alone
If you are tired of checking messages by hand, you can try automatic matching free during early access.