A “frozen-screen” UPI scam spreads through a deceptive process that tricks users into installing a malicious application. After installation, the app can interfere with the phone screen and use device permissions to monitor user actions, enabling it to misuse UPI access.
According to reporting on the scheme, the malicious app can also abuse accessibility and notification permissions to observe activity and capture one-time passwords (OTPs) used for payment authorisation. With OTPs obtained, fraudsters can complete transactions or gain control in ways that appear legitimate to the user’s device. Sources describe the “glitch” as a technical-sounding cover for the fraudulent activity, rather than a genuine system error.
While outlets differ in how they frame the mechanics—some emphasise the “glitch” narrative and others focus on permission abuse and OTP interception—both point to the same core threat model: a user installs malware, the app requests sensitive permissions, and the malware then enables account draining by capturing authentication data.