TL;DR
- Fake IRS crypto letters use QR codes to direct recipients to a fraudulent compliance portal that collects wallet and account details.
- The site gathers information such as exchange, estimated holdings, and phone number, which may support later social engineering attempts.
- IRS correspondence about crypto has become more common, making convincing fake notices harder to distinguish, while the scale and impact of this campaign remain unknown.
The IRS Criminal Investigation division warned on July 30 that fraudsters are mailing official-looking letters to cryptocurrency holders. The notices use a QR code to direct recipients to a fake “Digital Asset Compliance Portal.”
The fake IRS crypto letters mirror common phishing campaigns but use physical mail to add credibility. A convincing envelope and tax-notice format can make the request feel more legitimate than an unexpected email. The IRS says it is not an official portal and taxpayers do not need to register wallets or exchanges through it.
Coinbase Security and threat-intelligence firm DarkTower traced the mechanics of the campaign which gathers information that may support later social engineering attempts, like basic account details and phone numbers. The number of letters sent, and whether there are confirmed victims or losses, remains unknown.
The letter sends recipients to a look-alike site
The mailed notice copies elements of genuine government correspondence. These include Treasury and IRS references, a notice number and an urgent deadline. Its QR code points away from IRS.gov to a domain that resembles an official compliance service.
After a recipient scans the code, the site asks which exchange or wallet holds the person’s cryptocurrency. It lists both hardware wallets and major trading platforms. Next, it asks for an estimated account value which allows the operator to identify higher-value targets.
The site then signals a “platform approval” hand-off before requesting a phone number under a verification step. According to Coinbase and DarkTower, this prepares a possible follow-up call. The caller may pretend to represent the IRS, an exchange or a compliance service.
>>> Read more: Ledger and Trezor Seed Phrase Mail Scam
The potential phone call is where theft could occur
According to Coinbase and DarkTower, the phone-based step remains unconfirmed, as testing the flow caused the site to go dark after entering a number, leaving open whether a call follows or the number is stored for later use. If a call does occur, it would likely mirror common social engineering patterns. During such contact, a fraudster may seek an account password or a two-factor authentication code, or request a wallet recovery phrase, each of which can provide a route to an exchange account or self-custodied funds.
A caller may also instruct the recipient to transfer cryptocurrency to a “safe” wallet, which would send assets to an address controlled by the scammer. Even if the timing and trigger of any call remain unclear, these requests are key warning signs. A legitimate agency or exchange will not ask for credentials, recovery phrases, or transfers during an unsolicited call.
Coinbase said DarkTower traced the campaign domain to a Hong Kong registrar. Someone registered it shortly before the letters went out. The site used Romanian hosting infrastructure associated with other phishing pages. However, those technical locations do not establish the operators’ identities or nationality.
A paper notice can be real, but this portal is not
The IRS does send legitimate notices by mail, so a paper envelope alone is not proof of fraud.
Crypto tax reporting and disclosure requirements have expanded in recent years, making IRS correspondence about digital assets more common for many holders. This means that a convincing notice may appear routine at first glance and recipients may be less likely to scrutinize a letter from the IRS, which can increase the effectiveness of a well-crafted fake.
The decisive warning signs are the invented portal and the wallet-registration request. Before scanning any code or visiting the printed site or calling any number on the notice, recipients should check their official IRS online account or use contact details obtained directly from IRS.gov.
At this time, public sources have not explained how the senders obtained names and home addresses associated with crypto ownership. Neither Coinbase nor any other exchange or the IRS itself reported on a related database breach.
>>> Read more: IRS Cryptocurrency Tax Reporting 2025: What You Need to Know
Exposed information requires quick account checks
Anyone who entered information into the unverified compliance portal should treat it as compromised. Coinbase recommends changing the affected exchange password and checking the two-factor authentication method. Users should also contact the provider through its official app or website.
Never share a wallet recovery phrase with a caller or enter it into a tax-compliance site. If someone disclosed a phrase, the owner may need to move any remaining assets. They should use independently verified wallet guidance and act before a scammer can.
The IRS accepts reports about suspicious tax-related letters, websites and calls. In addition, victims can report fraud to the Federal Trade Commission. Exchange-specific incidents should go through the provider’s official support channel.








