
The US Internal Revenue Service (IRS) issued a fraud alert on July 30 warning that scammers are mailing counterfeit letters to cryptocurrency holders. According to reports from the agency's Criminal Investigation unit, these letters direct recipients to a fake 'Digital Asset Compliance Portal' designed to steal digital assets and personal data. The IRS emphasized that it does not operate any such portal and is not sending these letters to taxpayers. As reported by BeInCrypto, the agency's Criminal Investigation unit issued the fraud alert on Thursday, highlighting the urgent nature of this warning. Coinbase flagged the threat two days before the IRS announcement on July 28, publishing a consumer alert in collaboration with security firm DarkTower detailing how the letters use realistic formatting to bypass skepticism. IRS-CI chief Jarod Koopman stated that "Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence."
The counterfeit notices instruct recipients to enroll in the portal before a specified deadline. As reported by the IRS, the letters contain QR codes that redirect victims to spoofed websites when scanned. Once victims access these fraudulent sites, they are prompted to enter personal information including cryptocurrency wallet details, exchange account credentials, and other sensitive financial data. The agency specifically warned taxpayers not to scan QR codes from unsolicited letters, emails, or texts, and advised people to hang up on callers demanding payment. According to Coinbase and DarkTower, the letters arrive in plain envelopes and use realistic formatting to bypass typical phishing detection. The scheme represents a shift from typical crypto phishing, with the use of physical mail marking a new approach in fraudulent campaigns targeting cryptocurrency holders. The agency noted that 'that phone call is the actual attack' - scammers posing as support will try to trick victims into handing over account keys and moving funds to wallets they control.
According to reports from Coinbase and threat intelligence firm DarkTower, the letters reference tax years 2017 through 2026. The investigation revealed that the look-alike domain was registered through a Hong Kong registrar and hosted in Romania. Coinbase noted that the scheme represents a shift from typical crypto phishing, with the use of physical mail marking a new approach in fraudulent campaigns targeting cryptocurrency holders. The firm emphasized that 'vishing (voice phishing) is one of the most effective account-takeover techniques used against crypto holders today,' as scammers posing as support will try to trick victims into moving funds to wallets they control. Since 2019, the IRS has been sending legitimate educational compliance letters to individuals suspected of underreporting their digital asset activities, and the agency has steadily ramped up its scrutiny of digital asset reporting.
The IRS has established clear ground rules to help distinguish real communications from fakes. The agency does not send QR codes in its official correspondence, and if recipients receive a letter with one, that's their signal to stop and verify before doing anything else. Any legitimate IRS notice can be confirmed through the agency's official website, IRS.gov, or by calling the number listed on that site, not the number printed on a suspicious letter. The IRS also does not ask taxpayers to transfer digital assets as part of any compliance process. TradingView News advises that anyone with a sense of urgency is most likely a scammer, and users should keep their keys and wallet recovery phrases secret while reporting any suspicious activities to law enforcement agencies. The agency advises taxpayers to slow down and verify the situation before responding to unexpected requests, protect personal and financial information, and monitor financial accounts regularly for suspicious activity.