Fake IRS letters target cryptocurrency holders

The IRS warns that scammers are mailing fake letters to cryptocurrency holders in a sophisticated phishing campaign targeting digital assets.

By Central
Fraudulent IRS letters mimic official correspondence with a QR code directing victims to a fake compliance portal.
Highlights
  • Scammers are sending physical letters that mimic IRS notifications to steal cryptocurrency holder information.
  • The letters include a QR code leading to a fake 'Digital Asset Compliance Portal' website.
  • The IRS does not operate such a portal and never asks for sensitive information via QR code.

The United States Internal Revenue Service has issued a fraud alert after discovering that scammers are mailing official-looking letters to cryptocurrency holders, directing them to a fraudulent “Digital Asset Compliance Portal” designed to steal personal information and digital assets. If you hold cryptocurrency and have received such a letter, you are being targeted by what security researchers describe as a well-organized, internationally coordinated phishing campaign — and the IRS wants you to know that no such portal exists.

The letters, which have been observed by both the IRS Criminal Investigation division and security teams at major cryptocurrency exchanges, represent a significant escalation in phishing tactics targeting digital asset holders. Rather than relying on email or text messages, the scammers have invested in physical mailers that mimic genuine IRS correspondence, complete with official-looking notice numbers, Treasury Department references, and threatening language about registration deadlines.

How the Fake IRS Letter Scam Works: A Step-by-Step Breakdown

The scam begins when a victim receives an unmarked envelope containing a letter that purports to be from the Department of the Treasury, Internal Revenue Service, with a return address in Austin, Texas. The letter instructs the recipient to scan a QR code and enroll in something called the “Digital Asset Compliance Portal” before a stated deadline passes. Security researchers at Coinbase, who have analyzed examples of the fraudulent mailers, report that the letters imitate real IRS notifications with considerable attention to detail.

The letters use a notice number format similar to legitimate IRS correspondence — in observed cases, CP14-432RA — and reference a tax year range spanning 2017 through 2026. These details lend the letters an air of authenticity that might convince recipients who are already aware that the IRS has been tightening reporting requirements for cryptocurrency holdings.

Scanning the QR code takes victims to a website that visually impersonates IRS.gov, complete with government-style branding and a banner falsely claiming to be an official United States government website. The site asks visitors to specify which cryptocurrency wallets or exchanges they use, selecting from options including hardware wallets like Ledger and Trezor alongside exchanges like Coinbase and Binance.

Victims are then asked to estimate the total value of their cryptocurrency holdings, with ranges extending up to “$100,000+”. Security researchers believe this allows the fraudsters to prioritize which accounts to target for theft. Finally, the site requests a phone number for “verification” by a support representative, who will attempt to talk the victim into handing over passwords, recovery phrases, seed phrases, or two-factor authentication codes.

What Is the Digital Asset Compliance Portal and Why Doesn’t It Exist?

The “Digital Asset Compliance Portal” referenced in these fraudulent letters is entirely fictitious. The IRS does not operate any such portal, has never asked taxpayers to register their cryptocurrency holdings through a QR code, and does not request sensitive account information through unsolicited communications. The term appears to have been invented by scammers to exploit growing awareness that the IRS has increased its focus on cryptocurrency tax compliance.

This is a question many recipients may ask: Is there any legitimate IRS system for registering digital assets? The answer is no. While the IRS has updated tax forms to include a question about digital asset transactions and has issued guidance on how cryptocurrency should be reported on tax returns, there is no separate registration portal for cryptocurrency holders. Any communication that claims otherwise should be treated as fraudulent.

The scam exploits a genuine trend: the IRS has indeed been tightening requirements around cryptocurrency reporting, and written communications between the agency and taxpayers about digital assets have become more common. This makes a letter about registering digital assets feel less outlandish than it might have a few years ago, giving the scammers an opening they have exploited with precision.

Who Is Behind These Fake IRS Letters? What the Investigation Revealed

Investigations conducted by Coinbase’s security team in partnership with threat intelligence firm DarkTower have uncovered evidence pointing to a sophisticated, internationally coordinated operation. The domain used in the attack was registered just days before the fake letters were mailed out, suggesting a tightly planned campaign rather than a scatter-shot effort.

The domain was registered through a Hong Kong-based registrar, while the fraudulent website itself was hosted on servers located in Romania. Researchers discovered that the hosting infrastructure had previously been associated with phishing campaigns targeting banks and financial institutions, indicating that the same criminal operators — or groups sharing resources — have been active in financial fraud for some time.

The use of physical mailers adds a layer of complexity and cost that amateur cybercriminals rarely invest in. Printing, envelopes, postage, and mailing logistics represent a significant upfront investment, suggesting that the expected return on this campaign is substantial. The scammers are betting that the combination of official-looking physical mail and a convincing website will yield access to high-value cryptocurrency accounts.

Why This Scam Is Particularly Dangerous for Cryptocurrency Holders

Cryptocurrency transactions are, by design, irreversible. Once a victim hands over their private keys, recovery phrase, or seed phrase, there is no bank to call, no transaction reversal, no chargeback mechanism. The funds can be moved to new wallets within seconds, mixed through tumblers, and cashed out through exchanges in jurisdictions with weak oversight.

This makes cryptocurrency holders especially attractive targets for sophisticated phishing operations. Unlike bank accounts, which have fraud protection measures and regulatory safeguards, cryptocurrency wallets are only as secure as the secrecy of their private keys. A single moment of panic or confusion — triggered by an official-looking letter demanding immediate action — can result in the total loss of assets with no realistic path to recovery.

The scam also targets a population that may already be uncertain about their tax obligations. Cryptocurrency tax reporting is complex, and many holders are unsure about what forms they need to file, what information the IRS already has, and what the consequences of non-compliance might be. The scammers weaponize this uncertainty, using the threat of tax enforcement to pressure victims into acting without verifying the legitimacy of the communication.

How to Identify a Fake IRS Letter: Red Flags and Warning Signs

There are several telltale signs that distinguish fraudulent letters from genuine IRS correspondence. The IRS does not send unsolicited letters asking recipients to scan QR codes or visit third-party websites to register accounts. The agency communicates primarily through postal mail for official notices, but those notices reference specific tax accounts, filing statuses, and amounts owed — not generic instructions to register in a portal.

Real IRS letters include specific taxpayer information, such as the taxpayer’s Social Security Number or Employer Identification Number, and reference specific tax years, forms, or balances. The fraudulent letters observed in this campaign reference a broad tax year range from 2017 to 2026, which is not how legitimate IRS correspondence is structured. The IRS focuses on specific tax periods and specific filing obligations.

The IRS does not request sensitive financial account information, passwords, or authentication codes through letters, email, or phone calls. Any communication that asks for passwords, seed phrases, recovery phrases, or two-factor authentication codes is fraudulent regardless of how official it appears.

Perhaps most importantly, the IRS does not operate a “Digital Asset Compliance Portal” or any similar system requiring cryptocurrency holders to register their wallets or exchange accounts. This phrase alone should be enough to identify the letter as a scam.

What to Do If You Receive a Fake IRS Letter

If you receive one of these letters, do not scan the QR code and do not visit any website referenced in the letter. The safest course of action is to discard the letter entirely. If you have already scanned the QR code or visited the website but did not provide any information, change your passwords as a precaution and monitor your accounts for suspicious activity.

If you provided any information to the scammers — whether it was your phone number, wallet type, estimated holdings, or especially any passwords, recovery phrases, or authentication codes — you should take immediate action. Stop communicating with the scammers. Change your passwords on all cryptocurrency exchanges and wallets you use. Enable or strengthen two-factor authentication. Contact your cryptocurrency exchange’s support team and inform them that you may have been the victim of a phishing attack.

Preserve any evidence of your communications with the scammers, including the envelope, the letter, and any screenshots of the fraudulent website. This evidence can assist law enforcement in tracking the perpetrators. Report the incident to the IRS through their official fraud reporting channels at irs.gov.

If you are unsure whether a letter you received is legitimate, verify independently by visiting the official IRS website directly — by typing irs.gov into your browser, not by clicking any links or scanning any codes from the letter. You can also contact the IRS directly using the phone numbers listed on their official website.

The Broader Context: IRS Enforcement and Cryptocurrency Reporting in 2026 and Beyond

This scam arrives at a time when the relationship between cryptocurrency holders and tax authorities is undergoing significant change. The IRS has made digital asset compliance a priority, investing in data analytics, blockchain tracing tools, and information-sharing agreements with cryptocurrency exchanges. Tax forms now include a prominent question about digital asset transactions, and the agency has issued increasingly detailed guidance on how various cryptocurrency activities — trading, staking, mining, lending, airdrops, and NFTs — should be treated for tax purposes.

This heightened scrutiny creates a fertile environment for scams that reference tax compliance. Fraudsters know that many cryptocurrency holders are already anxious about getting their tax reporting right, and they exploit that anxiety with communications that threaten penalties, interest, or legal action for failing to register or report.

The IRS’s fraud alert specifically warns that the agency does not initiate contact with taxpayers through email, text messages, or social media to request personal or financial information. Official IRS communications come through the United States Postal Service, and even then, they reference specific accounts and tax obligations rather than demanding registration in generic portals.

Security researchers expect this type of scam to evolve. The successful use of physical mailers combined with QR codes and convincing impersonation websites represents a new vector for cryptocurrency phishing that may be adopted by other criminal groups. The infrastructure used in this campaign — Hong Kong domain registration, Romanian hosting, and connections to previous financial phishing operations — suggests a playbook that can be adapted and repeated with different branding and different targets.

Protecting Yourself: Practical Security Measures for Cryptocurrency Holders

The fundamental rule of cryptocurrency security applies here as it does everywhere: never share your private keys, recovery phrases, seed phrases, or passwords with anyone, under any circumstances. No legitimate organization — including the IRS, your cryptocurrency exchange, or any government agency — will ever ask you for these credentials. Anyone who does is attempting to steal from you.

Enable two-factor authentication on all cryptocurrency accounts, using an authenticator app rather than SMS where possible, as SIM-swapping attacks remain a common way for scammers to intercept text message codes. Use hardware wallets for significant holdings, and never enter your hardware wallet seed phrase into any website or software interface. The seed phrase should be written down on paper and stored securely offline.

Verify any communication that claims to be from the IRS or any government agency by contacting the agency directly through official channels. Do not use phone numbers or website links provided in the suspicious communication. Go to the official website independently and find the correct contact information there.

Be especially cautious of any communication that creates a sense of urgency or threatens negative consequences for failing to act quickly. Scammers rely on panic and pressure to bypass rational decision-making. Taking a few minutes to verify a claim independently can prevent the loss of years of savings.

The cryptocurrency ecosystem has matured significantly over the past decade, but the fundamental security challenges remain the same. The technology that makes cryptocurrency powerful — irreversibility, self-custody, pseudonymity — also makes it unforgiving of mistakes. A single compromised credential can mean total loss, and no centralized authority can reverse the transaction or recover the funds.

The emergence of physically mailed phishing letters targeting cryptocurrency holders marks a new chapter in the ongoing battle between scammers and the people they target. It demonstrates that criminals are willing to invest time, money, and coordination into attacks that promise high returns. For cryptocurrency holders, the defense remains the same as it has always been: skepticism, verification, and the absolute protection of private keys. The IRS will never ask for them. No legitimate portal requires them. And anyone who does is not trying to help you comply with tax law — they are trying to empty your wallet.

Share This Article