Fake IRS Letters Push Crypto “Compliance Portal”

Graham Cluley · High sophistication
Last updated August 4, 2026

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone number so a “support representative” can call and pressure them into sharing credentials, seed phrases, or MFA codes.

Key findings

  • Victims receive mailed, official-looking letters claiming they must register via a “Digital Asset Compliance Portal.”
  • Letters push recipients to scan a QR code that leads to a fake IRS-branded website posing as IRS.gov.
  • The phishing site asks where victims store crypto (wallets/exchanges), the approximate value held, and then requests a phone number for “verification.”
  • The likely goal of the follow-up call is to obtain passwords, recovery/seed phrases, or 2FA codes to take over accounts and steal digital assets.
  • Coinbase and DarkTower linked the hosting/infrastructure to prior phishing campaigns targeting banks and financial institutions, suggesting an organized fraud operation.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Customer support/helpdesk, Anyone who uses cryptocurrency.
  • Affected industries: Consumers / individual taxpayers, Cryptocurrency exchanges, Financial services.
  • Attack channels: physical, website, vishing.
  • Impersonated: IRS / U.S. Department of the Treasury, IRS “support representative”.

Awareness takeaways

  • Treat mailed letters with QR codes as potentially dangerous; don’t scan codes that route you to “compliance” or “account verification” pages.
  • Never share passwords, MFA/2FA codes, or recovery/seed phrases, no legitimate agency or support desk needs them.
  • Independently verify government communications by going directly to the official site (not via links/QR codes provided in messages).
  • If you suspect you shared sensitive info, stop engaging, change passwords, contact your crypto provider, preserve evidence, and report it.

Red flags to watch for

  • Unusual portal that the IRS does not operate (“Digital Asset Compliance Portal”)
  • Pressure/urgency (“before time runs out”)
  • QR code/website that only looks like IRS.gov (brand impersonation)
  • Any request to share a seed phrase/recovery phrase or 2FA code
  • Verification handled via an unsolicited inbound/outbound call tied to a suspicious website
  • Site asks where crypto is stored and how much is held (profiling for theft)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Do you hold cryptocurrency? Have you gotten an IRS letter pushing a “Digital Asset Compliance Portal” with a QR code? Here’s the scam: the letter says you must urgently enroll before time runs out. You scan the QR, land on a fake IRS.gov lookalike, and it asks where you keep your crypto, how much you hold, then your phone number to “get verified” by a support rep. A so-called IRS support rep then calls, using your answers to sound legit, and pressures you for passwords, recovery or seed phrases, or 2FA codes so they can drain your accounts. Your move: if a letter or site pushes a “Digital Asset Compliance Portal,” don’t scan, don’t click, go to IRS.gov yourself in a fresh browser tab and check there instead.

Similar attacks

Fake IRS Letters Push Crypto Users to QR Scam

Fake IRS Letters Push Crypto Users to QR Scam

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call.…

August 4, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
“Work Panel” Streamlines Vishing Into One Console

“Work Panel” Streamlines Vishing Into One Console

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites and guide victims through password and MFA capture. The tool clones brand look-and-feel for services like Okta and Microsoft 365, then lets a…

July 29, 2026
Deepfake FBI Videos Push Victims to Fake IC3 Sites

Deepfake FBI Videos Push Victims to Fake IC3 Sites

The FBI warned that scammers are impersonating IC3 leadership using AI-generated (deepfake) videos and spoofed IC3 websites to trick prior fraud victims into sharing more personal and financial information. In one example, victims are contacted on Facebook Messenger by someone posing as an FBI…

July 21, 2026