Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone number so a “support representative” can call and pressure them into sharing credentials, seed phrases, or MFA codes.
Key findings
- Victims receive mailed, official-looking letters claiming they must register via a “Digital Asset Compliance Portal.”
- Letters push recipients to scan a QR code that leads to a fake IRS-branded website posing as IRS.gov.
- The phishing site asks where victims store crypto (wallets/exchanges), the approximate value held, and then requests a phone number for “verification.”
- The likely goal of the follow-up call is to obtain passwords, recovery/seed phrases, or 2FA codes to take over accounts and steal digital assets.
- Coinbase and DarkTower linked the hosting/infrastructure to prior phishing campaigns targeting banks and financial institutions, suggesting an organized fraud operation.
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Executives, Customer support/helpdesk, Anyone who uses cryptocurrency.
- Affected industries: Consumers / individual taxpayers, Cryptocurrency exchanges, Financial services.
- Attack channels: physical, website, vishing.
- Impersonated: IRS / U.S. Department of the Treasury, IRS “support representative”.
Awareness takeaways
- Treat mailed letters with QR codes as potentially dangerous; don’t scan codes that route you to “compliance” or “account verification” pages.
- Never share passwords, MFA/2FA codes, or recovery/seed phrases, no legitimate agency or support desk needs them.
- Independently verify government communications by going directly to the official site (not via links/QR codes provided in messages).
- If you suspect you shared sensitive info, stop engaging, change passwords, contact your crypto provider, preserve evidence, and report it.
Red flags to watch for
- Unusual portal that the IRS does not operate (“Digital Asset Compliance Portal”)
- Pressure/urgency (“before time runs out”)
- QR code/website that only looks like IRS.gov (brand impersonation)
- Any request to share a seed phrase/recovery phrase or 2FA code
- Verification handled via an unsolicited inbound/outbound call tied to a suspicious website
- Site asks where crypto is stored and how much is held (profiling for theft)
Read the video transcript
Do you hold cryptocurrency? Have you gotten an IRS letter pushing a “Digital Asset Compliance Portal” with a QR code? Here’s the scam: the letter says you must urgently enroll before time runs out. You scan the QR, land on a fake IRS.gov lookalike, and it asks where you keep your crypto, how much you hold, then your phone number to “get verified” by a support rep. A so-called IRS support rep then calls, using your answers to sound legit, and pressures you for passwords, recovery or seed phrases, or 2FA codes so they can drain your accounts. Your move: if a letter or site pushes a “Digital Asset Compliance Portal,” don’t scan, don’t click, go to IRS.gov yourself in a fresh browser tab and check there instead.