Fake IRS Letters Push Crypto “Compliance Portal”

Graham Cluley · High sophistication
Last updated August 4, 2026

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone number so a “support representative” can call and pressure them into sharing credentials, seed phrases, or MFA codes.

Key findings

  • Victims receive mailed, official-looking letters claiming they must register via a “Digital Asset Compliance Portal.”
  • Letters push recipients to scan a QR code that leads to a fake IRS-branded website posing as IRS.gov.
  • The phishing site asks where victims store crypto (wallets/exchanges), the approximate value held, and then requests a phone number for “verification.”
  • The likely goal of the follow-up call is to obtain passwords, recovery/seed phrases, or 2FA codes to take over accounts and steal digital assets.
  • Coinbase and DarkTower linked the hosting/infrastructure to prior phishing campaigns targeting banks and financial institutions, suggesting an organized fraud operation.

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Executives, Customer support/helpdesk, Anyone who uses cryptocurrency.
  • Affected industries: Consumers / individual taxpayers, Cryptocurrency exchanges, Financial services.
  • Attack channels: physical, website, vishing.
  • Impersonated: IRS / U.S. Department of the Treasury, IRS “support representative”.

Awareness takeaways

  • Treat mailed letters with QR codes as potentially dangerous; don’t scan codes that route you to “compliance” or “account verification” pages.
  • Never share passwords, MFA/2FA codes, or recovery/seed phrases, no legitimate agency or support desk needs them.
  • Independently verify government communications by going directly to the official site (not via links/QR codes provided in messages).
  • If you suspect you shared sensitive info, stop engaging, change passwords, contact your crypto provider, preserve evidence, and report it.

Red flags to watch for

  • Unusual portal that the IRS does not operate (“Digital Asset Compliance Portal”)
  • Pressure/urgency (“before time runs out”)
  • QR code/website that only looks like IRS.gov (brand impersonation)
  • Any request to share a seed phrase/recovery phrase or 2FA code
  • Verification handled via an unsolicited inbound/outbound call tied to a suspicious website
  • Site asks where crypto is stored and how much is held (profiling for theft)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Do you hold cryptocurrency? Have you gotten an IRS letter pushing a “Digital Asset Compliance Portal” with a QR code? Here’s the scam: the letter says you must urgently enroll before time runs out. You scan the QR, land on a fake IRS.gov lookalike, and it asks where you keep your crypto, how much you hold, then your phone number to “get verified” by a support rep. A so-called IRS support rep then calls, using your answers to sound legit, and pressures you for passwords, recovery or seed phrases, or 2FA codes so they can drain your accounts. Your move: if a letter or site pushes a “Digital Asset Compliance Portal,” don’t scan, don’t click, go to IRS.gov yourself in a fresh browser tab and check there instead.

Similar attacks

AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
Fake IRS Letters Push Crypto Users to QR Scam

Fake IRS Letters Push Crypto Users to QR Scam

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call.…

August 4, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026