Fake IRS Letters Push Crypto Users to QR Scam

Help Net Security · Medium sophistication
Last updated August 4, 2026

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call. The phone call is used to trick people into giving up one-time codes, passwords, seed phrases, or moving funds to an attacker-controlled “safe” wallet.

Key findings

  • Scammers send physical letters styled as IRS/Treasury notices, including a notice number, tax year range, and a deadline to create urgency.
  • Letters instruct recipients to enroll in a fake “Digital Asset Compliance Portal” and include a QR code that leads to a convincing government-lookalike website.
  • The site asks which exchange/wallet the victim uses, estimated holdings value, and then requests a phone number for a “representative” to call.
  • Coinbase stated the phone call is where the real attack happens, with callers requesting one-time codes, passwords, seed phrases, or urging transfers to an attacker-controlled “safe” wallet.
  • DarkTower linked the site infrastructure to a newly registered domain (via a Hong Kong registrar) hosted in Romania on infrastructure previously tied to phishing pages impersonating banks and delivery services.
  • Victims who entered information are advised to change exchange passwords, review 2FA, and contact the exchange using official channels (not numbers provided in the letter/call).

Who’s being targeted

  • Commonly targeted roles: All employees (personal security), Finance team, Executives, Customer support / helpdesk (handling scam reports).
  • Affected industries: Cryptocurrency exchanges / fintech, Consumers (individual crypto holders), Government (impersonated brand).
  • Attack channels: physical, website, vishing.
  • Impersonated: IRS / U.S. Department of the Treasury (and later “support staff”/“representative”), IRS / Treasury.

Awareness takeaways

  • Treat unexpected government letters with QR codes and urgent deadlines as suspicious; verify through official government websites.
  • Never share one-time codes, passwords, or seed phrases with anyone who calls you, legitimate support will not ask for these.
  • If you already responded, reset passwords, review two-factor authentication, and contact your exchange using official in-app/site channels, not contact info provided by the letter or caller.
  • Stop and verify before responding to unexpected requests for personal information; report suspected fraud.

Red flags to watch for

  • Unexpected physical letter demanding urgent action “before a deadline” and threatening penalties
  • QR code leads to a portal that asks for exchange/wallet details and phone number for a call-back
  • Caller asks for sensitive secrets (one-time code, password, seed phrase) or to move funds to a new “safe” wallet
  • Government-style branding and formatting used to create false legitimacy
  • Workflow requests phone number for a call to “finish the verification”
  • The IRS explicitly denies operating the named portal
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an IRS letter at home about your crypto, with a notice number, tax years, a deadline, and a big QR code. It tells you to enroll in a ‘Digital Asset Compliance Portal.’ Scanning the QR lands on a site that looks like a U.S. government portal, asking which exchange you use, your holdings, and your phone number for a representative to call. Here’s the trap: Coinbase says the phone call is the real attack. The so-called support rep asks for one-time codes, passwords, seed phrases, or tells you to move funds into a new ‘safe’ wallet they control. Aha moment: the IRS does not operate a Digital Asset Compliance Portal. If you get a letter like this, ignore the QR and any phone numbers, go to IRS.gov or your exchange’s app yourself and verify there.

Similar attacks

Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026