Fake IRS Letters Push Crypto Users to QR Scam

Help Net Security · Medium sophistication
Last updated August 4, 2026

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call. The phone call is used to trick people into giving up one-time codes, passwords, seed phrases, or moving funds to an attacker-controlled “safe” wallet.

Key findings

  • Scammers send physical letters styled as IRS/Treasury notices, including a notice number, tax year range, and a deadline to create urgency.
  • Letters instruct recipients to enroll in a fake “Digital Asset Compliance Portal” and include a QR code that leads to a convincing government-lookalike website.
  • The site asks which exchange/wallet the victim uses, estimated holdings value, and then requests a phone number for a “representative” to call.
  • Coinbase stated the phone call is where the real attack happens, with callers requesting one-time codes, passwords, seed phrases, or urging transfers to an attacker-controlled “safe” wallet.
  • DarkTower linked the site infrastructure to a newly registered domain (via a Hong Kong registrar) hosted in Romania on infrastructure previously tied to phishing pages impersonating banks and delivery services.
  • Victims who entered information are advised to change exchange passwords, review 2FA, and contact the exchange using official channels (not numbers provided in the letter/call).

Who’s being targeted

  • Commonly targeted roles: All employees (personal security), Finance team, Executives, Customer support / helpdesk (handling scam reports).
  • Affected industries: Cryptocurrency exchanges / fintech, Consumers (individual crypto holders), Government (impersonated brand).
  • Attack channels: physical, website, vishing.
  • Impersonated: IRS / U.S. Department of the Treasury (and later “support staff”/“representative”), IRS / Treasury.

Awareness takeaways

  • Treat unexpected government letters with QR codes and urgent deadlines as suspicious; verify through official government websites.
  • Never share one-time codes, passwords, or seed phrases with anyone who calls you, legitimate support will not ask for these.
  • If you already responded, reset passwords, review two-factor authentication, and contact your exchange using official in-app/site channels, not contact info provided by the letter or caller.
  • Stop and verify before responding to unexpected requests for personal information; report suspected fraud.

Red flags to watch for

  • Unexpected physical letter demanding urgent action “before a deadline” and threatening penalties
  • QR code leads to a portal that asks for exchange/wallet details and phone number for a call-back
  • Caller asks for sensitive secrets (one-time code, password, seed phrase) or to move funds to a new “safe” wallet
  • Government-style branding and formatting used to create false legitimacy
  • Workflow requests phone number for a call to “finish the verification”
  • The IRS explicitly denies operating the named portal
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an IRS letter at home about your crypto, with a notice number, tax years, a deadline, and a big QR code. It tells you to enroll in a ‘Digital Asset Compliance Portal.’ Scanning the QR lands on a site that looks like a U.S. government portal, asking which exchange you use, your holdings, and your phone number for a representative to call. Here’s the trap: Coinbase says the phone call is the real attack. The so-called support rep asks for one-time codes, passwords, seed phrases, or tells you to move funds into a new ‘safe’ wallet they control. Aha moment: the IRS does not operate a Digital Asset Compliance Portal. If you get a letter like this, ignore the QR and any phone numbers, go to IRS.gov or your exchange’s app yourself and verify there.

Similar attacks

Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026
Fake Bank Calls and ClickFix Drive Data Theft

Fake Bank Calls and ClickFix Drive Data Theft

The roundup describes multiple real-world attacks where criminals manipulate people, not just systems, such as fake bank support calls that trick victims into installing phone malware, and “ClickFix” lures that convince Mac users to run malicious commands. It also highlights an AI-assisted…

August 21, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Fraud Ring Targets Crypto Users via Phone + Phish

Fraud Ring Targets Crypto Users via Phone + Phish

Researchers described a real fraud operation that first verified which phone numbers were tied to cryptocurrency exchange accounts, then targeted confirmed owners. The attackers used phishing emails, vishing calls, and fake wallet apps while impersonating popular hardware/software wallet brands,…

August 18, 2026
SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal Data Exposure Sparks Targeted Phishing Risk

SafePal disclosed that nearly 40,000 customers had personal and order information exposed due to an authorization flaw in an order-tracking plug-in. While wallet secrets were not exposed, SafePal warned that criminals can use the leaked order details to run highly convincing scams (fake support,…

August 17, 2026