Fake IRS Letters Push Crypto Users to QR Scam

Help Net Security · Medium sophistication
Last updated August 4, 2026

Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call. The phone call is used to trick people into giving up one-time codes, passwords, seed phrases, or moving funds to an attacker-controlled “safe” wallet.

Key findings

  • Scammers send physical letters styled as IRS/Treasury notices, including a notice number, tax year range, and a deadline to create urgency.
  • Letters instruct recipients to enroll in a fake “Digital Asset Compliance Portal” and include a QR code that leads to a convincing government-lookalike website.
  • The site asks which exchange/wallet the victim uses, estimated holdings value, and then requests a phone number for a “representative” to call.
  • Coinbase stated the phone call is where the real attack happens, with callers requesting one-time codes, passwords, seed phrases, or urging transfers to an attacker-controlled “safe” wallet.
  • DarkTower linked the site infrastructure to a newly registered domain (via a Hong Kong registrar) hosted in Romania on infrastructure previously tied to phishing pages impersonating banks and delivery services.
  • Victims who entered information are advised to change exchange passwords, review 2FA, and contact the exchange using official channels (not numbers provided in the letter/call).

Who’s being targeted

  • Commonly targeted roles: All employees (personal security), Finance team, Executives, Customer support / helpdesk (handling scam reports).
  • Affected industries: Cryptocurrency exchanges / fintech, Consumers (individual crypto holders), Government (impersonated brand).
  • Attack channels: physical, website, vishing.
  • Impersonated: IRS / U.S. Department of the Treasury (and later “support staff”/“representative”), IRS / Treasury.

Awareness takeaways

  • Treat unexpected government letters with QR codes and urgent deadlines as suspicious; verify through official government websites.
  • Never share one-time codes, passwords, or seed phrases with anyone who calls you, legitimate support will not ask for these.
  • If you already responded, reset passwords, review two-factor authentication, and contact your exchange using official in-app/site channels, not contact info provided by the letter or caller.
  • Stop and verify before responding to unexpected requests for personal information; report suspected fraud.

Red flags to watch for

  • Unexpected physical letter demanding urgent action “before a deadline” and threatening penalties
  • QR code leads to a portal that asks for exchange/wallet details and phone number for a call-back
  • Caller asks for sensitive secrets (one-time code, password, seed phrase) or to move funds to a new “safe” wallet
  • Government-style branding and formatting used to create false legitimacy
  • Workflow requests phone number for a call to “finish the verification”
  • The IRS explicitly denies operating the named portal
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an IRS letter at home about your crypto, with a notice number, tax years, a deadline, and a big QR code. It tells you to enroll in a ‘Digital Asset Compliance Portal.’ Scanning the QR lands on a site that looks like a U.S. government portal, asking which exchange you use, your holdings, and your phone number for a representative to call. Here’s the trap: Coinbase says the phone call is the real attack. The so-called support rep asks for one-time codes, passwords, seed phrases, or tells you to move funds into a new ‘safe’ wallet they control. Aha moment: the IRS does not operate a Digital Asset Compliance Portal. If you get a letter like this, ignore the QR and any phone numbers, go to IRS.gov or your exchange’s app yourself and verify there.

Similar attacks

Fake IRS Letters Push Crypto “Compliance Portal”

Fake IRS Letters Push Crypto “Compliance Portal”

Scammers are mailing official-looking “IRS” letters to cryptocurrency holders, urging them to scan a QR code and enroll in a fake “Digital Asset Compliance Portal.” The QR code leads to a fraudulent IRS-lookalike site that gathers wallet/exchange details and then prompts victims to provide a phone…

August 4, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Fake Job Interviews Used to Breach 1,600 Firms

Fake Job Interviews Used to Breach 1,600 Firms

A researcher says North Korean operators used fake high-salary job offers to trick software developers into downloading an “interview test” program that installed malware. He reports evidence that 1,640 organizations across 57 countries were impacted, with hundreds suffering serious intrusions,…

August 6, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026