Scammers are mailing physical letters that mimic official IRS notices and pressure cryptocurrency holders to “enroll” in a fake Digital Asset Compliance Portal. Victims are driven to scan a QR code, enter details about their exchange and holdings, and provide a phone number for a follow-up call. The phone call is used to trick people into giving up one-time codes, passwords, seed phrases, or moving funds to an attacker-controlled “safe” wallet.
Key findings
- Scammers send physical letters styled as IRS/Treasury notices, including a notice number, tax year range, and a deadline to create urgency.
- Letters instruct recipients to enroll in a fake “Digital Asset Compliance Portal” and include a QR code that leads to a convincing government-lookalike website.
- The site asks which exchange/wallet the victim uses, estimated holdings value, and then requests a phone number for a “representative” to call.
- Coinbase stated the phone call is where the real attack happens, with callers requesting one-time codes, passwords, seed phrases, or urging transfers to an attacker-controlled “safe” wallet.
- DarkTower linked the site infrastructure to a newly registered domain (via a Hong Kong registrar) hosted in Romania on infrastructure previously tied to phishing pages impersonating banks and delivery services.
- Victims who entered information are advised to change exchange passwords, review 2FA, and contact the exchange using official channels (not numbers provided in the letter/call).
Who’s being targeted
- Commonly targeted roles: All employees (personal security), Finance team, Executives, Customer support / helpdesk (handling scam reports).
- Affected industries: Cryptocurrency exchanges / fintech, Consumers (individual crypto holders), Government (impersonated brand).
- Attack channels: physical, website, vishing.
- Impersonated: IRS / U.S. Department of the Treasury (and later “support staff”/“representative”), IRS / Treasury.
Awareness takeaways
- Treat unexpected government letters with QR codes and urgent deadlines as suspicious; verify through official government websites.
- Never share one-time codes, passwords, or seed phrases with anyone who calls you, legitimate support will not ask for these.
- If you already responded, reset passwords, review two-factor authentication, and contact your exchange using official in-app/site channels, not contact info provided by the letter or caller.
- Stop and verify before responding to unexpected requests for personal information; report suspected fraud.
Red flags to watch for
- Unexpected physical letter demanding urgent action “before a deadline” and threatening penalties
- QR code leads to a portal that asks for exchange/wallet details and phone number for a call-back
- Caller asks for sensitive secrets (one-time code, password, seed phrase) or to move funds to a new “safe” wallet
- Government-style branding and formatting used to create false legitimacy
- Workflow requests phone number for a call to “finish the verification”
- The IRS explicitly denies operating the named portal
Read the video transcript
You get an IRS letter at home about your crypto, with a notice number, tax years, a deadline, and a big QR code. It tells you to enroll in a ‘Digital Asset Compliance Portal.’ Scanning the QR lands on a site that looks like a U.S. government portal, asking which exchange you use, your holdings, and your phone number for a representative to call. Here’s the trap: Coinbase says the phone call is the real attack. The so-called support rep asks for one-time codes, passwords, seed phrases, or tells you to move funds into a new ‘safe’ wallet they control. Aha moment: the IRS does not operate a Digital Asset Compliance Portal. If you get a letter like this, ignore the QR and any phone numbers, go to IRS.gov or your exchange’s app yourself and verify there.