Scammers Impersonate IRS, Target Crypto Holders with Fake Compliance Portal Scam
Fraudulent physical letters are being sent to cryptocurrency holders, directing them to a fake IRS compliance portal to trick them into revealing sensitive information.

Cybercriminals are employing a sophisticated phishing scheme that impersonates the U.S. Internal Revenue Service (IRS) to target cryptocurrency holders. The attackers are distributing physical letters designed to look like official IRS notices, instructing recipients to enroll in a fictitious "Digital Asset Compliance Portal" by a looming deadline to avoid penalties. The IRS has officially confirmed that it did not send these letters and does not operate any such portal, urging the public to disregard these fraudulent communications.
The scheme was brought to light through a customer report to Coinbase, which then collaborated with threat intelligence firm DarkTower to investigate. DarkTower's analysis revealed that the infrastructure for the fake portal was registered through a Hong Kong registrar mere days before the letters were disseminated. The hosting was traced to Romania, utilizing infrastructure previously associated with phishing pages impersonating banks and delivery services.
The physical letters are designed to create a sense of urgency and legitimacy. They arrive in plain envelopes, featuring Treasury and IRS branding, a fabricated notice number, a specified tax year range, and a deadline. Crucially, the letters include a QR code that, when scanned, directs the recipient to a website meticulously designed to mimic a government portal, complete with an "official website of the United States government" banner.
Once on the fraudulent site, victims are guided through a multi-stage process. They are prompted to select their cryptocurrency exchange or wallet provider, estimate the value of their holdings, and then provide a phone number. This information is intended to facilitate the next phase of the attack: a phone call from a scammer posing as a support representative.
During the phone call, the attackers attempt to extract sensitive information such as one-time codes, passwords, or seed phrases. In some instances, they may instruct the victim to move their cryptocurrency into a "safe" wallet controlled by the scammer, effectively stealing the funds. Coinbase noted that the immediate aftermath of submitting information on the website could lead to the site going dark, suggesting either a delayed phone call or the harvesting of personal data for future social engineering attempts.
To mitigate potential damage, individuals who have already entered information are advised to immediately change their exchange passwords, review their two-factor authentication settings, and contact their exchange directly through official channels rather than relying on information provided by the scam. Keeping screenshots and copies of the fraudulent correspondence is recommended as evidence.
IRS-CI Chief Jarod Koopman emphasized the ongoing trend of criminals exploiting public trust in government agencies by creating convincing fake websites and correspondence. He stressed the importance of verifying the source of any unexpected requests for personal information and reporting potential fraud to law enforcement.
This scam highlights the evolving tactics of cybercriminals, who are leveraging official-looking mail and QR codes to bypass digital defenses and directly target individuals with sophisticated social engineering. The involvement of cryptocurrency adds another layer of risk, as stolen credentials or funds can be difficult to recover.