IRS Warns of Fake Crypto Compliance Letters Sent by Mail
IRS Warns of Fake Crypto Compliance Letters – Physical Mail Scam Targets Digital Asset Holders
Key Takeaways
- The US Internal Revenue Service has warned that scammers are sending counterfeit letters to crypto holders.
- The letters direct recipients to a fake “Digital Asset Compliance Portal” designed to steal personal data and digital assets.
- The scam uses QR codes that lead to a spoofed website and may involve follow-up phone calls posing as support staff.
- According to Chainalysis, scams and fraud cost victims $17 billion in 2025, with impersonation scams up 1,400%.
- TRM Labs recorded 207 hacks in the first half of 2026, more than double the 83 reported a year earlier.
IRS Criminal Investigation Unit Issues Fraud Alert
The US Internal Revenue Service has issued a warning about a new scam targeting cryptocurrency holders through physical mail. According to the agency’s Criminal Investigation unit, scammers are mailing counterfeit letters that appear to be official IRS correspondence.
The letters instruct recipients to enroll in what is described as a “Digital Asset Compliance Portal” before a stated deadline. The IRS has clarified that it does not operate such a portal and is not sending these letters. The agency emphasized that any communication directing taxpayers to this portal is fraudulent.
The warning highlights a shift in tactics. While many crypto-related phishing campaigns rely on email or text messages, this scheme uses printed letters delivered to home addresses.
How the Fake Compliance Portal Scam Works
According to the IRS, the counterfeit notices contain QR codes. When scanned, these codes lead to a spoofed website designed to collect sensitive information.
Victims who access the site are prompted to enter personal data. The objective is to harvest identifying information and potentially gain access to digital assets. The IRS has advised taxpayers not to scan QR codes from unsolicited letters, emails, or text messages.
The agency also warned individuals to hang up on callers who demand payment or request sensitive information. The scam can escalate beyond the initial letter.
Coinbase and threat intelligence firm DarkTower flagged the campaign during the same week as the IRS alert. Their investigation found that the fraudulent letters reference tax years ranging from 2017 through 2026. The look-alike domain connected to the fake portal was reportedly registered through a Hong Kong registrar and hosted in Romania.
Coinbase described a related tactic known as vishing, or voice phishing. In this scenario, a scammer posing as support personnel contacts the victim after the initial interaction. According to Coinbase, the caller attempts to convince the individual to hand over account access details or move funds to a so-called safe wallet controlled by the attacker. The company characterized vishing as one of the most effective account takeover techniques currently used against crypto holders.
Impersonation Scams and Hacks Remain Widespread
The fake IRS letter campaign fits into a broader pattern of impersonation-driven fraud within the crypto sector.
Chainalysis estimated that scams and fraud cost victims $17 billion in 2025. The firm reported a 1,400% surge in impersonation scams during that period. These schemes typically involve attackers posing as trusted institutions, companies, or individuals to gain access to funds or personal information.
At the same time, technical attacks on crypto platforms and protocols continue. TRM Labs recorded 207 hacks in the first half of 2026. This figure represents more than double the 83 incidents logged during the same period a year earlier and marks the firm’s highest six-month count on record.
Despite the increase in the number of hacks, total losses declined. TRM Labs reported approximately $972 million in losses in the first half of 2026, compared with about $2.3 billion in the first half of 2025.
Taken together, the data indicates a changing threat landscape. While code-based exploits remain frequent, impersonation and social engineering attacks are gaining prominence. The IRS letter campaign illustrates how these tactics are expanding beyond digital channels.
What This Means for Crypto Users
For individuals holding or transacting in digital assets, the scam underscores the importance of verifying official communications. The IRS has explicitly stated that it does not operate a Digital Asset Compliance Portal and is not sending letters directing taxpayers to enroll in such a system.
The inclusion of QR codes in physical mail adds another layer of risk. QR codes can obscure the true destination of a web link, making it harder to identify fraudulent domains before visiting them.
The involvement of multiple jurisdictions in the domain registration and hosting infrastructure, as reported by Coinbase and DarkTower, also reflects the cross-border nature of crypto-related fraud. This can complicate enforcement and recovery efforts.
For users of crypto betting platforms, online casinos, and other digital asset services, the case highlights how attackers may exploit tax reporting obligations and regulatory themes to appear credible. Any request for wallet keys, fund transfers to unknown addresses, or urgent compliance actions should be independently verified through official channels.
Our Assessment
The IRS warning confirms that scammers are using counterfeit physical letters to target crypto holders with a fake compliance portal. The campaign combines QR code phishing, spoofed domains, and potential follow-up vishing calls to obtain personal data and digital assets. Data from Chainalysis and TRM Labs shows that impersonation scams and hacks remain widespread, with a sharp increase in impersonation activity in 2025 and a record number of hacks in early 2026. The case illustrates how fraud tactics in the crypto sector are evolving across both digital and physical communication channels.
