
Fraudsters are mailing physical letters to crypto holders, impersonating the IRS and directing recipients to a fake government website. The "Digital Asset Compliance Portal" referenced in the letter does not exist.
If you received one of these letters, or know someone who did, here is exactly what you need to know before clicking anything.
Coinbase and Its Partner Traced the Operation
Coinbase and its partner DarkTower traced the operation's infrastructure to a domain registered through a Hong Kong registrar, just days before the letters began arriving in mailboxes. The site itself was hosted in Romania on a network with a documented history of hosting financial phishing operations.
This was not a casual effort. The letters use official-looking IRS letterhead and design, include a fabricated enrollment deadline to create urgency, and rely on a QR code to push you past your instinct to manually type and verify a URL before visiting it.
The QR Code Is the Trap
The letter includes a QR code that redirects to a fake IRS.gov lookalike site. Once there, the site may ask for your crypto wallet credentials, exchange account login information, and personal identifying data.
That combination is enough to steal your identity and drain your digital assets. The QR code exists specifically because most people pause before typing an unfamiliar URL, but scan a code without a second thought.
The Classic Scammer Playbook Is Running Here
Three elements show up in almost every phishing operation like this: fake urgency through an enrollment deadline, design that mimics a trusted institution, and a technical mechanism, in this case a QR code, that bypasses normal skepticism.
The IRS does not initiate contact by asking you to enroll in a compliance portal via QR code. When the IRS contacts taxpayers by mail, it uses a specific notice number and instructs you to call or respond in writing, not to scan anything.
Three Rules Worth Memorizing
Do not scan QR codes from unsolicited letters. Never send crypto in response to an unexpected request. Never share your wallet recovery phrase or private keys, not from a letter, not on a phone call, not in any context.
That last one is absolute. No legitimate institution, including the IRS, Coinbase, or any exchange, will ever ask for your recovery phrase.
If You Already Clicked or Shared Information, Move Fast
Change passwords on every affected account immediately. Contact your exchange directly using the number or email on its official website. Preserve all evidence: screenshots, the original letter, any emails connected to it.
Then report the incident to IRS Criminal Investigation at IRS.gov/submitatip. Reporting matters because it helps authorities map the operation and protect other taxpayers who may receive the same letter.
Disclaimer: This post is informational only and is not intended as tax advice. For tax advice, please consult a qualified tax professional.
