The Internal Revenue Service (IRS) has warned cryptocurrency holders about counterfeit letters directing recipients to a fake compliance website designed to steal sensitive financial and personal information.
The scam correspondence tells recipients to register through a fictitious “Digital Asset Compliance Portal” before an urgent deadline. The language is intended to create pressure and encourage people to act before checking whether the demand is genuine.
The IRS issued its fraud alert on 30 July, amid increasingly sophisticated attempts to impersonate government agencies and target digital-asset investors.
Each letter contains a QR code that directs users to a website made to look like IRS.gov. The counterfeit portal can request personal details, cryptocurrency wallet information, exchange login credentials, recovery phrases, private keys and other information that could allow criminals to gain access to funds.
The alert said unsolicited QR codes and urgent deadlines were common warning signs of fraud. Official IRS guidance on tax scams also identifies unexpected messages, threats, financial pressure and demands for personal information as indicators of impersonation.
Recipients are advised not to scan QR codes received unexpectedly, open suspicious links or provide account credentials until the letter has been authenticated through official IRS channels.
Investigation traces website infrastructure
Crypto exchange Coinbase (Nasdaq: COIN) and cybersecurity firm Darktower traced the operation’s infrastructure to a domain registered through a Hong Kong registrar shortly before the letters began circulating.
According to the agency, the fraudulent website was hosted in Romania on a network previously linked to phishing pages impersonating financial institutions.
Taxpayers who receive suspicious correspondence can check their secure IRS Online Account, compare the document with recognised notice formats or contact IRS customer service directly. The agency’s guidance on determining whether a notice is legitimate sets out those verification methods.
Fake tax-related letters, emails, text messages, websites, social media accounts and telephone calls can also be reported through the IRS channels for reporting fraudulent communications.
The warning comes as impersonation scams continue to target customers of cryptocurrency exchanges. Criminals have used spoofed telephone calls, texts, emails, fabricated security alerts and false claims that digital assets must be moved immediately for protection.
A separate alleged Coinbase impersonation scheme involving about 100 victims allegedly resulted in the theft of nearly $16m after users transferred funds to wallets controlled by attackers.
Anyone who has disclosed login details should change the affected passwords immediately, notify the relevant bank or cryptocurrency exchange, preserve the messages and letters involved, and monitor their accounts for suspicious activity.
The IRS recommends using multifactor authentication. Cryptocurrency wallet holders are also advised never to disclose recovery phrases or private keys in response to any claimed compliance requirement.
Other government agencies have issued similar warnings as criminals increasingly combine official impersonation with cryptocurrency fraud.
The FBI has said unsolicited QR codes can lead users to phishing websites or prompt them to download malicious software. The Federal Trade Commission has separately warned that scammers posing as government officials may demand cryptocurrency payments through QR codes or crypto ATMs.
Some members of the cryptocurrency community assumed the IRS was reversing its reporting requirements, but all requirements remain firmly in place.
