Cryptocurrency investors across the United States are continued being targeted by a sophisticated mail-based phishing campaign that impersonates the Internal Revenue Service (IRS).
Fraudsters are sending official-looking paper notices that claim recipients must enroll in a nonexistent “Digital Asset Compliance Portal,” complete with QR codes designed to harvest personal data and crypto credentials.
The Internal Revenue Service first issued a formal fraud alert on July 30, 2026, stating clearly that it does not operate any such portal and that the letters are entirely fraudulent.
The scam has continued into mid-to-late August, with multiple users publicly sharing photos and accounts of receiving the counterfeit notices in their physical mailboxes. Earlier coverage by The Crypto Times on July 31, 2026, highlighted the shift of crypto-related fraud from purely digital channels into traditional postal mail, noting how scammers exploit growing IRS scrutiny of digital assets to make the fakes appear credible.
How the Scam Works and What Victims Are Seeing
The letters closely mimic legitimate IRS correspondence. They typically reference tax years spanning 2017 through 2026, carry a fabricated notice number, and impose an urgent deadline—often in early or mid-September—for enrollment. A prominent QR code is included with instructions to scan it using a mobile device to access the supposed Digital Asset Compliance Portal.
Scanning the code directs users to a phishing website designed to look like an official IRS page. Victims are then prompted to provide personal identification details, estimates of their crypto holdings, exchange account credentials, wallet information, and in some cases recovery phrases or private keys. Follow-up phone calls from individuals posing as IRS representatives have also been reported, further pressuring targets to share sensitive data or move funds.
Recent firsthand reports on X illustrate the ongoing reach of the campaign. On August 14, trader @OddStockTrader posted that he had “Got the FAKE IRS DACP Letter,” describing the quality of the forgery as alarmingly high. On August 17, user @imjgalt2 shared a photo of the notice and warned that it looked “totally legit,” suggesting the scammers may have obtained addresses from data breaches involving crypto exchanges.
More recently on August 19, User @woodificouldart posted images of the letter that arrived at his home, noting that the paper quality and timing felt suspicious and confirming that the IRS had already listed the portal as a scam.
These accounts align with earlier findings by Coinbase and cybersecurity firm DarkTower, which traced the underlying infrastructure to a domain registered shortly before the letters began circulating and hosted on networks previously linked to financial phishing operations.
Official Guidance and How to Stay Safe
In its July 30 alert, IRS Criminal Investigation Chief Jarod Koopman emphasized that criminals continue to exploit public trust in government agencies through convincing fake websites and correspondence. The agency has reiterated that it never initiates contact by demanding enrollment in online portals via QR codes, nor does it request wallet recovery phrases, private keys, or immediate transfers of digital assets.
Multiple warnings by users on X stated that those who receive one of these letters are advised not to scan the QR code, call any phone numbers printed on the notice, or provide any information. Instead, they should verify communications directly through the official IRS website at IRS.gov or by contacting the agency using published phone numbers.
Also read: Poolin Auction Set for September 10 as Objection Deadline Bars Late Creditors
