CRBC News
Security

IRS Warns: Fake Tax Letters With QR Codes Target U.S. Crypto Holders

IRS Warns: Fake Tax Letters With QR Codes Target U.S. Crypto Holders
Photo Credit: Getty Images

The IRS warns of a mail-fraud scheme that sends IRS-style letters with QR codes to U.S. crypto holders, directing them to a fake "Digital Asset Compliance Portal" designed to steal exchange and wallet data. Researchers traced the fraudulent domain to a Hong Kong registrar and Romanian hosting, and the FBI IC3 reported over $11 billion in crypto-related losses in 2025 with about 181,500 complaints. Do not scan suspicious QR codes—report such mail to the IRS and the FBI, change passwords if compromised, and consider a credit freeze if you shared sensitive personal data.

A new mail-fraud campaign is targeting U.S. cryptocurrency owners with convincing, IRS-style letters that include QR codes linking to a bogus "Digital Asset Compliance Portal." The fake portal is designed to harvest exchange account details, wallet information, passwords, and two-factor authentication codes.

How the Scam Works

According to reporting by AOL and an IRS Criminal Investigation, an international operation has been mailing letters that closely resemble legitimate IRS notices and instruct recipients to register on the purported compliance site. Scanning the embedded QR code routes victims to a cloned website that requests sensitive personal and financial data.

After data is submitted, fraudsters often follow up with phone calls impersonating IRS agents and ask for additional credentials—such as account passwords, 2FA codes, or private keys—to gain direct access to crypto holdings.

Jarod Koopman, Chief of IRS Criminal Investigation: "Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence."

Technical Tracing And Scale

Researchers working with Coinbase and cyberdefense firm DarkTower traced the fraudulent domain to a Hong Kong registrar and hosting to a Romanian server location previously linked to other impersonation schemes targeting banks and delivery services.

This campaign emerges amid large-scale crypto fraud: the FBI's Internet Crime Complaint Center (IC3) reported that cryptocurrency-related complaints were tied to more than $11 billion in losses in 2025, with roughly 181,500 complaints that year.

Why This Is Dangerous

Even a single QR-code scan or a rushed response to an official-looking letter can expose exchange accounts, wallet access, and broad personal information. If Social Security numbers or other sensitive identifiers are disclosed, the resulting identity theft can extend far beyond loss of cryptocurrency.

What The IRS Says

The IRS has emphasized that no legitimate "Digital Asset Compliance Portal" exists. The agency will not initiate contact asking for wallet addresses, exchange credentials, private keys, or seed phrases via unsolicited letters or QR-linked sites.

What To Do If You Receive One

  • Do not scan the QR code or click links in suspicious letters.
  • Stop communicating with the sender and report the mailer to the IRS and the FBI IC3 tipline. You can verify information on the official IRS website at IRS.gov.
  • If you think an exchange account is compromised, contact the exchange immediately and change passwords and recovery options.
  • If you shared personal identifiers (Social Security number, birthdate, etc.), consider placing a credit freeze and using identity-protection services.
  • Monitor accounts and consider enabling hardware 2FA for added security; never share private keys or seed phrases with anyone.

Final Advice

Scam letters, texts, and emails often use urgency and the appearance of official authority to short-circuit careful decision-making. Verify before you respond: check domain names, contact agencies through official channels, and treat any unsolicited government-style notice with skepticism.

Help us improve.

Related Articles

Trending