
Counterfeit notices reference a bogus Digital Asset Compliance Portal and mailed QR codes designed to capture crypto or personal data, as the IRS says it does not operate the portal and warns against vishing-style follow-up attacks.
The IRS warned that scammers are mailing counterfeit notices to crypto holders that direct recipients to a nonexistent Digital Asset Compliance Portal and use QR codes tied to a spoofed site designed to steal digital assets or personal information. The agency’s Criminal Investigation unit said the IRS does not operate such a portal, is not sending the letters, and urged taxpayers not to scan QR codes from unsolicited letters, emails, or texts or engage with callers demanding payment. The campaign shows how crypto phishing is moving beyond email and text messages into physical mail. Coinbase and threat intelligence firm DarkTower flagged the scheme earlier this week, saying the letters reference tax years 2017 through 2026 and route victims to a look-alike domain registered through a Hong Kong registrar and hosted in Romania. Coinbase said the phone call that can follow is the real attack, with scammers posing as support staff and using vishing to persuade victims to hand over account access or move funds to a so-called safe wallet. The warning lands amid a broader rise in impersonation-driven fraud. Chainalysis estimated scams and fraud cost victims $17 billion in 2025, with impersonation scams up 1,400%, while TRM Labs recorded 207 hacks in the first half of 2026, more than double the 83 logged a year earlier even as total losses fell to roughly $972 million from about $2.3 billion in H1 2025.