🚨 Fake IRS letters target crypto holders with QR codes and a phony “Digital Asset Compliance Portal” 🚨
Criminals are mailing IRS-style letters that direct crypto holders to a fraudulent website designed to steal personal information, exchange credentials, wallet data, and potentially private keys.
🔑 Key points
🔹 Official-looking letters: The scam uses government-style notices to create urgency and pressure recipients into acting quickly.
🔹 Fake compliance portal: The letters promote a nonexistent “Digital Asset Compliance Portal.”
🔹 QR codes lead to phishing sites: Scanning the code sends victims to an imitation website that requests financial and personal details.
🔹 Follow-up calls may occur: After information is submitted, scammers may impersonate IRS officials and request passwords, two-factor codes, wallet addresses, or private keys.
🔹 No legitimate portal exists: The IRS says it does not operate a “Digital Asset Compliance Portal.”
🔹 Website domain is a giveaway: The fraudulent site does not use the official IRS.gov domain.
🔹 International infrastructure was identified: Researchers linked the fake site to a Hong Kong registrar and Romanian hosting associated with other impersonation campaigns.
🔹 Crypto losses are already massive: FBI data reportedly tied more than $11 billion in losses to cryptocurrency-related complaints during 2025.
🔎 Why it matters
🔹 Physical mail is becoming a serious attack channel because people may trust official-looking letters more than emails or text messages.
🔹 QR codes bypass normal browsing habits and can send victims directly to convincing phishing sites.
🔹 A crypto scam can cause damage beyond wallet theft if victims also provide Social Security numbers, banking details, passwords, or identity documents.
🔹 The strongest defense is simple: government agencies will not ask for private keys, seed phrases, or exchange passwords.
🎯 Bottom line: Do not scan QR codes or respond to letters referencing a “Digital Asset Compliance Portal.” Verify independently through IRS.gov, report suspicious activity to the IRS and FBI’s IC3, contact your exchange if credentials may be exposed, and immediately change passwords if you already interacted with the scam.
https://www.thecooldown.com/green-business/fake-irs-letters-crypto-compliance-portal-scam/