Newsroom
1 August, 2026 / News / AI / Tags: notices, taxpayers, correspondence, letters, portal

The agency’s Criminal Investigation unit alerts taxpayers that counterfeit notices direct recipients to a nonexistent compliance portal via QR codes designed to harvest information
The U.S. Internal Revenue Service has issued a fraud alert after scammers began mailing counterfeit official letters to cryptocurrency holders in an effort to steal personal data and digital assets. The scheme centers on a fabricated Digital Asset Compliance Portal that the agency confirmed does not exist.
Recipients receive paper correspondence that mimics legitimate IRS formatting and includes a deadline for action. The notices instruct taxpayers to enroll in the nonexistent portal. Each letter contains a QR code that, when scanned, routes users to a spoofed website designed to collect personal details, wallet information, or exchange credentials. In some instances, the process may prompt transfers of cryptocurrency holdings to accounts controlled by the fraudsters.
Investigators noted that the letters reference tax years spanning 2017 through 2026. The look-alike domain was registered through a Hong Kong-based registrar and hosted in Romania. The use of physical mail represents a shift from the more common digital phishing methods that have long targeted the crypto sector.
The IRS has mailed genuine educational and compliance notices about digital asset activity since 2019, including more than 10,000 letters in earlier campaigns and a more recent increase in notices tied to crypto reporting requirements. As a result, correspondence from the agency about cryptocurrency no longer strikes many taxpayers as unusual. The agency has heightened scrutiny of digital asset disclosures on tax returns, further lending credibility to the idea of a formal compliance portal.
Officials stressed several clear distinctions. The IRS does not include QR codes in any authentic correspondence. It never requires taxpayers to transfer digital assets as part of a compliance process, and it operates no enrollment portal for digital assets. Legitimate notices can be confirmed through the agency’s official website or by calling numbers listed there.
Taxpayers who receive such a letter should refrain from scanning any QR code and avoid calling telephone numbers printed on the document. Personal information should never be entered on sites reached through links or codes in unsolicited mail. Account status can be checked using tools available on the agency’s own website. Suspicious activity may be reported through the designated tip submission channel on that site.
Private-sector firms have also flagged the campaign. One major exchange described a related voice-phishing tactic in which a caller posing as support attempts to persuade victims to move funds into a supposedly secure wallet under the scammer’s control.
The mailing campaign forms part of a larger rise in impersonation-driven fraud. One analytics firm estimated that scams and related schemes cost victims $17 billion in 2025, with impersonation cases increasing sharply. Separately, researchers recorded more than 200 hacks in the first half of 2026, more than double the prior-year figure for the same period, though total losses declined. The pattern indicates a growing focus on human targets rather than purely technical exploits.
Physical approaches have appeared in other forms as well, including so-called wrench attacks that rely on force or threats to obtain cryptocurrency. The IRS alert underscores that official-looking mail now joins the list of vectors used against digital asset holders.
No specific token prices or exchange operations have been disrupted by the letter campaign itself. The primary risk remains individual loss of funds or data for those who follow the instructions contained in the counterfeit notices.









