IRS Warns Fake Crypto Letters Target Wallets and Personal Data
The Internal Revenue Service (IRS) issued a fraud alert on July 30 about fake letters targeting cryptocurrency holders. The letters instruct recipients to register through a nonexistent ‘Digital Asset Compliance Portal’ before an urgent deadline, creating pressure to act without verifying the demand.
Each fraudulent letter contains a QR code directing recipients toward a website designed to resemble IRS.gov and collect valuable account information. The counterfeit portal may request personal details, cryptocurrency wallet information, exchange credentials, recovery phrases, private keys, or other data capable of enabling theft.
IRS Criminal Investigation (IRS-CI) Chief Jarod Koopman warned: ‘Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence. Before responding to unexpected requests for personal information, stop, verify the source, and report potential fraud schemes to law enforcement.’
Cryptocurrency exchange Coinbase and cybersecurity firm Darktower traced the operation’s infrastructure to a domain registered through a Hong Kong registrar shortly before the letters circulated. Investigators found the website hosted in Romania on a network previously associated with phishing pages impersonating financial institutions.
The IRS warns that unsolicited QR codes and urgent deadlines are common signs of fraud. Official IRS guidance also identifies unexpected messages, threats, financial pressure, and requests for personal information as warning signs of impersonation. The agency advises recipients not to scan unsolicited QR codes, open suspicious links, or share account credentials before verifying the correspondence through official IRS channels.
Taxpayers receiving suspicious letters can check their secure IRS Online Account, review recognized notice formats, or contact customer service directly for authentication. Fraudulent letters, emails, texts, websites, social media accounts, and telephone calls can be reported through the agency’s channels for reporting fake tax-related communications.
Anyone who disclosed credentials should immediately change affected passwords, notify the relevant financial institution or cryptocurrency exchange, preserve messages and letters, and monitor accounts. The IRS also recommends multifactor authentication, while wallet holders should never disclose recovery phrases or private keys under any claimed compliance requirement.
The FBI has also warned that unsolicited QR codes can direct users to phishing websites or prompt them to download malicious software. The Federal Trade Commission has cautioned that scammers posing as government officials often demand cryptocurrency payments through QR codes or crypto ATMs.