WARNING
If you received a physical letter claiming to be from the IRS about a “Digital Asset Compliance Portal” or “DACP”: do not scan the QR code, do not visit the website, do not call any number listed. The IRS did not send it. This portal does not exist. Report it at irs.gov/submitatip.
TL;DR
▶ Fake IRS letters are being mailed to crypto holders across the US, demanding enrollment in a nonexistent Digital Asset Compliance Portal before a deadline.
▶ The IRS issued a fraud alert July 30, 2026. The scam is still active as of August 26 with letters now citing September deadlines.
▶ Coinbase and DarkTower traced the domain to a Hong Kong registrar, hosted on servers in Romania known for financial phishing.
▶ The attack runs in five steps: physical letter, QR code, fake portal, holdings profiling, then a live vishing call from a scammer posing as a compliance officer.
▶ The goal: steal your 2FA codes, exchange credentials, or seed phrase to drain your wallet.
Fake IRS letters targeting cryptocurrency holders are arriving in physical mailboxes across the United States. The letters demand recipients enroll in a “Digital Asset Compliance Portal” before a deadline or face penalties. The portal does not exist. The IRS does not send QR codes. The letters are fraudulent.
The IRS Criminal Investigation division issued an official fraud alert on July 30, 2026. As of August 26, 2026, multiple users are still reporting receiving the letters in their mailboxes, now with September deadlines rather than August ones. The campaign is ongoing. Coinbase Security and DarkTower investigated the infrastructure behind the campaign on July 28 and established this as a professional, international operation running a five-step attack sequence designed to drain crypto wallets.
What makes this scam more dangerous than a phishing email: a physical letter arriving in a plain envelope, styled to look like an official IRS notice with a real-looking notice number, a Treasury Department header, and an Austin, Texas return address, bypasses every spam filter and triggers the trained instinct to take official government correspondence seriously. Understanding the full five-step attack sequence is the most effective protection against it.
What Does the Fake IRS Letter Look Like?
The letter is printed to imitate a real IRS notice. Based on the example Coinbase published, it is styled as coming from the Department of the Treasury, Internal Revenue Service, Austin, TX with a fake notice number in the format CP14-432RA, a tax year range of 2017 to 2026, and a deadline. The specific notice number and deadline date vary across different versions. The structure is the same.
The letter claims the recipient must enroll their cryptocurrency exchanges and wallets in the Digital Asset Compliance Portal before the deadline to remain compliant with federal tax reporting requirements. It instructs them to scan a QR code to begin enrollment. The QR code leads to a domain formatted to look like an IRS subdomain, such as irs.digitalcomplianceportal[.]com, but it is not irs.gov. Early letters cited August deadlines. Versions arriving in late August now cite September deadlines, confirming the campaign is still running.
How to tell a real IRS letter from a fake one
Real IRS letters reference your specific tax account by your Social Security Number or Employer Identification Number and direct you to your IRS Online Account at irs.gov. The IRS does not send QR codes directing you to enroll in portals. It does not ask which exchange you use or how much crypto you hold. If a letter asks you to scan a QR code, visit a non-irs.gov website, or call a number not listed on the official irs.gov contact page, it is not from the IRS. Verify any IRS communication by logging into your account at irs.gov directly.
How the Five-Step Fake IRS Crypto Scam Works
Each step is engineered to make the next step feel legitimate. Coinbase Security and DarkTower tested the full attack flow using a burner phone number.
The Fake IRS Crypto Scam: How It Flows
Source: IRS-CI fraud alert July 30 2026, Coinbase Security investigation | @cryptonewsbytes
✉ Physical Letter Arrives
Official-looking IRS notice. Treasury letterhead. Fake notice number (e.g. CP14-432RA). Tax years 2017-2026. Enrollment deadline. Not from the IRS.
Victim scans the QR code
🔗 QR Code Opens Fake IRS Website
Site looks like irs.gov. “Official website of the United States government” banner. IRS branding. Domain registered in Hong Kong. Hosted in Romania. Not irs.gov.
Victim clicks “Get Started”
📈 Portal Asks Which Exchange You Use
Logos: Coinbase, Kraken, Binance, Ledger, Trezor. Looks like a compliance form. Reality: scammers profiling which platform to impersonate when they call.
Victim selects their exchange
💵 Portal Asks Holdings Value
Ranges up to $100,000 and above. Feels like a tax form. Reality: scammers prioritising high-value targets for the follow-up call.
Victim enters phone number
📞 The Real Attack: Vishing Call
A scammer calls posing as an IRS compliance officer or exchange support. Armed with your name, exchange, and balance range. Goal: steal your 2FA code, password, or seed phrase to drain your wallet. This is the actual attack.
Outcome: Wallet Drained
Crypto transfers are irreversible. Once a seed phrase or 2FA code is shared, account takeover happens in seconds. Funds cannot be recovered.
Source: IRS-CI fraud alert July 30 2026, Coinbase Security and DarkTower investigation July 28 2026 | @cryptonewsbytes
Step 1: Physical Letter
A letter arrives that looks like an official IRS notice with a Treasury Department header, a notice number, a tax year range, and an enrollment deadline. The physical format is deliberate. Most people apply more trust to physical mail than to email, and physical letters bypass spam filters entirely.
The IRS has been increasing crypto reporting requirements, which makes a compliance letter feel plausible in 2026 in a way it would not have three years ago.
Step 2: QR Code and Fake Portal
Scanning the QR code takes you to a website engineered to look exactly like irs.gov, complete with the ‘official website of the United States government’ banner and IRS branding. The site prompts you to click ‘Get Started’ to begin enrollment.
The domain was registered days before the letters were mailed through a Hong Kong registrar. The site was hosted in Romania on infrastructure DarkTower had previously identified hosting FedEx and banking phishing pages.
Step 3: Exchange and Wallet Profiling
The portal asks which cryptocurrency exchanges and wallets you use, showing logos for Coinbase, Kraken, Binance, Ledger, Trezor, and others. This tells the scammers which platform to impersonate when they call you.
This step feels like a compliance form. It is the scammers building a target profile of exactly where your funds are held.
Step 4: Holdings Valuation
The site asks for the estimated value of your holdings, with ranges up to $100,000 and above. This lets the scammers prioritise high-value targets for the follow-up call.
Legitimate tax compliance never requires you to estimate and self-report holdings to a portal. The IRS has your tax filings. It does not need you to tell it how much crypto you own.
Step 5: Phone Number Harvest and the Vishing Call
The portal asks for your phone number so a ‘representative’ can call to complete your verification. When DarkTower entered a burner number and clicked continue, the site went dark. The call is the actual attack: a scammer posing as an IRS compliance officer or exchange support representative attempts to obtain your 2FA code, password, or seed phrase.
Armed with your name and address from the mailing, the exchange you use, and an estimate of your balance, the caller sounds credible. This is vishing, voice phishing, and it is one of the most effective account-takeover techniques used against crypto holders in 2026.
What Is Vishing and Why Does It Work on Crypto Holders?
What is vishing?
Vishing is voice phishing conducted by phone. Unlike email phishing, which relies on you clicking a link, vishing relies on a real person talking to you in real time. The caller uses information gathered in earlier steps, your name, your exchange, your estimated balance, to sound like a legitimate support representative. They create urgency, claim your account is at risk, and guide you through steps that hand them control. The most valuable targets in crypto vishing are seed phrases and 2FA codes, because either one provides full, irreversible access to a wallet or exchange account.
Crypto holders are specifically targeted for three reasons. First, cryptocurrency transactions are irreversible. Once funds leave a wallet they cannot be recalled. Second, a single credential can unlock significant uninsured assets. Third, the novelty of crypto tax compliance in 2026, particularly around the GENIUS Act and CLARITY Act reporting requirements, makes a letter about compliance obligations feel credible.
The specific mechanics: the caller posing as a compliance officer claims your account has been flagged for review and needs verification. They ask you to read them a one-time code sent to your phone. That code is your 2FA code. Reading it gives them full control of your account. Alternatively they may claim your wallet needs to be moved to a “protected government wallet” and ask for your 12-word seed phrase. No government wallet exists. Sharing the seed phrase transfers every asset in your wallet to the caller permanently.
Who Is Behind This? The Infrastructure Coinbase and DarkTower Found
DarkTower’s investigation confirmed this is a professional, coordinated operation. The look-alike domain was registered just days before the letters were mailed through a Hong Kong registrar. The site was hosted in Romania on a network DarkTower had previously identified hosting phishing pages impersonating FedEx and multiple financial institutions. IRS-CI Chief Jarod Koopman described it on July 30: “Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.”
The source of the physical mailing list of crypto holders’ home addresses is not confirmed in either the IRS alert or the Coinbase investigation. Possible sources include data from prior exchange breaches, purchased dark web data sets, and public blockchain analytics correlated to real-world identities through KYC data exposed in previous incidents. The DOJ $25M crypto fraud seizure CNB covered in July 2026 involved fraud networks that trade victim data across operations, and that cross-contamination of victim lists is a documented feature of organised crypto fraud in 2026.
The campaign running from late July into late August with updated deadlines confirms the operation is active and adapting. The scammers are reprinting letters with new deadlines as earlier versions expire. That level of operational maintenance, updating physical mail campaigns with new deadline dates, is consistent with a professional fraud operation rather than a one-time effort.
What to Do If You Received a Fake IRS Crypto Letter
What to Do: Complete Checklist
Do not scan the QR code
The QR code leads to a fraudulent website. If you already scanned it but did not enter any information, you are likely safe. If you entered any information, act immediately.
Do not visit the website in the letter
Any domain that is not exactly irs.gov is not the IRS. The real IRS website has no subdomains with words like ‘compliance’ or ‘portal’.
Do not call any number in the letter
The IRS’s official contact numbers are listed at irs.gov. Any number in this letter is a scammer’s line.
Never share 2FA codes, passwords, or seed phrases
No government agency, exchange, or compliance programme will ever ask for these. If someone asks, it is a scam regardless of how official they sound.
If you already entered information, act immediately
Change your exchange passwords. Confirm and update your 2FA. Contact your exchange’s official support through its app or official website. If you shared your seed phrase, move all funds to a new wallet immediately and treat the original wallet as permanently compromised.
Report it
Report to IRS-CI at irs.gov/submitatip. Report to the FTC at reportfraud.ftc.gov. Preserve the letter, envelope, and any screenshots.
Source: IRS fraud alert July 30 2026, Coinbase Security July 28 2026 | @cryptonewsbytes
What the IRS Will and Will Never Do
The IRS Will NEVER
Send a QR code directing you to enroll your crypto exchange in a portal
Ask which exchange or wallet you use or how much crypto you hold to stay compliant
Call, text, or email asking for your password, 2FA code, or seed phrase
Ask you to move funds to a protected, government, or safe wallet
Pressure you with a countdown or deadline to act immediately
The IRS WILL
Mail official notices to your address on file referencing your specific tax account
Direct you to irs.gov for all account information, payments, and correspondence
Give you time to respond and allow you to verify any notice through your IRS Online Account at irs.gov
Frequently Asked Questions
Is the Digital Asset Compliance Portal real?
No. There is no IRS Digital Asset Compliance Portal or DACP. This programme does not exist. Any letter, QR code, or website referencing one is fraudulent.
I got a fake IRS letter about crypto with a QR code. Is it a scam?
Yes. If the letter instructs you to scan a QR code, enroll your exchange, or verify your holdings by a deadline, it is a scam. Do not scan it. Verify any IRS communication by logging into your IRS Online Account directly at irs.gov.
Is the scam still active in August 2026?
Yes. Multiple users reported receiving letters in late August 2026 with September deadlines, confirming the campaign is still running. The scammers are updating the deadline dates as earlier versions expire.
I scanned the QR code but did not enter any information. Am I at risk?
Scanning and visiting the site without entering anything is unlikely to have compromised your accounts. The risk begins when you enter your phone number, exchange selection, or any other data. Monitor your accounts and do not take any calls related to the letter.
I already entered my phone number and selected my exchange. What should I do?
Assume the scammers know which exchange you use and your approximate balance. Be alert for calls from anyone claiming to be from the IRS, your exchange, or a compliance portal. Do not share any codes, passwords, or seed phrases. Contact your exchange through its official app to review recent activity.
I shared my seed phrase. What do I do?
Move all funds out of that wallet immediately to a new wallet whose seed phrase has never been shared. Use a hardware wallet or generate a completely new software wallet. The original wallet should be treated as permanently compromised. Contact your exchange’s official fraud support.
How do I verify a real IRS notice?
Log into your IRS Online Account at irs.gov. All genuine IRS notices appear there. You can see your balance, correspondence history, and any pending issues. If a letter about your account does not appear in your IRS Online Account, treat it as suspicious and contact the IRS using a number from irs.gov only, not from the letter.
Further Reading
The July 21 DOJ seizure covering pig butchering, romance scams, and recovery fraud. The same networks that run those operations also trade victim mailing lists used in campaigns like this one.
The Hacken Q2 2026 report on how crypto is lost in 2026. Social engineering and vishing are classified as operational failures and account for the majority of losses by dollar value.
Sources: IRS Criminal Investigation fraud alert July 30 2026 (primary: irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders), Coinbase Security and DarkTower investigation July 28 2026 (primary: coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam), CryptoTimes August 21 2026 (August continuation coverage), FTC report portal (reportfraud.ftc.gov), IRS submit a tip portal (irs.gov/submitatip) | Published August 26, 2026 | CryptoNewsBytes.com | Not financial or legal advice.

