IRS Warns Crypto Holders about Fake Official Letters Targeting Digital Assets Holdings and Personal Data

The US Internal Revenue Service (IRS) has issued a fresh warning to cryptocurrency owners about a sophisticated mail-based fraud campaign. Criminals are circulating counterfeit notices that closely resemble official agency correspondence, with the goal of tricking recipients into surrendering personal details or digital assets.

According to the agency’s Criminal Investigation division, the phony letters urge taxpayers to register for something called the “Digital Asset Compliance Portal” ahead of an impending deadline.

No such portal exists. Recipients are instructed to scan a QR code printed on the notice, which leads them to a carefully crafted website designed to look like the real IRS.gov site.

Once there, victims may be prompted to supply personal identifying information, cryptocurrency wallet details, exchange login credentials, or other sensitive data.

Fraudsters can then use that information to drain accounts or commit identity theft.

IRS Criminal Investigation Chief Jarod Koopman noted that offenders continue to capitalize on public confidence in government institutions by producing highly convincing counterfeit materials and websites.

He advised anyone who receives an unexpected request for private information to pause, independently confirm the source, and report any suspected fraud to authorities.

The letters reportedly reference tax years spanning a wide range, lending an air of legitimacy by appearing to address a taxpayer’s complete digital-asset history.

They often arrive in ordinary envelopes, further reducing immediate suspicion. Security researchers working with Coinbase and the firm DarkTower traced the supporting online infrastructure to a domain registered only days before the mailings began, using a Hong Kong registrar.

The phishing site itself was hosted on a Romanian network previously linked to similar financial phishing operations.Officials emphasize several protective steps.

Never scan QR codes contained in unsolicited mail, emails, or texts that claim to come from a government body.

If someone telephones claiming to represent the IRS and requests payment or personal data, hang up and contact the agency directly through numbers listed on its official website.

Avoid sharing wallet recovery phrases or private keys under any circumstances.

Monitor accounts closely, enable multi-factor authentication, and report suspicious activity promptly.

Anyone who has already interacted with such a letter should cease communication immediately, change relevant passwords, notify financial institutions or exchanges if credentials were shared, retain copies of the materials, and submit a tip through the IRS Criminal Investigation reporting portal.

The scheme highlights how physical mail can still circumvent purely digital security measures.

As the IRS continues to expand its focus on digital-asset reporting, the volume of legitimate correspondence has increased, making fraudulent notices harder to spot at first glance. Taxpayers are urged to treat any unexpected demand for enrollment, QR-code scanning, or credential sharing with extreme caution and to verify every claim through independent official channels.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend