IRS warns crypto holders of fake letters and QR scams
IRS warns mailed counterfeit notices direct crypto holders to a fake portal via QR codes that request wallet details, exchange logins, recovery phrases and private keys.
On July 30 the Internal Revenue Service issued an alert warning cryptocurrency holders about counterfeit letters mailed to taxpayers. The notices instruct recipients to register with a fake “Digital Asset Compliance Portal” and include QR codes that lead to sites designed to resemble IRS.gov. Those pages request wallet information, exchange logins, recovery phrases, private keys and other personal details, and the letters impose deadlines to create a false sense of urgency.
Investigators from crypto exchange Coinbase and cybersecurity firm Darktower traced parts of the operation to a domain registered through a Hong Kong registrar shortly before the mailings. The fake portal was hosted on servers in Romania, which the IRS reported were previously used for phishing pages impersonating financial institutions.
The IRS advised recipients not to scan unsolicited QR codes, open unexpected links or provide account credentials in response to mail they did not request. It recommended using the secure IRS Online Account, comparing the notice to recognized formats or contacting IRS customer service to confirm whether a notice is legitimate.
Jarod Koopman, IRS Criminal Investigation chief, advised: “Before responding to unexpected requests for personal information, stop, verify the source, and report potential fraud schemes to law enforcement.”
Federal agencies and security firms have issued related warnings. The FBI cautioned that unsolicited QR codes can lead to phishing websites or prompt users to download malware. The Federal Trade Commission warned that scammers sometimes demand cryptocurrency payments through QR codes or crypto ATMs. A separate alleged impersonation scheme that targeted Coinbase customers reportedly affected about 100 victims and resulted in nearly $16 million in losses after funds were moved to attacker-controlled wallets.
The IRS advised anyone who has provided credentials or private keys to change passwords immediately, notify their cryptocurrency exchange or financial institution, preserve any messages or letters, and monitor accounts for unauthorized activity. The agency also recommended enabling multifactor authentication and reiterated that recovery phrases and private keys should never be disclosed in response to a compliance request.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.








