← Back to News
Fake IRS letters direct crypto holders to bogus compliance portal

Fake IRS letters direct crypto holders to bogus compliance portal

Fake IRS letters direct crypto holders to bogus compliance portal - Help Net Security Help Net Security newsletters:

Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here! News Features CISO AI

Videos Product showcase Industry news Reviews Whitepapers Events Newsletters Please turn on your JavaScript for this

page to function normally. Sinisa Markovic, Managing Editor, Help Net Security August 4, 2026 Share Fake IRS letters

direct crypto holders to bogus compliance portal Scammers are sending physical letters to cryptocurrency holders that

copy the look of official IRS notices. The letters tell recipients they must enroll in something called a Digital Asset

Compliance Portal before a deadline, or risk penalties. “If you receive a letter claiming to be from the IRS that

instructs you to enroll in a Digital Asset Compliance Portal, don’t respond. The IRS did not send it. The IRS does

not operate a Digital Asset Compliance Portal. This is a scam,” IRS wrote. Coinbase, working with threat intelligence

firm DarkTower, published its own breakdown of the scheme after a customer reported receiving one of the letters.

DarkTower traced the site’s infrastructure to a domain registered through a Hong Kong registrar only days before

the letters went out, hosted in Romania on infrastructure previously linked to phishing pages impersonating banks and

delivery services. How the letter works The letter arrives in a plain envelope at a home address, styled with Treasury

and IRS branding, a notice number, a tax year range, and a deadline meant to push the recipient into acting before

thinking it through. It also includes a QR code. Scanning it leads to a site that copies the look of a government

portal, down to an “official website of the United States government” banner. From there, the scam unfolds

in stages. The visitor is asked to pick which exchange or wallet they use, then to estimate the value of their holdings,

then to enter a phone number so a “representative” can call to finish the “verification.” The

fake “Digital Asset Compliance Portal (DACP)” landing page (Source: Coinbase) “That phone call is the

actual attack,” Coinbase noted. Posing as support staff, they push the victim to hand over a one-time code, a

password, or a seed phrase, or to move funds into a “safe” wallet they control. DarkTower tested the flow

using a burner phone number. After clicking continue, the site went dark. No callback came, and no further page loaded.

According to Coinbase, that leaves two possibilities open. Either the call is meant to come later, or the phone number

and exchange choice are harvested for a future social engineering attempt. Anyone who already entered information should

change their exchange password, check their two-factor setup, and contact the exchange through its own app or site

rather than a number supplied in the letter or by a caller. Screenshots, letters, and emails are worth keeping as

evidence. “Criminals continue to exploit public trust in government agencies by creating convincing fake websites

and official-looking correspondence,” said IRS Criminal Investigation (IRS-CI) Chief Jarod Koopman. “Before

responding to unexpected requests for personal information, stop, verify the source, and report potential fraud schemes

to law enforcement,” Koopman added. More about Coinbase cryptocurrency scams Social engineering Share Featured news

Future AGI: Open-source platform for shipping self-improving AI agents What stops attackers wrecking industrial plants

is knowing how Digital executive protection is a strategic imperative for CEOs Download: The ultimate guide to network

operations management Resources Download: The High-Performance Team Playbook Simplify security management with CIS

SecureSuite Platform Download: The IT and security field guide to AI adoption Don't miss Future AGI: Open-source

platform for shipping self-improving AI agents What stops attackers wrecking industrial plants is knowing how Digital

executive protection is a strategic imperative for CEOs OWASP’s subtractive security project measures the attack

paths you erased Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials

Cybersecurity news HNS Daily Daily newsletter sent Monday-Friday HNS Newsletter Weekly newsletter sent on Mondays

InSecure Newsletter Editor's choice newsletter sent twice a month Cybersecurity news alerts Periodical newsletter

released for important security events and breaking news Cybersecurity jobs Weekly newsletter listing new cybersecurity

job positions Open source Monthly newsletter focusing on open source cybersecurity tools Subscribe I have read and agree

to the terms & conditions © Copyright 1998-2026 by Help Net Security Read our privacy policy | About us | Advertise

Follow us ×

Source: www.helpnetsecurity.com