The IRS has alerted crypto holders about a new scam involving counterfeit letters sent through the mail. These letters claim recipients must sign up on a so-called “Digital Asset Compliance Portal” by a certain deadline. In reality, the IRS does not operate any such portal nor send these notices. The fraudulent letters include QR codes that lead to a fake website designed to steal personal data and digital assets.

The IRS’s Criminal Investigation unit issued the warning after Coinbase and DarkTower flagged the scam. The fake site prompts users to enter sensitive information once the QR code is scanned. The domain behind it was registered in Hong Kong and hosted in Romania, indicating a global cybercrime operation. Users are urged not to scan QR codes from unsolicited letters, emails, or texts, and to hang up on calls demanding immediate payments.

Scammers often use “vishing” tactics, posing as support agents to trick victims into transferring funds to wallets they control. This physical mail approach marks a shift from typical crypto phishing attacks that usually happen via email or text messages. It highlights how attackers increasingly target human vulnerabilities instead of exploiting technical weaknesses.

Crypto fraud continues to surge, with impersonation scams rising by 1,400% and total losses in the sector reaching billions. According to Chainalysis, victims lost an estimated $17 billion to scams in 2025. Meanwhile, hacking incidents remain high, though losses have decreased, suggesting that criminals are focusing more on social engineering than pure code exploits. The IRS scam demonstrates that this shift now extends beyond digital channels into physical mailboxes.