Scammers are mailing physical letters to cryptocurrency holders that impersonate the IRS and U.S. Treasury, claiming recipients must register with a bogus Digital Asset Compliance Portal. The letters include a QR code that leads to a fake IRS-branded site asking for exchange or wallet provider details, estimated crypto holdings, and phone numbers. The IRS said it did not send the letters and does not operate any such portal, while reporting indicates the campaign was uncovered after a customer report to Coinbase.
Infrastructure analysis tied the phishing site to a recently registered domain using a Hong Kong-based registrar and hosting in Romania on systems previously associated with phishing pages targeting banks, financial institutions, and delivery services. Investigators said the web form likely serves as a lead-generation step for follow-on phone fraud, with impostors posing as support staff to steal one-time passcodes, passwords, seed phrases, or to pressure victims into transferring assets to attacker-controlled wallets.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The IRS publicly stated that it did not send the letters and does not operate any "Digital Asset Compliance Portal." IRS Criminal Investigation officials warned that criminals were exploiting trust in government branding and urged people to verify unexpected requests for personal information.
DarkTower assisted with threat intelligence analysis and traced the scam site to hosting in Romania. It also linked the infrastructure to prior phishing pages impersonating banks, delivery services, and other financial targets.
Coinbase published an analysis of the campaign after a customer reported receiving one of the fraudulent letters. Its review concluded that the fake portal was likely used to set up the real attack stage: a follow-up phone call by impostors seeking credentials, one-time codes, seed phrases, or fund transfers.
Investigators found the malicious domain used in the campaign had been registered only days before the fake letters were mailed. The domain was registered through a Hong Kong-based registrar.
A fraud campaign sent physical letters to cryptocurrency holders that impersonated IRS or Treasury notices and claimed recipients had to enroll in a "Digital Asset Compliance Portal" or face penalties. The letters used official-looking branding, notice details, and a QR code to drive victims to a phishing site.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
bitdefender.com
Open sourcehelpnetsecurity.com
Open sourcecoinbase.com
Open sourceirs.gov
Open sourceirs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.