Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called “Digital Asset Compliance Portal”?
If so, it’s time to hit the brakes, because it sounds like someone is trying to scam you.
The United States Internal Revenue Service (IRS) has issued a fraud alert after it was found that scammers are sending official-looking letters to people with cryptocurrency holdings, directing victims to a website designed to steal personal details and digital assets.
As Coinbase’s security team explains, the letters urge recipients to scan a QR code and enrol in a “Digital Asset Compliance Portal” before time runs out.

Scanning the QR code takes unsuspecting members of the public to a fraudulent website which poses as IRS.gov, but – to be absolutely clear – the IRS does not operate a Digital Asset Compliance Portal.
Coinbase described one of the letters they have seen. It arrived in an unmarked envelope, imitated a real notification from the IRS, and claiming to come from the Department of the Treasury, Internal Revenue Service, Austin, TX. The use of an official-looking notice number (CP14-432RA), and reference to the tax year range 2017–2026, would have made it appear even more plausible to many recipients.
Bear in mind that the criminals could easily vary these details from letter to letter.
The phishing page visited by potential victims continues the subterfuge with IRS-style branding and a banner claiming to be an “official website of the United States government.”

But what the site does is ask you to share where you keep your cryptocurrency (with a range of choices from hardware wallets like Ledger and Trezor to exchanges like Coinbase and Binance.)
The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to “$100,000+”. Presumably this helps the fraudsters determine which accounts to prioritise for plundering.
And then the site asks you for your phone number in order to “get verified” by a support representative. Of course, the purpose of such a call is to try and talk you into handing over the keys to your account – whether it be a password, a recovery or seed phrase, or a 2FA code.
Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders’ requirement to report details of their digital assets on their tax returns. As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.
In short, a letter from the IRS telling a US taxpayer to register their digital assets may not sound as outlandish as it might have done a few years ago.
Investigations by Coinbase’s security team and their partners at threat intelligence firm DarkTower found that the domain used in the attack had been registered just days before the fake letters were mailed out, through a Hong Kong-based registrar, with the fraudulent site itself hosted in Romania. It emerged that the site was hosted on infrastructure already associated with phishing campaigns targeting banks and financial institutions.
In other words, this does not sound like an amateur cybercriminal was at work here. The campaign has all the hallmarks of a well-organised, internationally-coordinated fraud.
So, what should you do about this threat? The advice is simple:
- If you receive one of these letters, do not scan the QR code and do not visit any website mentioned in them.
- Remember that you should never share your password, 2FA codes, or recovery/seed phrases with anyone.
- If in doubt, verify the facts independently by visiting the official IRS website at irs.gov.
- And if you believe you may have already handed over sensitive information to fraudsters, stop communicating with them, change your passwords, contact your cryptocurrency exchange immediately, preserve any evidence of communications you may have had with the scammers, and report what has happened to the IRS.

