U.S. Tax Service Details New Cryptocurrency Fraud Scheme

cryptonews.ruPublished on 2026-07-31Last updated on 2026-07-31

Abstract

The U.S. Internal Revenue Service (IRS) has warned of a new cryptocurrency fraud scheme. Scammers are sending paper letters impersonating official U.S. Department of the Treasury and IRS correspondence. These letters urge Americans to urgently register on a non-existent platform called the "Digital Asset Compliance Portal." The fraudulent letters contain QR codes linking to a phishing website disguised as the official IRS site. Victims are prompted to disclose their cryptocurrency exchange or wallet provider (examples given include Coinbase, Kraken, and Ledger) and the amount of crypto assets they hold. Jarod Koopman, Chief of the IRS Criminal Investigation Division, stated that criminals are exploiting public trust in government institutions by creating convincing fake websites and official-looking correspondence. According to the investigation, the infrastructure for this scam was set up just days before the mailing campaign began, using a domain registered through a Hong Kong-based registrar. The IRS assured taxpayers that it does not require them to provide wallet information via third-party sites or to click links from suspicious messages. The agency advised Americans to verify the authenticity of any notifications through official channels, such as making a phone call. This alert follows a recent FBI warning about a separate fraudulent scheme targeting cryptocurrency wallet holders on the Tron network.

Malicious actors are mailing out paper letters that mimic official correspondence from the U.S. Department of the Treasury and the IRS. The letters urge Americans to urgently register on a platform called the Digital Asset Compliance Portal. The IRS insists: no such service exists.

The letters contain QR codes leading to a phishing website disguised as the official tax service website. After clicking the link, the potential victim is prompted to specify the cryptocurrency exchange or wallet they use, including Coinbase, Kraken, and Ledger, as well as the amount of crypto assets held.

"Criminals continue to abuse the public's trust in government institutions by creating convincing fake websites and correspondence that looks official," said Jarod Koopman, Chief of the U.S. Internal Revenue Service Criminal Investigation Division.

According to the division, the infrastructure for the fraud scheme was created just days before the mailing campaign began, and the domain for the fake site was registered through a Hong Kong-based registrar.

The U.S. Internal Revenue Service assured that it does not require taxpayers to provide cryptocurrency wallet data through third-party websites or to click links from suspicious messages. The agency urged Americans to verify the authenticity of notifications through official channels of communication—for example, by calling a phone number.

Previously, the U.S. Federal Bureau of Investigation reported on a fraud scheme on the Tron network targeting cryptocurrency wallet owners.

end-content

Related Questions

QWhat is the main topic of the article?

AThe article reports on a new cryptocurrency fraud scheme involving fake letters and phishing websites impersonating the US IRS to steal personal and wallet information from taxpayers.

QHow are victims initially contacted in this scheme?

AVictims are initially contacted via physical paper letters that mimic official correspondence from the U.S. Department of the Treasury and the IRS.

QWhat is the 'Digital Asset Compliance Portal', according to the IRS?

AAccording to the IRS, the 'Digital Asset Compliance Portal' does not exist; it is a fabricated service used as part of the scam.

QWhat personal information are victims tricked into providing on the phishing website?

AOn the phishing website, victims are tricked into providing the cryptocurrency exchange or wallet they use (such as Coinbase or Ledger) and the amount of crypto assets they hold.

QWhat advice does the IRS give to the public to avoid this scam?

AThe IRS advises the public to verify the authenticity of any notifications through official communication channels and cautions that it does not require taxpayers to provide wallet information via third-party sites or links from suspicious messages.

Related Reads

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

Coldcard Hardware Wallet Hacked: Losses Mount Due to Vulnerable Seed Generation A critical vulnerability in Coldcard hardware wallets has led to a continued wave of fund thefts. According to Galaxy Research, the total stolen has reached 1,367.05 BTC (approx. $88.6 million) from 4,585 addresses, a significant increase from the initial 594.5 BTC reported on July 30, 2026. Most of the stolen funds remain on the attackers' addresses. The issue is not with the current firmware, which Coinkite has updated, but with seed phrases generated on vulnerable devices between March 2021 and the release of fixed firmware versions. Due to a programmer error, devices switched from using a hardware random number generator to the software-based Yasmarang generator, which was initialized with publicly accessible data like the chip's serial number. This made the seed phrases predictable through offline brute-force attacks, meaning wallets remain at risk until funds are moved to a new wallet generated with the patched firmware. Affected devices include Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3), Mk4/Mk5 up to version 5.6.0, and Q models up to 1.5.0Q. The only exceptions are seeds created with a high-entropy method like at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners must generate a new seed on the fixed firmware and transfer their assets. A case highlighting the human impact involves a 39-year-old long-term investor who lost 2 BTC (approx. $130,000) in minutes. He had accumulated the Bitcoin over eight years through physical labor, viewing it as a financial lifeline and a retirement plan in a country suffering from hyperinflation. His story underscores that even conservative "buy and hold in cold storage" strategies can be compromised by such underlying technical flaws. From a technical perspective, this incident echoes historical failures where weak random number generators undermined cryptographic security, challenging the assumption that offline storage is automatically foolproof.

cryptonews.ru3h ago

Bitcoin Withdrawals Continue: 8 Years of Storage in a Coldcard Cold Wallet Ended in Zero

cryptonews.ru3h ago

Trading

Spot
活动图片