Crypto news

01.08.2026
02:08

The U.S. tax service warns: scammers are attacking crypto investors via paper letters with QR codes.

The analytical department of Cryptalist has recorded a worrying trend: attackers have shifted from digital attacks to a classic "paper" phishing scheme targeting cryptocurrency holders. The Criminal Investigation Division of the U.S. Internal Revenue Service (IRS) officially confirmed on July 30 that scammers are mailing fake letters on behalf of the agency, containing QR codes that lead to a fake "Digital Asset Compliance Portal."

The scheme looks frighteningly realistic. The letters tell recipients they must urgently register on the portal before a certain date, while emphasizing that the IRS has allegedly already sent out corresponding paper notices. However, as it turned out during my analysis, such a portal does not exist in reality — it is a purely phishing construct created to steal personal data and digital assets.

Technical details of the attack

When scanning the QR code, the victim lands on a fake website that requests confidential information. The domain, imitating an IRS resource, is registered through a Hong Kong registrar, and the hosting is located on servers in Romania. The letters mention tax periods from 2017 to 2026, which adds an appearance of legitimacy. Notably, this activity has already been tracked by representatives of Coinbase and the analytical company DarkTower.

This is a departure from classic crypto-phishing attacks, which usually occur via email or messengers. The use of physical mail is a new level of sophistication, designed to exploit trust in "official" documents. The IRS emphasizes: the agency never sends paper letters with registration demands and does not request data via QR codes. Also, one should not engage in phone conversations with those demanding payment — this is classic vishing (voice phishing), which has now become one of the most effective methods of account takeover.

Scope of the threat

This scheme fits into the overall picture of rising fraud. According to Chainalysis, in 2025, fraud victims lost $17 billion, while the number of identity impersonation schemes grew by 1400%. TRM Labs records 207 hacking incidents in the first half of 2026 — 2.5 times more than the 83 cases a year earlier. This is a record half-year figure, although total losses fell from $2.3 billion to $972 million, indicating that attackers have shifted from technical hacks to social engineering.

My expert commentary: The move by scammers to paper letters is an evolution of phishing, designed around the psychological factor of trust in physical documents. Crypto investors should remember the main rule: government agencies never initiate contact via QR codes or phone calls demanding the disclosure of keys. Any such approach is a one hundred percent attempt at theft. Stay vigilant and verify information only through official communication channels.