Crypto news

01.08.2026
02:42

New phishing scheme: scammers send fake emails on behalf of the IRS and hunt for crypto assets

The U.S. Internal Revenue Service (IRS) is raising the alarm: scammers have moved to a new level of social engineering by sending physical letters to cryptocurrency holders. Instead of the usual email campaigns, phishers are using paper mail, inserting QR codes into envelopes that lead to a fake "Digital Asset Compliance Portal." The goal is to steal digital currencies and personal data from unsuspecting taxpayers.

The IRS Criminal Investigation division revealed the details of this scam on July 30. In the fake letters, victims are told they must urgently register on the fictitious portal before a certain date. The agency emphasizes that such a resource does not actually exist, and the IRS never sends paper notifications of this kind. Scanning the QR code redirects the user to a website requesting personal data, which opens a direct path to the theft of crypto assets.

Anatomy of the Attack: From Paper to Theft

This scheme stands out from typical crypto phishing attacks due to its offline nature. This week, representatives of the exchange Coinbase and the analytics company DarkTower discovered the forgery. The letters reference tax periods from 2017 to 2026, and the domain imitating the IRS was registered through a Hong Kong registrar and hosted on servers in Romania. This points to a high level of organization and an international footprint of the scammers.

"A phone call is the attack itself. A fraudster posing as support convinces you to hand over the keys to your account or transfer funds to a supposedly 'secure' wallet that they themselves control. This technique is called vishing (voice phishing). Right now, it is one of the most effective ways to take over crypto owners' accounts," Coinbase representatives note in their blog.

Fraud Reaches a New Level

This scheme fits into the overall trend of rising crime where scammers increasingly impersonate others. According to Chainalysis reports, in 2025, scam victims lost $17 billion, and the number of impersonation schemes grew by 1400%. At the same time, the number of hacks also increased significantly: TRM Labs recorded 207 incidents in the first half of 2026—2.5 times more than the 83 cases a year earlier. This is the highest six-month figure ever recorded. However, total losses fell during this period—from $2.3 billion in the first half of 2025 to $972 million.

These figures point to an important shift: scammers are moving from breaking code to deceiving people. Mailings under the IRS name are a clear signal that threats have moved beyond email and reached ordinary mailboxes.

My analysis: The decline in losses amid a rise in the number of attacks suggests that the industry is becoming more resilient to technical hacks, but the human factor remains the main vulnerability. Investors should remember: government agencies never request data via QR codes in paper letters. Any such "notification" is a red flag that requires immediate verification through official communication channels.