Crypto news

01.08.2026
11:15

New threat: scammers attack crypto investors via fake IRS letters

The U.S. Internal Revenue Service (IRS) is raising the alarm: attackers have moved to a new level of social engineering, sending fake notices to cryptocurrency holders via regular mail. Instead of the usual phishing emails, the attack comes through physical letters with QR codes that lead to a fraudulent "Digital Asset Compliance Portal."

The IRS Criminal Investigation division revealed the details of the scheme on July 30. In the letters, which mimic official agency documents, recipients are asked to "register" on the portal by a certain date, or face penalties. However, as the IRS emphasizes, such a portal does not exist at all, and the agency itself never sends paper notices of this kind.

The mechanics are simple and dangerous: the victim scans the QR code, lands on a fake website that requests personal data and, ultimately, cryptocurrency wallet keys. This is not a classic hack, but rather a manipulation of trust, which makes the scheme especially insidious.

Scope and Origin of the Threat

Analysts, including specialists from Coinbase and DarkTower, have already recorded the first cases. The fake letters reference tax periods from 2017 to 2026, and the domain masquerading as the IRS was registered through a Hong Kong registrar and is hosted on servers in Romania. This clearly points to the transnational nature of the criminal group.

Coinbase warns: "A phone call is already an attack. A fraudster posing as support convinces you to hand over keys or transfer funds to a 'secure' wallet controlled by the scammer." Such vishing (voice phishing) is today one of the most effective methods of account takeover.

Trend: From Hacks to Deception

This scheme fits into a global trend. According to Chainalysis, in 2025 fraud victims lost $17 billion, and the number of identity impersonation schemes grew by 1400%. At the same time, the number of hacks is declining: TRM Labs recorded 207 incidents in the first half of 2026 — 2.5 times more than a year earlier, but total losses fell from $2.3 billion to $972 million.

Clearly, cybercriminals are shifting from technical attacks to human psychology. The mailing campaign under the IRS name is an alarming signal: threats have moved beyond email and reached ordinary mailboxes. This requires investors to exercise not only technical but also basic behavioral caution.

My expert assessment: such hybrid attacks are just the tip of the iceberg. While the industry focuses on protecting code, fraudsters exploit trust in government institutions. The crypto community needs to develop new standards for verifying any official communications, especially paper ones.