TechNewsReel
Live

IRS Warns Crypto Holders of Phishing Scam Using Counterfeit Physical Mail

Scammers are using fake government letters and QR codes to steal private keys and wallet credentials from digital asset holders.

TechNewsReel Newsroom · August 1, 2026

The Internal Revenue Service (IRS) has issued a warning to cryptocurrency holders regarding a sophisticated phishing campaign utilizing counterfeit physical mail. The scam aims to deceive taxpayers into surrendering sensitive financial data and private keys through a fraudulent compliance portal.

According to the IRS, attackers are sending physical letters that instruct recipients to register for a non-existent "Digital Asset Compliance Portal" (DACP) by scanning a QR code. This code directs victims to a fraudulent website designed to mimic the official IRS.gov domain. Once on the site, users are prompted to provide personal identification, exchange credentials, wallet recovery phrases, and private keys, allowing attackers to permanently drain their digital assets.

The Shift to Hybrid Attacks

This campaign arrives as the IRS increases its focus on digital asset taxation and compliance, making official-looking correspondence more believable to the average taxpayer. By pivoting from traditional email phishing to physical mail, scammers are attempting to bypass digital security filters and exploit the inherent trust and fear associated with government tax agencies.

Fraudsters continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence to lure victims into compromising their security.

Rising Crypto Vulnerabilities

This evolution in social engineering reflects a broader, more aggressive trend in cryptocurrency crime. The threat landscape has grown increasingly volatile; according to Blockaid, crypto projects lost over $1.1 billion to hacks in the first half of 2026. Furthermore, CertiK reported 52 verified "wrench attacks" during the same period, resulting in more than $124 million in financial exposure.

What to Watch

Users are urged to verify all government communications through official, known channels and to never share private keys or recovery phrases on any website. As attackers continue to blend physical and digital tactics, the industry must monitor for similar hybrid schemes targeting other high-value financial assets. The IRS continues to emphasize that official portals will not be accessed via unsolicited QR codes in physical mail. Taxpayers should report any suspicious correspondence to the Treasury Inspector General for Tax Administration (TIGTA) to help mitigate the spread of these fraudulent campaigns.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.