IRS Warns Crypto Investors of Snail-Mail Scam Using Fake Compliance Portal
Fraudsters are using physical letters and a spoofed website to trick digital asset holders into surrendering their private keys.
An international fraud network is targeting cryptocurrency investors with sophisticated impersonation scams that utilize physical mail to steal digital assets. The scheme leverages the perceived authority of the Internal Revenue Service to deceive victims into handing over sensitive credentials.
According to reports from MoneyWise and the Journal of Accountancy, the scam begins with fake IRS letters sent via snail mail. These documents direct investors to a fraudulent "Digital Asset Compliance Portal" through QR codes or embedded links. The spoofed website, irs.digitalcomplianceportal[.]com, is designed to mimic the official IRS.gov site to harvest personal information and asset credentials. The fraudulent domain is hosted in Romania, a location previously linked to other impersonation schemes involving banks and FedEx.
Once a victim engages with the portal, the fraud often escalates to a phone call. In these interactions, criminals pose as IRS representatives to trick investors into revealing private keys, passwords, or two-factor authentication (2FA) codes. These credentials allow the attackers to gain full access to the victims' wallets and drain their funds.
The Psychology of Physical Mail
The use of physical correspondence marks a strategic shift in phishing tactics. While digital emails are often flagged by spam filters or viewed with suspicion, snail mail adds a layer of perceived legitimacy that can bypass the defenses of even cautious investors. Jarod Koopman, IRS Criminal Investigation Chief, noted that criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.
This tactic is particularly dangerous given the nature of blockchain technology. Because cryptocurrency transactions are irreversible, any assets transferred after a victim surrenders their seed phrase or private key are permanently lost, with no mechanism for recovery or reversal.
A Growing Trend in Digital Fraud
This campaign arrives amid a sharp increase in cryptocurrency-related crime. Data from the FBI's IC3 2025 Internet Crime Report highlights the scale of the problem, noting that cryptocurrency fraud was the largest single complaint category of the year. Total losses surpassed $11 billion in 2025, spanning approximately 181,500 individual complaints.
What to Watch
The IRS has explicitly stated that no "Digital Asset Compliance Portal" exists. Taxpayers are reminded that the agency does not initiate contact with taxpayers by email, text messages, or social media channels to request personal or financial information. Investors should remain vigilant against any unsolicited correspondence requesting private keys or 2FA codes, as these are never required for official tax compliance.