The letter comes in a plain envelope. No certified stamp. No tracking number. But the styling is right — official Treasury formatting, a notice number, a tax year window covering 2017 through 2026. The message is surgical: the IRS has detected unreported digital asset activity connected to your identity. Scan the enclosed QR code to access your "digital asset compliance portal" and verify your holdings.
That QR code is the entire operation.
IRS Criminal Investigation just issued a formal warning about these counterfeit letters, and Coinbase published samples alongside the alert. Jarod Koopman, IRS-CI's top executive, drew a clean line: the IRS does not send QR codes in its correspondence, and it does not require crypto holders to register their exchange or wallet with any compliance portal. t check.
What makes this more than a standard phishing tale is the engineering discipline. The fake domains were registered days before physical letters hit mailboxes. Hosted in Romania. Registered through a Hong Kong registrar. And the same infrastructure previously hosted FedEx phishing pages and bank credential harvesters.
This isn't a scam. It's a product line with seasonal branding.
Let's back up to the regulatory moment, because this attack doesn't exist in a vacuum. The IRS has been mailing real educational letters to crypto holders since 2019. Genuine letters, soft-touch enforcement, asking taxpayers to review their digital asset filings. By design, those letters are gentle — nudges before penalties escalate. But they created something the scammers instantly recognized: a legitimate precedent for the claim that the government mails crypto holders about their transactions.
The IRS has described these letters as part of an education-first strategy — help taxpayers correct their filings rather than punish every misstep. That's the right policy instinct. But it collapses the moment criminals can clone the exact same letterhead.
That precedent is the trust anchor. Every real IRS letter trains a population segment to expect official correspondence about their holdings. When a counterfeit letter arrives with matching styling, the victim's first instinct isn't suspicion. It's recognition. The scammers aren't inventing a threat model. They're piggybacking on the IRS's own outreach program.

The timing compounds the problem. The 1099-DA broker reporting regime is rolling in — third-party crypto transaction data flowing into IRS systems at unprecedented volume. More data means more discrepancies. More discrepancies means more letters. Every letter, real or fake, reinforces the same narrative loop. The bull market hardened this too: a generation of traders who spent 2021 chasing yield without thinking about tax consequences. Gas fees higher than the yield. Typical. Now those same traders receive letters about unreported activity, and they can't tell which notices are legitimate. The IRS had to know this was coming. Whenever a regulator builds a new enforcement channel, the phishing industry builds a clone. That's the predictable pattern.
The counterfeit letter's tax-year window — 2017 through 2026 — is itself a psychological weapon. It spans the exact period when crypto went from niche hobby to mainstream asset class. The letter is engineered to trigger the specific fear of unreported gains from the boom years. Koopman's warning even spells out the verification path: log into your official irs.gov online account and validate any notice there. But a taxpayer spiraling over a threatening letter isn't calmly navigating the IRS website. The manufactured fear is the vulnerability.

Now the attack chain, step by step. The sequencing is where the dark artistry lives.
Step one: physical delivery. Attackers replicated Treasury Department styling with enough fidelity that the letters carry real bureaucratic texture — notice numbers, dense formatting, official tone. This is the anti-digital move. Email phishing gets caught by spam filters and a public trained to distrust inbox links. Physical mail bypasses all of it. A stamped envelope still carries a presumption of legitimacy that digital channels lost years ago.
Step two: the QR code. No URL text. No clickable link. This is a deliberate technical decision. QR codes are invisible to automated text scanners and domain reputation systems. They obscure the destination entirely — on mobile, there's no hover preview, no status bar, no URL inspection. Scan, tap, and you're on a fake irs.gov lookalike before your brain registers the domain. The QR code also reads as modern and official, because government agencies have adopted them everywhere. The cognitive friction is near zero. QR phishing targets phones specifically — weaker URL inspection, no browser extension security layers, and often the same device holding the mobile wallet. The QR code is the shortcut that skips the entire inspection step.
Step three: the fake domain. Registered days before the mailing campaign. Hong Kong registrar. Romanian hosting. Three layers of separation — physical mail, registration, server location — each designed to stall attribution and burn investigator hours. If one layer gets compromised, the rest keep the operation alive.
Step four: the fake compliance portal. This is where the social engineering goes surgical. The portal asks for your exchange type. Your hardware wallet model. An estimate of your holdings. Your phone number. The holdings estimate is a qualification mechanism — attackers want to know if extraction is worth the effort. It also commits you to the fiction of noncompliance. You've now admitted, to a fake authority, that you hold crypto. That admission is the hook. Even if suspicion sets in later, you've already engaged with the premise.

Step five: the phone call. A "verification" call from someone impersonating IRS support. Multi-channel design at its finest — the letter establishes urgency, the portal collects data, and the call extracts the payload. You've complied twice already. You scanned. You filled the form. Compliance escalates. The caller asks for a one-time code, a password, or worse: recovery phrases.
Endgame. Private keys. Wallet drained. No chargeback. No insurance. No recourse.
The IRS verification path is refreshingly simple by contrast: any real notice can be validated through an official irs.gov online account. And Koopman's warning is unambiguous — official IRS correspondence doesn't include QR codes and never requires you to disclose your exchange or wallet. If a letter asks for either, it's fake. Full stop.
The reporting channels exist too — IRS and FTC both accept scam reports, and a joint effort is aggregating intelligence on these operations. Every data point helps. But that's the aftermath. The damage happens before anyone reports.
But here's the gap. IRS press releases don't reach the people who need them most. The victims aren't crypto natives reading IRS-CI alerts — they're casual holders, the ones who bought during the bull run, who hold on an exchange they barely understand, who received a real IRS letter last year and now can't distinguish official correspondence from counterfeit.
Coinbase deserves credit for acting as an intelligence node here — publishing sample letters, domain patterns, and the QR code flow for other security teams to study. That's proactive disclosure that makes the ecosystem safer. But the burden shouldn't fall on exchanges. The IRS created this communication pattern. It needs to own the defense.
Here's the angle nobody's covering: the real IRS is the unpaid marketing department for this scam. Every legitimate compliance letter validates the core premise — that the government reaches out to crypto holders about their transactions. The scammers didn't invent the fear. The IRS did. And every enforcement expansion — more letters, more third-party reporting, more taxpayer confusion — widens the attack surface for imitation.
The infrastructure pattern makes the threat clearer. The same domains that hosted FedEx phishing and bank credential harvesters now host IRS lookalikes. This is a multi-brand criminal operation rotating verticals by seasonality. FedEx during shipping peaks. Banks during tax season. IRS when crypto compliance dominates headlines. Same phishing kits, new letterhead.
Based on my years auditing phishing infrastructure — from the 2017 ICO sprint through every market cycle since — the timing detail is what hits me. Someone on this crew studied IRS crypto enforcement records closely enough to replicate notice formats and hit the 2017-2026 window with precision. They understand the audit cycle. They understand the templates. They understand the fear points. That's not amateur hour.
There's also a data dimension nobody's mentioning. The portal harvests intelligence even from victims who abandon the flow. Exchange types. Wallet models. Holdings estimates. Phone numbers. That's a structured target list — a database of crypto holders, their storage choices, and their compliance anxiety. That database has resale value, reuse value, and targeting intelligence that outlives any single campaign. The letter scam might be the retail front end of a larger profiling operation.
The structural fix would be for the IRS to add cryptographic verification to every letter it sends — digital signatures, uniform validation tokens, mandatory online-account confirmation. But government moves slow, and the next iteration of this scam is probably already being planned in some Romanian server room.
Until then, the rule is brutal and simple: no QR codes in IRS mail. No requests for exchange or wallet registration. No phone operator asking for recovery phrases. If a letter asks you to verify holdings on a portal you've never heard of, it's a trap. t check.
Pump, dump, debug. Repeat. The scam cycle doesn't end. It just adopts new letterhead.