Skip to main content
AVOID.NET

Audit log

Every state-changing event for IRS Digital Asset Compliance Portal Phishing Campaign 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-07-31 23:07:09Z
    Score: ?? (no score change)
    anchoranchored
    chain
    mainnet-betaslot 443,503,135
    sig
    3Aec5oZiUgnt…kApi5mefexplorer ↗
    hash
    6Qjb85D8Tmod…4PmpkRmksha256 → base58
    verifying row…full verify ↗
    canonical bytes (14377 B) ▸
    {"actor":"system:backfill","investigation_id":"ceb1d5c4-9dd4-4214-97fb-adc13a573ab8","kind":"publish","page_slug":"irs-digital-asset-compliance-portal-phishing-campaign-2026","published_at":"2026-07-31T23:07:08.992Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"IRS Digital Asset Compliance Portal Phishing Campaign 2026","sections":[{"content":"IRS Criminal Investigation (IRS-CI) issued a fraud alert on July 30, 2026, warning US cryptocurrency holders of a large-scale phishing campaign conducted through physical mail. Fraudsters distributed counterfeit letters impersonating the IRS, instructing recipients to scan an embedded QR code and enroll in a nonexistent 'Digital Asset Compliance Portal' before a stated deadline of August 10, 2026. The letters referenced tax years 2017 through 2026 to lend the appearance of a legitimate multi-year compliance notice. IRS-CI Chief Jarod Koopman stated: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.' The IRS confirmed that no Digital Asset Compliance Portal exists and that the agency does not send QR codes in official correspondence. Coinbase and threat intelligence firm DarkTower independently flagged the campaign on July 28, 2026, two days before the official IRS warning, identifying the physical mail distribution channel as a notable tactical shift from typical cryptocurrency phishing.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":1,"name":"IRS-CI Fraud Alert: Fake IRS Letters Target Cryptocurrency Holders (July 30, 2026)","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":2,"name":"IRS warns crypto holders fraudster sending fake letters — The Block","type":"news_article","url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]},{"content":"Victims received plain-envelope letters formatted to closely resemble official IRS correspondence. The letters claimed recipients were required to enroll in a 'Digital Asset Compliance Portal' before a fixed deadline to maintain compliance with IRS digital asset reporting requirements. An embedded QR code redirected to a spoofed website visually mimicking IRS.gov. The phishing site was designed to collect: personal identification details, cryptocurrency wallet information and recovery phrases, cryptocurrency exchange account credentials, and other financial data sufficient for identity theft or direct asset theft. A secondary social engineering step was reported by security researchers: after a victim enters credentials, a follow-up actor posing as 'IRS support' contacts the victim and attempts to convince them to move funds to a 'safe wallet' controlled by the fraudsters. The IRS confirmed it does not ask taxpayers to transfer digital assets as part of any compliance process.","heading":"Attack Mechanics and Data Harvested","severity":"critical","sources":[{"credibility":1,"name":"IRS-CI Fraud Alert: Fake IRS Letters Target Cryptocurrency Holders (July 30, 2026)","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":2,"name":"Did You Get an IRS Crypto Compliance Letter? It Probably Isn't Real — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/did-irs-crypto-compliance-letter-082951104.html"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"}]},{"content":"According to IRS-CI Chief Jarod Koopman and reporting by Bloomberg, the fraudulent domain was registered through a Hong Kong registrar days before the letters were mailed. The phishing site was hosted in Romania on network infrastructure with a documented prior history of hosting FedEx and banking phishing pages. The rapid domain registration relative to mailing date is consistent with organized phishing-as-a-service operations that prepare infrastructure immediately before a campaign launch to reduce detection windows. No individuals or specific criminal organizations have been publicly named in connection with the campaign as of July 31, 2026. The use of physical mail alongside digital phishing infrastructure suggests a well-resourced operation with knowledge of the US postal system and access to cryptocurrency holder address lists, potentially sourced from prior data breaches or public blockchain analytics.","heading":"Infrastructure and Attribution","severity":"high","sources":[{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":1,"name":"IRS-CI Fraud Alert: Fake IRS Letters Target Cryptocurrency Holders (July 30, 2026)","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":2,"name":"Scam artists are posing as IRS agents to drain crypto wallets — The Star","type":"news_article","url":"https://www.thestar.com.my/tech/tech-news/2026/07/31/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"}]},{"content":"The IRS Digital Asset Compliance Portal campaign emerged against a backdrop of sharply rising government impersonation fraud in the cryptocurrency space. Chainalysis's 2026 Crypto Crime Report estimated that crypto scam losses reached a record $17 billion in 2025, with impersonation scams experiencing the most explosive growth — surging more than 1,400% year-over-year. The average amount stolen per impersonation incident rose from $782 to $2,764 in 2025. AI-enabled scam operations were reported to be 4.5 times more profitable than traditional scams, with fraud groups deploying deepfake videos, automated messaging, and phishing-as-a-service toolkits. The IRS campaign's use of physical mail represents a tactical evolution: while most crypto phishing is conducted digitally, the combination of official-looking postal correspondence with a digital QR code redirect is a method documented in previous IRS impersonation campaigns and is harder to filter through standard email security controls.","heading":"Broader Context: Impersonation Scam Surge","severity":"high","sources":[{"credibility":2,"name":"2026 Crypto Crime Report: Scams — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"Impersonation Scams Surge 1,400% as Crypto Fraud Evolves — BeInCrypto","type":"news_article","url":"https://beincrypto.com/chainalysis-crypto-scams-impersonation-ai-trend/"},{"credibility":2,"name":"Chainalysis: Impersonation and AI scams are becoming crypto's biggest threat — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"}]},{"content":"IRS-CI issued the following guidance for recipients of suspected counterfeit letters: do not scan QR codes from unsolicited government correspondence; do not enter wallet credentials, recovery phrases, or private keys on any website reached via an unsolicited communication; verify all IRS contact through IRS.gov directly by typing the URL manually; enable multifactor authentication on all exchange and wallet accounts; and report suspicious IRS communications to IRS-CI at IRS.gov/SubmitATip. Coinbase additionally advised users to be skeptical of any follow-up contact from individuals claiming to be IRS support agents, as the secondary social engineering step attempts to convince victims to move funds to attacker-controlled wallets. The IRS reiterated that it does not request payment in cryptocurrency, does not operate wallet enrollment portals, and does not send QR codes in official letters.","heading":"Protective Measures and Reporting Channels","severity":"medium","sources":[{"credibility":1,"name":"IRS-CI Fraud Alert: Fake IRS Letters Target Cryptocurrency Holders (July 30, 2026)","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"}]}],"sources_used":[{"credibility":1,"name":"IRS-CI Fraud Alert: Fake IRS Letters Target Cryptocurrency Holders (July 30, 2026)","type":"regulatory","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"IRS warns crypto holders fraudster sending fake letters — The Block","type":"news_article","url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"official","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":2,"name":"IRS Warns Crypto Holders About Fake Tax Letter Scam — Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/07/31/irs-warns-crypto-holders-about-fake-tax-letter-scam/"},{"credibility":2,"name":"Did You Get an IRS Crypto Compliance Letter? It Probably Isn't Real — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/did-irs-crypto-compliance-letter-082951104.html"},{"credibility":2,"name":"IRS Warns: Impersonation Letters Include QR Codes — Gate News","type":"news_article","url":"https://www.gate.com/news/detail/us-irs-warns-impersonation-letters-contain-qr-codes-stealing-crypto-assets-23094072"},{"credibility":2,"name":"Scam artists are posing as IRS agents to drain crypto wallets — The Star","type":"news_article","url":"https://www.thestar.com.my/tech/tech-news/2026/07/31/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":2,"name":"2026 Crypto Crime Report: Scams — Chainalysis","type":"research","url":"https://www.chainalysis.com/blog/crypto-scams-2026/"},{"credibility":2,"name":"Chainalysis: Impersonation and AI scams are becoming crypto's biggest threat — CoinDesk","type":"news_article","url":"https://www.coindesk.com/business/2026/01/14/chainalysis-report-reveals-impersonation-and-ai-crypto-scams-surpass-cyberattacks"},{"credibility":2,"name":"IRS Warns 'Digital Asset Compliance Portal' Is A Scam — Bitcoin World","type":"news_article","url":"https://bitcoinworld.co.in/irs-warns-digital-asset-compliance-portal-scam/"},{"credibility":2,"name":"Crypto Regulation Sparks Crime: IRS Issues Phishing Warning — Coinpedia","type":"news_article","url":"https://coinpedia.org/news/crypto-regulation-sparks-crime-irs-issues-phishing-warning-lummis-gets-hacked/"}],"summary":"Beginning in late July 2026, an organized criminal operation mailed counterfeit IRS letters to US cryptocurrency holders directing them via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest credentials and drain digital asset accounts. IRS Criminal Investigation confirmed the campaign on July 30, 2026, stating no such portal exists; infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior phishing history.","timeline":[{"date":"2026-07-28","event":"Coinbase and threat intelligence firm DarkTower issue a consumer alert flagging the fake IRS Digital Asset Compliance Portal letter campaign, two days before the official IRS warning.","source":"Coinbase Blog / Crypto Briefing","source_url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"date":"2026-07-30","event":"IRS Criminal Investigation publishes an official fraud alert confirming the campaign. IRS-CI Chief Jarod Koopman states the fraudulent domain was registered through a Hong Kong registrar and hosted on Romanian servers previously used for phishing. Bloomberg reports on the warning.","source":"IRS.gov / Bloomberg","source_url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"date":"2026-07-31","event":"Multiple crypto and mainstream outlets report widely on the campaign. The IRS reiterates that no Digital Asset Compliance Portal exists and that the stated August 10 enrollment deadline is fabricated.","source":"The Block / Crypto Times / Crypto Briefing / Accounting Today","source_url":"https://www.theblock.co/post/410204/irs-crypto-holders-fraudster-sending-fake-letters-steal-digital-assets-data-bloomberg"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision e72ade1b-f608-4e97-8b57-30fb37be2a33
  2. #2reviewby reviewerreviewer
    2026-08-25 19:16:36Z
    Score: 00 (no score change)
    The page's core factual claims — the July 30, 2026 IRS-CI fraud alert, the fake 'Digital Asset Compliance Portal' mechanism, the Hong Kong-registrar/Romania-hosting infrastructure, the Koopman quote, the July 28 Coinbase/DarkTower alert, and the cited Chainalysis 2026 statistics — were independently verified against primary sources (IRS.gov, Chainalysis) or strongly corroborated by multiple independent secondary sources where the primary source (Bloomberg, Coinbase) could not be directly fetched. The page consistently and correctly treats the IRS as the impersonated party, never attributing the fraudulent portal or any real-world compliance action to the agency itself. Minor issues found are interpretive overreach (labeling registration timing as 'phishing-as-a-service' without a cited source saying so) and one timeline entry that attributes a 'reiteration' action to the IRS on July 31 when the cited sources are secondary coverage of the original July 30 alert.
    anchoranchored
    chain
    mainnet-betaslot 443,516,344
    sig
    4ziZkckj3HNk…Ravm7y1Uexplorer ↗
    hash
    6FpyNL9g3gg7…gx5ZiMiusha256 → base58
    verifying row…full verify ↗
    canonical bytes (1367 B) ▸
    {"actor":"reviewer","decided_at":"2026-08-25T19:16:36.273Z","decision":"review","investigation_id":"ceb1d5c4-9dd4-4214-97fb-adc13a573ab8","new_score":0,"page_slug":"irs-digital-asset-compliance-portal-phishing-campaign-2026","prev_score":0,"reason":"The page's core factual claims — the July 30, 2026 IRS-CI fraud alert, the fake 'Digital Asset Compliance Portal' mechanism, the Hong Kong-registrar/Romania-hosting infrastructure, the Koopman quote, the July 28 Coinbase/DarkTower alert, and the cited Chainalysis 2026 statistics — were independently verified against primary sources (IRS.gov, Chainalysis) or strongly corroborated by multiple independent secondary sources where the primary source (Bloomberg, Coinbase) could not be directly fetched. The page consistently and correctly treats the IRS as the impersonated party, never attributing the fraudulent portal or any real-world compliance action to the agency itself. Minor issues found are interpretive overreach (labeling registration timing as 'phishing-as-a-service' without a cited source saying so) and one timeline entry that attributes a 'reiteration' action to the IRS on July 31 when the cited sources are secondary coverage of the original July 30 alert.","score_delta":0,"sequence_num":2,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 36378fa1-172c-41be-9ed4-34d73c9ef11b
  3. #3review approveby judgejudge
    2026-08-25 19:16:36Z
    Score: 00 (no score change)
    Independent fact-checking of all 18 claims on this page found none disputed and none unverifiable, a 0% disputed rate that falls well within the approval range. Fifteen claims were directly confirmed against primary sources including the IRS's own fraud alert and Chainalysis's crime report; three (claim_findings[10], [15], [17]) were only partially supported due to minor framing issues — an unattributed analytical label, a slightly narrowed statistic, and an overstated dating of a follow-up IRS statement — none of which change the underlying facts or misrepresent the IRS's role as the impersonated party. Two apparent link-rot issues (Bloomberg and Coinbase URLs returning HTTP 403) were resolved as bot-blocking, not dead links, and corroborated through independent secondary sources and archive timestamps. The two coverage gaps the reviewer flagged (added context on real IRS tax-reporting rules, and reliance on a single DarkTower/Coinbase investigation for technical detail) are both rated medium priority and represent opportunities to expand the page, not flaws serious enough to require correction before publication.
    anchoranchored
    chain
    mainnet-betaslot 443,516,352
    sig
    5n1jWW7Lmz8x…iRarPzV9explorer ↗
    hash
    B6w6w9xogpXg…165ySb2ysha256 → base58
    verifying row…full verify ↗
    canonical bytes (1529 B) ▸
    {"actor":"judge","decided_at":"2026-08-25T19:16:36.273Z","decision":"review_approve","investigation_id":"ceb1d5c4-9dd4-4214-97fb-adc13a573ab8","new_score":0,"page_slug":"irs-digital-asset-compliance-portal-phishing-campaign-2026","prev_score":0,"reason":"Independent fact-checking of all 18 claims on this page found none disputed and none unverifiable, a 0% disputed rate that falls well within the approval range. Fifteen claims were directly confirmed against primary sources including the IRS's own fraud alert and Chainalysis's crime report; three (claim_findings[10], [15], [17]) were only partially supported due to minor framing issues — an unattributed analytical label, a slightly narrowed statistic, and an overstated dating of a follow-up IRS statement — none of which change the underlying facts or misrepresent the IRS's role as the impersonated party. Two apparent link-rot issues (Bloomberg and Coinbase URLs returning HTTP 403) were resolved as bot-blocking, not dead links, and corroborated through independent secondary sources and archive timestamps. The two coverage gaps the reviewer flagged (added context on real IRS tax-reporting rules, and reliance on a single DarkTower/Coinbase investigation for technical detail) are both rated medium priority and represent opportunities to expand the page, not flaws serious enough to require correction before publication.","score_delta":0,"sequence_num":3,"submission_content_hash":null,"submission_id":null,"submission_kind":null,"submission_valence":null,"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision dac62d17-fae8-4963-9980-6f095abebace
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.