Skip to main content
Sign in

Audit log

Every state-changing event for IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-07 12:30:18Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    5pZeeTLbJJ1K…1YfXFaDisha256 → base58
    verifying row…
    canonical bytes (19682 B) ▸
    {"actor":"system:backfill","investigation_id":"7f3566f6-b222-4575-8585-455856068743","kind":"publish","page_slug":"irs-fake-digital-asset-compliance-portal-letter-campaign-2026","published_at":"2026-08-07T12:30:18.699Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"IRS Fake Digital Asset Compliance Portal Letter Campaign — 2026","sections":[{"content":"The campaign uses physically mailed letters designed to closely mimic official IRS correspondence, including fictitious notice numbers (one example cited in security coverage is formatted as 'CP14-432RA'), treasury department references, and branding consistent with authentic IRS notices. The letters instruct recipients that they must enroll in a 'Digital Asset Compliance Portal' before a stated deadline — reported as August 10, 2026 in some accounts — or face penalties. The letters reference tax years 2017 through 2026, framing the demand as a comprehensive digital asset compliance review covering the recipient's full history of cryptocurrency activity. Each letter contains a QR code. Scanning the code redirects the recipient to a fraudulent website displaying 'official website of the United States government' branding while mimicking the visual design of IRS.gov. The use of physical postal mail rather than email is notable and unusual in the context of cryptocurrency-related phishing schemes, which typically rely on digital delivery vectors.","heading":"Campaign Overview and Mechanics","severity":"critical","sources":[{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"}]},{"content":"Cybersecurity firm DarkTower, working alongside Coinbase's security team, analyzed the campaign's operational flow in detail. The attack proceeds through at least four stages. In Stage 1, the recipient receives the physical letter and is directed to scan the embedded QR code. In Stage 2, the QR code redirects to a counterfeit IRS enrollment page where the victim is prompted to select their cryptocurrency storage method — options allegedly include hardware wallets such as Ledger and Trezor, as well as major exchanges including Coinbase and Binance — and to estimate the total value of their holdings in tiered ranges up to '$100,000+'. The victim is then asked for a phone number for alleged verification. In Stage 3, fraudsters place outbound calls to victims posing as IRS support personnel or compliance officers. In Stage 4, the callers attempt to extract passwords, two-factor authentication codes, seed phrases, or wallet recovery phrases, or to convince victims to transfer funds to wallets under the attackers' control. Coinbase and DarkTower characterized the operation as 'well-organised, internationally-coordinated fraud' rather than the work of unsophisticated actors.","heading":"Multi-Stage Attack Flow","severity":"critical","sources":[{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"},{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"news_article","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]},{"content":"DarkTower's threat intelligence analysis traced the fraudulent site's infrastructure to a domain registered through a Hong Kong-based registrar. The domain was registered only days before the physical mailing campaign was initiated, suggesting a tight operational timeline and advance preparation of the letter stock. The phishing site was hosted on Romania-based server infrastructure that DarkTower identified as previously associated with phishing campaigns impersonating banks and delivery services. No specific domain name was publicly disclosed in any of the reviewed reports as of the time of this investigation. The phishing site displayed the 'official website of the United States government' banner to increase perceived legitimacy. The technical profile — offshore registrar, foreign hosting with prior phishing association, rapid pre-campaign registration — is consistent with organized crime infrastructure rather than opportunistic individual fraud.","heading":"Technical Infrastructure","severity":"critical","sources":[{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Scammers Are Trying to Trick Crypto Holders with Fake IRS Letters — CPA Practice Advisor","type":"news_article","url":"https://www.cpapracticeadvisor.com/2026/08/03/scammers-are-trying-to-trick-crypto-holders-with-fake-irs-letters/187890/"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"}]},{"content":"IRS Criminal Investigation issued a formal public warning on July 30, 2026. The agency stated unambiguously: 'The IRS did not send it. The IRS does not operate a Digital Asset Compliance Portal. This is a scam.' IRS-CI Chief Jarod Koopman was quoted in multiple reports: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.' Koopman also advised: 'Before responding to unexpected requests for personal information, stop, verify the source, and report potential fraud schemes.' An IRS-CI representative clarified that while the agency does use QR codes on some legitimate notices (such as CP53E), taxpayers should navigate directly to IRS.gov to verify any correspondence rather than scanning codes from unsolicited letters. The campaign exploits the broader legitimate context of IRS digital asset enforcement: since 2019, the IRS has mailed genuine educational compliance letters to taxpayers suspected of underreporting cryptocurrency activity, making fraudulent letters appear more plausible. Phishing and impersonation appeared on the IRS's 2026 'Dirty Dozen' list of most dangerous tax scams, published in May 2026.","heading":"Official IRS Response and Regulatory Context","severity":"critical","sources":[{"credibility":2,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":1,"name":"Be aware of Dirty Dozen tax scams for 2026 — IRS.gov","type":"official","url":"https://www.irs.gov/newsroom/be-aware-of-dirty-dozen-tax-scams-for-2026"},{"credibility":2,"name":"IRS warns scammers are mailing fake letters to crypto holders — Northeast Times","type":"news_article","url":"https://northeasttimes.com/2026/07/31/irs-warns-scammers-are-mailing-fake-letters-to-crypto-holders/"},{"credibility":1,"name":"IRSnews on X: Digital Asset Compliance Portal is a SCAM","type":"official","url":"https://x.com/IRSnews/status/2082866098567819444"}]},{"content":"IRS-CI, Coinbase, and cybersecurity firms including Bitdefender published consistent guidance for recipients. Anyone who received a letter should not scan the embedded QR code, not visit any URL printed in the letter, and not call any phone number listed in the correspondence. Victims who did enter information on the phishing site are advised to immediately change passwords on all cryptocurrency exchange accounts, verify and update two-factor authentication settings, contact their exchange through the official app or the exchange's verified website — not through phone numbers provided in any letter or by callers — and enable any available account lock or withdrawal freeze features. Seed phrases or recovery phrases that were disclosed should be treated as fully compromised; any wallets associated with those phrases should be considered at risk and funds should be migrated to new wallets with new seed phrases as promptly as possible. Victims are directed to report to IRS Criminal Investigation at www.IRS.gov/SubmitATip and to document all physical letters, screenshots, and call logs as evidence.","heading":"Victim Guidance and Recommended Actions","severity":"high","sources":[{"credibility":2,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"},{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"}]},{"content":"The 2026 campaign occurs within a long-running trend of IRS impersonation fraud. The Treasury Inspector General for Tax Administration has described IRS impersonation as 'the largest, most pervasive impersonation scam in the history of the IRS.' Cumulative figures across all IRS impersonation schemes have exceeded 2.4 million targeted individuals in the United States with more than 14,700 victims reported losing a combined $72.8 million, though these figures encompass all IRS impersonation variants and are not specific to the digital asset compliance portal campaign. In 2026, threat intelligence data indicates that 152 new IRS-themed domains were registered, with approximately 82 percent characterized as actively malicious. The 2026 campaign is distinctive in using physical mail as a delivery vector — a vector that may be less expected by targets who are accustomed to being warned about email phishing — and in explicitly targeting cryptocurrency holders as a named population, which is consistent with the IRS's increasing public enforcement posture on digital asset tax reporting. No arrests or law enforcement actions against the operators of this specific campaign have been publicly reported as of early August 2026.","heading":"Broader IRS Impersonation Threat Landscape","severity":"high","sources":[{"credibility":2,"name":"IRS Impersonation Scams Are Running Ahead of Last Year — Bolster AI","type":"research","url":"https://bolster.ai/blog/irs-scams-data"},{"credibility":3,"name":"IRS impersonation scam — Wikipedia","type":"other","url":"https://en.wikipedia.org/wiki/IRS_impersonation_scam"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"}]},{"content":"No individuals or groups have been publicly named as responsible for the campaign as of early August 2026. The infrastructure profile — Hong Kong-registered domain, Romanian hosting, prior association with financial-sector phishing — is consistent with organized transnational fraud operations but does not uniquely identify any specific threat actor group. Coinbase and DarkTower characterized the operation as well-organized and internationally coordinated. IRS-CI has not announced any arrests or indictments in connection with this specific campaign. Victims are directed to report to IRS-CI at www.IRS.gov/SubmitATip to assist in the ongoing investigation.","heading":"Attribution and Investigation Status","severity":"medium","sources":[{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"news_article","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]}],"sources_used":[{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"news_article","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Consumer Protection Tuesday: Fake IRS Digital Asset Compliance Portal Letter — Coinbase Blog","type":"news_article","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":2,"name":"Scammers Are Trying to Trick Crypto Holders with Fake IRS Letters — CPA Practice Advisor","type":"news_article","url":"https://www.cpapracticeadvisor.com/2026/08/03/scammers-are-trying-to-trick-crypto-holders-with-fake-irs-letters/187890/"},{"credibility":2,"name":"IRS Warns: Impersonation Letters Include QR Codes, Forging a Digital Asset Compliance Portal — Gate News","type":"news_article","url":"https://www.gate.com/news/detail/us-irs-warns-impersonation-letters-contain-qr-codes-stealing-crypto-assets-23094072"},{"credibility":1,"name":"IRS Warns of Scam Using Fake Letters to Steal Crypto Wallets and Identities — Bloomberg","type":"news_article","url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"credibility":1,"name":"Be aware of Dirty Dozen tax scams for 2026 — IRS.gov","type":"official","url":"https://www.irs.gov/newsroom/be-aware-of-dirty-dozen-tax-scams-for-2026"},{"credibility":1,"name":"IRSnews on X: Digital Asset Compliance Portal is a SCAM","type":"official","url":"https://x.com/IRSnews/status/2082866098567819444"},{"credibility":2,"name":"IRS warns of phishing campaign targeting cryptocurrency holders — Digital Watch Observatory","type":"news_article","url":"https://dig.watch/updates/irs-letters-cryptocurrency-phishing-scam"},{"credibility":2,"name":"IRS issues strong warning on fake letters targeting Americans — TheStreet Crypto","type":"news_article","url":"https://www.thestreet.com/crypto/policy/irs-issues-strong-warning-on-fake-letters-targeting-americans"},{"credibility":2,"name":"IRS Warns Fake Crypto Letters Target Wallets and Personal Data — Bitcoin.com News","type":"news_article","url":"https://news.bitcoin.com/regulation-and-legal/irs-warns-fake-crypto-letters-target-wallets-and-personal-data/"},{"credibility":2,"name":"Did You Get an IRS Crypto Compliance Letter? It Probably Isn't Real — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/did-irs-crypto-compliance-letter-082951104.html"}],"summary":"A fraud campaign active as of late July 2026 in which unknown threat actors mail physically printed letters impersonating the IRS, instructing cryptocurrency holders to enroll in a nonexistent 'Digital Asset Compliance Portal' via an embedded QR code. The IRS Criminal Investigation division publicly confirmed on July 30, 2026 that it does not operate any such portal and did not send the letters. Infrastructure linked to the campaign was registered through a Hong Kong-based registrar and hosted on Romanian servers previously associated with financial phishing attacks.","timeline":[{"date":"2026-07-28","event":"Coinbase and threat intelligence firm DarkTower release a consumer alert identifying the fake IRS 'Digital Asset Compliance Portal' letter campaign after a customer report triggered investigation.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"date":"2026-07-30","event":"IRS Criminal Investigation issues formal public warning, confirming no 'Digital Asset Compliance Portal' exists and that the letters are fraudulent. IRS-CI Chief Jarod Koopman issues statement.","source":"Bloomberg","source_url":"https://www.bloomberg.com/news/articles/2026-07-30/scam-artists-are-posing-as-irs-agents-to-drain-crypto-wallets"},{"date":"2026-07-31","event":"Multiple outlets including Accounting Today, CryptoTimes, and The Star (Malaysia) report on the IRS-CI warning. IRSnews official X account posts alert.","source":"Accounting Today","source_url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"date":"2026-08-03","event":"CPA Practice Advisor publishes detailed breakdown of campaign mechanics and victim guidance, citing IRS-CI and DarkTower findings.","source":"CPA Practice Advisor","source_url":"https://www.cpapracticeadvisor.com/2026/08/03/scammers-are-trying-to-trick-crypto-holders-with-fake-irs-letters/187890/"},{"date":"2026-08-04","event":"Help Net Security and Bitdefender publish extended technical analyses of the multi-stage attack flow and phishing infrastructure.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"date":"2026-08-07","event":"No arrests or law enforcement actions against campaign operators publicly announced as of this date. Investigation is ongoing per IRS-CI guidance.","source":"AVOID.NET research compilation","source_url":"https://www.avoid.net"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 73fb4a3d-0f3a-4a82-9aa3-925fe2be42d0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.