Fact-check findings
What an automated fact-checker found when it re-read IRS Fake Digital Asset Compliance Portal Phishing Campaign 2026 against the sources the page cites. Only the most recent review is shown.
These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.
“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.
Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.
unverifiable
4 claimsNo source the reviewer could reach confirms or contradicts the claim.
- #16[unverifiable][awaiting moderator]in section: Technical Infrastructure
“No arrests or indictments directly related to this campaign had been announced as of August 1, 2026.”
reviewerNo arrests or indictments directly related to this campaign had been announced as of August 1, 2026.No source found explicitly states an arrest count; this is an absence-of-evidence claim. As of a September 2026 search, no subsequent reporting of arrests was located either, but no primary source directly affirms 'no arrests as of August 1' as a dated fact. - #20[unverifiable][awaiting moderator]in section: Official Warnings and Regulatory Response
“As of August 1, 2026, the IRS had not disclosed the volume of letters distributed nor any confirmed financial losses attributable to the campaign.”
reviewerAs of August 1, 2026, the IRS had not disclosed the volume of letters distributed nor any confirmed financial losses attributable to the campaign.This is an absence-of-evidence claim; no source explicitly confirms the IRS withheld this data as opposed to it simply not existing or not yet being reported. A search for updates through September 2026 also found no disclosed figures. - #29[unverifiable][awaiting moderator]in the timeline
“Coinbase Support posted a public advisory on X (Twitter).”
reviewerCoinbase Support posted a public advisory on X (Twitter) on July 31, 2026.The tweet's existence and content are corroborated, but its exact date could not be independently verified due to inability to fetch x.com directly; not disputed, but not confirmed either. - #30[unverifiable][awaiting moderator]in the timeline
“As of this date, no confirmed victim counts, financial losses, arrests, or indictments related to the DACP campaign had been publicly disclosed. The August 10 enrollment deadline cited in the fraudulent letters had not yet passed.”
reviewerAs of August 2026, no confirmed victim counts, financial losses, arrests, or indictments related to the DACP campaign had been publicly disclosed, and the August 10 enrollment deadline had not yet passed.The deadline-not-yet-passed portion is trivially true by the calendar; the absence-of-disclosure portion is an inference from silence in coverage rather than an affirmatively sourced fact, and a search for later updates (through September 2026) still found no arrest, victim-count, or loss figures reported.
link rot
2 claimsA cited source no longer resolves or no longer says what the page attributes to it.
- #17[link rot][awaiting moderator]in section: Official Warnings and Regulatory Response
“IRS Criminal Investigation issued a public alert on July 30, 2026, warning U.S. taxpayers of the campaign.”
reviewerIRS Criminal Investigation issued a public alert on July 30, 2026, warning U.S. taxpayers of the campaign.The underlying claim (an IRS-CI alert on July 30, 2026) is true, but the cited IRS.gov URL points to an unrelated 2022 alert about a different scam. The page's own archive_timestamp for this source (2026-02-09) predates the July 30, 2026 event it is meant to document, which is a further sign the citation is mismatched. This same wrong URL also appears in sources_used[0].Proposed correction (not yet applied)https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders - #31[link rot][awaiting moderator]in the cited sources
“https://www.irs.gov/compliance/criminal-investigation/irs-ci-issues-alert-about-potential-cryptocurrency-phishing-scam”
reviewerThe IRS-CI source cited in sources_used[0] documents the Digital Asset Compliance Portal alert.Highest-priority finding: the page's top-billed regulatory source (credibility 1, listed first in sources_used and cited in the 'Official Warnings and Regulatory Response' section) links to an unrelated 2022 alert rather than the actual July 30, 2026 DACP alert. The stored archive_timestamp (2026-02-09) for this URL also predates the July 30, 2026 event the page attributes to it, corroborating that this is the wrong URL rather than merely a redesigned page.Proposed correction (not yet applied)https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders
confirmed
25 claimsThe cited evidence supports the claim as written.
- #1[confirmed][no action needed]in the summary
“In late July 2026, an unidentified threat actor mailed counterfeit IRS letters to U.S. cryptocurrency holders directing them to a fictitious 'Digital Asset Compliance Portal' (DACP) at a lookalike domain.”
reviewerIn late July 2026 an unidentified threat actor mailed counterfeit IRS letters to U.S. crypto holders directing them to a fictitious Digital Asset Compliance Portal at a lookalike domain.Core framing is corroborated by the live IRS-CI alert and multiple independent outlets, though the specific URL cited on the page for the IRS.gov source is wrong (see separate link_rot finding). - #2[confirmed][no action needed]in the summary
“IRS Criminal Investigation (IRS-CI) issued a public warning on July 30, 2026, confirming no such portal exists and that the campaign was designed to harvest personal information, exchange credentials, and digital asset holdings.”
reviewerIRS Criminal Investigation issued a public warning on July 30, 2026 confirming no such portal exists and that the campaign harvested personal information, exchange credentials, and digital asset holdings.Date and substance confirmed against the live IRS-CI alert page (note: the URL actually cited by the page for this source is a mismatched 2022 alert, flagged separately). - #3[confirmed][no action needed]in the summary
“The phishing infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior history of financial phishing activity.”
reviewerThe phishing infrastructure was registered through a Hong Kong registrar and hosted on Romanian servers with a prior history of financial phishing activity.Confirmed by multiple independent outlets. - #4[confirmed][no action needed]in section: Campaign Overview
“The letters referenced tax years 2017 through 2026, claimed recipients were required to enroll in a 'Digital Asset Compliance Portal' (DACP) before an August 10, 2026 deadline, and included a QR code directing recipients to the fraudulent domain 'irs.digitalcomplianceportal.com'.”
reviewerThe letters referenced tax years 2017 through 2026, required enrollment before an August 10, 2026 deadline, and included a QR code to the domain 'irs.digitalcomplianceportal.com'.Tax year range, deadline, and domain all independently corroborated across multiple outlets. - #5[confirmed][no action needed]in section: Campaign Overview
“The campaign was identified by Coinbase and threat intelligence firm DarkTower, who issued a consumer alert on July 28, 2026.”
reviewerThe campaign was identified by Coinbase and threat intelligence firm DarkTower, who issued a consumer alert on July 28, 2026.Date corroborated by the page's own archive timestamp and independent search results. - #6[confirmed][no action needed]in section: Campaign Overview
“IRS Criminal Investigation formally warned the public on July 30, 2026.”
reviewerIRS Criminal Investigation formally warned the public on July 30, 2026.Confirmed. - #7[confirmed][no action needed]in section: Campaign Overview
“IRS-CI Chief Jarod Koopman stated: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.'”
reviewerIRS-CI Chief Jarod Koopman stated: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.'Quote and title both verified against the live IRS-CI fraud alert and independent confirmation of Koopman's April 2026 appointment as Chief. - #8[confirmed][no action needed]in section: Campaign Overview
“The IRS confirmed it operates no Digital Asset Compliance Portal and does not request digital asset transfers or sensitive credentials through mailed notices.”
reviewerThe IRS confirmed it operates no Digital Asset Compliance Portal and does not request digital asset transfers or sensitive credentials through mailed notices.Confirmed. - #9[confirmed][no action needed]in section: Attack Methodology
“The campaign used physical mail — an uncommon vector in cryptocurrency fraud — to bypass email spam filters and exploit the familiarity of crypto holders with genuine IRS digital asset letters the agency has sent since 2019.”
reviewerThe campaign used physical mail to bypass spam filters and exploited familiarity with genuine IRS digital asset letters sent since 2019.The 2019 reference to genuine IRS crypto letters is accurate background (IRS Letters 6173/6174/6174-A). - #10[confirmed][no action needed]in section: Attack Methodology
“The phishing site prompted victims to select which platform held their crypto assets — listing major exchanges including Coinbase, Kraken, and Binance — reportedly to identify which platform to subsequently impersonate.”
reviewerThe phishing site prompted victims to select which exchange held their crypto assets, listing major exchanges including Coinbase, Kraken, and Binance.Confirmed; page's list is a subset of the full list reported (which also includes hardware wallets), not a mischaracterization. - #11[confirmed][no action needed]in section: Attack Methodology
“According to Coinbase's consumer alert, after initial data entry a scammer posing as 'support' would attempt vishing (voice phishing) contact to further manipulate victims into transferring assets or surrendering account access.”
reviewerAfter initial data entry, a scammer posing as 'support' would attempt vishing contact to further manipulate victims into transferring assets.Confirmed near-verbatim against independent reporting on the Coinbase alert. - #12[confirmed][no action needed]in section: Attack Methodology
“The IRS confirmed that legitimate IRS letters do not contain QR codes.”
reviewerThe IRS confirmed that legitimate IRS letters do not contain QR codes.Confirmed. - #13[confirmed][no action needed]in section: Technical Infrastructure
“The fraudulent domain 'irs.digitalcomplianceportal.com' was registered through a Hong Kong-based domain registrar only days before the physical letters were distributed.”
reviewerThe fraudulent domain was registered through a Hong Kong-based registrar only days before the physical letters were distributed.Confirmed. - #14[confirmed][no action needed]in section: Technical Infrastructure
“The website was hosted on servers in Romania that were already known to security researchers for hosting phishing pages impersonating FedEx and financial institutions.”
reviewerThe website was hosted on Romanian servers already known for hosting phishing pages impersonating FedEx and financial institutions.Confirmed, including the specific FedEx detail. - #15[confirmed][no action needed]in section: Technical Infrastructure
“Reporting by The Star (citing Bloomberg) characterized the operation as a 'professional, international fraud operation' based on the rapid infrastructure setup and prior track record of the hosting network.”
reviewerReporting by The Star (citing Bloomberg) characterized the operation as a 'professional, international fraud operation'.The exact phrase is used in Bloomberg-linked reporting republished by The Star; attribution is reasonably accurate. - #18[confirmed][no action needed]in section: Official Warnings and Regulatory Response
“The Accounting Today report of the same date reproduced key IRS-CI guidance: cease communication with the sender, change any compromised passwords, contact financial institutions, preserve evidence, and report to IRS-CI.”
reviewerThe Accounting Today report reproduced key IRS-CI guidance: cease communication, change passwords, contact financial institutions, preserve evidence, and report to IRS-CI.Confirmed via direct fetch of the Accounting Today article. - #19[confirmed][no action needed]in section: Official Warnings and Regulatory Response
“Coinbase published a consumer warning on July 28, 2026, crediting DarkTower as the threat intelligence source that identified the campaign.”
reviewerCoinbase published a consumer warning on July 28, 2026, crediting DarkTower as the threat intelligence source.Confirmed. - #21[confirmed][no action needed]in section: Broader Context: Crypto Impersonation Scam Trends
“According to the FBI Internet Crime Complaint Center (IC3), Americans lost over $11 billion to crypto-related scams in 2025, a reported 22% increase year-over-year, with an average loss of $62,604 per victim and over 18,000 cases exceeding $100,000 in losses.”
reviewerAccording to the FBI IC3, Americans lost over $11 billion to crypto-related scams in 2025, a 22% YoY increase, average loss $62,604 per victim, over 18,000 cases exceeding $100,000.All four figures (total loss, YoY %, average loss, high-loss case count) independently verified against FBI IC3 2025 report coverage. - #22[confirmed][no action needed]in section: Broader Context: Crypto Impersonation Scam Trends
“Chainalysis data cited in reporting noted impersonation scams surged 1,400% in 2025, with total scam losses reaching $17 billion that year.”
reviewerChainalysis data noted impersonation scams surged 1,400% in 2025, with total scam losses reaching $17 billion that year.Confirmed; note some coverage frames the on-chain total as $14 billion with the $17 billion figure as an upper estimate, but $17 billion is the widely reported headline figure. - #23[confirmed][no action needed]in section: Broader Context: Crypto Impersonation Scam Trends
“TRM Labs recorded more than 207 hacks in the first half of 2026 — more than double the prior-year period — suggesting a broader industry shift from technical protocol exploits toward social engineering targeting individual holders.”
reviewerTRM Labs recorded more than 207 hacks in the first half of 2026, more than double the prior-year period.Figure and comparison confirmed; the page's inferential framing about a shift toward social engineering is a reasonable editorial gloss on the reported data (smart-contract exploits still dominated by count, but the broader trend narrative is consistent with widely reported industry commentary). - #24[confirmed][no action needed]in section: Broader Context: Crypto Impersonation Scam Trends
“In parallel, the FBI's IC3 warned in July 2026 of criminals impersonating IC3 itself using AI-generated videos and spoofed websites to re-victimize prior fraud victims.”
reviewerThe FBI's IC3 warned in July 2026 of criminals impersonating IC3 itself using AI-generated videos and spoofed websites to re-victimize prior fraud victims.Confirmed against the IC3's own PSA. - #25[confirmed][no action needed]in section: Identification and Protection Guidance
“IRS-CI and security researchers identified the following indicators of the fraudulent letters: (1) letters arriving in plain unmarked envelopes rather than official IRS envelopes; (2) inclusion of a QR code — the IRS states it does not include QR codes in official correspondence; (3) references to an 'August 10' enrollment deadline creating artificial urgency; (4) direction to a domain other than IRS.gov; (5) requests for cryptocurrency wallet credentials, recovery phrases, or exchange login details.”
reviewerIRS-CI and security researchers identified specific fraud indicators and recommended protective actions (plain envelopes, QR codes, artificial urgency deadline, off-IRS.gov domain, credential requests; do not scan/call/enter info, verify at IRS.gov, report to IRS-CI and IC3).Indicators and guidance are standard and consistently reported across IRS.gov, Coinbase, and independent coverage. - #26[confirmed][no action needed]in the timeline
“Coinbase and threat intelligence firm DarkTower issued a consumer alert identifying the fake DACP letter campaign.”
reviewerCoinbase and DarkTower issued a consumer alert identifying the fake DACP letter campaign on July 28, 2026.Confirmed. - #27[confirmed][no action needed]in the timeline
“IRS Criminal Investigation (IRS-CI) issued a formal public warning confirming the campaign. IRS-CI Chief Jarod Koopman stated criminals were creating convincing fake websites and official-looking correspondence. The IRS confirmed it operates no Digital Asset Compliance Portal.”
reviewerOn July 30, 2026, IRS-CI issued a formal public warning; Chief Koopman gave the quoted statement; the IRS confirmed it operates no Digital Asset Compliance Portal.Confirmed. - #28[confirmed][no action needed]in the timeline
“Multiple crypto and mainstream news outlets including The Block, Crypto Briefing, Crypto Times, and Gate News published coverage of the IRS warning.”
reviewerOn July 31, 2026, The Block, Crypto Briefing, Crypto Times, and Gate News published coverage of the IRS warning.Confirmed that all four named outlets published coverage in the July 31 - August 1, 2026 window.