IRS Fake Digital Asset Compliance Portal Scam (2026)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·yWnVMZ…PXw2Summary
Beginning in late July 2026, an organised threat actor began mailing physical letters to U.S. cryptocurrency holders that closely mimicked official IRS correspondence, directing recipients via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest wallet credentials, exchange logins, and identity data. The IRS issued a formal fraud alert on July 30, 2026, explicitly confirming it does not operate any such portal. Coinbase and cybersecurity firm DarkTower traced the campaign infrastructure to a recently registered domain hosted on Romanian servers previously linked to financial phishing networks, indicating a well-organised international fraud operation.
Connected Entities
2 entities · 60 linked investigations- IRS Fake Digital Asset Compliance Portal Scam (2026)→mentioned with→Coinbase(70%)
Connected Through
1 shared actor · 228 investigationsDistinct actors this investigation shares with others — holders, traders, and named parties. Shared infrastructure (exchanges, pools) is excluded.
- ♦Coinbasetoken
1 submission awaiting moderator review.
Timeline(9 events)
28 July 2026
Coinbase and cybersecurity firm DarkTower jointly identify the fraudulent Digital Asset Compliance Portal campaign and begin infrastructure analysis.
Crypto Briefing30 July 2026
IRS Criminal Investigation issues a formal fraud alert confirming it does not operate a Digital Asset Compliance Portal, and that the physical letters are fraudulent. IRS-CI Chief Jarod Koopman characterises the operation as a 'professionalized international scam operation.'
IRS.gov — Official Fraud Alert3 August 2026
Journal of Accountancy and CPA Practice Advisor publish warnings directed at accounting professionals and their clients, amplifying the IRS alert.
Journal of Accountancy4 August 2026
Help Net Security publishes a technical breakdown of the campaign, detailing the four-stage attack flow, Hong Kong domain registrar, and Romanian hosting infrastructure previously used for bank and FedEx impersonation phishing.
Help Net Security14 August 2026
Crypto holder @OddStockTrader publicly shares receipt of a fraudulent letter on X, confirming the campaign is actively reaching recipients weeks after the IRS alert.
The Crypto Times17 August 2026
Crypto holder @imjgalt2 shares a photo of the fraudulent notice on X, describing it as looking 'totally legit' and speculating recipient addresses may derive from exchange data breaches.
The Crypto Times19 August 2026
Crypto holder @woodificouldart posts images of a received fraudulent letter on X, further evidencing continued campaign distribution.
The Crypto Times20 August 2026
Forbes publishes an analysis by cryptocurrency tax CPA Shehan Chandrasekera (CoinTracker) explaining the scam's mechanics and providing preventive guidance.
Forbes21 August 2026
The Crypto Times publishes an updated summary of the campaign, confirming letters are still circulating into late August 2026 despite public warnings issued nearly a month prior.
The Crypto TimesDecision Log
- slot 443510900 · hash 4L1HGqFvbrFc11H1cgtS6nzDqs38NsH2wkbvVgtXZpz1
- slot 443510883 · hash Bbw9QzhuS2MfWp7aKSVv6taYX4Z44bML6EduXiQGkJAz
- slot 443509860 · hash Hm2ENjz1d1YoA6YDUxhYaZ8mFwbQURnzP8oGMSRSSHPc
This investigation is cryptographically anchored to the Solana blockchain (3 decisions). 12 of 12 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/22/2026, 11:07:19 PM
last updated: 8/25/2026, 3:16:41 AM
5 viewsavoid.net — verified advice for a post-truth world