← IRS Fake Digital Asset Compliance Portal Scam (2026)1 decision on this page
Audit log
Every state-changing event for IRS Fake Digital Asset Compliance Portal Scam (2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-22 23:07:27ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
Hm2ENjz1d1Yo…MSRSSHPcsha256 → base58
verifying row…canonical bytes (21477 B) ▸
{"actor":"system:backfill","investigation_id":"17a50b72-7abf-4a8f-8d89-8ac92e3fe502","kind":"publish","page_slug":"irs-fake-digital-asset-compliance-portal-scam-2026","published_at":"2026-08-22T23:07:27.094Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"IRS Fake Digital Asset Compliance Portal Scam (2026)","sections":[{"content":"Starting in late July 2026, fraudsters began mailing physical letters across the United States targeting cryptocurrency holders. The letters were designed to closely mimic official IRS correspondence, arriving in plain unmarked envelopes with bureaucratic formatting and fabricated notice numbers (such as CP14-432RA). Letters referenced tax years 2017 through 2026 and imposed urgent enrollment deadlines in early September 2026. Each letter included a QR code directing recipients to a fraudulent website operating under a domain resembling irs.digitalcomplianceportal[.]com — not the real IRS.gov. According to IRS Criminal Investigation, Coinbase, and cybersecurity firm DarkTower, the spoofed site displayed an 'official website of the United States government' banner and mimicked IRS.gov's design. The IRS has confirmed unequivocally that it does not operate any entity called a 'Digital Asset Compliance Portal.' The use of physical mail — rather than email — was a deliberate tactic to bypass email security filters and lend false credibility to the correspondence, representing an escalation in social engineering methodology targeting crypto holders.","heading":"Scam Overview and Modus Operandi","severity":"critical","sources":[{"credibility":1,"name":"Fraud alert: Fake IRS letters target cryptocurrency holders — IRS.gov","type":"official","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Crypto Alert: Fake IRS 'Digital Asset Compliance Portal' Letters Arrive in Mail — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"research","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]},{"content":"According to analysis by Coinbase and DarkTower, the fraudulent portal operated in multiple stages. In Stage 1, victims were asked to select their cryptocurrency exchange or wallet type. In Stage 2, they were prompted to estimate the value of their holdings, with ranges presented up to '$100,000+.' In Stage 3, a phone number was requested under the guise of identity verification. DarkTower, which tested the flow using temporary contact information, found that after submitting a phone number the site went offline, suggesting either delayed social engineering or data harvesting for future attacks. According to Coinbase's analysis, the subsequent phone call — if it occurred — constituted the primary attack vector: callers impersonated IRS or support representatives and attempted to extract one-time codes, passwords, seed phrases, or private keys, or persuaded victims to transfer funds to attacker-controlled wallets. The phishing site also solicited personal identification data, cryptocurrency wallet recovery phrases, and exchange account credentials. The IRS confirmed that the agency never requests wallet recovery phrases, private keys, or immediate asset transfers.","heading":"Attack Stages and Data Harvested","severity":"critical","sources":[{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"research","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":1,"name":"Fraud alert: Fake IRS letters target cryptocurrency holders — IRS.gov","type":"official","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"}]},{"content":"Coinbase and threat intelligence firm DarkTower jointly identified the fraudulent campaign's infrastructure. According to their published findings, the fraudulent domain was registered through a Hong Kong-based registrar only days before the letter campaign began mailing. The domain was hosted on Romanian servers that had previously been used in phishing campaigns impersonating banks and delivery services, including FedEx. DarkTower described the campaign as bearing 'hallmarks of a well-organised, internationally-coordinated fraud operation.' No specific domain name has been officially published in IRS materials; the domain pattern irs.digitalcomplianceportal[.]com has been cited by news sources including Help Net Security and Yahoo Finance. The Romanian infrastructure link to prior phishing operations indicates this is not an isolated or amateur campaign. IRS-CI Chief Jarod Koopman characterised the operation as a 'professionalized international scam operation' exploiting public trust in government agencies. As of late August 2026, no named individuals or criminal groups have been publicly identified as perpetrators, and no arrests directly tied to this campaign have been reported.","heading":"Infrastructure and Technical Attribution","severity":"critical","sources":[{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"research","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"IRS warns crypto investors of fake letters — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/irs-warns-crypto-investors-fake-113000642.html"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"research","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"}]},{"content":"The IRS issued a formal fraud alert on July 30, 2026, explicitly stating: 'The IRS does not operate a Digital Asset Compliance Portal. This is a scam.' IRS Criminal Investigation Chief Jarod Koopman issued a public statement reading: 'Criminals continue to exploit public trust in government agencies by creating convincing fake websites and official-looking correspondence.' Koopman also confirmed that the IRS 'never initiates contact by demanding enrollment in online portals via QR codes,' and that the agency does not request wallet recovery phrases, private keys, or immediate asset transfers. The IRS directed affected taxpayers to report suspicious letters to IRS Criminal Investigation at IRS.gov/SubmitATip. The IRS noted that while it does include QR codes on some legitimate notices, unsolicited correspondence with QR codes should be treated with extreme caution. The Journal of Accountancy, published by the American Institute of CPAs, independently verified and amplified the IRS warning for accounting professionals and their clients. IRS-CI's alert was issued approximately two days after Coinbase and DarkTower jointly flagged the campaign on or around July 28, 2026.","heading":"Official Government Response","severity":"critical","sources":[{"credibility":1,"name":"Fraud alert: Fake IRS letters target cryptocurrency holders — IRS.gov","type":"official","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":1,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":1,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"}]},{"content":"Multiple cryptocurrency holders publicly shared photographs of the fraudulent letters on social media platform X (formerly Twitter) between mid-August and late August 2026, confirming the campaign was actively reaching real recipients. Accounts including @OddStockTrader (August 14, 2026), @imjgalt2 (August 17, 2026), and @woodificouldart (August 19, 2026) posted images of letters they received. Observers, including @imjgalt2, noted the letters 'looked totally legit,' and speculated that recipient addresses may have been sourced from data breaches involving cryptocurrency exchanges. This hypothesis has not been independently confirmed by any Tier 1 or Tier 2 source as of August 2026. The campaign continued circulating into late August 2026, more than three weeks after the IRS fraud alert was publicly issued, indicating significant ongoing victim surface. No official victim count or aggregate financial loss figure specific to this campaign has been published by the IRS, FBI, or any law enforcement body as of the time of this investigation. For broader context, the FBI's Internet Crime Complaint Center reported that cryptocurrency-related fraud caused over $11 billion in losses across approximately 181,500 complaints in 2025.","heading":"Victim Surface and Targeting Method","severity":"high","sources":[{"credibility":2,"name":"Crypto Alert: Fake IRS 'Digital Asset Compliance Portal' Letters Arrive in Mail — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"credibility":2,"name":"IRS warns crypto investors of fake letters — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/irs-warns-crypto-investors-fake-113000642.html"},{"credibility":2,"name":"Scammers posing as the IRS are tricking Bitcoin holders with a fake 'Digital Asset Compliance Portal' — Moneywise","type":"news_article","url":"https://moneywise.com/news/top-stories/irs-impersonation-scam-crypto-bitcoin-holders"}]},{"content":"Security researchers and journalists have noted that the deliberate use of physical postal mail marks a significant tactical escalation over conventional email-based phishing. Physical letters bypass email spam filters, anti-phishing tools, and browser-based warnings. The IRS has sent legitimate educational compliance letters to cryptocurrency holders since 2019, which researchers at Crypto Briefing noted creates a plausible basis for recipients to treat such correspondence as genuine. Forbes contributor and CPA Shehan Chandrasekera, writing on August 20, 2026, characterised the scheme as exploiting 'compliance concerns regarding digital asset taxation' at a moment when U.S. cryptocurrency tax enforcement has been an active regulatory topic. The combination of physical mail, professional government-style design, fabricated notice numbers, QR codes, urgency deadlines, and a multi-stage phone-based social engineering component is consistent with organised criminal infrastructure rather than opportunistic fraud. No equivalent physical-mail IRS impersonation campaign targeting cryptocurrency holders at this scale has been publicly documented prior to this campaign.","heading":"Contextual Escalation: Physical Mail as Attack Vector","severity":"high","sources":[{"credibility":1,"name":"The Fake IRS Crypto Letter You Need To Know — Forbes","type":"news_article","url":"https://www.forbes.com/sites/shehanchandrasekera/2026/08/20/the-fake-irs-crypto-letter-you-need-to-know/"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"research","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"}]},{"content":"The IRS, Coinbase, Bitdefender, and the Journal of Accountancy have all published guidance for individuals who receive or have acted on these letters. Recommended steps include: do not scan QR codes from unsolicited correspondence claiming government origin; verify any IRS contact by navigating directly to IRS.gov and using official contact numbers; never share wallet recovery phrases, private keys, passwords, or two-factor authentication codes with any third party; if credentials were already shared, immediately change passwords on all financial and exchange accounts, enable multifactor authentication, and contact relevant exchanges and financial institutions; preserve the physical letter, envelope, and any screenshots as evidence; report the letter to IRS Criminal Investigation via IRS.gov/SubmitATip and to the FBI's Internet Crime Complaint Center at IC3.gov; and consider placing a credit freeze with the major credit bureaus if personal identity data was submitted. The IRS has also recommended monitoring financial accounts for unauthorized activity.","heading":"Guidance for Recipients","severity":"medium","sources":[{"credibility":1,"name":"Fraud alert: Fake IRS letters target cryptocurrency holders — IRS.gov","type":"official","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":1,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"research","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"}]}],"sources_used":[{"credibility":1,"name":"Fraud alert: Fake IRS letters target cryptocurrency holders — IRS.gov","type":"official","url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"credibility":1,"name":"IRS warns crypto holders about fake compliance portal scam — Journal of Accountancy","type":"news_article","url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"credibility":1,"name":"The Fake IRS Crypto Letter You Need To Know — Forbes","type":"news_article","url":"https://www.forbes.com/sites/shehanchandrasekera/2026/08/20/the-fake-irs-crypto-letter-you-need-to-know/"},{"credibility":1,"name":"IRS warns crypto holders of fake letters — Accounting Today","type":"news_article","url":"https://www.accountingtoday.com/news/irs-ci-warns-of-fake-irs-letters-targeting-crypto-holders"},{"credibility":2,"name":"Fake IRS letters direct crypto holders to bogus compliance portal — Help Net Security","type":"news_article","url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"credibility":2,"name":"Consumer Protection Tuesday: A Fake IRS 'Digital Asset Compliance Portal' Letter Is Targeting Crypto Holders — Coinbase Blog","type":"research","url":"https://www.coinbase.com/blog/consumer-protection-tuesday-fake-irs-scam"},{"credibility":2,"name":"Crypto Alert: Fake IRS 'Digital Asset Compliance Portal' Letters Arrive in Mail — The Crypto Times","type":"news_article","url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"credibility":2,"name":"Fake IRS letters target cryptocurrency holders — Bitdefender Hot for Security","type":"research","url":"https://www.bitdefender.com/en-us/blog/hotforsecurity/fake-irs-letters-cryptocurrency"},{"credibility":2,"name":"IRS warns of counterfeit letters targeting crypto holders — Crypto Briefing","type":"news_article","url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"credibility":2,"name":"IRS warns crypto investors of fake letters — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/irs-warns-crypto-investors-fake-113000642.html"},{"credibility":2,"name":"Scammers posing as the IRS are tricking Bitcoin holders with a fake 'Digital Asset Compliance Portal' — Moneywise","type":"news_article","url":"https://moneywise.com/news/top-stories/irs-impersonation-scam-crypto-bitcoin-holders"},{"credibility":2,"name":"IRS Warns: Impersonation Letters Include QR Codes — Gate News","type":"news_article","url":"https://www.gate.com/news/detail/us-irs-warns-impersonation-letters-contain-qr-codes-stealing-crypto-assets-23094072"}],"summary":"Beginning in late July 2026, an organised threat actor began mailing physical letters to U.S. cryptocurrency holders that closely mimicked official IRS correspondence, directing recipients via QR code to a fraudulent 'Digital Asset Compliance Portal' designed to harvest wallet credentials, exchange logins, and identity data. The IRS issued a formal fraud alert on July 30, 2026, explicitly confirming it does not operate any such portal. Coinbase and cybersecurity firm DarkTower traced the campaign infrastructure to a recently registered domain hosted on Romanian servers previously linked to financial phishing networks, indicating a well-organised international fraud operation.","timeline":[{"date":"2026-07-28","event":"Coinbase and cybersecurity firm DarkTower jointly identify the fraudulent Digital Asset Compliance Portal campaign and begin infrastructure analysis.","source":"Crypto Briefing","source_url":"https://cryptobriefing.com/irs-warns-counterfeit-letters-crypto-holders/"},{"date":"2026-07-30","event":"IRS Criminal Investigation issues a formal fraud alert confirming it does not operate a Digital Asset Compliance Portal, and that the physical letters are fraudulent. IRS-CI Chief Jarod Koopman characterises the operation as a 'professionalized international scam operation.'","source":"IRS.gov — Official Fraud Alert","source_url":"https://www.irs.gov/compliance/criminal-investigation/fraud-alert-fake-irs-letters-target-cryptocurrency-holders"},{"date":"2026-08-03","event":"Journal of Accountancy and CPA Practice Advisor publish warnings directed at accounting professionals and their clients, amplifying the IRS alert.","source":"Journal of Accountancy","source_url":"https://www.journalofaccountancy.com/news/2026/aug/irs-warns-crypto-holders-about-fake-compliance-portal-scam/"},{"date":"2026-08-04","event":"Help Net Security publishes a technical breakdown of the campaign, detailing the four-stage attack flow, Hong Kong domain registrar, and Romanian hosting infrastructure previously used for bank and FedEx impersonation phishing.","source":"Help Net Security","source_url":"https://www.helpnetsecurity.com/2026/08/04/fake-irs-crypto-letters-compliance-portal-scam/"},{"date":"2026-08-14","event":"Crypto holder @OddStockTrader publicly shares receipt of a fraudulent letter on X, confirming the campaign is actively reaching recipients weeks after the IRS alert.","source":"The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"date":"2026-08-17","event":"Crypto holder @imjgalt2 shares a photo of the fraudulent notice on X, describing it as looking 'totally legit' and speculating recipient addresses may derive from exchange data breaches.","source":"The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"date":"2026-08-19","event":"Crypto holder @woodificouldart posts images of a received fraudulent letter on X, further evidencing continued campaign distribution.","source":"The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"},{"date":"2026-08-20","event":"Forbes publishes an analysis by cryptocurrency tax CPA Shehan Chandrasekera (CoinTracker) explaining the scam's mechanics and providing preventive guidance.","source":"Forbes","source_url":"https://www.forbes.com/sites/shehanchandrasekera/2026/08/20/the-fake-irs-crypto-letter-you-need-to-know/"},{"date":"2026-08-21","event":"The Crypto Times publishes an updated summary of the campaign, confirming letters are still circulating into late August 2026 despite public warnings issued nearly a month prior.","source":"The Crypto Times","source_url":"https://www.cryptotimes.io/2026/08/21/crypto-alert-fake-irs-digital-asset-compliance-portal-letters-arrive-in-mail/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 8299a14d-423d-42ae-a991-91f15509dcb0
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.