惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
M
MIT News - Artificial intelligence
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
量子位
S
SegmentFault 最新的问题
V
Visual Studio Blog
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
小众软件
小众软件
Stack Overflow Blog
Stack Overflow Blog
Vercel News
Vercel News
D
Docker
J
Java Code Geeks
博客园 - 三生石上(FineUI控件)
博客园 - Franky
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
Y
Y Combinator Blog
云风的 BLOG
云风的 BLOG
V
V2EX

GRAHAM CLULEY

Former AT&T store worker jailed after moonlighting as a SIM-swap gang's inside man 'Anne Hathaway' admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars Smashing Security podcast #484: How websites are tracking you with silence CRPx0 ransomware: what you need to know The US military just turned off ad tracking on its phones. Maybe you should too How a hole in Lenovo's login system let hackers walk into 5,000 Dropbox accounts Smashing Security podcast #483: This AI helps thieves steal your iPhone Revolut scam steals £180,000 from Jersey residents in just four weeks Shai-Hulud hackers: two men charged over TeamPCP's global supply chain crime spree that hit OpenAI, and thousands more US Navy tells sailors and their families: scrub your social media, enemies are watching Smashing Security podcast #482: This hacker leaked GTA 6 - and launched their own cryptocurrency Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials Gunra ransomware: what you need to know Smashing Security podcast #481: Never say this to a robot dog Prison for data analyst who tried to extort $2.5 million from his employer An "invisible" car? Researcher uses machine learning to hide vehicles from Flock cameras Smashing Security podcast #480: This is the AI service you should never sign up to Meta's Ray-Bans are being banned from pubs, restaurants, and theatres Beware cut-price AI services that read your every word Apple's bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency The $5 million threat: AI Is supercharging phishing attacks North Korea's elite hackers turned on their own government — and got caught Smashing Security podcast #478: This job interview could destroy your company OpenAI's AI "goes rogue" and hacks Hugging Face: what you need to know Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker Ukraine warns fake CAPTCHAs are being used to make you hack yourself Google's Gemini lets strangers send messages from your locked Android phone Anubis ransomware: what you need to know
Fake IRS letters target cryptocurrency holders
Graham CLULEY · 2026-08-04 · via GRAHAM CLULEY

Do you hold cryptocurrency? Have you received a letter telling you that you must register with a so-called "Digital Asset Compliance Portal"?

If so, it's time to hit the brakes, because it sounds like someone is trying to scam you.

The United States Internal Revenue Service (IRS) has issued a fraud alert after it was found that scammers are sending official-looking letters to people with cryptocurrency holdings, directing victims to a website designed to steal personal details and digital assets.

As Coinbase's security team explains, the letters urge recipients to scan a QR code and enrol in a "Digital Asset Compliance Portal" before time runs out.

Scanning the QR code takes unsuspecting members of the public to a fraudulent website which poses as IRS.gov, but - to be absolutely clear - the IRS does not operate a Digital Asset Compliance Portal.

Coinbase described one of the letters they have seen. It arrived in an unmarked envelope, imitated a real notification from the IRS, and claiming to come from the Department of the Treasury, Internal Revenue Service, Austin, TX. The use of an official-looking notice number (CP14-432RA), and reference to the tax year range 2017–2026, would have made it appear even more plausible to many recipients.

Bear in mind that the criminals could easily vary these details from letter to letter.

The phishing page visited by potential victims continues the subterfuge with IRS-style branding and a banner claiming to be an "official website of the United States government."

But what the site does is ask you to share where you keep your cryptocurrency (with a range of choices from hardware wallets like Ledger and Trezor to exchanges like Coinbase and Binance.)

The scam site then asks victims to estimate how much value they have in their cryptocurrency wallets, with ranges up to "$100,000+". Presumably this helps the fraudsters determine which accounts to prioritise for plundering.

And then the site asks you for your phone number in order to "get verified" by a support representative. Of course, the purpose of such a call is to try and talk you into handing over the keys to your account - whether it be a password, a recovery or seed phrase, or a 2FA code.

Perhaps a reason why a scam like this can work is that the IRS has been tightening cryptocurrency holders' requirement to report details of their digital assets on their tax returns. As a result, written communications between the IRS and holders of cryptocurrency have become more frequent.

In short, a letter from the IRS telling a US taxpayer to register their digital assets may not sound as outlandish as it might have done a few years ago.

Investigations by Coinbase's security team and their partners at threat intelligence firm DarkTower found that the domain used in the attack had been registered just days before the fake letters were mailed out, through a Hong Kong-based registrar, with the fraudulent site itself hosted in Romania. It emerged that the site was hosted on infrastructure already associated with phishing campaigns targeting banks and financial institutions.

In other words, this does not sound like an amateur cybercriminal was at work here. The campaign has all the hallmarks of a well-organised, internationally-coordinated fraud.

So, what should you do about this threat? The advice is simple:

  • If you receive one of these letters, do not scan the QR code and do not visit any website mentioned in them.
  • Remember that you should never share your password, 2FA codes, or recovery/seed phrases with anyone.
  • If in doubt, verify the facts independently by visiting the official IRS website at irs.gov.
  • And if you believe you may have already handed over sensitive information to fraudsters, stop communicating with them, change your passwords, contact your cryptocurrency exchange immediately, preserve any evidence of communications you may have had with the scammers, and report what has happened to the IRS.