When the lever breaks, the story begins. This time, the lever wasn’t a smart contract, a bridge, or a governance exploit. It was a paper envelope.
On Thursday, IRS Criminal Investigation publicly warned that counterfeit “IRS” letters are being mailed to cryptocurrency holders. The letters tell recipients to register on a fake “Digital Asset Compliance Portal.” The IRS has made it unequivocally clear: that portal does not exist. The IRS does not send QR codes. It does not require you to register an exchange or wallet through a notice. It does not ask for your recovery seed phrase over the phone.
I have spent years tracking crypto phishing infrastructure. I have seen fake login pages, fake airdrops, fake Discord bots. This one is different. It is a cross-channel attack that uses the U.S. Postal Service as its opening move. Let me unpack the envelope.
Context: When the IRS Becomes the Brand
IRS-CI, the criminal investigation arm of the IRS, does not issue public fraud alerts for trivial reasons. When Jarod Koopman, who leads IRS-CI, steps in front of a microphone to say that scammers are using the IRS’s name, it means the campaign is already active and victims are already being targeted. The alert was amplified by Coinbase’s security blog, which is one of the reasons the story made its way into mainstream crypto media.
The counterfeit letters are not crude scans. They are modeled on the IRS’s real educational compliance notices, which the IRS has been sending since 2019 to taxpayers who might have underreported digital asset transactions. By 2025, the IRS had sent more than 10,000 such notices. The fake letters include notice numbers, cite tax years from 2017 through 2026, and direct recipients to scan a QR code. That QR code leads to a lookalike irs.gov domain that was registered only days before the letters were mailed.
This timing is important. Fresh domains avoid reputation lists. The domain was registered through a Hong Kong registrar and hosted in Romania on the same infrastructure that has previously hosted phishing pages for FedEx and banks. That is not a coincidence. That is a fingerprint.
Core: Anatomy of a Trust Drainer
Let’s walk through the attack the way a forensic analyst would.
Step one is the physical letter. In a world where our inboxes are full of phishing emails, paper still carries a strange kind of authority. It arrives next to bills and bank statements. It has a Treasury Department logo. It has a notice number. Most people do not immediately think “scam” when they see a letter with a government seal. The attacker is weaponizing that baseline trust.
Step two is the QR code. This is the quietest and most effective part of the attack. With an email link, you can hover, inspect the domain, and make a decision. With a QR code, you cannot. You pull out your phone, open the camera, and by the time your brain catches up, the page is already loading. The QR code bypasses the “look before you click” heuristic entirely. It takes a technical decision and turns it into a habit.
Step three is the fake portal. Based on the IRS-CI alert, the portal asks for the name of the exchange you use, the type of hardware wallet you own, an estimate of your crypto holdings, and your phone number. That is not tax compliance. That is asset reconnaissance. The attacker is not trying to determine whether you owe taxes. It is trying to determine how much you have and where you keep it. In my own security audits, I have seen this pattern again and again: the first phase is reconnaissance, the second phase is social engineering, and the third phase is extraction.

Step four is the phone call. After the victim submits the portal form, a fake “support” caller reaches out. The caller asks for a one-time verification code, a password, or a recovery seed phrase. Sometimes the caller will demand a transfer to a “safe” account. This is the closing move. The victim has already been primed by the physical letter and the official-looking portal. By now, the attacker is not a stranger. The attacker is the “IRS.” The psychological momentum is almost impossible to interrupt.
Step five is the drain. With a seed phrase or an authentication code, the attacker moves funds to a wallet under their control. There is no chargeback. There is no reversal. In a bear market, this is the difference between holding through a drawdown and losing everything. A drawdown recovers. A drained wallet does not.
The IRS has defined the boundaries of its own communication: no QR codes, no portal registration, no requests to register exchanges or wallets, no requests for seed phrases. The legitimate way to verify a notice is to log into your official IRS online account at irs.gov or to call the IRS using the number on the official website. If you receive a letter that asks for portfolio details or a recovery phrase, it should be treated as hostile. Report it to the IRS and the FTC.
Technical Trail: Reused Infrastructure and the Romanian Fingerprint
The fake domain tells us more than the letter does. It was registered only days before the letters were sent, through a Hong Kong registrar, and hosted in Romania on infrastructure already linked to FedEx and bank phishing pages. In the world of threat intelligence, infrastructure reuse is the closest thing we have to a face. This campaign is not a lone actor printing letters in a basement. It is an organized operation with established hosting relationships, phishing toolkits, and a willingness to spend real money on paper and postage.
I built my first phishing-tracking script in 2020, during DeFi Summer, when I was scraping Uniswap swaps and looking for sentiment anomalies in liquidity pools. That experience taught me that code reveals truth, but narrative explains it. The truth here is straightforward: the same Romanian network has been used before. The narrative is more uncomfortable: a criminal enterprise has calculated that the expected value of draining a crypto wallet is higher than the cost of a physical mail campaign. That calculation would not make sense unless crypto holders were a high-value target.
The 2017-2026 tax year range is another tell. The attackers did not need to know exactly when you traded. They just needed to make you believe the IRS had been watching you for years. The broad date range is a shotgun. It increases the probability that any given recipient will experience the moment of panic: “Wait, I did trade crypto back then.” That panic is the emotional trigger. It is not precision. It is probability.
This is the hidden narrative arc: as the IRS expands its compliance outreach, the attack surface expands with it. The IRS is becoming a bigger presence in the lives of ordinary crypto holders. That is a regulatory trend, but it is also an opportunity for fraud. Scammers do not create stories from scratch. They impersonate the stories that already exist. Today the IRS story is the one they are borrowing.
The pulse didn’t register on-chain this time. It never does. It was in the mailroom, in the scan of a QR code, in the moment a nervous holder answered a phone call from an unknown number. That makes it harder to track than any smart contract exploit. But it also means the defense is not technical. It is narrative.
Contrarian: The Real Notice Is Now the Bait
Here is the counterintuitive angle that most security briefings miss.
The IRS is about to send more real letters. The 1099-DA regime will give the IRS far more data from exchanges, which will in turn generate more legitimate educational compliance notices. The IRS has already sent more than 10,000 of these letters by 2025, and that number will only grow. The more real letters the IRS sends, the easier it is for fake letters to hide in the noise.
This creates a dangerous paradox. If every official-looking envelope could be a scam, some users will respond by ignoring everything, including real notices. They will miss deadlines, trigger penalties, and build a genuine tax problem. Other users will respond by engaging with a fake notice because they are terrified of missing a deadline. The scam does not just steal from the careless. It poisons trust for everyone.
There is also a technical blind spot. I have watched security engineers fall for phishing because they overestimated their ability to detect a fake under pressure. A physical letter bypasses the “check the sender” heuristic. A QR code bypasses “hover before you click.” A phone call adds a voice of authority. When the attack arrives through a channel that is outside your default threat model, your cryptographic savvy does not help. The attacker is not hacking your code. The attacker is hacking your story about who is trying to help you.
Falling through the floor to find the foundation is the only way forward. The foundation is not a better antivirus or a longer blocklist. It is a personal verification ritual: never enter sensitive data through the channel that contacted you. If a letter asks you to scan a QR code, close the envelope. If an email asks you to click a link, open a browser yourself and type the official domain. If someone calls asking for a seed phrase, hang up. The official IRS channel is irs.gov. That is the only door.
The Market Read: Bear-Market Survival, Not Price Signal
Does this news move markets? No. It is not a protocol exploit. It is not a stablecoin depeg. It will not show up on a candlestick. But in a bear market, this is precisely the kind of risk that matters more than price volatility.
The bear market has already squeezed out the speculators. The people still holding crypto are the ones who intend to hold for years. For them, asset safety is the top priority. A phishing attack that targets a seed phrase is more dangerous than a 20% drawdown, because a drawdown can recover while a drained wallet cannot. The IRS letter scam is a reminder that the biggest risk to a portfolio is not the market. It is the moment you hand over the key to someone who asked nicely.

This also reshapes the competitive landscape. Exchanges and wallet providers now have a clear obligation to push anti-phishing education into the user experience. Coinbase helped amplify the IRS-CI alert, and that is a good start. But every platform should be asking: what happens when a user tells us they received a letter from the IRS asking for a seed phrase? The answer should not be a help-center article. It should be an in-app alert, a blocking screen, and a direct link to the IRS’s official verification channel.
There is also an opportunity for crypto tax compliance tools. Services like CoinTracker, Koinly, and others are already the bridge between raw blockchain data and tax obligations. After this attack, more users will be afraid to respond to any IRS communication on their own. They will want a trusted third party to tell them whether a notice is real. The tax-software sector can become the “designated verifier” for crypto holders, reducing the surface area for fraud by centralizing verification. That is a product narrative, not just a compliance feature.
Takeaway: The Seed Phrase Is a Nuclear Code
The IRS has drawn a clear line. It will not send QR codes. It will not ask you to register your exchange or wallet. It will not ask for your recovery phrase. No regulator will ever ask for your recovery phrase. The only person who needs your seed phrase is the person who wants to take everything you have.
When the lever breaks, the story begins. But the story does not have to end in a drained wallet. It can end with a new habit: before you scan, before you click, before you answer, verify through the channel you already trust. Type irs.gov yourself. Call the official IRS number. Report the suspicious letter to the IRS and the FTC. And if a “government official” ever asks for your seed phrase, hang up. Close the envelope. Walk away.
The next narrative arc is already forming. As 1099-DA expands the IRS’s reach, the volume of real and fake IRS communications will rise together. The only way to survive that collision is to make verification reflexive. Not cautious. Reflexive.
The lever broke. Now we rebuild the floor. Let’s make sure it’s solid.