
Counterfeit IRS letters with QR codes are draining crypto wallets through a phishing site hosted in Romania and registered in Hong Kong, Darktower and Coinbase found.
Fraudsters are sending counterfeit IRS notices to cryptocurrency holders, directing them to a fake "Digital Asset Compliance Portal" that steals wallet access and credentials, security firms said.
The letters carry a QR code that leads to a phishing site mimicking IRS.gov, according to Darktower, which traced the operation alongside Coinbase. The domain was registered in Hong Kong and the site is hosted in Romania, the firms found. The international setup is deliberate, researchers said. Takedowns requiring coordination between agencies in multiple countries take longer, giving scammers time to shift to fresh infrastructure.
This is not the first targeted campaign. In 2019, phishing emails hitting Binance and Kraken users stole thousands of credentials before the scope became known, security researchers said. In 2022, scammers posed as health authorities to extract crypto assets during the pandemic. The method stays the same: impersonate a trusted institution, copy its look and tone, manufacture urgency.
The IRS angle is especially effective because tax compliance already carries a built-in fear response, analysts said. An official-looking letter with a QR code and an urgent deadline short-circuits caution. The counterfeit notices mimic real IRS correspondence closely, down to letterhead and formatting, Darktower said. The phishing site is a near-copy of IRS.gov, with only slight differences in the domain name.
The damage runs in two directions. For victims, the immediate cost is lost funds and stolen identity documents that can be used for further fraud, including opening accounts in their name, security experts said. For the broader crypto industry, each successful scam reinforces a reputation that the space is insecure, regardless of the underlying blockchain technology.
The IRS has warned taxpayers not to scan unsolicited QR codes or submit personal information through links in unexpected letters, the agency said. The FBI has issued similar warnings about fake compliance portals. Both agencies urge recipients to verify any communication through official channels before acting.
Coinbase and Darktower are mapping the scam's infrastructure. Private-sector trace work gives law enforcement a concrete starting point, Darktower said. The number of phishing incidents reported to the IRS over the coming months will show the campaign's true reach. A sharp increase in reports would mean the letters reached a wider audience than currently known.
Exchange responses also matter. Platforms can flag unusual login behavior and push user warnings in real time, Coinbase said. Whether other major exchanges adopt similar security measures will affect how many additional victims fall for the scheme.
The domain in Hong Kong and the hosting in Romania give investigators threads to pull. The speed of international cooperation around that infrastructure will shape how quickly this operation gets disrupted, security experts said. The IRS guidance is direct: verify through official channels, and never scan unsolicited QR codes.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.