TX
TaxProExchange

Fake IRS 'Digital Asset Compliance Portal' Letters Are Landing in Mailboxes — What Tax Pros Need to Tell Crypto Clients

The IRS confirmed on July 30, 2026 that the 'Digital Asset Compliance Portal' does not exist. Here's how the mailed QR-code scam works, the exact red flags, and the script tax pros can send clients today.

By Koen Van Duyse
Fake IRS 'Digital Asset Compliance Portal' Letters Are Landing in Mailboxes — What Tax Pros Need to Tell Crypto Clients

Fake IRS "Digital Asset Compliance Portal" Letters Are Landing in Mailboxes — What Tax Pros Need to Tell Crypto Clients

It shows up in a plain, unmarked envelope mixed in with the junk mail — which is exactly the point.

Inside is a letter that looks like a routine IRS notice: Treasury letterhead, an official-sounding notice number, a tax year range, a deadline, and a QR code "to enroll." It tells the recipient they need to register in something called the Digital Asset Compliance Portal or face penalties.

There is no Digital Asset Compliance Portal. The IRS said so directly in a fraud alert issued July 30, 2026: "The IRS did not send it. The IRS does not operate a Digital Asset Compliance Portal. This is a scam."

Your crypto-holding clients are the target list. A lot of them will forward the letter to their preparer before they do anything — and what you say next matters. Here's the breakdown, and a client warning you can send today.

What the Fake Letter Looks Like

Reported copies share a consistent template:

  • A plain, unmarked envelope — deliberately forgettable, so it doesn't get flagged as suspicious the way a flashy piece of mail would.
  • Official-looking letterhead claiming to be from the "Department of the Treasury, Internal Revenue Service, Austin, TX."
  • An official-looking notice number, such as CP14-432RA, and a tax year range like 2017–2026 to make it feel plausible.
  • A hard deadline creating urgency to act before the recipient slows down to verify.
  • A QR code instead of a phone number — scan it and you're routed to a look-alike site, not IRS.gov.

The scammers vary the notice numbers and dates from batch to batch, so there is no single number that identifies every fake. The structure is the tell.

Why This Scam Is Smarter Than the Usual IRS Phone Call

Most IRS impersonation scams fail on the same rule: the real IRS contacts you by mail first, so a cold call demanding payment or a text about a refund is obviously fake — if the recipient knows the rule.

This campaign weaponizes that rule. It leads with the mail. It's dressed as the very thing we teach clients to trust, which strips out the usual "you should have gotten a letter first" defense.

The QR code is the second half of the trick. You can't hover over a QR code to preview the destination the way you can a link in an email. The victim finds out where they were going only after they've already scanned — and by then the page has loaded with a government-looking banner and a short, paperwork-feeling sequence.

Coinbase, working with the security firm DarkTower, traced the infrastructure behind one wave: the fake domain was registered through a Hong Kong registrar just days before the letters were mailed, then hosted on servers in Romania on a network previously linked to phishing pages impersonating banks. This isn't a sloppy robocall — it's purpose-built infrastructure designed to survive a client's quick Google search.

What the Fake Portal Actually Harvests

The look-alike site walks the victim through what feels like enrollment:

  1. Which exchange or wallet they use
  2. An estimate of their holdings
  3. A phone number so a "representative" can call back to "finish verification"

That callback is vishing — a live person posing as support — and it's the part that converts stolen data into stolen funds. Victims are talked into moving assets into a "safe wallet" controlled by the scammers.

The credentials harvested along the way are worse than a password reset:

  • Exchange account logins → direct access to balances
  • Wallet recovery phrases (seed phrases) → the ability to restore and drain the wallet anywhere, forever
  • Private keys → irrevocable control of the funds

A seed phrase is not like a password. You can't change it after the fact. Handing it over is handing over the wallet permanently.

What the Real IRS Actually Does With Digital Assets

Your clients will ask, reasonably, "But don't I have to report crypto to the IRS?" Yes — and this is where you add value instead of just forwarding a warning.

The legitimate reporting landscape is forms and questions, not portals and enrollment deadlines:

  • The digital asset question on Form 1040.
  • Form 1099-DA, the new broker reporting form for digital asset sales — a real form issued by real brokers, not a QR code in a plain envelope.
  • Genuine IRS notices that arrive with a notice or letter number and clear instructions, which you can verify through IRS.gov or by contacting the IRS using a number you looked up.

The IRS never sends you to a QR code to enroll in a compliance portal and never demands an enrollment fee on a deadline. If a letter's only call to action is "scan this and register," treat it as fraudulent, full stop.

The Exact Protocol to Give Clients

Send them this, in plain language:

  1. Don't scan the QR code. Don't reply, don't call any number printed in the letter.
  2. Verify independently. Log into IRS.gov directly, or call the IRS at the number listed on IRS.gov — never the contact method in the suspicious letter.
  3. If you already scanned or entered anything: change your exchange and email passwords immediately, contact your exchange, revoke API keys, enable multi-factor authentication, and — if a seed phrase or private key was exposed — move the assets to a brand-new wallet with a brand-new seed phrase. Don't reuse the compromised one.
  4. Preserve the evidence. Keep the letter, the envelope, and screenshots of any site you visited.
  5. Report it. IRS-CI at IRS.gov/submitatip, the FTC at ReportFraud.ftc.gov, and the FBI's Internet Crime Complaint Center at ic3.gov. If a wallet or exchange account was compromised, report that too.

What Tax Pros Should Do Right Now

This is a cheap, high-trust reason to contact your entire client list — and a chance to look sharp doing it.

  • Send a proactive client alert. Crypto holders first, but explain it to everyone — plenty of clients own digital assets you don't know about yet. A two-paragraph email now prevents a January conversation where a client has already been drained.
  • Add an IRS-contact protocol to your onboarding. Tell clients up front: "If you get an IRS letter, send it to us before you respond." That single sentence protects them and keeps you in the loop on real notices too.
  • Verify any "notice" a client forwards. Look up the notice number on IRS.gov before you act. Real notices have real numbers; this scam's numbers don't correspond to anything the IRS issues.
  • Watch the follow-on fear. Clients who get burned often stop trusting everyone — including legitimate calls from you and the IRS. Getting ahead of the scam is how you avoid being collateral damage to a fraudster.
  • Document your warning. A dated alert in your client newsletter or portal is a small piece of evidence that you flagged the risk.

The Bottom Line

The letters rely on one assumption: that a client who's been told "the IRS always mails you first" will trust the mail enough to scan the code. Break that assumption with your own message, before the scammers' letter gets there.

  • There is no Digital Asset Compliance Portal. The IRS does not run one, and a QR code demanding enrollment is fraud by definition.
  • The real reporting path is forms and verification — the 1040 digital asset question, Form 1099-DA, and notice numbers you can check on IRS.gov — not enrollment portals with deadlines.
  • Send the warning today. It's the single highest-confidence, lowest-effort client touch you'll make this month, and it earns trust that pays off long after the scam letter is in the recycling bin.

About the Author

Koen Van Duyse

Koen Van Duyse

Koen has been working in AI for the last two years, with an emphasis on conversational AI. In his spare time he is partner of a small tax firm in Southern California and runs the Tax Pro Exchange.

TaxProExchange

More Articles