IRS Warns of QR-Code Crypto Tax Scam: Fake DACP Portal Used for Vishing
The US IRS (July 30) warned crypto holders about a QR-code phishing scam targeting investors’ tax compliance. Victims receive paper letters that appear to be from the Treasury/IRS (notice ID: CP14-432RA) and instruct them to register on a “Digital Asset Compliance Portal (DACP)” before a deadline. The IRS says the letter is not theirs and the DACP website does not exist.
Coinbase Security and threat intel firm DarkTower reviewed a captured sample and found the scam’s core is not the web form itself, but the follow-up phone call. The fake site copies US government page templates and collects only three items: which exchange/wallet the victim uses (e.g., Ledger/Trezor, Coinbase/Kraken/Binance), a rough portfolio size (including “$100,000+”), and the victim’s phone number. There is no password or seed phrase entry on the page.
During vishing (voice phishing), the attacker impersonates an “official specialist” and pushes for sensitive access—such as 2FA codes, account passwords, or even a 12-word seed phrase—sometimes claiming it is a “safe transfer” to move funds.
The article links the scam’s personalization to prior data leaks: Trezor’s logistics partner incident exposed customer name/address/phone (reported ~14,000 affected), SafePal reported ~40,000 orders exposed, and Ledger-related leaks had already circulated in black markets.
For traders: this is primarily a security risk (not a market-news driver), but any successful credential theft can create sudden sell pressure on affected accounts and increase short-term volatility around major custody providers.
Neutral
This news is mainly about fraud and account security, not about protocol changes, regulation outcomes, or tokenomics—so it’s unlikely to be a direct bullish/bearish catalyst for the whole market. However, scams like this can create localized bearish pressure: victims may lose access to funds and then liquidate quickly, which can cause short-term volatility around affected custody/exchange users. Historically, major security incidents (exchange/custody breaches and targeted social engineering) tend to produce brief “risk-off” reactions—wider market usually stabilizes once details and remediation are clear. Over the long term, repeated phishing campaigns can raise compliance/operational caution for institutions and retail users, but they generally don’t change chain-level fundamentals unless tied to a systemic exploit.