The weak point is no longer the inbox. A paper IRS-style letter can make the fraud feel official, and the real theft happens later on the phone, where the victim is pushed to hand over a one-time code, password, or seed phrase themselves.
Coinbase and DarkTower traced the scheme after a customer reported one of the letters. The mailing uses Treasury and IRS branding, a QR code, and a fake “Digital Asset Compliance Portal” that leads into a callback request; DarkTower also tied the domain to infrastructure registered days earlier and previously linked to phishing pages impersonating banks and delivery services.
That means email filters and bad-link blocking miss the main control point. The same official-looking notice plus callback pattern can be reused against crypto accounts and other high-value targets that rely on phone-based verification.