-
A fake letter pretending to be from France’s tax office, the DGFiP, reportedly reached a crypto user.
-
The letter asks people to list their crypto exchanges, wallets, and full transaction history.
-
It uses a QR code instead of a real government link, a trick that hides where the code truly leads.

A new scam letter is targeting crypto users in France. It looks like it comes from the Direction générale des Finances publiques (DGFiP), France’s tax authority.
A French internet user named Cyril Blondel shared the letter online. He warned that its QR code sent people to a strange website. Crypto news site Cryptoast then reported on the letter. The outlet called it a fake legal notice built to look official.
Fraudulent Letter Mimics French Tax Authority
According to Cryptoast, the letter asks the reader for a lot of private information. It wants the names of every crypto exchange they use. It also wants details about their digital wallets and DeFi platforms.
On top of that, it demands their full transaction history. Instead of pointing readers to the real government site, the letter gives them a QR code to scan. That code reportedly leads to a fake website. There, the goal is to trick users into typing in personal and financial details.
A letter arriving by post feels more trustworthy to many people than an email. That trust is exactly what scammers count on here. The QR code adds another layer of trickery. It hides the true web address until someone actually scans it. Most people cannot tell a safe link from a dangerous one just by looking at a printed code.
Scam Exploits New Crypto Reporting Law
This scam works so well because it borrows a real event. New European tax rules, called DAC8, started on January 1, 2026. These rules widen tax reporting to cover crypto assets. Crypto companies must now collect data on certain transactions. They must also share that data with tax offices. The first batch of reports covers deals made in 2026. Actual reporting and data sharing will happen later.
Because these rules are real, the fake letter feels believable. A person who already knows tax offices are watching crypto more closely may not question the letter. They may assume a request for wallet details is normal. That assumption is exactly what the scam relies on.
A similar QR code scam has exploited geopolitical tensions. In early 2026, researchers uncovered a phishing campaign impersonating government civil defense agencies with fake missile alert emails. The emails carried urgent warnings and instructed recipients to scan a QR code for “official emergency procedures.” The codes redirected to fake Microsoft login pages designed to harvest credentials, using panic to override caution.
The letter reportedly points to a website address called directiondac8.com. That domain shows up in a public list of new .com website registrations dated August 31, 2026. A domain name built to sound official does not prove it is safe. Anyone can register a web address that sounds like a government site.
Letter May Link to Past Data Breach
Cryptoast said the person who got this letter was not part of the recent DGFiP data leak. Instead, the outlet linked the exposure to an older event. That event was the 2020 Ledger data breach. This link matters because breaches often expose home addresses along with names. Criminals can use old, leaked addresses to find people who likely own crypto. They then mail scam letters straight to those addresses.
This specific link between the victim and the Ledger breach has not been confirmed by another source. It should be treated as a reported claim, not a proven fact. Even so, the pattern fits earlier cases. Past scams have used fake Ledger letters with QR codes to push victims toward harmful websites. Criminals are now mixing old leaked data with new physical scam letters.
Mail scams that use QR codes are sometimes called quishing. This kind of trick works because a physical letter feels more official than a random email. The QR code then quietly carries the victim from paper to a fake website. Once there, they may give away serious financial details without realizing the danger.
The risk grows larger when crypto ownership is involved. Wallet addresses, exchange names, and transaction records can reveal who holds real money. Criminals could use that information to plan bigger attacks. They might target these people again through other scams later on.
Anyone who gets a surprise tax letter should not scan its QR code. They should also avoid typing information into any link from that letter. Instead, they should visit the tax office’s real website on their own. From there, they can check if the letter is genuine.
This case shows that crypto scams are moving past emails and fake websites. Criminals are now mixing paper mail, fake government branding, QR codes, and old breach data. Together, these tools make scam letters look real and help attackers find valuable targets.