Scammers Exploit the MiCA Licensing Transition
The problem has emerged as the European Union completes its transition to the Markets in Crypto-Assets Regulation. MiCA has applied across the bloc since December 2024, but some providers were allowed to continue operating under national rules until July 1, 2026.
After that deadline, companies without MiCA authorisation could no longer rely on the transitional regime and were expected to stop serving EU customers or arrange an orderly transfer of their accounts and assets.
This does not mean that every European crypto investor has to change platforms. The risk mainly concerns customers whose provider failed to obtain authorisation and can no longer legally continue its existing operations in the EU.
Fraudsters Pose as Regulators and Crypto Exchanges
France’s financial regulator, the Autorité des Marchés Financiers, has reported several cases in which fraudsters pretended to be AMF employees or representatives of crypto exchanges. Victims were directed to fake websites and told to move their cryptocurrencies to supposedly authorised accounts.
The European Securities and Markets Authority has also confirmed that criminals are misusing its name and logo and circulating falsified documents to make fraudulent offers appear legitimate.
Investors searching for a replacement platform are particularly exposed because they may already be expecting instructions about withdrawals, account migrations or new compliance requirements. A message that would normally look suspicious can appear more convincing when it refers to a real regulatory deadline.
Only 323 Providers Had Secured MiCA Authorisation
At the end of July, 323 crypto-asset service providers were listed as authorised under MiCA, according to the Financial Times’ review of the ESMA register. The figure should not be confused with the number of individual brands available across Europe. A single authorised company may provide several services or operate in multiple countries through the MiCA passporting system.
Data provider VASPnet estimated that more than 1,700 providers without the necessary authorisation could be required to close, relocate or stop serving EU customers. This is an industry estimate rather than an official ESMA figure.
Several major exchanges have already secured access to the European market. Kraken received its MiCA licence in Ireland, while Bybit launched a separate European platform after obtaining authorisation in Austria.
How Investors Can Check a Crypto Provider
European regulators advise investors to verify a company directly through the official ESMA register or the register maintained by the relevant national authority. Users should avoid following links sent through unexpected emails, private messages or phone calls. A regulator will not ask an investor to transfer cryptocurrency to a special wallet, recovery account or temporary address.
Anyone whose provider is not authorised should contact the company through its official website and review the available withdrawal options. ESMA says customers may consider transferring their assets to a MiCA-authorised provider or to a self-hosted wallet.
Conclusion: MiCA is intended to make the European crypto market safer, but the transition has created a temporary opening for impersonation scams. Investors who need to move their assets should avoid acting under pressure, verify every provider independently and never rely on account details or wallet addresses supplied through unsolicited messages.