European regulators have warned that criminals are impersonating financial authorities and authorised crypto businesses to target customers moving their assets after the European Union’s MiCA licensing deadline.
The warning follows a reported increase in fraud since 1 July, when crypto-asset firms operating in the EU were required to hold authorisation under the Markets in Crypto-Assets (MiCA) Regulation. Companies that failed to obtain approval had to wind down their services or help customers transfer their funds to licensed providers.
The Financial Times, citing European regulators, reported that scammers are exploiting the uncertainty created by the migration process. Users looking for a replacement platform may be approached by fake representatives or directed to fraudulent websites designed to look like official services.
At the end of MiCA’s transition period, crypto-asset service providers serving customers across the EU without authorisation were required to stop regulated activities. They also had to assist clients in moving their assets either to an authorised provider or to a self-hosted wallet.
Stephane Pontoizeau, an official at France’s Autorite des Marches Financiers (AMF), said the regulator had identified cases involving criminals pretending to work for the organisation. Victims were persuaded to transfer their crypto assets through websites that falsely appeared to be connected to the AMF.
The fraudulent sites did not operate in the same way as legitimate regulators, which generally do not contact investors directly to arrange asset transfers. Instead, the scammers instructed users to move their holdings by claiming the action was necessary for regulatory protection or compliance.
The European Securities and Markets Authority (ESMA) told the Financial Times that criminals had also used its name, logo and forged documents to make their approaches appear genuine.
ESMA said customers searching for a licensed replacement after their former crypto provider withdrew from the European market could be particularly vulnerable. Regulators are therefore urging users to check communications carefully and rely on official information when verifying a firm’s authorisation.
ESMA’s public register, updated at the end of July, contained 323 crypto companies authorised under MiCA across the EU. Earlier estimates from data provider VASPnet indicated that more than 1,700 firms operating without MiCA licences would eventually have to stop serving EU customers once the transition period ended.
The changes represent one of the most significant regulatory shifts in Europe’s crypto market. Before MiCA became fully effective, more than 3,000 crypto firms operated under a range of national registration systems.
The number of companies securing approval under the new framework rose from 194 in May to about 300 close to the July deadline, before reaching 323 in ESMA’s updated register.
MiCA differs from the previous national systems because authorisation is not simply a one-off process. Licensed firms must maintain continuing controls covering governance, capital, cybersecurity, complaints handling, market conduct and anti-money laundering.
Industry participants have previously warned that the cost of meeting those obligations could prompt consolidation. Smaller companies may seek mergers, acquisitions or partnerships with banks as they adjust to the ongoing compliance requirements.
The post-MiCA environment has also been shaped by other regulatory developments. Last month, the Council of the European Union adopted sanctions preventing Belarusian nationals and residents from owning, controlling or serving on the governing bodies of MiCA-authorised crypto-asset service providers from 25 August.
Those restrictions form part of the EU’s sanctions policy linked to Russia’s war against Ukraine and were introduced after the completion of the MiCA transition period.
Hungary, meanwhile, has removed a separate national requirement for cryptocurrency validators that had operated alongside MiCA. The Hungarian Parliament voted to repeal the additional approval process after the government said the previous system had disrupted the domestic market and caused several businesses to suspend or reduce their services.
The change does not affect MiCA’s licensing or compliance rules. It removes an additional layer of domestic transaction validation.
Shortly before the legislative change, Budapest-based CoinCash became the first company in Hungary to receive direct MiCA authorisation from the National Bank of Hungary. That approval allowed it to gradually restore and expand its regulated crypto services.
Regulators have warned that the combination of firms leaving the market, customers transferring assets and users searching for authorised alternatives has created an opportunity for fraudsters. They advise customers to verify the identity of anyone claiming to represent a regulator or crypto business and to use official registers when checking whether a provider is authorised.
