European Union financial watchdogs have issued an urgent warning about a surge in cryptocurrency scams exploiting the recently ended MiCA licensing transition. According to reports from the Financial Times, fraudsters are impersonating regulatory bodies and legitimate crypto firms to trick investors into transferring their assets to fraudulent accounts.
The scams capitalize on the confusion caused by the Markets in Crypto-Assets (MiCA) framework, which required all crypto service providers to obtain authorization or cease EU operations after the transitional period ended on July 1, 2026. As some firms halted services or withdrew applications, scammers began sending fake notices that mimic official communications. These messages often claim that users must move their funds to an “approved” wallet or complete urgent KYC verification to avoid losing access.
France’s Autorité des Marchés Financiers (AMF) has confirmed cases where criminals posed as AMF representatives and directed victims to phishing websites. The European Securities and Markets Authority (ESMA) has similarly reported misuse of its identity and logo through falsified documents, emails, and cloned websites. Criminals use copied branding, fake case numbers, and convincing language to make the fraudulent messages appear authentic.
An ESMA list at the end of July contained 323 authorized provider records, while data provider VASPnet estimated that roughly 1,700 providers were active under national regimes without MiCA authorization before the deadline. The discrepancy highlights the scale of the regulatory shift, and scammers have exploited this moment of uncertainty.
The fraudulent communications typically redirect users away from official platforms, often requesting login credentials, authentication codes, seed phrases, or direct crypto transfers. Some cloned platforms display fabricated account balances and then demand a “tax” or compliance payment when users try to withdraw funds. Regulators stress that they never instruct consumers to send crypto to regulator-controlled wallets, nor do they contact individuals for recovery payments or personal information.
ESMA and the AMF urge investors to verify any request through official channels—directly through a provider’s established app or a previously saved website—and to check the full domain and sender address carefully. Even a provider’s valid MiCA authorization does not guarantee that a message is genuine, as scammers can also impersonate licensed firms. National blacklists of fraudulent sites are helpful but not exhaustive, as new domains appear continuously.
Victims of impersonation scams should preserve all evidence, including emails, phone numbers, social-media profiles, wallet addresses, and transaction hashes, and report the incident to the relevant exchange, wallet provider, local police, and national financial authority immediately. ESMA updates its central register weekly, so users can cross-check authorization status there or through national regulators.
The MiCA regime is designed to strengthen investor protection, but this warning underscores that regulatory progress can be accompanied by new forms of fraud. As the European crypto market adjusts to the new rules, both regulators and investors must remain vigilant against evolving scam tactics.