
BaFin issued 24 series warnings in 2026 covering 639 domains. A third carry .de suffixes. The check: not the warning list, but the licence register.
Germany's financial regulator, BaFin, issued its 24th warning of 2026 on August 7, covering a set of websites nearly identical in wording and layout. Standalone three-address notices usually pass without note. The cumulative picture is starker.
A review of BaFin's public warning archive, compiled on August 11, found 2,194 consumer notices from 2022 through mid-2026. The method: all 34 result pages of the regulator's notice format were retrieved, deduplicated, and sorted by year, series membership, and listed domains. The full text of each 2026 series notice was read.
The headline finding: the total number of warnings is flat, but the structure of fraud is changing. Fraudsters increasingly launch offerings in batches, not one site at a time. BaFin has coined the term "platform series" or "series of near-identical websites" for offerings so alike in design and advertising copy that a single notice covers them.
For a user, the series format is more dangerous than a single bad actor. Searching for an address and finding nothing negative is often read as reassurance. With a series, that is exactly what you would expect: the domain is new, without history, reviews, or complaints. The template behind it is old; the specific address is not.
Warning volume is stagnating, not exploding
The count by year:
The low figures for 2022 and 2023 likely reflect older notices being removed from the public stock. Only the last two years are reliably comparable. At 397 notices in 223 days, the annualised rate for 2026 is roughly 650, against 709 in 2025. Within the year, volume varies: April was quiet at 33 notices; July was the heaviest month at 69.
Series share has quintupled
The shift is in the format. Every notice whose title identifies it as a platform series or a series of near-identical websites was counted separately.
While total warnings edge down, the share of series notices has more than quintupled within two years. The 24 series published this year list 639 individual domains between them. None appears in two different notices. The remaining 373 warnings of the year mostly concern a single provider each.
In at least eight of the 24 series, BaFin explicitly names crypto-asset services in the decisive sentence. In six further cases the wording could not be automatically assigned. The crypto series count is therefore higher than eight.
Domain breakdown: .de is no shield
The 639 addresses break down by ending:
Almost every third warned address carries the German country suffix. Many investors read .de as a sign of supervision and legal recourse. A .de domain can be bought from any registrar; it implies neither a German business address nor a BaFin licence. The same applies to a legal notice, a phone number, or a euro account.
What the MiCA rule change means
Since the European MiCA regulation took full effect and Germany embedded it through the Crypto Markets Supervision Act (KMAG), the legal position is clearer. Anyone offering crypto-asset services commercially in Germany – trading, exchange, custody, or intermediation – needs a BaFin licence and appears in public registers.
That simplifies the check. A provider targeting German customers that appears in no official register is very probably operating without authorisation. Which providers have been through the licensing process is covered in our list of regulated crypto exchanges.
The licence is not a verdict on fees or usability. It says a company exists, has been vetted, and answers to a supervisor you can contact. The comparison takes less than five minutes. Search for the company name from the legal notice, not for the website's brand name; with unauthorised offerings the two frequently diverge. No result is itself a result. Where there is a hit, compare the registered office and legal form against the legal notice. If anything differs, the register entry prevails.
Pay attention to what the database records as the licence. A licence for payment services does not cover crypto trading. That blurriness is what many questionable offerings exploit, invoking a licence that exists but was granted for something else. The database is available directly from BaFin's company database.
Many providers with German customers are licensed in another member state and operate under a European passport. These firms do not necessarily appear in the BaFin database, but they do appear in the European Securities and Markets Authority (ESMA) register, which lists licensed crypto service providers of all member states. A miss in the BaFin database is not yet proof. Only when a provider is absent from both registers is the matter settled.
Industrial-scale production
How industrially these offerings are produced is clear from one notice. On March 11, 2026, BaFin warned about a series of near-identical websites and listed 248 domains in it. The regulator named financial and crypto-asset services said to be offered there without authorisation.
Three further notices run to 92, 59, and 48 domains. At the other end are series with two or three addresses; the median is five. Putting another copy online costs the operators almost nothing, while every single warning requires investigation, documentation, and publication on the regulator's side.
BaFin itself points out that its warnings can never be complete because dubious providers and their methods change constantly. That qualification matters more than it sounds. The absence of a warning proves nothing. Anyone who looks for an address on the warning list and fails to find it has established only that the regulator has not so far commented on that address. With a series platform registered three weeks ago, that is exactly what you would expect.
The check has to run the other way. The question that holds up is whether a provider appears in a licensing register. The warning list collects individual cases; the register is exhaustive. Only the second source allows a firm no.
If you have already paid in
One thing counts above all: make no further payment. Being asked to transfer taxes, fees, or a deposit first in order to release a supposed withdrawal is standard repertoire. BaFin explicitly advises consumers to exercise great caution with online investments and to research thoroughly before the first transfer.
Three parallel steps make sense: a report to the police, an immediate notification to your own bank or payment service provider, and a tip-off to BaFin, which feeds such reports into its investigations. With card payments and direct debits there are recovery options that deteriorate by the day. With an international transfer or a cryptocurrency payment the prospects are slim, but the documentation remains important for investigations and tax questions.
This analysis rests on the regulator's publications, not on loss figures. How much money flowed through the 639 domains, how many people are affected, and how many of the addresses are still reachable today does not emerge from the notices and could not be verified. Nor can it be established whether the same operators are behind several of the series.
The full stock of BaFin warnings is available online at any time.
(As of Aug. 11, 2026. This article is not investment advice. Prices and fee structures change; check terms with the provider before you buy.)
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.