
BaFin warns that a "back office" crypto job ad is a money mule scheme. Forwarding fraud victims' funds through your account can mean a prison sentence under Section 261 StGB, even without criminal intent.
Alpha Score of 62 reflects moderate overall profile with strong momentum, weak value, moderate quality, moderate sentiment.
Germany's financial regulator BaFin published a consumer notice on August 18, 2026 aimed at a group that rarely features in crypto coverage: people applying for a job. The warning concerns advertisements for a role described as "back office and administration support, home office." According to the regulator, there are grounds to suspect that crypto-asset services are being provided behind the offer without the required authorisation.
The dangerous pivot sits in the second sentence of the notice. BaFin says the work consists of receiving third-party payments through your own domestic bank account and forwarding them on instruction, or exchanging them into crypto-assets. Anyone doing that is not working in a company's back office. They are making their current account available as a transit station for money the regulator assesses as probably originating from victims of criminal acts, fraud in particular.
The notice names the website through which the positions are advertised and the suspicion: unauthorised crypto-asset services. As the legal basis for publication, BaFin cites Section 10(7) of the Crypto Markets Supervision Act (KMAG). That is the provision which, since Germany's legislation accompanying the EU's Markets in Crypto-Assets regulation (MiCA), allows the regulator to inform the public and name the company before proceedings have concluded.
What stands out is BaFin's express note that it has warned about this activity several times before. It used to run frequently under the label "work as a trust assistant." The packaging changes while the pattern stays the same. Lay the warnings of recent years side by side and the same description reappears under different job titles.
A consumer notice of this kind is not a court judgment. It records a suspicion the regulator considers sufficiently substantiated to inform the public.
Advertisements of this construction read harmlessly. What is promised: home working, flexible hours, a manageable weekly workload, and pay that looks conspicuously high for the effort involved. No specialist knowledge is required, only reliability, a German bank account, and a willingness to process matters promptly. Those three requirements are the actual job description.
As the application progresses, the task shifts. "Check payment processing" becomes "confirm receipt and forward." "Forward" becomes "exchange the amount into crypto-assets at a particular trading venue and send it to a specified address." The justification sounds commercial: saving on fees, serving a foreign group company, testing a payment service. Queries are answered politely, though never with anything verifiable.
BaFin words the origin of the amounts carefully and still clearly: the funds transferred to the employee's account probably come from individuals or companies who have themselves become victims of criminal acts, fraud in particular. In practice these are sums from sham investment platforms, from manipulated invoices, or from shock calls.
What emerges is a chain that begins with an investor who has lost money and ends at a wallet address abroad. In the middle sits a person with a real name, a real address, and a real account. They are the only point in that chain investigators can identify without effort.
A bank transfer can be clawed back, at least within a window and with some prospect of success. Once the amount has been exchanged into crypto-assets and sent to an external address, that possibility ends. The exchange step is therefore no incidental part of the instruction. It is its purpose. It turns a reversible booking into a transaction that can no longer be unwound in practice.
BaFin writes one sentence on this that carries the legal classification: the transfer and exchange of funds require permission or authorisation. That holds regardless of whether someone performs the work as an employee, as a freelancer, or as a favour.
The technical modesty of the approach is striking. It needs no exploit, no malware, no stolen seed phrase. It needs a lawful account, made available voluntarily.
Section 261 of the Criminal Code (StGB) makes money laundering an offence. Subsection 1 covers, among other things, a person who exchanges, transfers, or moves an object deriving from an unlawful act with the intention of frustrating its discovery, its confiscation, or the investigation of its origin, and equally a person who obtains it or uses it for a third party. The sentencing range extends to five years' imprisonment or a fine. Under subsection 3, the attempt alone is punishable.
Decisive for someone who took such a position in good faith is subsection 6. Under it, a person is also punished who fails through gross negligence to recognise that the object derives from an unlawful act; here the sentencing range is up to two years' imprisonment or a fine. Intent is therefore not a requirement. Pushing aside the obvious doubts is enough.
Gross negligence means an aggravated form of carelessness. Receiving conspicuously high pay for a simple forwarding step, taking in amounts from complete strangers, getting no written information about the principal, receiving instructions through a messenger app rather than a company address: doing all of that assembles precisely the circumstances a court later puts together. An employment contract offers no relief here, because it says nothing about where the money came from.
Subsection 5 comes on top: in particularly serious cases the sentencing range runs from six months to ten years. Such a case generally arises where a person acts commercially or as a member of a gang. Anyone forwarding amounts regularly over months and being paid for it moves close to that description without ever having felt like a gang member.
The law provides a route to impunity, and it is narrowly cut. Under Section 261(8) StGB, a person is not punished who voluntarily reports the offence to the competent authority or voluntarily causes such a report to be made. Voluntariness falls away where the offence had already been discovered in whole or in part at that point and the person knew this or had to reckon with it on a reasonable assessment of the situation. In the cases under subsections 1 and 2, the provision additionally requires that the object be secured.
In practice the timing decides. Anyone who waits until the bank freezes the account or a police summons lands in the letterbox has usually missed the route. This passage is why the matter is urgent as soon as the suspicion arises.
The supervisory side sits in the KMAG. Under Section 9(1) sentence 1 number 3, BaFin can order the immediate cessation of business operations and their prompt wind-down where crypto-asset services are offered without the authorisation required by Article 59(1)(a) of MiCA. The order can expressly extend beyond the company to its shareholders and the members of its governing bodies.
This authorisation is the core of European crypto regulation. A provider serving customers in Germany needs it. It is publicly viewable and it can be checked.
For assessing a job offer, a simple order of operations follows. First comes the question of whether the company is authorised at all. Only after that is it worth looking at pay, working hours, and contract terms.
One detail of the statute is rarely mentioned and hits applicants directly. Where it is established, or facts justify the assumption, that a company provides unauthorised business or is involved in initiating, concluding, or settling it, then under Section 10(1) KMAG not only the company but also the members of its governing bodies, its shareholders, and its employees must, on request, provide BaFin and the Deutsche Bundesbank with information on all business matters and submit documents.
Sentence 2 of the same provision extends this duty beyond the employment relationship: an employee must provide information and submit documents on request even after leaving the company. Resigning therefore does not end the obligation to cooperate. Anyone who may have to produce documents should keep them from the outset rather than reconstruct them afterwards.
Under subsection 1 sentence 3, the regulator can also issue directions to secure customer funds, data, crypto-assets, and other assets. Anyone holding their own balances with a provider under investigation is indirectly affected by such measures.
In its notice, BaFin itself points to the tool with which the suspicion can be confirmed or dispelled in a few minutes: the regulator's company database. The directory is publicly accessible and lists the institutions and service providers authorised in Germany. The comparison works best using the full corporate name from the legal notice, not the brand from the job advertisement.
Three outcomes are possible. If the company appears with a matching permission, the formal hurdle is cleared. If a company of the same name appears with a permission for something entirely different, that is a warning sign of identity misuse. If nothing appears, there is no authorisation, and therefore no reason to make a bank account available.
It is also worth looking at the public register of the European Securities and Markets Authority (ESMA), because a provider may hold its authorisation in another member state. Both registers are free and require no sign-up.
To gauge how often crypto now features in the regulator's warnings, we retrieved the consumer notices listed on BaFin's overview page on August 18, 2026. Every consumer notice linked from the "news and warnings" page was retrieved individually over HTTP. The body text was read out, and for each notice we recorded the date, the category, the legal basis cited by BaFin, and the presence of crypto-assets and features of the job scheme. Objects tested: 24 notices – twelve from the unauthorised business category with publication dates from August 10 to 18, 2026, and twelve from the further consumer notices category with dates from May 4 to August 13, 2026. All 24 retrievals returned HTTP 200.
What we could not check is the full year: the overview page outputs only the twelve most recent entries per category, and a browsable archive was not reachable by that route. Equally unverifiable is the outcome of the proceedings, since a consumer notice records a position and not a result.
The result of the count came out more clearly than expected. Of the twelve notices in the unauthorised business category, six cite Section 10(7) KMAG as the legal basis, five cite Section 37(4) of the Banking Act, and one cites none. Across nine days, half of all warnings about unauthorised business concerned the crypto supervisory regime.
The comparison also shows an exact overlap: precisely those six notices resting on the KMAG mention crypto-assets in their text. None of the five Banking Act warnings does. The legal basis cited is therefore a reliable indicator of what a warning is about, even before you read it. Two of the twelve cases concerned the misuse of well-known company names for fixed-term and overnight deposit offers, and only a single case in the entire retrieval described the job scheme with account pass-through covered here: the notice of August 18, 2026.
A sober assessment follows. In the regulator's statistics the job advertisement scheme is one isolated case among many, while fake trading platforms account for the bulk of the notices. The harm to the individual in the job variant is of a different kind, however, because it does not consist in money lost but in criminal proceedings against you personally.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.