
Germany's BaFin published two warnings on 19 August 2026. The key question: when does a wallet app need a licence under MiCA? The answer hinges on who controls the keys.
Germany’s financial regulator BaFin posted two consumer warnings on 19 August 2026, both targeting wallet-like offerings that appear to operate without the required authorisation. One hits a website. The other names a website plus an app that shows up in the usual stores under its own product label. In both cases the supervisor said it found the operators active without a licence and not under its supervision. In one of the two cases it is investigating operators whose identities it does not know.
Both warnings rest on the same legal peg: Section 10(7) of the German Crypto Markets Supervision Act, or KMAG. That provision lets BaFin inform the public, naming the company, when facts justify the assumption of unauthorised business – or when the finding is already established. The company must be heard before the publication. If the warning later turns out wrong, the supervisor has to correct the record by the same route.
The more interesting part sits in the same provision’s second sentence. It also bites when a company does not actually provide the unauthorised service but creates the public impression that it does. For wallet apps that is the more common case: an app that promises to hold and grow a balance does not have to actually hold that balance to fall within the scope.
When a Wallet Needs a Licence
The KMAG is not a free-standing body of rules. Its Section 1 says it implements the EU’s Markets in Crypto-Assets Regulation (MiCA). The substantive definitions live there, and one of them decides the whole question.
Article 3(1)(17) of MiCA defines the custody and administration of crypto-assets on behalf of clients as the safekeeping or controlling of crypto-assets, or of the means of access to such crypto-assets, on behalf of clients, where applicable in the form of private cryptographic keys. That sentence contains three switches.
First, the word controlling. It is enough that a provider has control over the means of access; it does not have to keep the crypto-assets itself. Second, the means of access. The point of attachment is not the coins but what gets you to them. Third, the words on behalf of clients. Anyone holding only their own balances keeps custody of nothing for a client and therefore provides no service within the meaning of the regulation.
From those three switches follows the dividing line. A wallet where you alone hold the keys and the maker only supplies software does not fall under custody, because nobody is controlling on your behalf. As soon as somebody else can hold or restore the means of access, the condition is met.
The terms custodial and non-custodial appear in neither provision. As industry shorthand, though, they capture exactly the distinction the regulation draws. Custodial means the provider holds the means of access. Non-custodial means you hold them alone.
In practice you spot the difference at setup. A wallet that shows you a recovery phrase on first use and prompts you to write it down away from the device is handing you the means of access with that step. An application where you log in with an email address and a password and never see such a phrase has kept the means of access. Vocabulary is no reliable guide here, because the word wallet is not protected and is used for both.
There is a single test that brings immediate clarity in the vast majority of cases, and it costs less than a minute. Ask yourself what happens if you lose your password. If the provider can give you back access, then it must hold the means of access or be able to reconstruct them. That is precisely the control in Article 3(17). If it cannot and points you to your recovery phrase, then the means of access sit with you and the provision does not bite to that extent. A provider advertising convenient recovery while stressing that it has no access whatsoever to your balances is asserting two things that are hard to hold at once. That tension is the point at which asking questions pays off.
Custody is only the first of ten items. Article 3(1)(16) lists exhaustively what counts as a crypto-asset service: custody and administration, operation of a trading platform, exchange of crypto-assets for funds, exchange for other crypto-assets, execution of orders on behalf of clients, placing of crypto-assets, reception and transmission of orders on behalf of clients, advice, portfolio management and provision of transfer services on behalf of clients. An application can be clean on custody and still need an authorisation because it offers one of the other nine activities. The most frequent case in practice is the exchange function. Many wallets that correctly leave the keys with the user display a button that swaps one token directly for another. Depending on how that is structured technically and contractually, it touches items (c), (d), (e) or (g) from the Article 3 list.
For a user that means one thing above all: the authorisation question is not about the app as a whole but about each function individually. A wallet can be unproblematic at its core and still offer something at the checkout that would require an authorised company behind it.
Article 59(1) of MiCA frames the prohibition subject to authorisation. A person shall not offer crypto-asset services in the Union unless that person has either been authorised as a crypto-asset service provider under Article 63 or is one of the institutions named in Article 60 – a credit institution, investment firm or electronic money institution permitted to provide the services on that basis. There are two lawful routes and no third.
Paragraph 2 of the same provision works as a quick plausibility test. Authorised providers must have a registered office in a Member State in which they carry out at least part of their business. Their place of effective management must be in the Union, and at least one of the directors must be resident in the Union. Where a wallet provider’s legal notice shows only a company in a third country and gives no address in the Union, that does not fit the conditions Article 59(2) attaches to an authorisation. It is not yet proof of anything, but it is reason to check the registers rather than rely on the presentation.
German enforcement sits in Section 9 of the KMAG, headed there as intervention against unauthorised business. Under paragraph 1, first sentence, item 3, BaFin can order the immediate cessation of business operations and their prompt winding up where crypto-asset services are offered without the authorisation required by Article 59(1)(a) of the regulation. Two details of that provision matter to those affected. First, the powers under paragraph 1 extend beyond the company itself to its shareholders, to the members of its governing bodies and to undertakings involved in the initiation, conclusion or settlement of such business. Second, the supervisor can order cessation as soon as facts justify the assumption of unauthorised business. It does not have to wait for proof. Section 10(8) additionally allows it to prohibit the business provisionally pending clarification.
For a user that carries something uncomfortable which the warning notices rarely spell out: where the supervisor intervenes and appoints a liquidator, your balance is part of a winding up. That is a drawn-out process with an uncertain outcome, and it begins the moment the provider has to cease operating.
Section 10(7), third sentence, KMAG requires the company to be heard before publication. That hearing takes time. Between the moment an offering appears on the market and the moment a warning is published there is therefore necessarily a stretch in which the supervisor already knows and the public does not. From that follows the most important caveat about any warning list. It can contain only what has already been investigated and heard. An offering not on the list is merely not the subject of a completed publication. That is a long way from having been examined and found sound.
The standard advice with any provider is to check BaFin’s company database. It is sound advice, but with wallets it runs into a peculiarity. A database of authorised companies lists companies holding an authorisation. The maker of a pure self-custody wallet needs no authorisation and is therefore routinely absent from it. Its absence is in that case the expected consequence of its doing nothing requiring authorisation, and does not work as a warning signal. Conversely, the absence of a provider offering custody or exchange is a very clear signal indeed. The database query alone therefore does not answer the question. It only becomes meaningful once you have decided beforehand which of the two categories the offering falls into.
An app being available in one of the large stores says nothing about its regulatory position. The store operators check technical guidelines and formal details; they grant no authorisation under Article 59 of the regulation and are not competent to do so. One of the two notices of 19 August expressly concerns an app and not merely a website. Ratings, download counts and a cleanly designed appearance carry no weight against the provisions at issue here. Authorisation is a property of the company, not of the product.
A closing boundary this piece should not cross. The authorisation requirement is a regulatory category and not a statement about the technical security of an application. An authorised custodian can be attacked, and a self-custody wallet requiring no authorisation can be superbly built. The two questions run across each other, and both have to be answered. Whoever holds the keys themselves carries sole responsibility for keeping them safe. Whoever hands them over trades that risk for the risk that things go badly for the custodian. Authorisation says something about the second case and nothing about the first.
The two notices of 19 August 2026 can be retrieved from the supervisor’s portal. What is described there are suspected cases under Section 10(7) KMAG and not facts established by a court.
Prepared with AlphaScala editorial tooling from the source reporting linked above. Indexable analysis may include a cited Alpha Score value. Publishing checks screen each story before release. Educational coverage, not personalized advice.