
EU regulators warn that impersonation scams have surged since MiCA's July 1 deadline forced unlicensed crypto firms to exit, with fraudsters posing as authorities to steal assets.
The July 1 deadline for Europe's Markets in Crypto-Assets regulation did more than clean up the industry. It also opened a door for fraudsters.
EU officials told the Financial Times that impersonation scams have increased since unlicensed crypto firms were forced to stop serving clients. Criminals are posing as regulators or licensed exchanges, directing investors to fake websites.
Stéphane Pontoizeau, head of market intermediaries and infrastructure supervision at France's Autorité des Marchés Financiers (AMF), said the transition created “an opportunity for scammers more than usual.”
The Dutch Authority for the Financial Markets (AFM) warned that investors searching for licensed providers have become primary targets. France has documented cases where criminals impersonated AMF agents, sending investors to counterfeit government sites. The European Securities and Markets Authority (ESMA) issued a similar alert after scammers used its name, logo and branding in phishing schemes. ESMA stressed that official communications come from @esma.europa.eu addresses and that regulators never ask investors to transfer crypto for compliance reasons.
The mechanics are straightforward. Hundreds of firms stopped serving EU investors around the July 1 deadline. Users received emails about moving accounts or assets. Those messages are easy for criminals to copy. Security experts said these scams rely on psychological pressure, not technical hacks. Official logos, regulatory jargon and a sense of urgency are designed to bypass caution.
ESMA's MiCA registry listed 338 registered crypto-asset service providers as of July 31, up from roughly 194 in May. That is a 74% increase in three months. Still, that represents a small fraction of the more than 3,000 crypto companies previously operating under national licenses. Data provider VASPnet estimates that more than 1,700 firms will eventually stop serving EU clients.
The imbalance pushes a large share of investors toward a small number of licensed platforms. Every account migration – verifying identity, transferring assets, updating credentials – creates a moment where users are vulnerable. Binance was the most notable firm to wind down EU services without a MiCA license. Its former EU clients now have to move assets to an authorized platform, re-verify their identities and follow instructions that look similar to what a phishing email might contain.
National regulators are publishing warnings about unauthorized crypto businesses. Belgium's Financial Services and Markets Authority (FSMA) reminded investors that cryptocurrency holdings are generally not covered by compensation schemes.
Chainalysis estimated that crypto-related scams generated roughly $17 billion in illegal revenue in 2025. AI-powered social engineering has made phishing campaigns more effective through fake websites, counterfeit customer-support agents and authentic-looking emails.
Impersonation scams existed before MiCA. The transition gave fraudsters a wider window. Regulatory changes that force users to move between platforms create short windows of confusion that criminals exploit. The lesson extends beyond Europe: any major regulatory shift that relocates clients – new licensing rules, exchange closures – will produce the same pattern.
ESMA's advice is the simplest defense. Verify instructions by going to the regulator's website directly, rather than clicking links in an email or message.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.