
Scammers are impersonating ESMA and AMF officials to reach customers of 1,700 unlicensed MiCA firms. Only 323 crypto firms gained licenses by July's deadline.
Scammers are working the EU's MiCA licensing shakeout from the inside, impersonating regulators and crypto firms to pull assets from customers who lost their provider on July 1. That was the hard deadline under the Markets in Crypto-Assets Regulation, Europe's licensing regime for digital-asset firms. Companies without a valid license had to stop serving EU customers or transfer those operations. The messy exit process left a large pool of users unsure where to turn, and criminals have moved into it.
The numbers outline the scale. By the end of July, the European Securities and Markets Authority counted 323 crypto firms with MiCA licenses. VASPnet, a public registry, put the number of companies that must stop operating at more than 1,700. Hundreds of thousands of customers, perhaps more, fall between those two lists. They are actively searching for a new platform, and ESMA has warned that fraudsters are misusing its identity and logo, circulating falsified documents that appear official.
Stéphane Pontoizeau of the AMF, France's markets regulator, said scammers have been impersonating AMF representatives directly, pushing users to move their assets through deceptive websites. Pontoizeau described the approach as targeted social engineering aimed at people already anxious about their funds. A customer who just learned their exchange is leaving the EU wants their money safe. That anxiety is the opening the scammers are working, he said.
MiCA licensing is not a quick process. Applications carry detailed requirements, and member-state authorities handle them on different timelines. The count of 1,700-plus unlicensed firms does not distinguish between companies still working through an application and companies that chose to leave the market. From the customer's side, that distinction does not help. The market is a gray zone, and scammers are filling it.
The public response so far has been guidance. ESMA is updating its list of licensed entities as a reference point. The AMF has published warnings. Both assume a user will stop to verify any urgent message before moving funds. The assumption does heavy lifting at a moment when the message looks like it comes from a regulator.
No specific countermeasures beyond awareness campaigns have been disclosed. Coordinated enforcement across member states has not been announced. National regulators keep their own enforcement powers. Whether any have opened investigations is not public.
For affected customers, the practical question is who to trust. ESMA's list of MiCA-licensed firms is the reference point the regulators keep pointing to. The list had 323 entries as of the end of July.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.