
1,062 EEA crypto firms lack MiCA authorization as of July 1. Scammers impersonate regulators and exchanges. ESMA warns users to verify providers before transferring assets.
European crypto users are facing a wave of impersonation scams after the European Union’s final MiCA grandfathering period expired on July 1. Unauthorized crypto asset service providers must stop onboarding new EU clients and limit activity to an orderly exit: selling, transferring or reallocating assets and closing positions. Custody may continue only as long as necessary to complete that exit, ESMA said in a June statement.
The regulator tells customers to check whether a provider appears in its official MiCA register before moving assets. European watchdogs now say fraudsters are exploiting those genuine migration messages. They impersonate regulators and licensed exchanges, directing users to fake websites, wallets or platforms.
The scale of the migration is large. Numbers require qualification. A widely repeated estimate of more than 1,700 unlicensed platforms came from data provider VASPnet, not ESMA. CoinDesk cited that estimate alongside ESMA register data showing 323 authorized crypto companies in a late-July snapshot.
A separate Aug. 7 analysis from TRM Labs identified 1,343 operating EEA crypto providers in its dataset as of July 1. Of those, 281 had MiCA authorization and 1,062 did not. TRM said its figures count firms it could identify as actually providing crypto services, rather than every entry in old national registers, which explains part of the difference between datasets.
That distinction makes “1,700 platforms halted services” too definitive. The verified regulatory position is that customers of unauthorized providers do not receive MiCA safeguards and should act promptly if their provider is absent from the register.
The claim that as many as 10 million users may need to migrate is likewise a media estimate, not a figure published in ESMA’s wind-down statement.
The migration creates a useful script for social engineering. CoinDesk reported that France’s AMF had encountered criminals posing as regulator employees and asking victims for upfront administrative fees to recover funds. ESMA separately warns that scammers use its name, logo, counterfeit documents and copied websites to appear legitimate.
The Dutch AFM told CoinDesk that fraudsters may target retail investors searching for replacement licensed providers. Austria’s FMA has advised customers of unauthorized firms to verify providers in ESMA’s register and, where appropriate, transfer assets to an authorized CASP or a self-hosted wallet.
European regulators warned earlier that criminals were exploiting the MiCA licensing transition by impersonating regulators and licensed crypto businesses. TRM’s dataset found 1,062 EEA firms without MiCA authorization at the July 1 deadline, showing why customer migration remains a live fraud and compliance risk.
For customers, the central check is the specific legal entity serving the account. A global exchange brand may operate through multiple subsidiaries. A MiCA authorization held by one entity does not automatically cover every affiliate or product. Regulators therefore advise users to verify the provider and permitted services before transferring assets.
The ESMA register remains the authoritative EU source. A third-party CASP tracker launched in August makes the information easier to search, its operators themselves say final verification should still be completed against ESMA and the relevant national regulator.
The next phase is enforcement and supervision. ESMA said it and national competent authorities will monitor whether major unauthorized cross-border providers wind down without delay and can take coordinated action where necessary.
Users meanwhile face an ongoing phishing risk while genuine providers continue issuing withdrawal, transfer and account-restriction notices. ESMA says it will “never approach you” to request personal information under the pretext of recovering funds or demand an administrative fee. Any unsolicited migration request asking a user to transfer crypto should be independently verified before assets move.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.