
Fraudsters are exploiting the MiCA wind-down: 1,700+ unlicensed providers must close, and phishing letters look real. Check the ESMA register before moving funds.
Since 1 July 2026, crypto service providers in the European Union can only operate with an authorisation under the MiCA regulation. Firms that missed the deadline have to wind down their EU business and tell customers to withdraw their balances. Roughly 1,700 providers are in that position, while around 323 have received authorisation, according to analyses of the register published in late July. Further authorisations are coming through, so the count keeps moving.
That gap now feeds a wave of fraud. Tens of thousands of European investors are receiving a message that is entirely routine: their provider is closing its EU operation and the balance has to move. For the criminals behind the wave, the request no longer has to be made to sound plausible. It only has to look genuine.
The French markets regulator AMF warned on 5 and 6 August that perpetrators are posing as staff of supervisory authorities or licensed trading venues and telling customers of unauthorised providers to move holdings quickly. Stéphane Pontoizeau, who covers this area at the AMF, said in international reporting that the current moment offers fraudsters a better opportunity than usual. ESMA, the EU-wide securities supervisor, has found its own name and logo being misused in letters of this kind.
The forgeries are well made. The warnings document copied letterheads and file references, rebuilt websites that mirror a genuine provider's layout, transfer instructions pointing to wallets owned by the operators, and phone calls from supposed officials.
What the letters almost never include is a register entry the customer could look up, or an independent way to reach the sender. What they do include is a destination address and a reason to hurry.
A second variant is subtler. Instead of an address, the message carries a link to a platform that claims to be MiCA-licensed. The customer opens an account and verifies their identity with an ID document. The balance they see on the screen is a number on an interface controlled by the operators. Withdrawals later fail over alleged taxes. This version is more dangerous because it copies the ordinary account-opening process.
One check settles most of these cases, and it takes about two minutes. Look the provider up in an official register, using an address you type yourself rather than a link from the message. Fraudsters can rebuild any logo and fake any confirmation page. They cannot create an entry in a supervisor's database. If a supposedly licensed provider is not listed, the matter is settled, however convincing the letter looks.
The European securities regulator maintains the central directory of all MiCA-authorised service providers. It shows whether a company holds an authorisation and which member state granted it. The entry also lists the services the authorisation covers. A provider can be authorised without the authorisation covering everything it offers. Search for the legal entity name, not the brand. Many venues trade under a brand name while the registration sits under a different company. If the message gives no company name at all, that is itself a finding. Of the roughly 323 authorised companies, only 21 are trading platforms in the narrow sense, meaning venues where retail investors actually buy and sell.
For providers with a German authorisation, BaFin keeps a company database that shows which permission was granted. It needs no registration and is the faster route when the provider is based in Germany.
The registers only answer whether a company is authorised. They do not answer whether the message in front of you came from it. So the second step: take no contact route from the message. No telephone number from the email, no link, no attached PDF, no QR code. Open the app already on your phone, or type the provider's domain into the browser yourself. If there is no wind-down notice inside the logged-in area, then for your purposes that wind-down does not exist. A firm genuinely telling EU customers to withdraw does so in the account itself, precisely because it fears this confusion.
The AMF said it deliberately avoided short wind-down deadlines, because time pressure drives victims straight into the hands of the perpetrators. A genuine wind-down gives you time. A message that demands speed is itself a warning signal.
Suppose the check comes out the other way. Your provider did not get a MiCA authorisation and is closing its EU business. The order of steps matters, because a wrong first move gets expensive.
Secure your paperwork first. Download transaction history and account statements while you still have access. Export the tax reports at the same time. Once the service is switched off, that data usually only comes back through written requests. For a German tax return you need the acquisition date and acquisition cost of every position, because those decide whether a later sale falls under the one-year holding period.
Then pick a destination. An authorised trading venue is the obvious choice if you want to keep trading; our comparison of regulated crypto exchanges covers which providers cleared the MiCA hurdle and how they differ on fees and custody. If you intend to hold long term, self-custody removes you from the authorisation question entirely.
Move money only after that, and start with a test amount. Send a small sum, wait for it to arrive, then transfer the rest. One extra network fee protects you from the most expensive mistake, a wrongly copied address.
One tax note: a transfer between two accounts that both belong to you is not a disposal and triggers no German tax. Selling because the provider only pays out in euro is a taxable event, so check beforehand whether the wind-down hands over the coins themselves.
A crypto transfer cannot be reversed. Anyone promising otherwise on the telephone belongs to a second wave of the same fraud. So-called recovery services, which contact victims after a loss and offer to retrieve funds against an advance payment, are a documented fraud pattern in their own right. Report the incident to the police, because investigators piece addresses together and exchanges can freeze funds when a withdrawal is attempted. Report it to BaFin as well. Keep the messages and transaction hashes before the other side shuts its infrastructure down. Change the passwords and two-factor methods of every account you logged into on the fake site.
One rule covers most of the remaining doubt. Neither BaFin nor ESMA will email a retail investor asking them to move balances to a particular address. A message that does exactly that while looking official can be treated as a forgery without further checking.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.