MiCA Scammers Target EU Crypto Users During Exchange Closures

MiCA’s transition deadline has produced legitimate closure and migration notices across the European Union. Criminals are copying those communications to impersonate regulators and crypto companies, redirecting users to fake websites, support channels and wallet addresses.
Key Takeaways
- Providers not authorised or otherwise permitted to operate under MiCA had to wind down their EU services after the transitional period ended on July 1, 2026.
- Fraudsters are impersonating regulators and crypto businesses through fake websites, documents and support accounts.
- ESMA and national regulators do not instruct consumers to transfer crypto to regulator-controlled wallets.
- A provider’s valid authorisation does not prove that a message, website or social-media account genuinely belongs to it.
- Users should verify the legal entity, communication channel and requested action before moving funds.
Customers can genuinely receive instructions to withdraw assets, migrate accounts or select another provider after a platform is no longer permitted to serve EU clients.
According to reporting by the Financial Times, several EU watchdogs have seen an increase in impersonation scams since the MiCA deadline. France’s Autorité des Marchés Financiers encountered cases in which criminals posed as AMF representatives and directed users to transfer assets through fake websites.
ESMA has also reported criminals misusing its identity and logo through falsified documents and other fraudulent communications. Real platform closures and account changes make unfamiliar instructions appear more credible.
Real MiCA Notices Give Fake Messages Credibility
MiCA’s transitional period ended across the European Union on July 1, 2026. After the deadline, only MiCA-authorised providers and certain regulated financial firms using the applicable notification route could continue offering crypto-asset services in the EU.
ESMA instructed providers that could no longer operate legally to wind down their EU activities in an orderly manner. Providers were expected to give customers sufficient notice and allow them to transfer their assets to an authorised provider or a self-hosted wallet.
Criminals can reproduce the language of those notices and substitute their own website, support account or wallet address. The message may claim that assets must be moved before access is restricted.
The Financial Times reported that an ESMA list updated at the end of July contained 323 authorised-provider records. Data provider VASPnet had estimated shortly before the deadline that roughly 1,700 providers remained active under national regimes without MiCA authorisation.
The ESMA figure covers authorised providers after the deadline, while the VASPnet estimate covered legacy entities before the transition ended. The VASPnet figure is not an official ESMA count and does not mean that 1,700 companies were individually ordered to close.
The Message Redirects Users Away From Official Channels
The first contact may appear to come from an exchange, ESMA, the AMF or another national financial authority. Criminals use copied logos, official-looking signatures, fake case numbers and cloned websites to make the message appear legitimate.
The warning may claim that:
- The customer’s exchange is no longer permitted to serve EU clients.
- Assets will be frozen unless the account is verified before a deadline.
- Funds must be moved to a temporary compliant platform.
The message then redirects the user away from the exchange’s official application or website. A phishing page may request login credentials, authentication codes or wallet recovery information. In other cases, the victim is instructed to send crypto directly to a wallet controlled by the scammers.
Some cloned platforms go further by displaying a fabricated account balance. When the victim attempts to withdraw, the site demands an additional “tax” or compliance payment.
ESMA says impersonators use email, telephone calls, text messages and social media. The authority has also identified counterfeit certificates, falsified documents and websites reproducing its name and visual identity.
Regulators Do Not Send Consumers Deposit Wallets
A platform that is winding down may legitimately ask customers to withdraw, sell or transfer their assets. Those instructions should be available through the provider’s verified application, website or established support channel.
The AMF has said affected providers should give sufficient notice and allow clients to transfer their crypto to an authorised provider, move it to a self-hosted wallet or sell it before services end.
ESMA separately warns that it does not contact individuals to recover funds, request personal information or demand administrative payments. The same principle applies to messages claiming that the authority must receive assets during a MiCA-related migration.
The AMF similarly warns that it does not offer financial services or contact people to conduct financial operations on its behalf.
A message claiming that a watchdog has created a temporary wallet, escrow address or safeguarding account should therefore be treated as fraudulent.
Verify the Company, Channel and Request
Verify the company
Identify the legal entity named in the customer agreement, then search it in ESMA’s interim MiCA register and the relevant national register.
MiCA authorisation applies to a specific legal entity, not automatically to every affiliated company using the same commercial brand.
Authorisation alone does not prove that the message or website contacting the customer is genuine. Criminals can also impersonate authorised providers.
ESMA updates its central register weekly, so recently submitted national information may not appear immediately. Users can cross-check the relevant national regulator when a provider’s status is unclear.
French users can consult the AMF’s authorised-provider lists and its separate blacklists of unauthorised companies and fraudulent websites. Absence from a blacklist does not prove that a website is safe because new domains appear continuously.
Verify the channel
Do not use links, telephone numbers or support accounts included in the warning. Open the exchange through its official application or a previously saved address, then contact support through an established channel.
Check the full domain and sender address rather than relying on the displayed name. ESMA’s official email addresses end in @esma.europa.eu, but criminals may use visually similar characters or domains.
Verify the request
A legitimate provider or regulator does not need a seed phrase or private key to verify an account. Do not disclose authentication codes, passwords or wallet recovery information.
A request to send crypto to prove ownership, pay an emergency compliance fee or deposit funds into a temporary regulator wallet gives the recipient control of the assets. Do not send a test or “verification” transfer.
Blockchain transactions generally cannot be reversed after confirmation.
Preserve Evidence and Report the Scam
After receiving a suspicious message, stop communication and preserve the email, telephone number, social-media profile, website domain, wallet address and any documents provided.
Confirm any claimed account change through the platform’s established support channel. Suspected ESMA impersonation can be reported through the contact information on ESMA’s fraud and scam page.
Anyone who has already transferred assets should preserve the transaction hash and notify the exchange or wallet provider immediately. The incident should also be reported to local police and the relevant national financial authority.
The end of the MiCA transition may require some customers to change providers, but any instruction should be verified through the platform’s established official channels before assets are moved.
- Methodology: This article uses Financial Times reporting on MiCA-related impersonation scams, official MiCA transition guidance, ESMA’s interim register and impersonation warning, the AMF’s authorised-provider and blacklist resources, and a VASPnet estimate of legacy providers operating without MiCA authorisation. The VASPnet figure is a private estimate and not an official ESMA total.
- Disclaimer: This article is provided for informational and educational purposes only. Authorisation status, platform availability and fraudulent domains may change. Users should verify information directly with ESMA, their national regulator and the provider’s official support channel.









