EU crypto scammers are exploiting MiCA’s licensing chaos to steal assets

When regulators force thousands of crypto companies out of a market overnight, someone is going to exploit the confusion. That’s exactly what’s happening in the EU right now, and the people getting hurt are ordinary customers who just want to move their assets somewhere legal.

According to Cointelegraph, EU financial watchdogs have seen a rise in impersonation scams since the July 1 deadline under the Markets in Crypto-Assets (MiCA) Regulation came into force. Under MiCA, crypto service providers operating in the EU were required to obtain formal authorization. Companies that missed the cut must wind down or transfer their European operations, which means their customers have to move their assets to a licensed alternative. And scammers spotted that window immediately.

The French financial regulator, the Autorité des Marchés Financiers (AMF), reported cases where fraudsters posed as AMF representatives and directed users to transfer funds through fake websites. That’s a classic social engineering move, and it works precisely because users are already in a state of uncertainty. They’ve just been told their current provider is no longer authorized. They’re looking for instructions. A fake email or website from what appears to be an official regulator can look very convincing in that moment.

The European Securities and Markets Authority (ESMA) also said it was aware of scammers misusing its name and logo, including through falsified documents. ESMA warned that criminals may specifically target customers who are searching for a licensed replacement provider. Think about what that means in practice: someone Googling “MiCA licensed crypto exchange” could end up on a fraudulent site that looks legitimate, hands over their funds, and has no legal recourse.

The scale of disruption here is significant. An ESMA list updated at the end of July showed only 323 crypto companies had secured licenses. Data provider VASPnet previously estimated that more than 1,700 unlicensed companies would need to exit the EU market. That’s potentially millions of customers who need to find a new home for their assets, all at roughly the same time. Scammers do not need a sophisticated operation to take advantage of that kind of mass confusion. They just need a convincing domain name and a sense of urgency.

This is the uncomfortable side of regulation that rarely gets discussed in policy announcements. MiCA is a serious attempt to bring consumer protection and market integrity to the crypto sector, and on paper those are good goals. But hard deadlines and mass license denials create a specific kind of vulnerability. Customers who are displaced quickly, often without clear communication from their old provider, are exactly the kind of target that fraud operations look for.

The red flags to watch for right now include:

  • Unsolicited emails claiming to be from ESMA, the AMF, or any national regulator asking you to move funds
  • Websites that mimic official regulator domains but have slight variations in the URL
  • Falsified documents with regulator logos requesting personal information or wallet transfers
  • Any communication creating time pressure around asset transfers

No legitimate regulator will ever contact you directly and ask you to move your crypto. If you’re trying to find a MiCA-licensed provider, go directly to the official ESMA register and verify the URL manually. Don’t click links from emails, and don’t trust a site just because it looks official. MiCA was supposed to make the crypto market safer. Right now, its rollout is being used as cover for fraud.