European regulators are warning that fraudsters are exploiting the market disruption caused by the EU’s MiCA licensing transition, with scams aimed at crypto users who are moving assets after service providers lost the right to operate without authorization.

Following the end of MiCA’s transition period on July 1, unauthorized crypto-asset service providers serving customers across the bloc were required to stop regulated activities and help clients transfer holdings to an authorized provider or to a self-hosted wallet. According to the Financial Times, that migration has created an opening for impersonation scams involving both regulators and licensed firms.

Fake regulators and forged documents

France’s Autorité des Marchés Financiers has seen cases in which criminals pretended to be AMF representatives and pushed users to move crypto assets through fraudulent websites made to look official. The report said the scammers used the pretext of regulatory protection or compliance to persuade victims to transfer funds.

The European Securities and Markets Authority has issued a similar warning. ESMA told the Financial Times that criminals have been using the authority’s name, logo and forged documents to appear legitimate, even though genuine regulators would not handle customer transfers in that way.

Customers seeking licensed replacements are a key target

ESMA said scammers may be focusing on customers who are trying to find a new licensed provider after their previous platform exited the EU market. That risk has grown as investors increasingly turn to official registers to confirm whether a company is authorized under MiCA.

At the end of July, ESMA’s public register listed 323 crypto firms with MiCA authorization across the European Union. The figures underline how sharply the market has narrowed as firms move from older national registrations into the bloc-wide regime.

A much smaller licensed market under MiCA

Before MiCA fully took effect, more than 3,000 crypto firms were operating under a patchwork of national registration systems. During the new licensing process, only 194 had secured MiCA approval by May, a total that climbed to around 300 near the July deadline and then reached 323 by the end of that month, according to ESMA’s register.

Earlier estimates from data provider VASPnet suggested that more than 1,700 companies operating without MiCA licenses would eventually have to stop serving EU customers once the transition ended. That large-scale exit has made asset transfers and account changes a central issue for affected users.

MiCA also imposes continuing obligations beyond a one-time approval process, including requirements tied to governance, capital, cybersecurity, complaint handling, market conduct and anti-money laundering controls. Industry participants have previously said those ongoing compliance costs could drive mergers, acquisitions or partnerships with banks.

Broader enforcement and the next step

The post-transition environment is still evolving as EU countries align their domestic rules with MiCA. Last month, the Council of the European Union adopted sanctions that from Aug. 25 will bar Belarusian nationals and residents from owning, controlling or serving on the governing bodies of MiCA-authorized crypto-asset service providers. The measures are part of the bloc’s sanctions policy linked to Russia’s war against Ukraine.

Hungary, by contrast, has removed a separate national cryptocurrency validator requirement that had operated alongside MiCA. Parliament voted to repeal the extra approval process after the government said the earlier framework had disrupted the local market, while leaving MiCA’s licensing and compliance rules in place.

For now, the clearest confirmed message from regulators is that users moving assets because of licensing changes should treat unsolicited communications with caution. Officials say criminals are trying to take advantage of the shift by posing as public authorities and as authorized crypto businesses.

Source: crypto.news