NewsCryptoFraudsters Impersonate EU Regulators to Target Crypto Users Displaced by MiCA Deadline

Fraudsters Impersonate EU Regulators to Target Crypto Users Displaced by MiCA Deadline

Author: CryptoNewsNet·

Key Takeaways

  • The MiCA transitional period officially closed on July 1, leaving 322 authorized crypto-asset service providers listed across 26 EU member states as of ESMA's August 4 register update.
  • Scammers are exploiting the mandated asset relocation by contacting customers of unauthorized firms while posing as regulators or exchange staff, directing victims to fraudulent websites controlled by criminals.
  • Chainalysis recorded a 1,400% year-over-year increase in impersonation scams during 2025, with the average fraudulent payment rising from $782 to $2,764 and total crypto scam losses estimated at roughly $17 billion.
  • Regulators stress that official authorities never cold-contact consumers with instructions to transfer funds and advise users to verify provider authorization through ESMA's publicly searchable register.
  • ESMA has indicated that national competent authorities are now positioned to take coordinated enforcement action against any providers continuing to operate without proper MiCA authorization.
Fraudsters Impersonate EU Regulators to Target Crypto Users Displaced by MiCA Deadline

Fraudsters Impersonate EU Regulators to Target Crypto Users Displaced by MiCA Deadline

Fraudsters impersonating financial regulators and licensed cryptocurrency exchanges are actively targeting crypto holders still relocating their assets five weeks after the EU's licensing deadline under the Markets in Crypto-Assets Regulation (MiCA) passed. MiCA is the EU's comprehensive framework governing crypto-asset issuers and service providers — covering custody, exchange operations, trading platforms, and advisory services — and represents one of the first such regimes enacted by a major global jurisdiction.

Multiple regulators — including France's Autorité des Marchés Financiers (AMF), the Dutch Authority for the Financial Markets (AFM), and the European Securities and Markets Authority (ESMA) — described the fraudulent pattern to the Financial Times.

According to the regulators, scammers contact customers of firms that failed to obtain MiCA authorization, identify themselves as staff members of either a regulatory body or a cryptocurrency exchange, and then direct victims to a fraudulent website or account under criminal control. Regulators emphasized that they never cold-contact consumers with instructions to transfer funds to any specific account.

The MiCA transitional period officially closed on July 1. As of ESMA's August 4 register update, 322 authorized crypto-asset service providers (CASPs) were listed across 26 EU member states. Every provider not included on that register lost the legal right to serve clients within the EU. The register is publicly searchable on ESMA's website, giving consumers a direct way to verify whether a firm holds valid authorization before initiating any transfer.

Regulators Instructed Users to Relocate Assets

In a public statement issued on June 23, ESMA ordered unauthorized providers to "immediately stop onboarding new EU clients" and to restrict their remaining services strictly to "actions necessary to sell or transfer crypto-assets, reallocate assets, or close positions." Custody services, the statement noted, may continue only for the period strictly required to complete an orderly exit.

The same statement advised clients to consult the official ESMA register and, if their provider was unauthorized, to transfer their holdings "to an authorized CASP, where one is identified, or to a self-hosted wallet."

Regulators explained that this mass relocation window is exactly what fraudsters are exploiting: large numbers of users are simultaneously receiving legitimate instructions to move their funds, creating an environment ripe for impersonation schemes.

Authorization approvals clustered heavily ahead of the deadline. Seventy-six firms entered the register in June — more than in any other single month since the MiCA regime opened — with an additional 31 firms added in July. OKX European CEO Erald Ghoos had previously predicted that 80% of crypto companies would fail to meet MiCA requirements and would be forced out of the bloc.

Impersonation Fraud on the Rise

Data from Chainalysis showed a 1,400% year-over-year increase in impersonation scams during 2025, with the average fraudulent payment rising from $782 to $2,764. The blockchain analytics firm estimated total cryptocurrency scam and fraud losses for the year at approximately $17 billion.

CryptoPotato reported a case in which £2.1 million in Bitcoin was stolen from a cold wallet after a caller posed as a senior UK police officer and directed the victim to a website designed to capture their seed phrase. Separately, the FBI has issued warnings about a fraudulent token bearing an "FBI message" subject line deployed on the Tron network, engineered to harvest wallet access credentials.

ESMA stated that national competent authorities are in direct contact with the affected firms and are now positioned to take coordinated enforcement action against unauthorized providers, given that the transitional period has formally concluded.