EU Authorities Warn of Surge in Crypto Impersonation Scams Following MiCA Compliance Deadline
Key Takeaways
- •The July 1 deadline for the EU's MiCA regulation required unauthorized crypto firms to wind down operations, displacing investors who must now migrate their assets.
- •Fraudsters are exploiting the mass migration by impersonating regulatory authorities like ESMA and AMF to launch phishing attacks.
- •As of late July, only 338 firms are registered as compliant crypto-asset service providers under MiCA, a sharp drop from the over 3,000 companies previously operating under national regimes.
- •Security experts emphasize that official regulators will never ask investors to transfer cryptocurrency for compliance purposes, urging users to verify sources directly.

European authorities are warning of a significant increase in cryptocurrency-related impersonation scams following the July 1 compliance deadline for the Markets in Crypto-Assets (MiCA) regulation. According to EU officials, fraudsters posing as regulatory authorities and licensed exchanges have intensified their operations after the deadline, which required unlicensed businesses to cease serving EU customers and displaced investors who now must migrate their assets to compliant platforms.
MiCA is the European Union's comprehensive framework for regulating crypto-asset service providers, stablecoin issuers, and token offerings — the first such regime enacted by a major economic bloc. Its July 1 deadline marked the end of an 18-month transition period during which firms operating under legacy national regimes were expected to either obtain authorization as crypto-asset service providers (CASPs) or wind down EU-facing operations.
The mass migration — rather than cryptocurrency price movements — has become the defining story of the MiCA rollout. As hundreds of firms withdraw from the EU market, users face account transfers and identity verification requirements, creating the kind of uncertainty that impersonation scams thrive on. Cryptocurrency markets have remained relatively stable, with Bitcoin trading around $64,700 and Ether at $1,910 on the morning of August 6.
Scammers Exploit the MiCA Transition
MiCA's transition phase ended on July 1, meaning crypto firms without authorization to operate as crypto-asset service providers (CASPs) could no longer legally provide services to customers within the EU and the European Economic Area (EEA).
This regulatory shift has prompted many users to move their assets to licensed exchanges or self-custody wallets. Cybersecurity professionals have long warned about the risks associated with large-scale migrations, noting that investors expect to receive emails requesting identity verification and instructions for transferring funds — communications that criminals can easily replicate.
The Financial Times reported that French regulators, Dutch authorities, and EU officials have all confirmed an increase in these scams. The Dutch Authority for the Financial Markets (AFM) has warned that investors searching for licensed providers could be targeted.
How the Impersonation Scams Operate
Stéphane Pontoizeau, head of market intermediaries and infrastructure supervision at France's Autorité des Marchés Financiers (AMF), stated that the transition has created "an opportunity for scammers more than usual."
The French government has documented cases of fraudsters impersonating AMF agents and directing investors to counterfeit websites designed to mimic official government services. Similarly, the European Securities and Markets Authority (ESMA) issued an alert after criminals began exploiting ESMA's name, logo, and branding in phishing schemes. ESMA has assured the public that official communications always come from an email address ending with @esma.europa.eu and that authorities would never ask investors to transfer cryptocurrency for compliance purposes.
🛑 #Fraud alert: scammers are impersonating #ESMA and exploiting the end of the #MiCA transition! ❌ Don't engage with suspicious messages 📤 Report scams to your national authorities 🛡️ Verify sources. Official ESMA emails → @esma.europa.eu Website → pic.twitter.com/MaMIUoyO4c
— ESMA – EU Securities Markets Regulator 🇪🇺 (@ESMAComms) July 9, 2026
Security experts note that these scams rely on psychological manipulation rather than technical exploits. Criminals use official brand logos, regulatory terminology, and urgency tactics to pressure victims into acting quickly to avoid alleged legal violations. One of the most effective protective measures, according to experts, is verifying instructions by visiting the regulator's official website directly rather than responding to unsolicited emails or messages.
Scale of EU Crypto Migration Fuels Phishing
The scope of MiCA implementation helps explain why fraudsters are concentrating their efforts on the transition period. As of July 31, MiCA's registry listed 338 registered CASPs, up from approximately 194 in May — an increase of roughly 74% in three months. However, this figure represents only a small fraction of the more than 3,000 crypto companies previously registered under national licensing regimes. According to VASPnet, an estimated 1,700 or more companies are expected to eventually cease operations for EU clients.
This dramatic contraction consolidates a large share of EU crypto activity onto a limited set of licensed platforms, reshaping the competitive landscape and concentrating risk during the migration window. Each migration campaign — instructing users to move from an old platform to a new one — gives fraudsters another opportunity to impersonate the legitimate destination for displaced users.
Binance was among the platforms that lost its MiCA license ahead of the deadline and terminated services for EU users. Clients departing unlicensed major platforms are required to update their accounts, verify their identities, and transfer their assets — the point at which they are most vulnerable to phishing attacks.
National regulators are also publicizing the names of violators. Belgium's Financial Services and Markets Authority (FSMA) has alerted the public about unauthorized crypto businesses and reminded investors that cryptocurrency investments are typically not eligible for compensation schemes.
A Trend That Predates the Deadline
Impersonation scams did not originate with MiCA, but the regulation's implementation has provided fraudsters with a significant new opportunity. Chainalysis estimates that cryptocurrency-related scams and fraudulent activities generated approximately $17 billion in illegal revenue in 2025, as AI-powered social engineering techniques enhanced the effectiveness of phishing attacks through counterfeit websites, fake customer support agents, and authentic-looking emails.
The implications extend beyond Europe. Major regulatory changes — whether new licensing frameworks or large-scale platform migrations — create temporary windows of opportunity that fraudsters are quick to exploit. The United Kingdom and Hong Kong are advancing their own crypto licensing regimes, and similar transitional risks are likely to emerge in those jurisdictions as deadlines approach. While MiCA is designed to strengthen investor protection over time, its introduction demonstrates that regulatory transitions can generate short-term risks, underscoring the importance for investors to verify the legitimacy of the platforms and service providers they engage with.