NewsCryptoMiCA Scammers Target EU Crypto Users During Exchange Closures

MiCA Scammers Target EU Crypto Users During Exchange Closures

Author: Coindoo·

Key Takeaways

  • The MiCA transitional period ended on July 1, 2026, after which only MiCA-authorised providers and certain regulated financial firms may legally offer crypto-asset services in the EU.
  • Fraudsters are impersonating regulators and exchanges by copying logos, fabricating documents, and cloning websites to trick users into transferring assets to wallets controlled by criminals.
  • ESMA and the AMF have explicitly stated that regulators never contact individuals to recover funds, request personal information, demand administrative payments, or provide deposit wallet addresses.
  • An ESMA list updated at the end of July contained 323 authorised-provider records, while VASPnet estimated roughly 1,700 providers had been active under national regimes without MiCA authorisation before the deadline.
  • Users should verify any platform-related instructions through established official channels, avoid clicking links in unsolicited messages, and never disclose seed phrases, authentication codes, or wallet recovery information.
MiCA Scammers Target EU Crypto Users During Exchange Closures

Fraudsters are exploiting the end of the European Union's MiCA transitional period to impersonate regulators and crypto businesses, directing users to transfer assets through fake websites and wallet addresses controlled by criminals.

According to reporting by the Financial Times, several EU watchdogs have observed a rise in impersonation scams following the MiCA deadline of July 1, 2026. France's Autorité des Marchés Financiers (AMF) has documented cases in which criminals posed as AMF representatives and instructed users to move assets via fraudulent websites. The European Securities and Markets Authority (ESMA) has also reported misuse of its identity and logo through falsified documents and other deceptive communications.

MiCA — the Markets in Crypto-Assets Regulation — is the EU's comprehensive framework governing crypto-asset service providers and token issuers, covering areas such as custody, exchange operations, and stablecoin issuance. It is among the first full-scale crypto regulatory regimes enacted by a major jurisdiction. The wave of genuine platform closures and account migrations resulting from MiCA compliance has made unfamiliar instructions appear more credible to consumers, creating conditions that scammers are actively leveraging. Fraud surges during regulatory transitions are a recurring pattern in financial markets, as criminals exploit consumer uncertainty around new rules and changing provider relationships.

Genuine MiCA Wind-Downs Create an Opening for Fraud

MiCA's transitional period concluded across the European Union on July 1, 2026. Only MiCA-authorised providers and certain regulated financial firms using the applicable notification route may continue offering crypto-asset services in the EU.

ESMA instructed providers that could no longer operate legally to wind down their EU activities in an orderly manner. Providers were expected to give customers sufficient notice and allow them to transfer assets to an authorised provider or a self-hosted wallet.

Criminals can replicate the language of those legitimate notices while substituting their own websites, support accounts, or wallet addresses. Messages may claim that assets must be moved before access is restricted.

The Financial Times reported that an ESMA list updated at the end of July contained 323 authorised-provider records. Data provider VASPnet had estimated shortly before the deadline that roughly 1,700 providers remained active under national regimes without MiCA authorisation. The ESMA figure covers authorised providers after the deadline, while the VASPnet estimate reflected legacy entities before the transition concluded. The VASPnet figure is not an official ESMA count and does not indicate that 1,700 companies were individually ordered to close. The gap between the two figures underscores the scale of the transition under way across the EU market.

How the Scam Messages Operate

Initial contact may appear to originate from an exchange, ESMA, the AMF, or another national financial authority. Criminals use copied logos, official-looking signatures, fabricated case numbers, and cloned websites to lend legitimacy to their communications.

A typical fraudulent warning may claim that:

  • The customer's exchange is no longer permitted to serve EU clients.
  • Assets will be frozen unless the account is verified before a deadline.
  • Funds must be moved to a temporary compliant platform.

The message then redirects the user away from the exchange's official application or website. A phishing page may request login credentials, authentication codes, or wallet recovery information. In other cases, victims are instructed to send crypto directly to a wallet controlled by the scammers.

Some cloned platforms go further by displaying fabricated account balances. When the victim attempts to withdraw, the site demands an additional "tax" or compliance payment.

ESMA states that impersonators use email, telephone calls, text messages, and social media. The authority has also identified counterfeit certificates, falsified documents, and websites reproducing its name and visual identity.

Regulators Do Not Provide Deposit Wallet Addresses

A platform that is winding down operations may legitimately ask customers to withdraw, sell, or transfer their assets. Those instructions should be accessible through the provider's verified application, website, or established support channel.

The AMF has stated that affected providers should give sufficient notice and allow clients to transfer their crypto to an authorised provider, move it to a self-hosted wallet, or sell it before services end.

ESMA separately warns that it does not contact individuals to recover funds, request personal information, or demand administrative payments. The same principle applies to messages claiming that the authority must receive assets during a MiCA-related migration.

The AMF similarly warns that it does not offer financial services or contact people to conduct financial operations on its behalf. Any message claiming that a regulator has created a temporary wallet, escrow address, or safeguarding account should be treated as fraudulent.

Verifying the Company, Channel, and Request

Verify the company

Identify the legal entity named in the customer agreement, then search for it in ESMA's interim MiCA register and the relevant national register. MiCA authorisation applies to a specific legal entity, not automatically to every affiliated company using the same commercial brand.

Authorisation alone does not prove that a message or website contacting the customer is genuine. Criminals can impersonate authorised providers as well.

ESMA updates its central register weekly, so recently submitted national information may not appear immediately. Users can cross-check the relevant national regulator when a provider's status is unclear. French users can consult the AMF's authorised-provider whitelists and its separate blacklists of unauthorised companies and fraudulent websites. Absence from a blacklist does not prove a website is safe, as new domains appear continuously.

Verify the channel

Do not use links, telephone numbers, or support accounts included in a warning message. Open the exchange through its official application or a previously saved address, then contact support through an established channel.

Check the full domain and sender address rather than relying on the displayed name. ESMA's official email addresses end in @esma.europa.eu, but criminals may use visually similar characters or domains.

Verify the request

A legitimate provider or regulator does not need a seed phrase or private key to verify an account. Do not disclose authentication codes, passwords, or wallet recovery information.

A request to send crypto to prove ownership, pay an emergency compliance fee, or deposit funds into a temporary regulator wallet gives the recipient control of the assets. Users should not send test or "verification" transfers. Blockchain transactions generally cannot be reversed after confirmation, meaning that assets sent to a fraudster's wallet are extremely difficult to recover.

Preserving Evidence and Reporting Incidents

After receiving a suspicious message, users should stop communication and preserve the email, telephone number, social-media profile, website domain, wallet address, and any documents provided.

Any claimed account change should be confirmed through the platform's established support channel. Suspected ESMA impersonation can be reported through the contact information on ESMA's fraud and scam page.

Anyone who has already transferred assets should preserve the transaction hash and notify the exchange or wallet provider immediately. The incident should also be reported to local police and the relevant national financial authority.

The conclusion of the MiCA transition may require some customers to change providers, but any instruction should be verified through the platform's established official channels before assets are moved.