NewsCryptoRegulators Warn of Phishing Scams Exploiting MiCA Compliance Deadline

Regulators Warn of Phishing Scams Exploiting MiCA Compliance Deadline

Author: Crypto Valley Journal·

Key Takeaways

  • The MiCA transition period expired on July 1, 2026, requiring all crypto-asset service providers operating in the EU to hold a CASP authorization or cease serving EU clients.
  • Only 16 of the 100 largest global crypto exchanges by trading volume have obtained MiCA licenses, while Binance, the world's largest exchange, has not yet received authorization.
  • ESMA, AMF, and AFM have all documented phishing scams in which fraudsters impersonate regulators to deceive investors into transferring crypto balances to fraudulent websites.
  • Chainalysis reported approximately USD 14 billion in confirmed on-chain fraud losses globally for 2025, with identity fraud increasing more than 1,400 percent year over year.
  • Swiss investors are not covered by MiCA protections, but eight Swiss crypto companies have obtained EU CASP licenses through subsidiaries across five different national supervisory authorities.
Regulators Warn of Phishing Scams Exploiting MiCA Compliance Deadline

The EU-wide transition period for the Markets in Crypto-Assets regulation (MiCA) expired on July 1, 2026. Since that date, both the European Securities and Markets Authority (ESMA) and France's Autorité des marchés financiers (AMF) have reported a marked increase in phishing scams that use forged regulator identities to deceive investors.

MiCA establishes the EU-wide licensing framework for crypto-asset service providers and is the first comprehensive, harmonized crypto-asset regime adopted by a major global economy. Exchanges, brokers, and custodians operating in the bloc must obtain a Crypto-Asset Service Provider (CASP) authorization, which imposes requirements related to capital, compliance, and investor protection. Providers without this license can no longer serve EU clients. The original transition period granted existing operators up to 18 months of continued operation, with deadlines staggered across member states. By the end of July 2026, the ESMA register listed 323 authorized CASPs. While the transition was designed to deliver legal certainty for investors, the compressed timeframe also created a new and significant attack surface for fraudsters.

Only 16 of the 100 Largest Exchanges Hold a MiCA License

The deadline has substantially reduced the number of legally accessible providers in the EU. The public ESMA register details each granted CASP authorization along with the responsible national supervisor. Once issued by a national authority, a license applies across the entire single market via the EU passporting mechanism. New authorizations continue to arrive on a weekly basis, shifting the total number of entries.

The departures, however, far outnumber the additions. Data provider VASPnet estimates that more than 1,700 unlicensed crypto service providers were forced to cease serving EU clients, though official confirmation of that figure remains unavailable.

Among the largest trading venues, license density remains low. Of the 100 crypto exchanges with the highest trading volume globally, only 16 hold MiCA authorization, including Coinbase, Kraken, Bybit, OKX, Crypto.com, and KuCoin. At the very top, the ratio is comparatively higher — six of the ten highest-volume exchanges are licensed. Binance, the world's largest exchange by trading volume, has not yet received an EU-wide MiCA license. Consequently, unlicensed providers have been barred from actively serving EU clients since July, forcing European users to reorient within a matter of weeks.

The staggered national deadlines compounded the uncertainty. Germany set its national transition deadline at December 31, 2025, six months ahead of the EU maximum. France, by contrast, granted its providers the full 18 months. Customers with accounts in both jurisdictions saw their platforms withdraw at different times. Existing clients had to withdraw their balances, transfer them to a licensed provider, or move them into self-custody — a situation that scammers have actively exploited.

MiCA Phishing Scams Impersonate ESMA and AMF

The AMF has documented cases in which perpetrators posed as staff members of the authority, instructing investors to transfer their balances to fraudulent websites under the pretext of safekeeping. The ruse is particularly effective because many customers were already required to switch providers. Once transferred, crypto balances are almost never recoverable.

For this reason, France's supervisor refrained from imposing a hard shutdown deadline for unlicensed exchanges, calculating that an abrupt market exclusion would have handed scammers additional pretexts. ESMA has experienced similar misuse. In comments to the Financial Times, the authority confirmed that its logo and forged documents have been used without authorization. ESMA stressed that official communications come exclusively from addresses ending in @esma.europa.eu. The Dutch Authority for the Financial Markets (AFM) has likewise reported targeted attacks on consumers searching for licensed alternatives.

Regulators identified several hallmarks of genuine communication. Supervisory bodies never request asset transfers, nor do they charge fees for recovering lost funds. Artificial deadlines are not part of their standard practices. Investors can verify a provider's license status directly through the ESMA register or the AMF website. Any communication that creates time pressure should be treated with suspicion.

Identity Fraud Surged by Over 1,400 Percent

The escalation in such cases, however, began well before the MiCA deadline. Chainalysis, in its Crypto Crime Report 2026, placed confirmed on-chain fraud losses for 2025 at approximately USD 14 billion. The analytics firm evaluates payment flows on public blockchains for the report; with full coverage, it projects total losses of up to USD 17 billion. Chainalysis had initially reported USD 9.9 billion for 2024 and later revised that figure to USD 12 billion. Year over year, total damage climbed by roughly 17 percent.

Identity fraud was the fastest-growing category. Chainalysis recorded an increase of more than 1,400 percent year over year in this scheme, while the average payment per case rose by over 600 percent. Across all fraud schemes, the average payment grew from USD 782 to USD 2,764. These figures pertain to the global crypto landscape in 2025, not to the MiCA transition specifically, but they illustrate how lucrative impersonating an institution has become.

Attack techniques are also evolving. Scam Sniffer recorded losses of USD 6.27 million from so-called signature phishing in January 2026 alone — a 207 percent increase from December 2025. The number of victims fell by 11 percent to 4,741 during the same period. Two large investors alone accounted for 65 percent of total losses, indicating that mass campaigns are declining in significance as attackers concentrate on a small number of wealthy targets, a practice the industry calls whale hunting.

Swiss Investors Remain Without MiCA Protection

MiCA does not apply in Switzerland. Because the country is neither an EU nor an EEA member, the Swiss Financial Market Supervisory Authority (FINMA) cannot grant a MiCA license. Investors who trade through an EU-licensed platform still benefit from the regulation's investor protection rules. However, if that EU platform loses or lacks a license, the protection disappears entirely. The same applies to affiliated companies and providers based outside the Union. The AMF emphasized this point in its June statement, noting that Swiss customers bear the risk alone in such cases.

Several Swiss crypto companies have secured EU market access through subsidiaries. Crypto Finance received a CASP license from Germany's BaFin in January 2025, becoming the first firm to do so. AMINA Bank subsequently obtained authorization through Austria's FMA, while Relai and SwissBorg were licensed via France's AMF. Swissquote secured its authorization in April 2026 from Luxembourg's CSSF. RuleMatch, Bitcoin Suisse, and Sygnum Bank received their approvals in June 2026 through Liechtenstein. In total, these eight licenses span five supervisory authorities.

Switzerland has no direct equivalent to the MiCA transition. FINMA nonetheless maintains a warning list of providers that falsely suggest they hold a license. The list is based on reports and FINMA's own inquiries and is therefore not exhaustive. It serves as a supplementary checking tool but does not replace the official authorization register. The Swiss Federal Office for Cybersecurity registered just under 65,000 reports in 2025, approximately 19 percent of which involved phishing. In the second half of 2025, 6,299 phishing reports were filed — a 17 percent increase year over year. The office does not break down how many of those cases involved crypto investors.