MiCA Scam Warnings Rise as Over 1,000 Firms Lose EU Access

ETH
LINK
MATIC
SOL
SUI
UNI
European UnionImpersonationCrypto ScamregulationphishingMiCA
9 hours agoSource: crypto.news
MiCA Scam Warnings Rise as Over 1,000 Firms Lose EU Access

MiCA migration scams are targeting European crypto users after the European Union’s final grandfathering period ended on July 1, forcing unauthorized crypto asset service providers to wind down covered services and move customers toward licensed firms or self-hosted wallets. 

Summary

  • MiCA’s July 1 deadline forced unauthorized crypto providers to wind down regulated services across Europe.
  • ESMA’s late-July register listed 323 authorized providers while VASPnet estimated over 1,700 firms faced exits.
  • Regulators warn scammers are impersonating authorities and exchanges, directing migrating users toward fraudulent crypto platforms.
  • TRM identified 1,062 operating EEA firms without MiCA authorization in its July 1 market snapshot.
  • ESMA advises users to verify providers through its official register before transferring crypto assets elsewhere.

ESMA’s June statement requires unauthorized providers to stop onboarding new EU clients and limit activity to an orderly exit.

The regulator also tells customers to check whether a provider appears in its official MiCA register before moving assets. European watchdogs now say fraudsters are exploiting those genuine migration messages by impersonating regulators and licensed exchanges and directing users to fake websites, wallets or platforms.

MiCA deadline created a new migration attack surface

The scale of the migration is large, but the numbers require qualification. A widely repeated estimate of more than 1,700 unlicensed platforms came from data provider VASPnet, not ESMA. CoinDesk cited that estimate alongside ESMA register data showing 323 authorized crypto companies in a late-July snapshot.

A separate Aug. 7 analysis from TRM Labs identified 1,343 operating EEA crypto providers in its dataset as of July 1. Of those, 281 had MiCA authorization and 1,062 did not. TRM said its figures count firms it could identify as actually providing crypto services, rather than every entry in old national registers, which explains part of the difference between datasets.

Moreover, that distinction also makes “1,700 platforms halted services” too definitive. ESMA’s rules require unauthorized CASPs to stop new onboarding, marketing and new client relationships immediately, while allowing only the services needed to sell, transfer or reallocate assets and close positions during an orderly wind-down. Custody may continue only for as long as necessary to complete that exit.

The claim that as many as 10 million users may need to migrate is likewise a media estimate, not a figure published in ESMA’s wind-down statement. The verified regulatory position is that customers of unauthorized providers do not receive MiCA safeguards and should act promptly if their provider is absent from the register.

Regulators warn scammers are copying real migration notices

The migration creates a useful script for social engineering. CoinDesk reported that France’s AMF had encountered criminals posing as regulator employees and asking victims for upfront administrative fees to recover funds. ESMA separately warns that scammers use its name, logo, counterfeit documents and copied websites to appear legitimate.

The Dutch AFM told CoinDesk that fraudsters may target retail investors searching for replacement licensed providers. Austria’s FMA has advised customers of unauthorized firms to verify providers in ESMA’s register and, where appropriate, transfer assets to an authorized CASP or a self-hosted wallet.

As crypto.news previously reported, European regulators warned that criminals were exploiting the MiCA licensing transition by impersonating regulators and licensed crypto businesses. In related coverage, TRM’s dataset found 1,062 EEA firms without MiCA authorization at the July 1 deadline, showing why customer migration remains a live fraud and compliance risk.

Users should verify the legal entity, not just the brand

For customers, the central check is the specific legal entity serving the account. A global exchange brand may operate through multiple subsidiaries, and a MiCA authorization held by one entity does not automatically cover every affiliate or product. Regulators therefore advise users to verify the provider and permitted services before transferring assets.

The ESMA register remains the authoritative EU source. A third-party CASP tracker launched in August makes the information easier to search, but its operators themselves say final verification should still be completed against ESMA and the relevant national regulator. As crypto.news reported, the new MiCA CASP tracker turns ESMA authorization data into a searchable directory.

Finally, the next phase is enforcement and supervision. ESMA said it and national competent authorities will monitor whether major unauthorized cross-border providers wind down without delay and can take coordinated action where necessary.

Users meanwhile face an ongoing phishing risk while genuine providers continue issuing withdrawal, transfer and account-restriction notices. ESMA says it will “never approach you” to request personal information under the pretext of recovering funds or demand an administrative fee. Any unsolicited migration request asking a user to transfer crypto should therefore be independently verified before assets move.