The regulatory action
The European Union's Markets in Crypto-Assets regulation (MiCA) entered its full application phase for crypto-asset service providers (CASPs) in 2026, requiring firms to obtain authorization or cease operations. The transition forced millions of retail users to migrate accounts to newly licensed platforms or withdraw funds. Fraudsters have seized on this mandatory migration, sending communications that mimic official regulator notices and exchange compliance emails to steal login credentials and private keys.
What the scams actually do
Attackers spoof domains resembling national financial authorities — such as BaFin in Germany, AMF in France, and CONSOB in Italy — and major exchanges that have secured MiCA licenses. The messages claim the recipient's account will be frozen unless they "verify" their identity via a linked phishing page. Some campaigns replicate the exact branding and language of legitimate migration notices sent by licensed CASPs, making visual detection difficult. The stolen credentials are then used to drain wallets or sell access on illicit markets.
Affected firms and tokens
The scams target users of any platform operating under MiCA's CASP regime, including centralized exchanges, custodial wallet providers, and tokenized-asset platforms. No specific token is implicated; the fraud is platform-agnostic and exploits the regulatory process itself. Licensed exchanges including Bitstamp, Kraken, and Coinbase EU entities have published advisories warning customers to verify sender domains and avoid clicking unsolicited links.
The procedural path ahead
National competent authorities (NCAs) across the EU are coordinating through the European Securities and Markets Authority (ESMA) to issue public warnings and share takedown requests for phishing domains. ESMA's supervisory convergence work on MiCA includes guidance on communication standards for authorized firms, which may reduce spoofing success over time. The next structural deadline is the full MiCA application for asset-referenced tokens and e-money tokens, expected to drive another user migration cycle in 2027.
Market reaction and the long-term read
Crypto-phishing reports to national Computer Emergency Response Teams (CERTs) rose in the weeks following the CASP authorization deadline, according to data shared by ENISA. The total value stolen remains unquantified at the EU level; member states have not yet published aggregated loss figures. The desk's read is that the scam wave will persist until authorized CASPs adopt a unified, verifiable communication standard — such as DMARC-enforced domains and in-app notifications — and until regulators publish a centralized list of licensed entities with verified contact channels.