Skip to main content
Join

MiCA Deadline Drives Regulator Impersonation Scams Across EU

MiCA Compliance Deadline Fuels Regulator Impersonation Scams Across EU

Evidence trail

Research and market information only — not financial advice. Report a correction or contact [email protected].

cryptocurrency market intelligence visualization for: MiCA's cleanup is creating a new scam wave across the European Union. CoinBatmi editorial illustration.
CoinBatmi feature visual — market neutral — MiCA's cleanup is creating a new scam wave across the European Union

The regulatory action

The European Union's Markets in Crypto-Assets regulation (MiCA) entered its full application phase for crypto-asset service providers (CASPs) in 2026, requiring firms to obtain authorization or cease operations. The transition forced millions of retail users to migrate accounts to newly licensed platforms or withdraw funds. Fraudsters have seized on this mandatory migration, sending communications that mimic official regulator notices and exchange compliance emails to steal login credentials and private keys.

What the scams actually do

Attackers spoof domains resembling national financial authorities — such as BaFin in Germany, AMF in France, and CONSOB in Italy — and major exchanges that have secured MiCA licenses. The messages claim the recipient's account will be frozen unless they "verify" their identity via a linked phishing page. Some campaigns replicate the exact branding and language of legitimate migration notices sent by licensed CASPs, making visual detection difficult. The stolen credentials are then used to drain wallets or sell access on illicit markets.

Affected firms and tokens

The scams target users of any platform operating under MiCA's CASP regime, including centralized exchanges, custodial wallet providers, and tokenized-asset platforms. No specific token is implicated; the fraud is platform-agnostic and exploits the regulatory process itself. Licensed exchanges including Bitstamp, Kraken, and Coinbase EU entities have published advisories warning customers to verify sender domains and avoid clicking unsolicited links.

The procedural path ahead

National competent authorities (NCAs) across the EU are coordinating through the European Securities and Markets Authority (ESMA) to issue public warnings and share takedown requests for phishing domains. ESMA's supervisory convergence work on MiCA includes guidance on communication standards for authorized firms, which may reduce spoofing success over time. The next structural deadline is the full MiCA application for asset-referenced tokens and e-money tokens, expected to drive another user migration cycle in 2027.

Market reaction and the long-term read

Crypto-phishing reports to national Computer Emergency Response Teams (CERTs) rose in the weeks following the CASP authorization deadline, according to data shared by ENISA. The total value stolen remains unquantified at the EU level; member states have not yet published aggregated loss figures. The desk's read is that the scam wave will persist until authorized CASPs adopt a unified, verifiable communication standard — such as DMARC-enforced domains and in-app notifications — and until regulators publish a centralized list of licensed entities with verified contact channels.

Frequently Asked Questions

How can users verify a migration notice is legitimate?

Check the sender domain against the exchange's official website, access the platform directly via bookmarked URL or app, and confirm the notice appears in the platform's in-app notification center.

Has any EU authority published total losses from these scams?

No aggregated EU-wide loss figure has been published; national authorities have issued warnings but not consolidated financial impact data.

Will the scam wave end after the CASP migration concludes?

Analysts expect a second wave when stablecoin and e-money token holders face mandatory migrations in 2027, unless verified communication standards are adopted beforehand.