Newsroom

EU MiCA Deadline Sparks Crypto Platform Exits and Surge in Migration Scams

17 August, 2026   /   News   /  AI   /   Tags:  esma, unauthorized, providers, mica, fraudsters

EU MiCA Deadline Sparks Crypto Platform Exits and Surge in Migration Scams

Unauthorized crypto providers must wind down EU services after July 1, leaving millions of users to transfer assets while fraudsters impersonate regulators and licensed firms

The full enforcement of the European Union’s Markets in Crypto-Assets regulation has forced hundreds of unauthorized crypto asset service providers to halt or limit operations for EU clients, creating a large-scale migration of user funds and a parallel rise in sophisticated scams targeting those transfers.

The transitional period ended on July 1, 2026. Under rules set by the European Securities and Markets Authority, firms without MiCA authorization must stop onboarding new EU clients, cease marketing, and restrict activity to the orderly sale, transfer or reallocation of assets needed to close positions. Custody services may continue only as long as required to complete the exit.

Scale of the Market Exit

Data provider VASPnet estimated that more than 1,700 unlicensed platforms faced the requirement to stop serving EU users. A late-July snapshot of the official ESMA register listed 323 authorized providers. A separate analysis by TRM Labs of operating EEA crypto firms as of July 1 identified 1,343 providers in its dataset, of which 281 held authorization and 1,062 did not. Differences in counting methods explain part of the variation between the figures.

Media estimates have suggested that as many as 10 million users may need to move assets to licensed platforms or self-hosted wallets. Regulators stress that customers of unauthorized providers lack MiCA investor protections and should act promptly once a firm is confirmed absent from the official register.

Authorization under MiCA covers capital requirements, governance, custody controls and operational resilience. Most licensed entities hold permissions for custody, asset transfer or exchange rather than full trading-venue operations. A mid-August review of the register found only a limited number of firms authorized to operate trading platforms. Several major exchanges secured licenses through member states including Ireland, Luxembourg, Malta and Austria, while some large global brands still lacked matching entries at that time. Traditional banks have also obtained custody and settlement permissions.

Fraudsters Exploit Migration Confusion

National regulators and ESMA report that criminals are capitalizing on the volume of genuine withdrawal, transfer and account-restriction notices issued by departing platforms. Fraudsters copy official language, misuse regulator names and logos, produce counterfeit documents and direct users to fake websites, wallets or platforms.

France’s Autorité des marchés financiers has encountered cases in which scammers posed as regulator staff and demanded upfront administrative fees to recover funds. ESMA has confirmed awareness of criminals misusing its identity, including through falsified documents, to claim that user funds were at risk. The Dutch Authority for the Financial Markets stated that the migration process itself creates an attack surface for those searching for replacement licensed providers. Austria’s Financial Market Authority has similarly advised customers of unauthorized firms to verify status before moving assets or to consider self-hosted wallets.

ESMA will never approach you to request personal information under the pretext of recovering funds or demand an administrative fee.
European Securities and Markets Authority

Unsolicited contacts requesting the transfer of crypto assets should be treated with suspicion and independently verified. Genuine regulators publish warnings on their own websites and do not solicit private messages asking for fund movements.

Verification Requirements for Users

Regulators consistently advise that users check the specific legal entity providing the service against the official ESMA MiCA register rather than relying on a global brand name. Authorization held by one subsidiary does not automatically extend to affiliates or every product offered under the same corporate group. Third-party trackers that surface register data exist, yet final confirmation must still be obtained from ESMA and the relevant national competent authority.

ESMA and national supervisors have indicated they will monitor whether major unauthorized cross-border providers complete orderly wind-downs and will take coordinated action where delays occur. In the meantime, the combination of mass account migrations and ongoing legitimate communications from authorized firms continues to create opportunities for social-engineering attacks.

Users transferring assets are urged to confirm authorization status and permitted services before any movement of funds, and to disregard approaches that request personal data or fees under the guise of regulatory assistance.

Disclaimer
This article was generated by AI using information from multiple industry sources. It has not been reviewed or verified by a human editor and may contain inaccuracies, omissions, or misinformation. Readers are encouraged to independently verify any information before making decisions based on its content.
This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency and related investments involve substantial risk, and past performance does not guarantee future results.