Background on the MiCA Roll‑out

On 1 July, the European Union’s Markets in Crypto‑Assets (MiCA) framework became fully operational. The new regime forced more than 1,700 crypto service providers that lacked a MiCA licence to cease operations for EU customers and to redirect those users toward authorised alternatives. At that moment only 323 entities possessed a valid MiCA authorisation, meaning up to 10 million retail investors were instructed to relocate their digital assets.

How Scammers Are Exploiting the Transition

Criminal groups have taken advantage of the mass migration by mimicking official communications. They replicate the wording of legitimate migration alerts, pose as regulators or exchange staff, and steer victims to counterfeit platforms that appear authentic until the fraud is discovered. This social‑engineering approach mirrors patterns already observed in 2025, when WhiteBIT reported that roughly 41 % of crypto‑related incidents involved deceptive offers or impersonation.

Regulator Alerts Across Member States

  • France (AMF): The Autorité des marchés financiers warned that fraudsters are pretending to be AMF officials and demanding upfront administrative fees to supposedly retrieve stolen funds.
  • European Securities and Markets Authority (ESMA): ESMA confirmed that its name, logo and documents are being forged to convince users that their holdings are in danger.
  • Netherlands (AFM): The Authority for the Financial Markets highlighted that the very process of moving away from unlicensed exchanges creates a fertile attack surface. It urged investors to confirm any prospective provider on the official ESMA register before transferring assets and to treat unsolicited fund‑transfer requests with extreme caution.
  • Austria (FMA): Austria’s Financial Market Authority issued a comparable warning, noting that hundreds of platforms lost their legal status on 1 July. It advised retail users to cross‑check providers against official databases and, where possible, to move assets to self‑custody wallets to avoid migration traps.
  • United Kingdom (FCA): The Financial Conduct Authority reported 4,465 incidents of fake FCA impersonations in the first half of 2025, with 480 individuals handing over money. A typical scam involves the fraudster claiming the FCA has recovered funds from an illicitly opened wallet and using screen‑sharing tools to set up a bogus crypto account on the victim’s behalf.

Common Tactics and Red Flags

Legitimate exchanges are currently notifying customers about withdrawals, account limits and other operational changes, which makes it easier for scammers to imitate official messages and generate urgency. Both the AFM and AMF stressed that they never request fund transfers via private messages and that any legitimate communication will be published on their official websites. They also direct users to consult the ESMA register (or national registers) to verify a provider’s licensing status.

Practical Guidance for Investors

Regulators across the EU converge on a single precaution: before moving any crypto holdings, confirm the exact legal entity that holds a MiCA licence, not merely the overarching brand name. MiCA’s investor protections only apply when the service is delivered by a fully authorised EU operation; a parent company licensed in another jurisdiction does not automatically extend coverage to all its subsidiaries.

Outlook

The rapid shift mandated by MiCA has unintentionally broadened the attack surface for fraudsters targeting retail investors. Continuous vigilance, verification against official registers, and awareness that regulators will not solicit private fund transfers are essential steps for anyone navigating the new regulatory landscape.