The European Union’s crypto regulatory framework MiCA has been fully implemented, and fraudsters are rapidly exploiting the regulatory vacuum and the mass migration of users that followed. Millions of users who must move assets from unlicensed platforms to licensed ones have become prime targets.
According to CoinDesk on the 16th (local time), MiCA’s full implementation on July 1 forced more than 1,700 unlicensed crypto platforms to suspend services to EU customers and direct users to licensed alternative platforms. At the time, only 323 firms held valid MiCA authorization, leaving up to 10 million users needing to relocate their digital assets.
This large-scale migration process itself became an attack surface for scammers. The tactics are simple but devastating: fraudsters replicate legitimate platform migration notices or impersonate regulators to steer users toward fake platforms.
A spokesperson for France’s Financial Markets Authority (AMF) said scammers are “impersonating AMF staff and demanding advance fees from victims for the recovery of stolen funds.” The European Securities and Markets Authority (ESMA) also confirmed it is aware that its name and logo are being exploited in criminal schemes, including forged documents.
The Netherlands Authority for the Financial Markets (AFM) warned that “the migration process from unlicensed exchanges itself has become an attack surface,” adding that “fraudsters are likely targeting individual investors seeking licensed platforms.” The AFM urged users to verify platforms on ESMA’s official registry before moving assets and to treat unsolicited requests for fund transfers with suspicion.
Austria’s Financial Market Authority (FMA) issued a similar warning. The FMA noted that hundreds of platforms lost their legal status as of July 1 and recommended that users verify providers in official databases before transferring assets or moving them to self-custody wallets.
Regulator impersonation is already a widely used tactic in crypto fraud. The UK’s Financial Conduct Authority (FCA) reported receiving 4,465 impersonation reports in the first half of 2025 alone, with 480 people suffering actual financial losses.
According to the FCA, one of the most common schemes involves scammers claiming to have recovered funds from crypto accounts illegally opened in the victim’s name. The FCA also noted a rise in cases where fraudsters use screen-sharing software to open fake crypto accounts under victims’ identities.
Research from crypto exchange WhiteBIT found that approximately 41% of crypto incidents in 2025 involved social engineering tactics such as fake investment offers or impersonation. Since MiCA’s implementation, European regulators have consistently reported an increase in crypto-related fraud.
Legitimate exchanges also contact customers about withdrawals, transfers, and account restrictions, making it easier for scammers to mimic official communications and create a sense of urgency.
Investor Protection Only Through Licensed Entities
Regulators uniformly emphasize that they “never initiate contact via personal messages or request fund transfers.” The AMF has posted warnings on its website, while the AFM directs users to check both the ESMA registry and its own registry.
MiCA’s investor protections apply only when services are accessed through EU-licensed entities. A parent company brand holding authorization in another region does not mean all subsidiaries are covered.
The consistent guidance from regulators is clear: before moving assets, verify the actual entity holding MiCA authorization—not just the parent company brand. Checking providers against ESMA’s official registry and treating unsolicited fund transfer requests with suspicion remains the best defense.
