TLDR
EU regulators are warning that MiCAs new licensing regime is being exploited by scammers impersonating regulators and exchanges to steal funds from EU crypto users.
- Scammers are posing as EU watchdogs and MiCA-compliant platforms, sending fake notices that trick users into moving assets to fraudulent sites.
- The risk is highest for customers of unlicensed firms, with over 1,700 providers exiting the EU while only about 320-323 are on ESMAs MiCA register.
- The safest response is to treat any unsolicited MiCA message as suspicious, verify firms directly in official registers, and never move funds via links in messages.
Deep Dive
1. How The New Scams Work
European regulators report a surge in impersonation scams where criminals copy the branding of authorities such as Frances AMF, the Dutch AFM and ESMA, as well as licensed exchanges, to appear legitimate. Officials describe cases where victims receive emails or calls from supposed regulators telling them to protect their assets by transferring them to a new MiCA-compliant platform that is actually a phishing website or scam wallet address.
Reports from outlets like Cointelegraph and others detail that scammers use forged documents and cloned sites to add credibility, and sometimes claim to be investigating the users exchange to create urgency. ESMA has specifically warned that it never contacts individual investors to recover funds or request fees.
2. Why MiCA Has Created An Opening
MiCA requires any crypto firm serving EU clients to obtain an EU wide license. As of late July, roughly 320-323 firms are authorized, while estimates suggest that more than 1,700 unlicensed platforms must wind down or restrict EU operations.
That shift forces many users to move funds off old providers, exactly the moment scammers want. In some countries, legitimate exchanges are sending genuine notices about withdrawals or migrations, which makes it easier for impostors to mimic the tone and timing of real messages. French regulators have even delayed strict wind-down deadlines to avoid pushing users into rushed, unsafe decisions.
3. Practical Checks For EU Crypto Users
- Verify licenses only through official sources such as ESMAs public MiCA register or your national regulators website, not through links in emails or social posts.
- Treat any unsolicited regulator or compliance contact as suspect, especially if it asks you to move assets, pay a fee, or share codes or keys. Regulators do not ask for passwords, seed phrases or one time codes.
- Be skeptical of marketing that oversells MiCA protections. Regulators have cautioned against firms implying that losses are guaranteed or fully insured just because a license exists.
MiCA improves long term oversight, but during the transition the main edge is careful verification, slow decisions and ignoring any migration request that does not match what you see on official registers and known exchange domains.
Conclusion
MiCA is tightening the rules for crypto in Europe, but its licensing shakeout has temporarily increased attack surface as users move funds and scammers exploit confusion. If you hold crypto in the EU, the key is to slow down, verify every claimed MiCA instruction against official registers and known platforms, and refuse any transfer path that starts from an unsolicited message rather than from a site or app you navigate to yourself.
