The European Union’s (EU) crypto clean-up has handed scammers a weapon.
When the Markets in Crypto-Assets (MiCA) framework became fully effective on July 1, over 1,700 unregistered crypto platforms were compelled to cease servicing EU clients and steer them toward licensed options. At that moment, just 323 firms possessed a valid MiCA authorization. That shortfall, affecting as many as 10 million users told to transfer their digital assets, created exactly the opportunity fraudsters were seeking.
The method is simple. Fraudsters mirror the wording of legitimate migration alerts, pose as authorities, and guide users toward counterfeit platforms before victims notice the discrepancy.
Social engineering scams were already concerning in 2025. Crypto exchange WhiteBIT found that nearly 41% of crypto incidents last year involved malicious actors deceiving victims through fake investment offers or impersonation. European regulators, however, say they have seen an increase in crypto scams since the July 1 deadline.
A spokesperson for France’s Autorité des marchés financiers (AMF) noted scammers were posing as AMF employees, convincing victims to pay upfront administrative fees to recover stolen funds.
The European Securities and Markets Authority (ESMA) has confirmed awareness of criminals abusing its identity, name, and logo—even via forged documents—to persuade people that their money is in danger.
The Netherlands’ Authority for the Financial Markets (AFM) warned that the migration of unregulated crypto exchanges itself was the attack surface. “Fraudulent actors may indeed see an opportunity to scam retail investors who are in the process of looking for an alternative licensed provider,” the AFM told CoinDesk. It urged investors to verify any provider on the official ESMA register before transferring assets, and warned that unsolicited approaches requesting fund transfers should be treated with suspicion.
Austria’s Financial Market Authority recently issued a similar warning, showing a bigger shift in how regulators keep markets honest during migrations. In practice, this means officials give formal notices and practical steps that retail users can use right away. They stress not only checking a platform’s licensing status but also understanding what the license covers: some entities may have a license in one country but not in others, or work under a group brand that has several unrelated entities. The alert suggests a clear investor checklist: confirm the exact legal name and registration number of the compliant entity, check the license’s validity date, and make sure the platform’s registration is on official lists such as ESMA’s or the local regulator’s database. Beyond simple checks, they call for due diligence on safeguards like data protection practices, clear withdrawal steps, and transparent fee structures to reduce hidden charges or sudden freezes during migrations. The authority also notes the need to stay informed through official channels, such as regulator portals or consumer protection agencies, instead of trusting social media rumors or unsolicited contacts. As part of a preventive plan, they may advise small test transactions to verify the platform’s legitimacy before larger sums, and to use diversified storage methods like cold wallets for long-term holdings or multi-signature setups where appropriate. This ongoing vigilance helps protect users from migration-related scams and reinforces that legitimacy comes from verifiable, regulator-endorsed credentials rather than brand name alone.
Regulator Warnings
The scammers’ modus operandi follows a pattern regulators know all too well. The U.K.’s Financial Conduct Authority (FCA) told CoinDesk via email that it has 4,465 reports on record of fake FCA impersonations in the first half of 2025 alone, with 480 victims tricked into handing over money.
One of the most common methods involved fraudsters claiming the FCA had recovered funds from a crypto wallet opened illegally in the victim’s name. The FCA told CoinDesk that screen-sharing software was increasingly being used to help set up fake crypto accounts on victims’ behalf.
Genuine exchanges are contacting customers about withdrawals, transfers, and account restrictions, making it easier for fraudsters to mimic official communications and create a sense of urgency.
The AFM and AMF repeated the same message, stressing that they do not request funds from individuals and never reach out to clients through private messages. The AMF posts cautions on its website. The AFM directs investors to consult its own register in addition to ESMA’s.
For those investing through the transition, regulators gave a single, clear directive: confirm the exact legal entity that carries MiCA authorization, rather than only the overarching brand, before transferring any assets.
MiCA’s investor protections apply only when users are served by a regulated EU operation. A firm’s broader group brand holding a license elsewhere does not cover all subsidiaries.