Scammers Pose as EU Regulators to Target Crypto Users Displaced by MiCA Deadline
Scammers are impersonating financial regulators and licensed exchanges to target crypto holders who are still moving assets five weeks after the EU’s licensing deadline under the Markets in Crypto-Assets Regulation (MiCA).
According to multiple regulators, including France’s Autorité des Marchés Financiers (AMF), the Dutch Authority for the Financial Markets (AFM), and the European Securities and Markets Authority (ESMA), fraudsters are contacting customers of firms that failed to win authorization. They present themselves as staff of a regulator or an exchange, then direct the customer to a website or account the criminals control. Regulators stress that they never cold-contact consumers with instructions to send funds to a particular account.
The transitional period under MiCA closed on July 1. ESMA’s register listed 322 authorized crypto-asset service providers across 26 member states as of its August 4 update, and every provider outside that list lost the right to serve EU clients. In a June 23 statement, ESMA ordered unauthorized providers to immediately stop onboarding new EU clients and limit services to actions necessary to sell or transfer crypto-assets, reallocate assets, or close positions. Clients were told to check the register and, where their provider is unauthorized, transfer holdings to an authorized provider or a self-hosted wallet.
Regulators say that this overlap is what fraudsters are exploiting, with large numbers of users being legitimately told to move funds in the same window. Authorizations clustered ahead of the cutoff, with 76 firms entering the register in June—more than any other month since the regime opened—and 31 added in July.
The scale of impersonation scams is growing. Chainalysis reported a 1,400% year-over-year increase in impersonation scams in 2025, with the average payment rising from $782 to $2,764. Total crypto scam and fraud losses for the year were estimated at nearly $17 billion. Examples include a £2.1 million Bitcoin theft from a cold wallet after a caller posed as a senior UK police officer, and an FBI warning about a fake token on Tron designed to harvest wallet access.
ESMA said that national competent authorities are directly engaged with the firms concerned and may now take coordinated action against unauthorized providers, as the transitional period has ended.