EU Crypto Investors Targeted by Widespread Phishing Scam After MiCA Deadline
Starting July 1, 2026, crypto service providers in the European Union are only allowed to operate if they have obtained an authorisation under the MiCA regulation. Those who failed to obtain one by this date must wind down their EU business and ask customers to withdraw their balances.
This has led to a wave of phishing scams, with tens of thousands of investors across Europe receiving legitimate-looking messages telling them to move their money elsewhere. The messages are being sent by scammers posing as staff from supervisory authorities or licensed trading venues, instructing customers to urgently move their holdings.
According to the French markets regulator AMF, this is a better opportunity for fraudsters than usual. ESMA has also found that its own name and logo are being misused in these letters.
To spot a genuine withdrawal request, one can check two official registers: the ESMA register, which lists all service providers authorised under MiCA, and the BaFin database, which contains information on crypto custody and trading in Germany. The registers can be used to verify if a company is indeed authorised, but not to confirm whether an email came from that company.
Authorities virtually never write to retail investors directly in such cases. A legitimate wind-down notice would be made available inside the logged-in area of the account, and it would not instruct customers to move their balances immediately.