MiCA Deadline Exploited by Scammers as Legitimate Withdrawal Requests Flood In
As of July 1st, 2026, cryptocurrency service providers in the European Union are required to hold an authorisation under the MiCA regulation to operate. Those who failed to obtain one by this date must wind down their EU business and ask customers to withdraw their balances.
This has led to a wave of legitimate withdrawal requests from unauthorised providers, which are being exploited by scammers. According to the French markets regulator AMF, perpetrators pose as staff of supervisory authorities or licensed trading venues and instruct customers of unauthorised providers to move their holdings urgently.
To avoid falling victim to these phishing scams, investors should first check if their provider is MiCA-licensed by looking them up in an official register. The European securities regulator ESMA maintains a central directory of all service providers authorised under MiCA, which can be searched using the legal entity name, not the brand.
If the message appears to be legitimate but does not provide sufficient information, investors should contact their provider through the official channel, avoiding any contact routes provided in the email. Authorities do not typically write directly to retail investors in such cases, and messages that appear official can be treated as forgeries without further checking.