MiCA Deadline Fuels Phishing Wave: How to Spot Legitimate Withdrawal Requests
A wave of phishing scams has hit Europe since July 1, as crypto service providers who failed to obtain MiCA authorisation by that date are winding down their EU business and asking customers to withdraw their balances. According to the French markets regulator AMF, perpetrators pose as staff of supervisory authorities or licensed trading venues and instruct customers to move their holdings urgently.
Stéphane Pontoizeau, who covers this area at the AMF, says that the current moment offers fraudsters a better opportunity than usual. The ESMA has found its own name and logo being misused in letters of this kind.
To spot a genuine withdrawal request, one must check if the provider is listed in an official register, such as the ESMA MiCA register or the BaFin database for providers holding a German authorisation. One should also reach out to the provider through their official channel, using no contact route taken from the message.
The letters that have reached the authorities are well-made, but they often leave out essential details such as file references and registration numbers. They may also include rebuilt websites, copied letterheads, and fake transfer instructions pointing to wallets belonging to the perpetrators.