The European Securities and Markets Authority confirmed this week, that scammers are impersonating the regulator and national watchdogs to steal crypto assets from investors navigating the EU’s MiCA licensing deadline, which took effect July 1, 2025.
The warning comes as hundreds of crypto firms race to comply with Europe’s landmark digital asset legislation, while many businesses that failed to obtain authorization are being forced to either shut down their EU operations or transfer customers to licensed providers. Security experts say this period of uncertainty has created an ideal environment for fraudsters seeking to capitalize on investor confusion.
MiCA license deadline creates new opportunities for fraudsters
The MiCA license deadline marked a major milestone for the European Union’s effort to establish a unified regulatory framework for crypto assets. From July 1, crypto asset service providers that failed to obtain authorization under MiCA were required to comply with national transition arrangements or cease serving customers where applicable, depending on the member state’s implementation timeline.
As customers search for compliant platforms to move their holdings, scammers have seized the opportunity to imitate trusted institutions.
According to a report by the Financial Times, multiple European financial watchdogs have detected an increase in fraudulent activity since the regulatory deadline took effect. Criminals have allegedly built convincing fake websites and circulated falsified regulatory documents to persuade users that they are dealing with legitimate authorities or licensed crypto firms.
One of the most concerning tactics involves impersonating financial regulators themselves. Victims are instructed to transfer crypto assets to fraudulent wallets under the false pretense of securing or verifying their funds during the migration process.
The scam campaigns demonstrate how major regulatory transitions can inadvertently become fertile ground for cybercrime, particularly when customers are required to make time-sensitive decisions regarding their digital assets.
French and European regulators sound the alarm
French market regulator the Autorité des Marchés Financiers (AMF) has confirmed that it has encountered several impersonation cases linked to the regulatory transition.
Stéphane Pontoizeau, an official at the AMF, said fraudsters had posed as representatives of the regulator and directed investors to fake websites where they were instructed to transfer their crypto assets.
The warning extends beyond France. The European Securities and Markets Authority (ESMA) also confirmed that criminals have been misusing its identity, including its official logo and fabricated documentation, to deceive investors.
In its public warning, ESMA said it is aware of scammers falsely presenting themselves as the regulator and cautioned users to remain vigilant when searching for an alternative licensed crypto service provider.
“ESMA is aware that third parties are improperly using ESMA’s name and logo and producing falsified documents,” the regulator warned, urging investors to verify information only through official channels.
The agency also advised users never to rely solely on emails, unsolicited messages, or unofficial websites claiming to represent European financial authorities.
Only a fraction of crypto firms have secured approval
The MiCA license deadline has significantly reshaped the competitive landscape for crypto businesses operating in Europe.
According to ESMA’s official register, updated at the end of July, only 323 crypto companies had successfully obtained MiCA authorization across the European Union.
That figure highlights the scale of the industry’s transition. Market intelligence platform VASPnet had previously estimated that more than 1,700 unlicensed crypto companies would ultimately need to stop serving EU customers unless they secured authorization or qualified under national transitional arrangements.
MiCA, formally known as the Markets in Crypto-Assets Regulation, is widely regarded as one of the world’s most comprehensive crypto regulatory frameworks. The legislation introduces harmonized licensing requirements for crypto asset service providers, consumer protection rules, operational resilience standards, and stricter governance obligations throughout the European Union.
Industry observers have largely welcomed the framework for providing greater legal certainty, although many smaller firms have acknowledged that obtaining authorization requires substantial compliance investments.
As firms exit the market or consolidate operations, customers are increasingly required to identify regulated alternatives—a process that has become the focal point of many recent fraud campaigns.
Experts urge investors to verify every licensing claim
The MiCA license deadline is expected to strengthen Europe’s crypto market over the long term, but regulators say investors must remain cautious during the transition period.
ESMA recommends that consumers independently verify whether a crypto service provider is authorized by consulting official regulatory registers rather than relying on links provided through emails, social media, or messaging applications.
Likewise, national regulators continue to remind users that they will never request crypto transfers or ask customers to move funds for “verification” purposes.
Security professionals also advise investors to confirm website addresses carefully, avoid clicking unsolicited links, and contact firms directly through official communication channels before taking any action involving digital assets.
The recent surge in impersonation scams serves as a reminder that regulatory milestones often attract opportunistic criminals looking to exploit uncertainty. While the MiCA license deadline is designed to improve transparency and investor protection across the European crypto market, authorities warn that bad actors are attempting to undermine those objectives through increasingly sophisticated social engineering attacks.
For investors, the safest approach remains verifying every licensing claim through official sources before transferring assets. As Europe’s crypto ecosystem adapts to the new regulatory environment, vigilance may prove just as important as compliance itself.
The MiCA license deadline is likely to remain a defining moment for the European digital asset industry, not only because it raises regulatory standards but also because it underscores the importance of investor awareness.
With fraudsters continuing to exploit the transition, regulators are expected to intensify public education efforts while expanding enforcement against impersonation scams. As the market matures under MiCA, maintaining trust will depend on both robust oversight and informed users capable of recognizing increasingly sophisticated threats.