European regulators have reported a surge in impersonation scams targeting crypto users forced to move assets after the EU’s Markets in Crypto-Assets regulation ended its transition period on July 1.
More than 1,700 unlicensed platforms were required to stop serving EU customers and direct them to authorised alternatives, according to figures cited by CoinDesk. Only 323 firms held valid MiCA authorisation when the deadline arrived, leaving as many as 10 million users needing to migrate holdings.
The Financial Times, citing European regulators, reported that several watchdogs have identified rising fraud since the deadline. Authorities said scams involve impersonation of regulators including France’s AMF, the European Securities and Markets Authority, the Netherlands’ AFM and the UK’s Financial Conduct Authority, alongside forged documents and screen-sharing software used to create fake crypto accounts.
The Netherlands Authority for the Financial Markets told CoinDesk the migration process has itself become an attack surface, and that fraudsters may target retail investors searching for authorised platforms.
The numbers are less precise than they appear
The widely quoted figures merit qualification, and the discrepancy is instructive.
A separate analysis published by TRM Labs on August 7 identified 1,343 operating EEA crypto providers in its dataset as of July 1, of which 281 held MiCA authorisation and 1,062 did not. TRM said its figures count firms it could identify as actually providing crypto services, rather than every entry in older national registers.
That distinction matters. Many entities listed in legacy national registries were dormant, defunct or never meaningfully active, so counting them inflates the apparent scale of the exit. It also makes the framing of “1,700 platforms halting services” more definitive than the underlying data supports.
The direction is not in dispute. A substantial majority of crypto service providers operating in the European Economic Area lacked authorisation when the deadline passed, and the resulting migration is real regardless of which count is used.
What the rules actually require
ESMA’s requirements are narrower than a simple shutdown, which is part of why the transition has been confusing enough to exploit.
Unauthorised crypto-asset service providers must immediately stop new onboarding, marketing and new client relationships. They may continue only the services necessary for existing clients to sell, transfer or reallocate assets. Firms that failed to secure approval must either wind down operations or move customers to an authorised provider or a self-hosted wallet.
That creates a legitimate wave of migration notices from real platforms, arriving simultaneously across the bloc, instructing users to move funds urgently. Scammers have copied the language of those notices almost exactly.
MiCA became fully applicable on December 30, 2024, but Article 143 permitted qualifying providers already operating under national law to continue during a transitional period lasting no later than July 1, 2026. Member states could shorten or eliminate that window, producing different timelines across Europe. Users in different countries therefore received genuine migration instructions at different points over an 18-month stretch, further muddying what a legitimate notice looks like.
Why impersonation works here
The mechanics are straightforward and depend on confusion rather than technical compromise.
Fraudsters replicate official migration notices, pose as regulators or licensed exchanges, and direct users to fake platforms before victims recognise the difference. The messages are plausible because the underlying instruction is genuine: users really are being told to move assets, and the deadline really has passed.
Screen-sharing software adds a second layer. Rather than simply harvesting credentials, scammers walk victims through setting up accounts on fraudulent platforms while observing the process, which allows them to capture recovery phrases and transfer details directly.
Regulator impersonation is a well-established technique. The UK’s FCA said it received 4,465 reports in the first half of 2025 involving scammers impersonating the regulator, with 480 people suffering actual losses.
Regulators have stressed that MiCA investor protections apply only when using an authorised legal entity within the EU, meaning users who move funds to an unlicensed or fraudulent platform lose the safeguards the regulation was designed to provide.
Verification is the only defence
The guidance from national authorities is consistent and specific.
Users should check any platform against ESMA’s official register of authorised crypto-asset service providers before transferring assets, rather than relying on links or documentation supplied in a migration notice. Unsolicited requests for fund transfers should be treated as suspect regardless of how official they appear. Regulators do not contact individual investors instructing them to move crypto holdings.
Self-hosted wallets remain a permitted destination under the wind-down rules, which gives users an option that does not require trusting a new counterparty at the moment when identifying trustworthy counterparties is hardest.
The broader cost
The episode illustrates a recurring pattern in crypto regulation: enforcement actions that improve the market’s long-term structure create short-term windows of vulnerability.
MiCA’s core purpose is to remove unlicensed operators and give EU users a supervised market with clear investor protections. Achieving that required a compulsory migration on a fixed deadline involving millions of people, most of whom had no reason to be familiar with what a legitimate regulatory communication looks like.
The result is that a regulation designed to reduce fraud has, in its implementation phase, produced conditions ideal for it. Whether the eventual protections outweigh the transitional losses depends largely on how many users complete the migration without incident, and there is currently no public estimate of how much has been stolen.
Disclaimer: This article is for informational purposes only and does not constitute financial or legal advice. Cryptocurrency investments carry significant risk. Always conduct your own research before making any investment decisions.



















