Hungary Scraps Crypto Conversion Penalties
Hungary has repealed criminal offenses that exposed crypto users and service providers to prison terms of up to eight years for using or providing unauthorized crypto conversion services.
Act XXXVIII of 2026 took effect on August 7 after parliament adopted it on July 28, and it was promulgated on July 30. The law also dismantles the national transaction-validation regime introduced in 2025.
Crypto Users no Longer Face Five-Year Maximum for Unauthorized Conversions
Hungary’s 2025 rules made it a criminal offense to convert significant amounts of crypto through an unauthorized conversion service. Users faced maximum prison terms of two years at the lowest criminal threshold, three years for higher-value activity and five years for the highest category.
Service providers faced maximum terms of three years, one to five years and two to eight years depending on transaction value. Act XXXVIII repeals both offenses and removes provisions requiring covered crypto-to-fiat and crypto-to-crypto conversions to receive validation from a separately licensed provider.
Hungary Removes Validation Regime to Align With MiCA
The law’s explanatory memorandum said Hungary’s validation requirement was not consistent with EU crypto-market regulation and needed to be aligned with the directly applicable Markets in Crypto-Assets Regulation.
Hungary’s Supervisory Authority for Regulated Activities separately repealed its detailed licensing and registration rules for validation providers effective August 2. Act XXXVIII requires the authority to terminate pending validation licensing and supervisory proceedings. Existing validation-provider licenses expired when the law took effect on August 7.
MiCA Authorization Rules Still Apply to Crypto Providers
The repeal does not remove Hungary’s broader regulation of crypto-asset service providers under MiCA.
Hungary’s domestic MiCA grandfathering period ended on July 1, 2025. The Hungarian National Bank said it subsequently took measures against providers that had not obtained the required authorization.
The repeal also required validation providers and the supervisory authority to irreversibly delete data collected about crypto conversions and unauthorized transactions within three working days of Act XXXVIII taking effect.