Euro banknotes with EU stars and “MiCA” text in a blue-toned graphic illustration.
REGULATION

MiCA Migration Deadline Triggers Wave of Crypto Impersonation Scams

Image credit: Shutterstock

Key Takeaways

  • MiCA’s July 1 deadline forced over 1,700 unlicensed platforms to stop serving EU users, pushing millions to migrate accounts.
  • Regulators across France, the Netherlands, Austria, and the UK report a surge in impersonation scams tied to the migration.
  • Authorities urge users to verify the specific licensed entity via official registers before transferring funds.

Fraudsters are exploiting the European Union’s crypto licensing cleanup, impersonating regulators and licensed exchanges to steal funds from users forced to move their accounts. The wave follows the July 1 deadline under the Markets in Crypto-Assets Regulation, when more than 1,700 unlicensed platforms had to stop serving EU customers.

What Changed Under MiCA and Why Millions of Users Were Affected

MiCA’s transitional period for crypto-asset service providers ended on July 1. At that point, unlicensed platforms operating in the EU had to cease serving customers in the bloc and direct them toward MiCA-authorized alternatives. 

Only 323 companies held valid authorization at the time, creating a large gap between the number of platforms exiting the market and the number of licensed replacements available.

An estimated 10 million users were told to relocate their digital assets during the transition, according to prior reporting on the rollout. The volume of account migrations, combined with a compressed timeline, coincided with a rise in fraud attempts targeting users mid-transition. 

Scammers began copying the language of legitimate migration notices, impersonating regulators and exchanges, and directing victims to fraudulent platforms before the difference became apparent.

Regulators Report a Rise in Impersonation Scams Since the Deadline

Multiple national regulators say they have observed increased scam activity tied to the migration period. France’s Autorité des marchés financiers said scammers have posed as AMF staff, convincing victims to pay upfront fees under the pretense of recovering stolen funds.

The European Securities and Markets Authority said it is aware of criminals misusing its name, identity, and logo, including through falsified documents, to convince users their funds were at risk. The Netherlands’ Authority for the Financial Markets said the migration process itself has become a target for scammers.

“Fraudulent actors may indeed see an opportunity to scam retail investors who are in the process of looking for an alternative licensed provider.”

The AFM urged investors to verify any provider against the official ESMA register before transferring assets and to treat unsolicited requests for fund transfers as suspicious. Austria’s Financial Market Authority issued a similar warning, telling retail crypto users that hundreds of platforms lost their legal status on July 1. 

The regulator advised them to check official databases before moving assets, or to consider self-hosted wallets to avoid the migration process altogether.

Fake Fund-Recovery Claims Are a Common Attack Method

The U.K.’s Financial Conduct Authority said it logged 4,465 reports of fake FCA impersonations in the first half of 2025, with 480 victims tricked into handing over money. One recurring method involved fraudsters claiming the FCA had recovered funds from a crypto wallet allegedly opened illegally in the victim’s name.

The FCA said screen-sharing software is increasingly used by scammers to help set up fraudulent crypto accounts on victims’ behalf. 

Because legitimate exchanges routinely contact customers about withdrawals, transfers, and account restrictions, fraudulent messages that mimic official communications and create urgency can be difficult for users to distinguish from genuine outreach.

Social Engineering Was Already a Leading Threat Before the Deadline

Crypto exchange WhiteBIT reported that social engineering accounted for nearly 41% of crypto security incidents in 2025, with malicious actors relying on fake investment offers and impersonation rather than technical exploits. 

That pattern predates the MiCA transition, which added a new, time-limited theme to already prevalent social engineering tactics rather than a new method.

What Regulators Are Telling Investors to Check Before Moving Funds

The AFM and AMF both said they never ask individuals to transfer funds and never contact customers through private messages. The AMF publishes fraud warnings on its website, while the AFM directs investors to its own register alongside ESMA’s EU-wide list of authorized providers.

Regulators offered a consistent instruction for anyone still migrating accounts: verify the specific legal entity holding MiCA authorization, not just the parent brand. MiCA’s investor protections apply only to the regulated EU entity itself. A group’s brand holding a license in one jurisdiction does not automatically extend that coverage to all of its subsidiaries or affiliated platforms.

More For You

Explore More News