MiCA Transition Opens a New Attack Surface for Impersonation Scams

Fraudsters are posing as exchanges and regulators while EU customers move accounts after the bloc's crypto licensing deadline.

By Matteo Lindberg • • EU Regulation

An unmarked gold envelope on a stone corridor floor beneath a distorted shadow

Europe's MiCA licensing transition has created a new opportunity for impersonation fraud. Regulators in France and the Netherlands told the Financial Times that criminals are targeting customers of crypto businesses that failed to secure authorization before the July 1 deadline.

The tactics exploit a real administrative process. Unlicensed providers must restrict services, wind down or help customers move their assets. Fraudsters mirror those messages, pose as exchange staff or regulators and direct users to counterfeit websites. France's AMF has identified cases involving people pretending to be its employees, while ESMA said its name, logo and fabricated documents have been used to lend credibility to scams.

ESMA's current register lists 323 authorized crypto businesses. Data cited by the FT estimates that more than 1,700 unlicensed firms may have to leave or limit the EU market. The gap creates a large pool of customers searching for a new provider at the same time.

Why it matters

MiCA reduces regulatory ambiguity, but the migration itself has become a security event. The risk sits at the boundary between a genuine compliance instruction and a fraudulent transfer request. The practical control is exact-entity verification through official registers, not reliance on a familiar brand name or an unsolicited message.

Source: Financial Times