MiCA's cleanup is creating a new scam wave across the European Union
The European Union's crypto clean-up has handed scammers a weapon. When the Markets in Crypto-Assets (MiCA) regulations' framework came into full force on July 1, more than 1,700 unlicensed crypto platforms were required to stop serving EU customers and direct them to lic…
Intelligence analysis by Llama

The EU's crypto clean-up has created a new scam wave, with scammers impersonating regulators and licensed crypto exchanges to steal funds from users forced to migrate their accounts after the EU's MiCA deadline.
Imagine you're moving to a new house, and someone calls you saying they're from the moving company, but they're actually a scammer trying to get your money. That's what's happening with some people who are moving their money to new crypto accounts after the EU's new rules came in. Scammers are pretending to be the real moving company, or even the government, to get people's money.
Analysis
MiCA's Cleanup Creates a New Scam Wave Across the European Union
The European Union's (EU) crypto clean-up has handed scammers a weapon. When the Markets in Crypto-Assets (MiCA) regulations' framework came into full force on July 1, more than 1,700 unlicensed crypto platforms were required to stop serving EU customers and direct them to licensed alternatives. Only 323 companies held a valid MiCA authorization at the time. That gap, in which up to 10 million users were told to move their digital assets, is exactly what fraudsters needed.
The mechanism is straightforward. Scammers copy the language of real migration notices, impersonate regulators, and push users to fake platforms before victims realize the difference. Social engineering scams were already concerning in 2025. Crypto exchange WhiteBIT found that nearly 41% of crypto incidents last year involved malicious actors deceiving victims through fake investment offers or impersonation. European regulators, however, say they have seen an increase in crypto scams since the July 1 deadline.
A spokesperson for France's Autorité des marchés financiers (AMF) noted scammers were posing as AMF employees, convincing victims to pay upfront administrative fees to recover stolen funds. The European Securities and Markets Authority (ESMA) confirmed it was aware of criminals misusing its identity, name, and logo, including through falsified documents, to convince users that their funds were at risk. The Netherlands' Authority for the Financial Markets (AFM) warned that the migration of unregulated crypto exchanges itself was the attack surface.
"Fraudulent actors may indeed see an opportunity to scam retail investors who are in the process of looking for an alternative licensed provider," the AFM told CoinDesk. It urged investors to verify any provider on the official ESMA register before transferring assets, and warned that unsolicited approaches requesting fund transfers should be treated with suspicion. Austria's Financial Market Authority issued a similar warning recently, telling retail crypto users that hundreds of platforms lost legal status on July 1 and urged them to verify providers against official databases before moving assets or transferring to self-hosted wallets to avoid migration traps entirely.
Regulator warnings The scammers' modus operandi follows a pattern regulators know all too well. The U.K.'s Financial Conduct Authority (FCA) told CoinDesk via email that it has 4,465 reports on record of fake FCA impersonations in the first half of 2025 alone, with 480 victims tricked into handing over money. One of the most common methods involved fraudsters claiming the FCA had recovered funds from a crypto wallet opened illegally in the victim's name. The FCA told CoinDesk that screen-sharing software was increasingly being used to help set up fake crypto accounts on victims' behalf. Genuine exchanges are contacting customers about withdrawals, transfers, and account restrictions, making it easier for fraudsters to mimic official communications and create a sense of urgency.
The AFM and AMF reiterated the same point, stating that they never ask people to transfer funds nor do they ever contact customers via private messages. The AMF publishes warnings on its website. The AFM directs investors to its own register alongside ESMA's. For investors navigating the migration, regulators offered one consistent instruction: verify the specific legal entity holding MiCA authorization, not just a parent brand, before moving any assets. MiCA's investor protections apply only when users are served by a regulated EU operation. A firm's broader group brand holding a license elsewhere does not cover all subsidiaries.
Key points
- The EU's crypto clean-up has created a new scam wave, with scammers impersonating regulators and licensed crypto exchanges to steal funds from users.
- Regulators have seen an increase in crypto scams since the July 1 deadline, with scammers posing as AMF employees and convincing victims to pay upfront administrative fees.
- The AFM and AMF have warned investors to verify any provider on the official ESMA register before transferring assets and to treat unsolicited approaches requesting fund transfers with suspicion.
- Regulators have offered one consistent instruction: verify the specific legal entity holding MiCA authorization, not just a parent brand, before moving any assets.
If the EU's regulators can work together to create a more secure and transparent system for crypto users, it could help reduce the number of scams and make it easier for people to trust the system. This could lead to more people using crypto and investing in it, which could have positive effects on the economy.
If the scammers continue to find ways to exploit the system and deceive people, it could lead to a loss of trust in the crypto market and a decrease in investment. This could have negative effects on the economy and make it harder for people to access financial services.



