Particle.news
Download on the App Store

MiCA Migration Fuels Wave of Impersonation Scams Across the EU

Regulators say the forced transfer of customers to licensed firms has created an easy script for fraudsters and pushed authorities into active supervision and enforcement.

Overview

  • MiCA took full effect on July 1, 2026, requiring unauthorized crypto firms to stop onboarding EU customers and to wind down or redirect clients to licensed providers or self-custody.
  • Official and private datasets show a large gap between authorized and unauthorized firms, with ESMA listing about 323 authorized firms while TRM Labs and VASPnet identified many hundreds to more than 1,700 providers outside the register.
  • Fraudsters are copying real migration notices, impersonating regulators and exchanges, cloning websites and documents, and using screen-sharing and social engineering to trick users into moving or paying for their crypto.
  • Regulators advise users to verify the exact legal entity that holds MiCA authorization on ESMA’s public register before transferring assets and warn that they will never ask for transfers or up‑front recovery fees in private messages.
  • Supervisors have moved from the authorization phase to active monitoring, custody reviews and coordinated enforcement, a shift that could speed market consolidation and leave migrating retail users exposed to phishing and loss.