GAMBITY
Gambity Commercial Law EU crypto users hit by scam wave as unlicensed pla…
Commercial Law Analysis

EU crypto users hit by scam wave as unlicensed platforms shut

The European Securities and Markets Authority confirmed it was aware of criminals using its identity, name, and logo — including through falsified documents — to persuade users their funds were at risk.
EU crypto users hit by scam wave as unlicensed platforms shut

MiCA migration scam wave hits EU crypto users as unlicensed platforms shut

When 1,700 unlicensed crypto platforms stopped serving European Union customers on July 1, the directive went out to roughly ten million users: find a licensed alternative and move your assets. Only 323 companies held valid MiCA authorization at that moment. The gap between those two numbers is where the fraud began.

The mechanism is not complicated. Scammers copied the language of real migration notices, impersonated regulators, and directed users to fake platforms before anyone checked the domain name. The European Securities and Markets Authority confirmed it was aware of criminals using its identity, name, and logo — including through falsified documents — to persuade users their funds were at risk. France's Autorité des marchés financiers reported scammers posing as its own employees, demanding upfront administrative fees to recover assets that had never actually been seized.

The Netherlands' Authority for the Financial Markets put it plainly: the migration itself was the attack surface. That is the thing the framing of MiCA as a cleanup exercise misses. A compliance deadline that forces millions of retail users to transfer assets simultaneously, under time pressure, to unfamiliar platforms, does not tighten the perimeter. It widens it. Retail users following instructions are the easiest users to deceive, because following instructions and following fraudulent instructions look identical from the inside.

The UK's Financial Conduct Authority reported 4,465 instances of fake FCA impersonation in the first half of 2025 — before MiCA's July 1 deadline created a fresh wave of plausible cover. One common method: fraudsters claiming the FCA had recovered funds from a crypto wallet illegally opened in the victim's name, then requesting a fee to release them.

I have watched this pattern appear in financial regulation before, in contexts with no crypto component at all. When a compliance event forces account migration at scale, the structural vulnerability is not the bad actors who were already operating illegally. It is the cover the event provides to a second class of bad actor who had no prior relationship with the user, the platform, or the assets. The legitimate notice and the fraudulent one are indistinguishable without verification that most retail users do not perform.

Austria's Financial Market Authority recommended that users either verify any new provider against the official ESMA register before transferring assets, or move to self-hosted wallets to avoid the migration trap entirely. That is sound guidance, but it assumes a user who reads the fine print on both the legitimate notice and the fraudulent one — a user who, by definition, is not the most exposed person in this situation.

MiCA was designed to bring order to a fragmented and often predatory market. That regulatory goal is defensible. What the drafters appear not to have weighted was that a hard deadline applied to a large and technically unsophisticated user base generates the same pressure that fraud has always run on: urgency, authority, and the appearance of legitimacy. The cleanup handed scammers the first two for free.

Kendall Cross
About the analyst
Legal Markets Analyst & Paralegal
Kendall Cross graduated first in her class from Yale Law, lasted eight months at a top Wall Street firm before going over a partner's head to correct a material error in a client brief, and joined Gambity when Victoria Blackwell called and said four words: "I need someone honest." Kendall arrived the next morning.
Share this analysis
Frequently Asked

MiCA required roughly ten million European Union crypto users to move assets from 1,700 unlicensed platforms to one of only 323 licensed alternatives by July 1, 2025. Scammers exploited this forced migration by copying legitimate regulatory notices, impersonating ESMA, France's Autorité des marchés financiers, and other authorities, then directing users to fake platforms. The Netherlands' Authority for the Financial Markets identified the migration itself as the attack surface: retail users following instructions cannot distinguish between legitimate and fraudulent notices without verification most do not perform.

The UK's Financial Conduct Authority reported 4,465 instances of fake FCA impersonation in the first half of 2025, with a common method involving fraudsters claiming the FCA had recovered funds from a crypto wallet illegally opened in the victim's name and requesting an upfront fee to release them. France's Autorité des marchés financiers separately reported scammers posing as its own employees with the same fee-extraction tactic. The European Securities and Markets Authority confirmed criminals were using its identity, name, and logo including through falsified documents.

Retail users exposed to fraudulent migration notices lack a reliable way to distinguish them from legitimate ones without performing verification most do not do. Austria's Financial Market Authority recommended users either check the official ESMA register before transferring assets or move to self-hosted wallets to avoid the migration trap entirely. Users following migration instructions face a structural vulnerability: scammers create plausible cover by mirroring the language and authority of real regulatory compliance events, making the fraudulent notice indistinguishable from the legitimate one.

Continue Reading