The Netherlands Authority for the Financial Markets (AFM) warned that "the migration process from unlicensed exchanges itself has become an attack surface," adding that "fraudsters are likely targeting individual investors seeking licensed platforms." The AFM urged users to verify platforms on ESMA's official registry before moving assets and to treat unsolicited requests for fund transfers with suspicion.
Austria's Financial Market Authority (FMA) issued a similar warning. The FMA noted that hundreds of platforms lost their legal status as of July 1 and recommended that users verify providers in official databases before transferring assets or moving them to self-custody wallets.
Regulator Impersonation: A Proven Scam Pattern
Regulator impersonation is already a widely used tactic in crypto fraud. The UK's Financial Conduct Authority (FCA) reported receiving 4,465 impersonation reports in the first half of 2025 alone, with 480 people suffering actual financial losses.
According to the FCA, one of the most common schemes involves scammers claiming to have recovered funds from crypto accounts illegally opened in the victim's name. The FCA also noted a rise in cases where fraudsters use screen-sharing software to open fake crypto accounts under victims' identities.
Research from crypto exchange WhiteBIT found that approximately 41% of crypto incidents in 2025 involved social engineering tactics such as fake investment offers or impersonation. Since MiCA's implementation, European regulators have consistently reported an increase in crypto-related fraud.
Legitimate exchanges also contact customers about withdrawals, transfers, and account restrictions, making it easier for scammers to mimic official communications and create a sense of urgency.
Investor Protection Only Through Licensed Entities
Regulators uniformly emphasize that they "never initiate contact via personal messages or request fund transfers." The AMF has posted warnings on its website, while the AFM directs users to check both the ESMA registry and its own registry.
MiCA's investor protections apply only when services are accessed through EU-licensed entities. A parent company brand holding authorization in another region does not mean all subsidiaries are covered.
The consistent guidance from regulators is clear: before moving assets, verify the actual entity holding MiCA authorization—not just the parent company brand. Checking providers against ESMA's official registry and treating unsolicited fund transfer requests with suspicion remains the best defense.