Team
Author
Isabella Rivera
8 min read
Updated
17-08-2026
MiCA migration scams targeting EU crypto users

MiCA Migration Scams: How Fraudsters Are Targeting EU Crypto Users in 2026

The final phase of the European Union’s Markets in Crypto-Assets Regulation (MiCA) has changed which crypto companies can legally serve customers across the EU.

It has also created a new opportunity for scammers.

Since the MiCA transitional period ended on July 1, 2026, crypto-asset service providers (CASPs) that have not obtained the required authorisation must wind down their EU activities. Customers of affected platforms may therefore receive genuine messages about withdrawals, account restrictions or moving their crypto elsewhere.

Fraudsters are exploiting exactly this situation. European regulators have reported criminals impersonating crypto companies and financial authorities, using the regulatory transition to persuade users to send crypto to fraudulent platforms or accounts. (CoinDesk)

The problem is that a fake MiCA migration request can look surprisingly similar to a legitimate one.

Here is what EU crypto users need to know.

What Changed After July 1, 2026?

MiCA introduced a common regulatory framework for crypto-asset services across the EU.

Companies authorised as CASPs can provide covered crypto services under the MiCA framework, including across EU Member States through passporting. Companies that were already operating under certain national regimes were allowed to continue temporarily under transitional arrangements.

That transition reached its final deadline on July 1, 2026.

ESMA has instructed unauthorised CASPs to stop accepting new EU customers, cease marketing to them and limit existing services to what is necessary for an orderly exit. This may include allowing customers to sell positions, withdraw crypto or transfer their assets elsewhere.

ESMA has also specifically advised customers using unauthorised providers to check their provider’s status and, where necessary, consider transferring crypto to a MiCA-authorised CASP or to a self-hosted wallet.

This means that messages such as:

are not inherently suspicious.

And that is precisely what makes the current environment attractive to scammers.

Why MiCA Migration Creates an Opportunity for Scammers

Most phishing attacks have an obvious weakness: the attacker has to invent a convincing reason why the victim needs to act.

MiCA has provided one for them.

Some European crypto users genuinely need to reconsider where they hold or trade their assets. Some exchanges have genuinely changed the services available to EU customers. And legitimate providers may genuinely contact customers about withdrawals, transfers or account restrictions.

A fraudster can imitate that communication, add a fake deadline and direct the victim somewhere else.

According to reporting based on comments from European regulators, scammers have been impersonating both crypto companies and regulatory authorities since the end of the MiCA transition. The Dutch Authority for the Financial Markets (AFM) warned that criminals may specifically target investors looking for a new licensed provider, while France’s AMF has reported cases involving fraudsters posing as regulatory officials. (CoinDesk)

ESMA itself warns that criminals misuse its name and logo, create counterfeit documents and imitate official websites. (ESMA)

Crypto transfers make this particularly dangerous. Once assets are sent to an attacker-controlled wallet, reversing the transaction may be impossible.

How MiCA Migration Scams Work

There is no single MiCA scam template, but several variations follow the same basic pattern.

Fake Exchange Migration Messages

A user receives an email, SMS or social media message claiming that their exchange can no longer serve EU residents.

The message might say that the account will soon be frozen or closed and provide a link for transferring assets to a new “MiCA-compliant” platform.

The website may closely resemble a legitimate exchange. In reality, the deposit address belongs to the scammers.

Fake MiCA-Authorised Exchanges

Another approach is to advertise a fraudulent crypto platform as being “MiCA approved,” “EU licensed” or “ESMA authorised.”

The regulatory terminology creates legitimacy, but the claimed authorisation may not exist.

This is why the name of an exchange on its website is not enough. MiCA authorisation applies to a specific legal entity, and its status should be independently checked against official records.

Regulator Impersonation

Scammers may also claim to represent ESMA or a national regulator.

They might tell a victim that their current exchange is operating illegally, that their assets are at risk or that they must transfer funds as part of a regulatory process.

ESMA explicitly warns that fraudsters use its identity in this way and may contact victims through email, telephone, SMS or social media. The authority also states that it will not approach consumers asking for personal details or administrative payments under the pretext of recovering lost funds. (ESMA)

Fake Recovery or Compliance Services

A variation of the same scam may claim that crypto has been blocked because of MiCA, AML or compliance requirements.

The victim is then asked to pay an “administrative,” “verification,” “tax” or “release” fee before the assets can supposedly be transferred.

Requests for additional payments often continue until the victim stops sending money.

Red Flags to Watch For

A message mentioning MiCA is not proof that it is legitimate.

Be particularly cautious if:

Logos, professional-looking websites and official terminology should not be treated as evidence of legitimacy. ESMA specifically warns that scammers create counterfeit documents and websites imitating the authority itself. (ESMA)

How to Check Whether a Crypto Exchange Is MiCA-Authorised

The safest approach is to verify the company independently rather than relying on information contained in a message or advertisement.

ESMA maintains a central MiCA register containing authorised crypto-asset service providers as well as a separate list of non-compliant entities. The register is based on information supplied by national competent authorities and is updated regularly. As of August 12, 2026, ESMA states that it publishes updated register data on a weekly basis. (ESMA)

When checking a provider:

  1. Find the company in the official ESMA MiCA register.
  2. Check the legal entity name, not only the consumer-facing brand.
  3. Check which national authority granted the authorisation.
  4. Compare the company information with the details shown on the exchange’s own official website.
  5. Access the exchange independently rather than through a link received in an unsolicited message.

A company saying that it is “registered in Europe,” “EU compliant” or “regulated” does not necessarily mean it holds a MiCA CASP authorisation.

For a detailed walkthrough, see our guide on how to check whether a crypto exchange is MiCA-licensed in 2026.

How to Move Crypto Safely

If your existing provider really does require you to withdraw or migrate your assets, treat the transfer like any other security-sensitive crypto transaction.

First, verify the information through the provider’s official app or website. Instead of clicking a link in an email, open the service independently and check its announcements or support section.

Then verify where the assets are going.

If you are moving to another exchange, confirm that you have created the account yourself and check the provider’s MiCA status independently.

If you are withdrawing to a self-hosted wallet:

Never share a seed phrase or private key as part of a “migration.”

And if an exchange supposedly contacts you with a new deposit address, do not simply copy that address from the message. Log in to the genuine platform independently and generate or verify the deposit address there.

What to Do If You Suspect a MiCA Scam

If you receive a suspicious migration request but have not transferred anything, do not interact with the sender further.

Check the information independently using the official website of the exchange, ESMA or the relevant national regulator.

If you have already sent crypto or provided account credentials:

  1. Stop communicating with the suspected scammers.
  2. Change compromised passwords and enable or reset two-factor authentication where necessary.
  3. Contact the genuine crypto provider immediately.
  4. Preserve emails, messages, wallet addresses, transaction hashes and screenshots.
  5. Report the incident to your local law-enforcement authority.
  6. Notify the relevant national financial regulator.

ESMA recommends that victims stop interactions with fraudsters, report the case to local law enforcement and inform the relevant National Competent Authority. (ESMA)

Because blockchain transactions are generally irreversible, acting quickly does not guarantee that stolen crypto can be recovered. However, exchanges or authorities may still be able to identify or restrict funds if they reach a custodial platform.

MiCA Does Not Eliminate Crypto Scams

MiCA is designed in part to increase transparency and consumer protection in the European crypto market. But regulation cannot prevent criminals from pretending to be regulated.

In fact, the current transition creates an unusual security problem: scammers can imitate communications that some users are genuinely expecting to receive.

The safest response to any MiCA-related migration message is therefore not to trust the message itself.

Verify the provider. Verify the legal entity. Access services through their official channels. And verify the destination before transferring crypto.

The existence of MiCA authorisation can be checked independently. A request to move your assets should be treated the same way.

Keep Reading