The EU-wide transition period for the crypto regulation MiCA expired on July 1, 2026. Since then, ESMA and France's AMF have reported a rise in phishing scams that use faked regulator identities.
MiCA stands for Markets in Crypto-Assets and forms the EU-wide licensing regime for crypto service providers. Exchanges, brokers and custodians therefore need a CASP authorization with requirements on capital, compliance and investor protection. Without that license, they can no longer serve EU clients. Originally, the transition period allowed existing providers up to 18 months of continued operation, staggered by member state. At the end of July 2026, the ESMA register listed 323 authorized CASPs. For investors, the switch promised legal certainty above all. Yet the short term produced a new attack surface.
Only 16 of the 100 largest exchanges hold a MiCA license
The deadline has noticeably narrowed the circle of legally accessible providers. The public ESMA register lists every granted CASP authorization together with the responsible national supervisor. Once a supervisor issues a license, it applies across the entire single market through the EU passport. The number of entries shifts weekly because new authorizations keep arriving. Far larger, however, is the group of departures. Data provider VASPnet estimates that more than 1,700 unlicensed crypto service providers had to stop serving EU clients. Official confirmation for that estimate is missing.
Among the largest trading venues, license density stays low. Of the 100 crypto exchanges with the highest volume worldwide, only 16 hold a MiCA authorization. They include Coinbase, Kraken, Bybit, OKX, Crypto.com and KuCoin. At the top, the ratio runs comparatively higher, because six of the ten highest-volume exchanges hold a license. Binance, the world's largest exchange by trading volume, has so far not received an EU-wide MiCA license. As a result, all other providers may no longer actively serve EU clients since July. European users had to reorient within a few weeks.
The staggered timing added to the uncertainty. Germany set its national deadline at December 31, 2025, half a year ahead of the EU maximum. France, by contrast, gave its providers the full 18 months. Anyone holding accounts in both markets thus saw their platforms withdraw at different points in time. Existing customers had to pull their balances, move them to a licensed provider or take them into self-custody. Scammers exploit exactly this confusion.
MiCA phishing scams impersonate ESMA and AMF
The AMF documented cases in which perpetrators posed as staff of the authority. They told investors to move their balances to faked websites for supposed safekeeping. The pretext sounds plausible, especially since many customers had to switch providers anyway. Transferred crypto balances are also almost never recoverable.
France's supervisor therefore refrained from a hard shutdown deadline for unlicensed exchanges. An abrupt market exclusion would have handed the perpetrators additional pretexts. ESMA's name serves as a template as well. Speaking to the Financial Times, the authority confirmed the misuse of its logo and of forged documents. Official communications come exclusively from addresses ending in @esma.europa.eu. The Dutch AFM likewise reports targeted attacks on consumers who are looking for licensed alternatives.
Regulators name several markers of genuine communication. Supervisory bodies never ask for a transfer of assets. Moreover, they charge no fees for recovering lost funds. Artificial deadlines are equally absent from the official repertoire. Investors can check a provider's license status directly in the ESMA register or on the AMF website. Anyone facing time pressure should thus turn suspicious.
Identity fraud grew by more than 1,400 percent
The rise in such cases nevertheless began long before the deadline. The Crypto Crime Report 2026 from Chainalysis puts confirmed on-chain fraud losses for 2025 at around USD 14 billion. For the report, the analytics firm evaluates payment flows on public blockchains. With full coverage, it projects up to USD 17 billion. Initially, Chainalysis had reported USD 9.9 billion for 2024. The firm later revised that figure to USD 12 billion. Overall, the damage total climbed by around 17 percent compared with 2024.
Fraud using someone else's identity grew fastest. Chainalysis puts the increase at more than 1,400 percent year over year. At the same time, the average payment per case of this scheme rose by more than 600 percent. Across all fraud schemes, the average also went up, from USD 782 to USD 2,764. These figures refer to the global crypto year 2025 and not to the MiCA transition. Still, they show how lucrative impersonating an institution has become.
The attack technique is shifting too. Scam Sniffer recorded losses of USD 6.27 million from so-called signature phishing in January 2026. Against December 2025, that marks a gain of 207 percent. The number of victims fell at the same time by 11 percent to 4,741. Two large investors accounted for 65 percent of the loss total alone. Mass campaigns are consequently losing importance. The industry calls this concentration on a few wealthy targets whale hunting.
Swiss investors remain without MiCA protection
MiCA does not apply in Switzerland. The country belongs to neither the EU nor the EEA, so FINMA cannot grant a MiCA license. Anyone trading through an EU-licensed platform still benefits from the investor protection rules of the regulation. With an EU platform that is no longer licensed, however, that protection falls away entirely. The same holds for affiliated companies and for providers outside the union. The AMF points this out in its June statement. Swiss customers accordingly carry the risk alone in these cases.
Various Swiss crypto companies have secured access through subsidiaries in the EU and EEA. Crypto Finance received a CASP license from Germany's BaFin in January 2025, the first house to do so. Subsequently, AMINA Bank followed via Austria's FMA, as did Relai and SwissBorg via France's AMF. Swissquote secured its authorization in April 2026 from Luxembourg's CSSF. RuleMatch, Bitcoin Suisse and Sygnum Bank finally received their approvals in June 2026 in Liechtenstein. Altogether, the eight licenses spread across five supervisory authorities.
A direct Swiss equivalent to the MiCA transition does not exist. FINMA nonetheless keeps a warning list of providers that create the appearance of a license. It rests on reports and its own inquiries, so it is not exhaustive. As a checking tool, the list complements the authorization register but does not replace it. The Federal Office for Cybersecurity registered just under 65,000 reports in 2025, around 19 percent of them about phishing. In the second half of 2025, 6,299 phishing reports came in, 17 percent more than a year earlier. The office does not break out how many of them involved crypto investors.








