Fraudsters are exploiting the upheaval created by the European Union’s new crypto rules, impersonating financial regulators and crypto exchanges to steal customers’ funds, several of the bloc’s top watchdogs have warned. In interviews with the Financial Times, regulators, including France’s Autorité des Marchés Financiers (AMF) and the EU’s markets authority, ESMA, said they had seen an increase in such scams since the MiCA licensing deadline passed on July 1.
Why This Moment Is Ripe for Fraud
The opening was created by the rules themselves. Under the Markets in Crypto-Assets Regulation, crypto firms that failed to secure authorization by July 1 are now operating illegally in the EU and must tell their customers to withdraw or transfer their assets elsewhere. That has left large numbers of users simultaneously being told, legitimately, to move their money—the exact condition impersonation scammers thrive on.
The scale of the disruption is significant. ESMA’s register listed 323 authorized crypto firms at the end of July, while data provider VASPnet estimated last month that more than 1,700 unlicensed companies would have to cease EU operations. Major exchanges including Coinbase, Kraken, and OKX have secured licenses; Binance, the largest exchange by trading volume, is the most prominent firm to have failed to become EU-regulated, leaving many of its European customers among those needing to move funds.
Tom Keatinge of the UK’s Royal United Services Institute told the FT that fraudsters routinely prey on regulatory uncertainty and that people facing the disruption of their provider shutting down are more exposed to traps such as fake websites designed to get them to move their money. The AMF’s Stéphane Pontoizeau put it bluntly, calling the moment “an opportunity for scammers more than usual,” per the FT.
How the Scam Works—and Who’s Being Impersonated
The regulators described a consistent pattern rather than a single scheme. Fraudsters contact customers of unlicensed firms while posing as staff of a regulator or a crypto exchange, then instruct them to move their holdings to what is in fact a fake website or account controlled by the criminals, according to the AMF. ESMA said it was aware of fraudulent activity misusing its own logo and identity, including falsified documents, to lend scams a veneer of official legitimacy. The Dutch regulator, the AFM, said fraudsters may see an opportunity to target consumers who are in the process of looking for a licensed alternative.
The context is a fast-growing global problem. Losses to crypto scams and fraud reached $17 billion last year, up from $6 billion five years earlier, according to blockchain analytics firm Chainalysis, which said impersonation fraud has been among the fastest-growing categories.
Notably, France’s approach has been to avoid manufacturing urgency. Rather than imposing an aggressive shutdown deadline on unlicensed firms, the AMF said it deliberately wanted to prevent a “false emergency feeling” among clients—precisely the panic that pushes people into scams.
How to Protect Yourself
The regulators’ guidance points to a few clear safeguards for anyone whose EU crypto provider is winding down:
- Slow down. A forced withdrawal is not an emergency. The AMF’s explicit advice was to take your time choosing a licensed provider; urgency is the scammer’s tool, not yours.
- Verify the license yourself. Check whether a provider is authorized directly on ESMA’s official public register, rather than trusting a link, document, or logo sent to you.
- Distrust anyone who contacts you asking you to move funds. Regulators do not cold-contact consumers to instruct them to transfer assets to a specific account or site. The AFM advised caution whenever a third party requests a transfer and to avoid it in cases of doubt.
- Go to the source. Confirm any withdrawal instructions through your exchange’s official website or app that you navigate to yourself—not through a link, email, or message you received.
- Beware “recovery” offers. As Belgium’s FSMA has separately warned, fraudsters also target prior victims by posing as asset-recovery services for an upfront fee—a common second scam.
If you believe you have been targeted, regulators advise stopping any transfers immediately, preserving records, and reporting the incident to your national watchdog and police; the AMF said it refers cases of impersonation to law enforcement.
The Bigger Picture
The scam wave is an unintended side effect of a transition otherwise designed to protect consumers. MiCA’s licensing regime aims to raise standards across the bloc, but the mass migration it triggered—with unlicensed firms forced to exit and users moving funds in large numbers—has created friction that criminals are moving to exploit. It echoes a separate warning from EU anti-money-laundering officials that the same rush of withdrawals strains oversight. For now, the watchdogs’ message to users is less about the rules than about vigilance: in a moment when being told to move your money is legitimate, verifying who is doing the telling matters most.
