European regulators are warning cryptocurrency investors about a surge in migration-related scams as the European Union’s Markets in Crypto-Assets regulation forces potentially more than 1,700 unlicensed platforms and entities to restrict or discontinue services across the bloc. The disruption follows the July 1, 2026 expiration of MiCA’s maximum transitional period for crypto-asset service providers, or CASPs, that had previously been allowed to operate under national regulatory regimes.

Only 323 companies held valid MiCA authorization when the deadline arrived, according to figures cited by CoinDesk. Estimates suggest more than 1,700 other entities could be affected, potentially forcing as many as 10 million users to move digital assets to authorized providers. Fraudsters are exploiting that migration by impersonating both regulators and legitimate crypto companies, sending users fake notices claiming that assets must urgently be transferred to remain compliant with MiCA.

Scammers Exploit a Genuine Regulatory Deadline

The effectiveness of the scam comes from its resemblance to legitimate communications. ESMA had already instructed unauthorized CASPs to stop onboarding new EU clients and begin winding down their activities while protecting existing customers. Providers were expected to give users sufficient opportunity to withdraw assets or transfer them elsewhere. Criminals can replicate those instructions through fraudulent emails, websites and support accounts before directing customers toward attacker-controlled wallets or fake exchanges. Stéphane Pontoizeau, executive director of the French Autorité des Marchés Financiers, told CoinDesk that the regulatory transition had created an unusually attractive opportunity for scammers.

ESMA has specifically advised investors to verify that a provider appears in its Interim MiCA Register before investing or transferring funds. Checking the precise legal entity is also important. A globally recognized exchange brand can operate through multiple corporate entities, while MiCA authorization applies to the specific European entity holding the licence rather than automatically covering every company within the group.

MiCA Moves From Transition to Enforcement

MiCA became fully applicable on December 30, 2024, but Article 143 allowed qualifying crypto providers already operating under national law to continue doing so during a transitional period lasting no later than July 1, 2026. Member states could shorten or eliminate that period, producing different transition timelines across Europe. That flexibility has now largely disappeared. ESMA said in June that CASPs without authorization after the deadline must take immediate steps toward an orderly EU wind-down while safeguarding customer interests and market integrity. The regulator has also told national authorities to scrutinize migration arrangements and take action against unauthorized crypto services continuing after the transition.

MiCA is intended to replace Europe’s fragmented national crypto regimes with a common framework governing exchanges, custodians and other service providers. The system establishes authorization, governance, disclosure and consumer-protection requirements while allowing licensed providers to operate across the European Economic Area. The migration period, however, has created an unintended security problem. Millions of customers have legitimate reasons to expect emails about account closures, transfers and new European entities. That makes fraudulent messages considerably harder to distinguish from genuine regulatory communications. MiCA is therefore entering its enforcement phase with an unusual challenge: regulators must remove unauthorized providers while ensuring that the resulting customer migration does not itself become an opportunity for criminals to steal the assets the new regime was designed to protect.