Community Trust ScoreVerified
Fraudsters are moving fast. The EU’s crypto licensing shakeout has handed scammers a ready-made playbook — fake websites, forged documents, and impersonated regulators — all aimed at customers suddenly left without a licensed provider.
The trigger was July 1. That’s when the Markets in Crypto-Assets Regulation, known as MiCA, set its hard deadline for crypto firms operating inside the European Union to either hold a valid license or wind down. Companies that didn’t make the cut must cease or transfer their EU operations. And that exit process — messy, disruptive, and confusing for ordinary customers — is exactly the kind of chaos scammers thrive in. Criminals are posing as financial regulators and as the crypto businesses themselves, steering affected users toward fake platforms and fraudulent asset transfers. It’s a straightforward con, and it’s working.
Stéphane Pontoizeau, from France’s Autorité des Marchés Financiers — the AMF — said scammers have been impersonating AMF representatives directly, pushing users to move their assets through deceptive websites. That’s not a vague phishing attempt. That’s targeted social engineering aimed at people who are already anxious about what happens to their funds.
323 Licensed Firms, 1,700 That Aren’t
The numbers are pretty stark. By the end of July, the European Securities and Markets Authority — ESMA — reported that only 323 crypto companies had successfully obtained MiCA licenses. Meanwhile, VASPnet put the number of unlicensed firms that must stop operating at over 1,700. So there’s a massive gap. Hundreds of thousands of customers, probably more, are caught in the middle — looking for compliant alternatives, unsure who to trust, and apparently being found by scammers before they find a legitimate provider.
ESMA has warned publicly that criminals are misusing its own identity and logo, circulating falsified documentation that looks official. The authority cautioned that these fraudsters are specifically targeting people shopping around for new licensed providers — basically the most vulnerable group in this whole transition. Someone who just found out their exchange is shutting down EU operations isn’t thinking clearly about verification. They want their money safe. Scammers know that.
And it’s not just ESMA. The AMF warning from Pontoizeau makes clear this is happening at the national level too, not just through EU-wide bodies. That means the attack surface is wider than a single regulator’s communications. Scammers are apparently willing to impersonate whoever gets them closest to a target.
Why the Compliance Gap Is So Dangerous
Getting a MiCA license isn’t simple. The application process is involved, the requirements are detailed, and regulators across member states have varying timelines and capacities to process applications. So the gap between 323 licensed firms and 1,700-plus unlicensed ones isn’t necessarily a sign that all those companies are bad actors — many probably just didn’t make the cut in time. But from a consumer protection standpoint, that distinction doesn’t really matter. What matters is that a huge chunk of the market is in a gray zone, and scammers are filling the void.
Regulators are urging consumers to verify the authenticity of any contact or documentation claiming to come from an official body. ESMA is updating its list of licensed entities to give people a reference point. That’s a reasonable step. But it assumes the average crypto user knows to check that list before responding to what looks like an urgent message from a regulator telling them to move their funds now.
No specific countermeasures beyond awareness campaigns have been disclosed yet. That’s a gap. Unclear whether coordinated enforcement actions are being planned across member states, or whether this stays at the level of public advisories for now.
The broader picture is that MiCA, whatever its long-term merits, has created a short-term vacuum. Regulatory transitions always do. The timeline compression — firms either licensed or out by July 1 — left a lot of customers scrambling, and scammers don’t wait for the dust to settle. They move in while it’s still airborne.
ESMA’s licensed entity list currently sits at 323 firms.
Frequently Asked Questions
How many crypto companies obtained MiCA licenses by the end of July?
According to ESMA, 323 crypto companies had successfully obtained MiCA licenses by the end of July 2025.
How are scammers exploiting the MiCA licensing deadline?
Fraudsters are impersonating regulators like the AMF and ESMA, using fake websites and falsified documents to trick customers of unlicensed firms into transferring their assets to fraudulent platforms.





