The fallout from the EU's MiCA licensing deadline has opened a new front for fraud. France's securities regulator, the Autorité des Marchés Financiers, says criminals are impersonating its own staff, contacting customers of newly unlicensed crypto firms and directing them to move their holdings to fake websites built to look like official channels.
The European Securities and Markets Authority has reported a parallel pattern at the EU level, warning of “fraudulent practices involving the misuse of ESMA's logo and identity,” including falsified documents used to lend scams a veneer of official legitimacy. In both cases, the scammers are exploiting the same moment of confusion: thousands of users being told, correctly, that they need to move their assets somewhere else.
A Deadline That Created the Perfect Opening
The transition period for the EU's Markets in Crypto-Assets Regulation closed on July 1, 2026. By the end of July, only 323 crypto firms had secured a MiCA license, while more than 1,700 unlicensed companies were left required to wind down their EU operations and tell customers to withdraw or transfer funds elsewhere. Licensed platforms including Coinbase, Kraken and OKX cleared the bar; Binance remains the largest exchange still operating without one. An AMF official put the dynamic bluntly: “This moment is an opportunity for scammers more than usual” — precisely because so many real users are simultaneously receiving legitimate instructions to move their assets, making a fraudulent version of that same message much easier to disguise.
Part of a Fast-Growing Category of Fraud
The impersonation wave fits a broader trend. Blockchain analytics firm Chainalysis estimates that crypto scam and fraud losses reached $17 billion in 2025, up from roughly $6 billion in 2020, with impersonation schemes among the fastest-growing subcategories. Regulatory transitions have proven especially fertile ground for this kind of fraud elsewhere too — a dynamic echoed in other jurisdictions overhauling their own crypto rules this year, including Russia's newly signed comprehensive crypto market law, which is likely to trigger its own wave of compliance-related confusion as firms there adjust to a new licensing regime.
What Regulators Are Telling Users to Do
Authorities are urging traders not to act on unsolicited outreach, however official it looks. The AMF and ESMA both advise verifying any request to move funds directly against the regulator's own published website and app listings rather than links or contact details supplied by the person reaching out — a basic precaution that remains one of the few reliable defenses against impersonation fraud built specifically to mimic the exact channel a user would otherwise trust.