Crypto Phishing After MiCA: Check the Withdrawal Email

Blockonomics
Bybit


Since 1 July 2026, crypto service providers in the European Union may only operate if they hold an authorisation under the MiCA regulation. Anyone who failed to obtain one by that date has to wind down their EU business and ask customers to withdraw their balances. A wave of fraud has grown out of exactly that: tens of thousands of investors across Europe are right now receiving a perfectly legitimate message telling them to move their money elsewhere. For criminals this is the most convenient starting position in years, because their own demand no longer has to sound plausible. It only has to look genuine.

Supervisors in several EU member states have issued warnings over the past few days. According to the French markets regulator AMF, quoted in international reporting on 5 and 6 August, perpetrators pose as staff of supervisory authorities or licensed trading venues and instruct customers of unauthorised providers to move their holdings urgently. Stéphane Pontoizeau, who covers this area at the AMF, is quoted as saying that the current moment offers fraudsters a better opportunity than usual. The same reports note that ESMA has found its own name and logo being misused in letters of this kind.

This article is written as a checklist: how to recognise a genuine withdrawal request, which two registers you need for that, and what to do if your provider really is winding down.

Binance

Why crypto phishing works so well after the MiCA deadline

Fraud in the crypto market normally depends on talking a victim into an action they would never take on their own. A stranger writes that there is a security problem and that the balance has to move to a safe wallet immediately. Anyone who has read about this before grows suspicious, because the request comes out of nowhere.

In the summer of 2026 that layer of protection is missing. The request does not come out of nowhere. It is the routine process that the supervisors themselves ordered. According to reporting on the state of the register, around 323 companies have received a MiCA authorisation, while more than 1,700 others have to stop doing business in the EU. Those figures come from analyses at the end of July and keep shifting, because further authorisations are still coming through. In our own review of the register, only 21 of those entries were trading platforms in the narrower sense, meaning providers where retail investors actually buy and sell. How it came to that is set out in our analysis of the MiCA register.

The result is a window in which a great many people are all expecting a legitimate message that tells them to move their money. The AMF says it deliberately avoided short wind-down deadlines, because time pressure drives those affected straight into the hands of the perpetrators. After this week, that is the most important point for you: a genuine wind-down gives you time. If something is rushing you, that alone is the warning signal.

What a fake withdrawal request looks like

The letters that have reached the authorities are well made. What has been described includes rebuilt websites that follow a genuine provider or authority down to the layout, documents carrying copied letterheads and file references, messages from supposed officials, and transfer instructions pointing to wallets that belong to the perpetrators. Phone calls come on top of that.

What is striking is what these letters regularly leave out. They rarely give the file reference of a wind-down, they do not point to a register entry you could look up yourself, and they give you no route by which to reach the sender independently. What they do supply is a destination address and a reason to hurry.

A second variant is more subtle. Instead of a wallet address you receive a link to a platform that is supposedly MiCA-licensed. You open an account there, you even verify yourself with an ID document, and you then see your balance as a number on an interface that belongs to the operators. Withdrawals subsequently fail because of alleged taxes. This version is the more dangerous one, because it copies the familiar process of opening an account.

The register test: is the crypto exchange MiCA-licensed at all?

There is one check that settles the great majority of these cases, and it costs you two minutes: look the provider up in an official register, using an address you type in yourself rather than a link from the message.

The reason is straightforward. Fraudsters can send any claim, rebuild any logo and fake any confirmation page. What they cannot do is create an entry in a supervisory authority’s database. If a supposedly licensed provider is not in there, the matter is settled, however convincing the letter looks.

The ESMA register: every MiCA authorisation in the EU

The European securities regulator maintains the central directory of all service providers authorised under MiCA. It shows you whether a company holds an authorisation, which member state granted it and which services it covers. A provider may well be authorised without that authorisation covering every activity. Open the ESMA MiCA register and search for the legal entity name, not the brand. Many trading venues operate under a brand name but are registered under a different company. If the message gives no company name at all, that too is a finding.

The BaFin database: crypto custody and trading in Germany

For providers holding a German authorisation, the Federal Financial Supervisory Authority maintains its own company database. It is the faster route if your provider is based in Germany, and it additionally shows which permission was granted. The BaFin company database can be used without registering.

Both registers, however, only answer the question of whether a company is authorised, not the question of whether your email really came from that company. Hence the second step.

Second step: reach the provider through the official channel

Once you know the provider exists, you check whether the message came from it. A single rule applies here, and it is less comfortable than it sounds: you use no contact route whatsoever taken from the message. No telephone number from the email, no link, no attached PDF, no QR code.

Instead you open the app you already have on your phone, or you type in the provider’s domain yourself. If there is no notice about a wind-down inside the logged-in area, then as far as you are concerned that wind-down does not exist. A company telling its EU customers to withdraw does so in the account itself, precisely because it fears this kind of confusion.

Authorities, incidentally, virtually never write to retail investors directly in such cases. Neither BaFin nor ESMA will email you asking you to move balances to a particular address. A message that does exactly that while looking official can be treated as a forgery without any further checking.

Language markers: how to spot a phishing email in the text

If you have a message in front of you and cannot reach the registers at that moment, a handful of markers will help. None of them is proof on its own, but together they paint a clear picture.

  • A specific destination address in the text. Genuine wind-down notices describe routes, not wallets. If a recipient address appears in the message, that is the clearest indication there is.
  • A deadline of a few days or hours. Wind-downs under MiCA run over weeks and months.
  • A new contact channel. If the conversation moves to a messenger when everything so far arrived by email, something is wrong.
  • A request for login credentials or the recovery phrase. There is no legitimate process in which anybody needs your twelve or twenty-four words.
  • A domain that is almost right. An extra hyphen, a different ending, one letter swapped. Compare it character by character against your password manager.
  • Fees payable before the withdrawal. If you are asked to pay in order to reach your own balance, the case is clear.

Conversely, a professional appearance is not a mark of authenticity. The forgeries the supervisors are warning about are a problem precisely because they are well made. Spelling mistakes as a giveaway are advice from an earlier era.

When your crypto exchange really does close its EU business

Suppose the check comes out like this: the message is genuine, your provider did not receive a MiCA authorisation and is closing its EU business. You then have a real but solvable problem. The order matters, because a wrong first step gets expensive.

Secure your paperwork first. Download transaction histories, account statements and tax reports while you still have access. Once the service is switched off you often only reach that data through written requests, and you need it for your German tax return: the acquisition date and acquisition cost of every position decide whether a later sale falls under the one-year holding period.

Only then do you look for a destination. An authorised trading venue is the obvious choice if you want to carry on trading; which providers cleared the MiCA hurdle and how they differ on fees and custody is set out in our comparison of regulated crypto exchanges. If you intend to hold for the long run anyway, self-custody is the alternative that makes you independent of the authorisation question.

Only after that do you move any balance, and you do it with a test amount. Send a small sum, wait for it to arrive and transfer the rest afterwards. That costs one extra network fee and protects you from the most expensive mistake of all, the wrongly copied address.

One note on tax: a pure transfer between two accounts that both belong to you is not a disposal and triggers no tax in Germany. Selling because the provider only pays out in euro, by contrast, is a taxable event. So check beforehand whether it hands over the coins themselves.

Crypto sent and fraud noticed: what still helps

A crypto transfer cannot be reversed. Anyone promising you otherwise on the telephone belongs to the second wave: so-called recovery services, which get in touch after a loss and offer to retrieve the funds against an advance payment, are a well-documented fraud pattern in their own right.

Plenty is still worth doing. File a report with the police, because investigators piece addresses together and exchanges can freeze blocked funds when a withdrawal is attempted. Report the incident to BaFin. Preserve messages, domains and transaction hashes before the other side shuts its infrastructure down. And change the passwords and two-factor methods of every account you logged into on the fake site.

What changes permanently for crypto investors in the EU

For you, the licensing requirement leaves behind a habit that outlasts this summer: before you deposit money with a provider, you look it up in the register. That was hard before MiCA, because there was no single directory. Since this year it is one search query. Anyone wanting to follow the market clear-out in context will find the wider picture in our analysis of the winners and losers of the MiCA deadline.

Transparency note: in our comparisons we assess providers with some of whom partnerships exist. This has no bearing on the checks described here; the registers linked above are official directories.

What to take away

  1. Check the provider in the register before you move anything. Type the address of the ESMA register or the BaFin database in yourself and search for the legal entity name. If it is not there, the message is dealt with. Which authorised trading venues are open to you is shown in our comparison of regulated crypto exchanges.
  2. Confirm every withdrawal request inside your logged-in account. Open the app or the website by your own route, never through a link from the message. If no notice is waiting there, you do nothing. If you are switching anyway, our overview of crypto exchanges compared will help you choose.
  3. Move your holdings into self-custody if you intend to hold for the long run. That way you no longer depend on any service provider’s authorisation. Which device is suitable and what matters for the backup is covered in our hardware wallet comparison. Here too, send a test amount first.

(As of August 7, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

Source: https://cryptoticker.io/en/crypto-exchange-withdrawal-phishing-mica-check/



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*