Real Registration Number, Borrowed Firm

Bybit
Coinmama


The BaFin published a consumer notice on the website nova-c-solutions(.)com on 28 September 2026. According to its findings, financial and securities services as well as crypto-asset services are offered there without the required authorisation. What makes the case interesting is less the warning itself than the route by which the site acquires an air of respectability: the operators give a business address in Pompano Beach in the United States, and at that address, on the BaFin’s account, a company called Nova Capital Solutions, LLC is indeed registered with the US Securities and Exchange Commission.

The regulator states explicitly that it has no indications whatsoever that this company or the people responsible for it are connected to the website. Instead, it says, this is presumably a case of identity theft at the expense of Nova Capital Solutions, LLC and its executives. For you as an investor, an uncomfortable conclusion follows: a genuine registration number proves nothing so long as it does not belong to the counterparty addressing you. That is precisely where the standard advice to “look it up in the register” breaks down.

The notice is a consumer communication about a website operating without authorisation, not a charge and not a verdict. Its legal basis is section 37(4) of the German Banking Act and section 10(7) of the German Crypto Markets Supervision Act. The substance in brief: the site offers financial, securities and crypto-asset services; the BaFin has granted no authorisation for them.

Anyone offering such services in Germany needs that authorisation. It is no formality: capital requirements, rules on the safekeeping of client funds, reporting duties and supervision itself all hang on it. Where it is missing, so is the entire apparatus that would take hold in a dispute.

Binance

One point matters for context. With a notice of this kind the BaFin is not saying that any particular investor has suffered a loss. What it establishes is that an offer is being made without authorisation — and the regulator makes that public so that nobody else falls for it.

Identity theft: why the US company named is the presumed victim, on the BaFin’s account

This point deserves care, because it is easily misread. Nova Capital Solutions, LLC appears in the notice not as an accused party but as a presumed injured one. The BaFin cites the company in order to explain why the address given on the website survives an initial inspection, and makes clear in the same paragraph that it has no indications of any link between that company and the site.

The suspicion of identity theft is likewise a suspicion, and it comes from the regulator rather than from us: the BaFin phrases it with the word “presumably”. Whether a third party’s identity was in fact used here, and by whom, is therefore not conclusively established.

A note on what can be substantiated, which we disclose rather than smooth over: we were unable to confirm the SEC registration of Nova Capital Solutions, LLC independently, because a query of the SEC’s EDGAR database returned nothing usable. The statement stands here as what it is, an account given by the BaFin.

The same blueprint as watermarkinvestments.com

In its notice the BaFin points out that nova-c-solutions(.)com bears strikingly strong similarities to the site watermarkinvestments(.)com, which it had already warned about on 8 July 2026. That is the real news for the reader: this is a template in repeated use rather than an isolated case.

When a template runs more than once, the name and the domain change while the structure, the boilerplate and the manner of legitimation stay the same. Anyone who knows the structure once will recognise the next version, whatever it is called. That is where the value of such a warning lies beyond the individual case.

A balance scale with two almost identical metal plaques on its pans, a struck coin below
Two presences can look alike – only one of them belongs to the company that is actually on the register.

A register entry alone does not separate real company names from borrowed ones

The common advice runs: establish whether the provider is registered or licensed. The advice is sound and remains the first step, but this case exposes its gap. That enquiry answers the question “Does this company exist?”. The question that matters, however, is a different one: “Is the company that exists the same one writing to me here?”

A register entry is an entry about a company, not about a website. It says nothing about who operates a domain, who sends an email or who is on the telephone. Where a genuine company address is used on somebody else’s site, the enquiry adds up formally and misses the substance.

What makes the difference is reversing the direction of the enquiry: instead of typing the details from the website into a register, work back from the official site of the registered company. Is the domain that approached you named there? Is the telephone number the same? Does the official site carry this offer at all? If any of those answers comes back negative, the register entry is worthless, however genuine it may be.

Section 10 of the Crypto Markets Supervision Act: how to spot a BaFin crypto warning

The BaFin publishes warnings about providers operating without authorisation on a rolling basis, and only a small share of them concern crypto-assets. There is, however, a reliable marker: the legal basis cited. The reference to section 10(7) of the Crypto Markets Supervision Act (KMAG) does not appear under every notice; it is set deliberately where an offer covers crypto-asset services.

By way of comparison, warnings about leasing offers or interest-rate portals from the same days do not carry that line, only the basis drawn from the Banking Act. For anyone who looks through the BaFin warning list from time to time and wants the crypto cases alone, that line serves as a usable filter.

The KMAG is the German statute that accompanies the European regulation on markets in crypto-assets and gives the BaFin its supervisory powers over crypto-asset service providers. It is the reason the regulator can act at all today against a crypto platform without authorisation.

The BaFin company database and its limits

For the question of whether a provider is licensed in Germany, the BaFin maintains a public company database. It shows whether an institution holds an authorisation, and for which business.

The limits of that database are the limits of any register. The database tells you which company holds an authorisation. What it does not answer is whether the website that approached you belongs to that company. A provider can sit in the database and still turn up on a forged site, which is exactly the process at issue here, only with a German rather than a US register.

That is why the order matters: first look in the database, then open the official presence of the company you found and work onward from there, never through a link somebody has sent you. Anyone who would rather stay with providers whose EU licensing is documented will find them in the overview of regulated crypto exchanges.

MiCA authorisation: what a licence in the EU actually covers

MiCA is the EU regulation on markets in crypto-assets, in force in stages since 2024, which requires providers of crypto-asset services to hold an authorisation. Such an authorisation means a provider is supervised, has to meet organisational requirements and must keep client assets segregated.

What it does not mean: that your market losses would be insured, that a provider cannot become insolvent, or that every service the provider offers is covered by the authorisation. A licence applies to particular business, not across the board to everything a company sells.

For the nova-c-solutions(.)com case the position is simpler. There, on the BaFin’s account, no authorisation exists at all, so the question of its scope never arises.

How a borrowed company profile shows up in conversation

The patterns that recur in this kind of operation can be named without knowing who is behind it:

  • The approach comes from outside. A regulated institution rarely contacts you unprompted through messenger apps, social networks or phone calls.
  • The legitimation is supplied for you. Registration number, address and screenshots all come from the other side. Only what you have found yourself, by your own route, can be tested.
  • A second channel is missing. The official main switchboard of the supposed company does not lead to your contact person.
  • Withdrawals require a payment first. Fees, taxes or an “unlocking” charge payable before a withdrawal are not standard practice.
  • Time pressure stands in for documents. An offer with a deadline that leaves no room for scrutiny is built as a sales argument, not as information.

None of these features proves anything on its own. Several together are the point at which it pays to transfer nothing and let a day pass instead. Anyone holding their balance in their own custody shrinks the attack surface considerably: the comparison of hardware wallets shows what that costs and what responsibility it brings.

A brass magnifying glass on an open register page, next to a struck coin
The register entry may be genuine – the question is who is invoking it.

When money has already moved: which routes are still open

Where a transfer has already gone out, much depends on the payment method and on time. With a classic bank transfer it is worth calling your own bank immediately to attempt a recall, and the chances fall with every hour. With a card payment, a chargeback procedure through the card issuer comes into consideration.

With a transfer in crypto-assets the position is different: a transaction on a blockchain cannot be recalled. What remains is the documentation, meaning the transaction hash, the recipient address, the timestamp, the entire correspondence and a screen capture of the website with its date. Those records are the basis for a report to the police and for a notification to the BaFin, which accepts information on unauthorised business.

Stay realistic: the prospect of recovering funds in cases like this is slim. That makes the part you can influence all the more important, namely making no further payment. The demand for an additional fee to release a supposedly blocked withdrawal is the most common pattern by which one loss becomes a larger one.

Four cases in six weeks: the pattern these BaFin warnings share

This case is not the first we have traced this year, and set side by side the pattern becomes clear. In August there was a warning in which another company’s name was likewise used, and the analysis of it appears in the piece on identity misuse at a crypto platform. Alongside it came the warning about a wallet application, the survey of entire platform series, and the compilation of how to place a crypto provider before the first euro changes hands.

Across all the cases the same construction repeats: a professional presence, a verifiable but borrowed legitimation, no evidence of authorisation for the business on offer, and an approach that comes from the other side. The names change faster than a warning list can absorb them. The construction does not.

From that follows the practical consequence for how to handle such lists. A warning list is a rear-view mirror. It reliably shows what has come to notice, but never the full picture of what is running right now. That a name is not on the list is therefore no certificate of good standing, an inference drawn surprisingly often in practice.

BaFin warning: How to proceed now

  1. Work in the reverse direction before money moves. Instead of typing the provider’s details into a register, start from the official presence of the registered company and see whether the domain is named there at all. Anyone who would rather begin with providers holding documented EU authorisation will find them in the comparison of regulated crypto exchanges.
  2. Shrink the attack surface. A balance that does not sit on somebody else’s platform cannot be frozen there either. What self-custody costs and demands is set out in the comparison of hardware wallets.
  3. Document everything you pay and receive. That holds for the worst case as much as for your tax return, because complete transaction data are the basis in both. Tools for it appear in the overview of crypto tax software.

And the most important sentence from this case, because it carries over to every next one: a genuine register entry proves that a company exists. It does not prove that you are talking to it.

(As of September 28, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Source: BaFin consumer notice of 28 September 2026.

Frequently asked questions about the BaFin warning on nova-c-solutions.com



Source link

Blockonomics

Be the first to comment

Leave a Reply

Your email address will not be published.


*