What the Crypto Markets Supervision Act Means

Ledger
fiverr


The Crypto Markets Supervision Act, or KMAG for short, is the German law that enforces the European regulation on markets in crypto-assets. For you as a customer it has one very practical consequence: anyone offering crypto-asset services in Germany needs a licence for it, and the Federal Financial Supervisory Authority is allowed to name providers that lack one. That is exactly what the regulator is doing at the moment, almost daily.

Between late September and early October, BaFin published nine consumer notices on unauthorised business within four days. Five of them concern crypto-asset services, and five close by expressly citing “section 37(4) of the Banking Act, section 10(7) of the Crypto Markets Supervision Act”. That single line at the foot of the notices is the real finding: Germany’s young crypto supervision law has moved out of the licensing department and arrived in consumer warnings.

The Crypto Markets Supervision Act is Germany’s implementation of the MiCA regulation

The KMAG dates from December 27, 2024 and appears in the Federal Law Gazette 2024 Part I under number 438. It was last amended on March 25, 2026. Its opening section states in one clause what it is for: it “serves to implement Regulation (EU) 2023/1114”, the regulation on markets in crypto-assets known as MiCA.

The division of labour behind this matters for understanding the case. The European regulation prescribes what applies: which licence a provider needs, what obligations it carries, which information it has to publish. The KMAG governs who enforces that in Germany, and with which instruments. The regulation applies directly across Europe; the act puts the tools in BaFin’s hands.

coinbase

Why the law carries its own name although MiCA applies directly

An EU regulation takes effect without a national implementing act, but it contains no German procedural rules. Who issues an order, how you challenge it in court, which fines are possible, when an authority may go public: all of that has to be written by the national legislator. The KMAG is that supplement. It entered into force as Article 1 of the Financial Market Digitalisation Act and replaced the crypto rules in the Banking Act, where they had been housed until then as the “crypto custody business”.

Section 10(7) KMAG allows BaFin to name a company in public

The provision the warnings rest on is headed “Prosecution of unauthorised business”. The first sentence of subsection 7 reads: “Insofar and for as long as facts justify the assumption, or it is established, that an undertaking provides unauthorised business within the meaning of section 9(1) sentence 1, the Federal Authority may inform the public of the suspicion or of that finding, stating the name or the company name of the undertaking.”

Three things about it are worth keeping in mind when you read a warning of this kind.

First, a suspicion is enough. BaFin does not have to wait until a court has ruled; facts that justify the assumption suffice. That is why the notices almost always carry the formula “there is a suspicion” and not the claim that somebody has committed fraud.

Second, the provision also covers firms that do no business at all but behave as though they did. Sentence 2 of the subsection makes clear that the same power applies where an undertaking “does not provide the unauthorised business but creates a corresponding impression in public”. That catches the sham platforms which only collect contact details.

Third, the procedure is not one-sided. Sentence 3 directs: “Before the decision under sentence 1 or sentence 2, the undertaking shall be given a hearing.” A warning therefore stands at the end of an administrative procedure. Where BaFin reaches nobody because no one behind a website is identifiable, the notice simply calls them “the unknown operators”.

Five of nine consumer notices from four days concern crypto-asset services

Between September 28 and October 1, 2026, BaFin published nine consumer notices on unauthorised business. Counted in the full text of each individual notice, this is the picture:

  • Five notices name the term “crypto-asset services” expressly.
  • Five notices list the Crypto Markets Supervision Act at the foot as the legal basis.
  • Four of them do both, so the two sets do not overlap completely.
  • Three cases describe identity misuse at the expense of a genuinely existing company.

That the two groups of five come apart is not a counting error but revealing. In the notice on btcx(.)investments of September 29 the wording is about banking business and financial services, yet the legal basis at the foot still names the Crypto Markets Supervision Act. Conversely, the notice on staublicapital(.)com from the same day lists crypto-asset services in its general part but does not rely on the KMAG. The supervisor is still sorting this out, and with a legal framework less than two years old that is to be expected.

Two almost identical polished brass company signs side by side on a dark stone wall, the right one screwed on slightly crooked
The name of a registered company can be copied; the licence behind it cannot.

The bitbucks(.)space case: identity misuse at the expense of a Stuttgart company

The most interesting of the five cases is the one from September 30. In its consumer notice, BaFin warns about offers on the website bitbucks(.)space and puts it like this: “There is a suspicion that the unknown operators of the website bitbucks(.)space are offering financial and securities services as well as crypto-asset services without authorisation.”

Then comes the sentence that sets the case apart from an ordinary fake broker: “Contrary to the operators’ statements, there is no connection with Frank und Freunde GmbH, based in Stuttgart. This is a case of identity misuse.” BaFin expressly establishes that this company stands in no connection with the website and the services offered there.

That is an important distinction, and it holds in both directions. On the supervisor’s account, the Stuttgart company named is the injured party in this matter, not the accused one. For you that means: the company name on a website, the imprint and even a genuine commercial register entry say nothing about who actually runs the page. We had a similar pattern back in August, when BaFin warned about a provider using a borrowed corporate identity.

28 nearly identical websites serve to solicit business, BaFin says

A day before the BitBucks case, on September 29, BaFin named a whole series of sites at once. The notice says the unknown operators were offering crypto-asset services there without a licence; the sites had no legally valid imprint. Interested parties were asked to enter their details in a contact form, and those customer records then went to operators of unauthorised online trading platforms.

28 addresses are listed in that single notice, from altrevia-ai(.)click through blitzkapitenz(.)live to zylkex(.)online. Several names appear with two or three different endings. The pattern behind it is cheap and effective: one template is duplicated, every copy gets a new invented name, and as soon as one address is burned the inflow runs through the next.

What a site without a legally valid imprint means in practice

In Germany an imprint is mandatory for commercial websites. If it is missing, or if it contains invented details, you have nobody you could sue in a dispute and no address for service of documents. That the supervisor mentions this point separately in the notice is therefore not a formality. It describes the state your money is in once you have paid it in.

The transitional licence under section 50 KMAG expired on December 31, 2025

When the new rules started there was a grace period. Section 50 KMAG allowed companies that were permitted to run crypto business under the old law on December 29, 2024 to continue their activity for the time being; the old licence counted “as continuing to that extent”. Among those affected were institutions with a licence under section 32 of the Banking Act, investment firms and payment service providers.

That transitional period is over. Subsection 2 of the section names three grounds for expiry, and the third is a hard calendar date: the continuing licence expires “at the latest at the end of December 31, 2025”. Since January 1, 2026 there is therefore no legacy arrangement left in Germany. Anyone offering crypto-asset services today must hold the licence under the MiCA regulation, or they are working without authorisation.

For the provider landscape that was a noticeable break, and it explains why the warnings are increasing right now. Which obligations came at the companies with it is something we gathered in our overview of the MiCA licence.

Ten services fall under the term crypto-asset service

Crypto-asset service is a defined legal term, not a loose description. In Article 3 the MiCA regulation lists exactly ten services and activities:

  1. Custody and administration of crypto-assets on behalf of clients
  2. Operation of a trading platform for crypto-assets
  3. Exchange of crypto-assets for funds
  4. Exchange of crypto-assets for other crypto-assets
  5. Execution of orders for crypto-assets on behalf of clients
  6. Placing of crypto-assets
  7. Reception and transmission of orders for crypto-assets on behalf of clients
  8. Advice on crypto-assets
  9. Portfolio management of crypto-assets
  10. Provision of transfer services for crypto-assets on behalf of clients

The list explains why almost every provider where you can buy, swap or simply leave Bitcoin falls under the licensing requirement. The plain exchange of euros into a crypto-asset is already number three on the list. An exchange that also holds balances provides at least two of these services at the same time. For an overview of trading venues with a licence in the EU, see our comparison of regulated crypto exchanges.

Where the licensing requirement ends

Not every piece of software is a service provider. A wallet that runs exclusively on your device and whose keys only you know legally holds nothing for you, because nobody else has control over the keys. As soon as a company controls access, the picture changes. Where exactly that line runs is something we broke down using the example of the licensing requirement for wallet apps.

Wall of many identical steel letterboxes in a dark hallway, a single flap standing open with the compartment behind it empty
Nearly identical sites under ever new names are the pattern of the warning series of September 29.

BaFin’s company database is the official register for licences

Each of the nine notices points at the end to the same place: BaFin’s company database, where you can look up whether a particular company is licensed by the supervisor. This official register is freely accessible and costs nothing.

In addition, section 14 KMAG requires BaFin to announce the granting and the withdrawal of a licence to provide crypto-asset services in the Federal Gazette. So there are two official traces: the database entry as a status display and the announcement as an event. A search engine, a review portal or a tip in a chat group is not a third trace.

A concrete step-by-step guide to querying the database, including the usual stumbling blocks, is in our guide to BaFin warnings and checking a provider.

A licence covers supervision, not price losses and not a faked website

The BitBucks case shows the limit of this tool very clearly. An entry in the company database says that a particular company holds a particular authorisation. It says nothing about whether the website you are currently on belongs to that company. Anyone who copies a genuine company name produces a hit in the database that has nothing to do with their own offer.

That is why a check always includes a second step: the path leads from the database to the company’s website, not the other way round. If the database shows an address in Stuttgart while the page asking you to deposit sits under an invented domain with no imprint, then the entry does not match the offer.

Even a genuine licence is no guarantee for your money. Behind it stand ongoing supervision, capital and organisational requirements and reporting duties. A promise of rising prices is not part of it, and neither is an assurance that a company will never become insolvent. Deposit protection for crypto balances does not exist in Germany in any case.

Hearing and correction: the procedure behind a BaFin warning

Because naming a company in public can hit it hard, the legislator built in counterweights. Before the decision, the undertaking has to be given a hearing. If the facts communicated by the authority later turn out to be wrong, or the circumstances to have been rendered inaccurately, the provision requires the supervisor to inform the public about that in the same manner.

For placing a warning in context that means: a notice of this kind is an official statement of suspicion within a regulated procedure, not a judicial finding and not a verdict on individuals. Serious reporting therefore carries the attribution with it. Where this text says that a suspicion exists against the operators of a site, that suspicion is BaFin’s.

Section 45 KMAG governs the allocation of custodied crypto-assets in insolvency

One part of the act that is rarely mentioned concerns the most unpleasant case. Chapter 6 of the KMAG contains provisions for special situations, among them section 44 on insolvency and section 45 on the “allocation of custodied crypto-assets” and the costs of segregation. Behind that lies the question of whether crypto-assets a licensed custodian holds for you belong to the estate in its insolvency or remain allocated to you.

That the legislator regulates this point separately at all is an indication of how little the allocation can be taken for granted. With a provider that has no licence the question does not even arise in this form, because neither the separation of client holdings nor supervision over it is secured there. Anyone holding larger amounts has an alternative in self-custody, which works independently of a service provider’s licensing status.

Crypto Markets Supervision Act: How to proceed now

Three steps that take a few minutes and mirror the sequence of the case of September 30.

  1. The database first, then the website. Look up the company name in BaFin’s company database and go from there to the company’s official address. If you are simply looking for a trading venue with a demonstrable licence in the EU, the comparison of regulated crypto exchanges helps as a starting point.
  2. Hold the offer and the entry against each other. Company name, registered office and type of authorisation have to match what is being offered to you. A licence for investment advice does not cover a crypto exchange. If you want to compare how established providers state their licence and their fees, you will find that in our overview of crypto exchanges.
  3. Spread the holdings you do not need for trading. A balance that sits permanently with a service provider depends on that provider’s survival. Self-custody takes that dependency out; the devices and their differences are in the hardware wallet comparison.

The warning series from the end of September is not an isolated case and will not be the last. What has changed is the basis: since the Crypto Markets Supervision Act came into force and the transitional period ran out, a clear licensing requirement stands behind every one of these notices. That makes the check easier for you, because for crypto providers in Germany there is no grey area left that anyone could invoke.

(As of October 4, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Frequently asked questions about the Crypto Markets Supervision Act



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*