- The Financial Conduct Authority, HM Revenue & Customs and the Metropolitan Police took action at three London premises on 10 September over suspected illegal peer-to-peer crypto trading.
- Cease-and-desist letters were issued at all three, requiring the traders to stop. No arrests, seizures of funds or charges were announced.
- The FCA says there are currently no registered peer-to-peer crypto businesses operating in the UK at all.
Three addresses in London were visited last week by the FCA, HMRC and the Metropolitan Police. Much of the coverage since has used the word raid. The regulator’s own account of the day is narrower: letters were handed over, and the people behind the counter were told to stop.
If you have ever bought or sold crypto face to face, or through a small UK operator that takes cash over a counter and sends coins to your wallet, that business was not registered with the FCA. On the regulator’s own figures, none of them are. There is no approved anti-money-laundering process behind the transaction, and no compensation scheme standing behind your money if the business closes, disappears or is told to stop mid-trade.
What peer-to-peer trading means here
Peer-to-peer, usually shortened to P2P, means buying and selling directly with another party rather than through an exchange order book. In practice that covers everything from a matching service where two strangers agree a price, to a physical shop or office where someone hands over cash and receives bitcoin at an agreed rate.
The legal distinction matters more than the mechanics. Any firm carrying on cryptoasset exchange activity in the UK by way of business has to register with the FCA under the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, the same rules the 10 September action was taken under. Running that business without registering is a criminal offence, whether the trades themselves are honest or not.
Registration is worth understanding properly, because it is routinely mistaken for something it is not. It is an anti-money-laundering check: whether the firm knows who its customers are, screens them, and reports what it is supposed to report. It is not a solvency test, it does not make the coins safer, and registered firms are still outside the Financial Services Compensation Scheme for crypto holdings. A registered exchange can still lose your money. An unregistered one has simply never been examined at all. If you are weighing up where to buy, our guide to buying crypto in the UK covers who is on the register and what that does and does not buy you.
What the FCA actually did

The action took place on 10 September at three premises in London, with cease-and-desist letters issued at each one. The FCA press release does not name the businesses, the individuals involved, or say how many customers used them. It follows a similar FCA-led operation in April, and the regulator says evidence gathered then is being used in ongoing criminal investigations.
In the release, Steve Smart, the FCA’s executive director of enforcement and market oversight, said: “Anyone running an unregistered peer-to-peer crypto business should assume we are looking at them.” The same statement sets out the regulator’s reasoning for pursuing this corner of the market at all: “By operating outside the FCA’s registration regime, they avoid controls designed to detect and prevent money laundering.” Both lines come from the regulator’s own announcement, and describe suspicion rather than anything established in court. Nobody has been charged in connection with this particular operation, at least not publicly.
Where the framing runs ahead of the paperwork
CoinDesk reported the operation under the language of a multi-agency raid and the end of the UK’s light-touch era. The second phrase came from Caroline Black, a consultant at Gherson Solicitors, who told the outlet that “this second coordinated enforcement operation in six months confirms the FCA’s shift from warnings to active disruption”. That is a lawyer’s reading of a pattern, and a reasonable one. It is not how the FCA described its own day’s work.
The same piece sets the enforcement alongside a policy statement, PS26/18, issued by the FCA earlier that week on the cryptoasset regulatory perimeter, covering , exchanges, dealing, safeguarding and staking. CoinDesk reports the full UK framework taking effect on 25 October 2027, with an authorisation window opening on 30 September 2026 and closing on 28 February 2027. We have not read that document directly, so treat the dates as reported rather than confirmed. What the FCA does say plainly in its press release is that crypto in the UK remains largely unregulated until October 2027, apart from the money-laundering rules and the financial promotion regime.
So the two halves of the story sit further apart than a single headline suggests. One is a rulebook that does not bite for more than a year. The other is three letters delivered to three addresses under rules that have been in force since 2017. More UK policy coverage is collected here as the authorisation window runs.
What to watch
Whether charges follow. The April operation was described as feeding ongoing criminal investigations, and the test of a genuine shift from warnings to enforcement is a prosecution rather than a letter. Watch, too, for the first P2P business to appear on the FCA register. As long as that number stays at zero, every operator in the category is outside the regime, and the regulator has an open field.