- Fraudsters are impersonating financial regulators and licensed exchanges to target people whose crypto accounts genuinely had to move under the EU’s MiCA rules.
- The approach works because the real messages look much the same: new terms to accept, fresh identity checks, an unfamiliar company name on the account.
- UK holders aren’t covered by MiCA, but plenty use EU-licensed platforms, so they receive the same emails and have a different register to check against.
Anyone holding crypto on a European platform has probably had an email this year asking them to accept new terms, confirm their identity again, or move across to a newly named account. Most of those emails were genuine. A growing number are not.
The usual advice for spotting a scam message is that it will arrive out of nowhere and ask for something odd. Neither applies here. The email is expected, the request is plausible, and the timing fits, because the legitimate version looks almost identical.
So the safe assumption for the next few months is that a migration message has to be checked somewhere other than in the message itself, whichever platform it appears to come from.
What MiCA required, and why accounts had to move

MiCA is short for Markets in Crypto-Assets, the European Union’s single rulebook for crypto firms. Before it existed, a company could operate across the bloc under a patchwork of national rules, or in some countries under almost none. MiCA replaced that with one licence, granted by a regulator in a single member state, which then lets the firm serve customers across the EU.
The practical effect is that any exchange, broker or custody service wanting European customers needs authorisation as a crypto-asset service provider. Firms had a transitional window to get it. Firms that didn’t either had to stop serving EU customers or restructure so that a properly licensed entity took over the accounts.
That restructuring is the part ordinary customers actually experienced. A platform might have moved its European users onto a newly licensed subsidiary in another country, with a different legal name, updated terms and, in many cases, a repeat of the identity checks the customer had already been through. Emails asking people to log in, confirm details and agree to a new agreement were entirely real.
What the scams look like
CoinDesk reports fraudsters posing as both regulators and licensed exchanges, aimed squarely at users caught up in that migration. The pattern is the one that always follows a legitimate industry-wide notice: a lookalike domain, familiar branding, a deadline, and a link that leads to a login page built to capture credentials.
The regulator impersonation is the more effective half of it, because a message that appears to come from a supervisory authority carries an authority that an exchange email does not. Some versions push the target towards a phone call, where the pressure is easier to apply.
Two things are worth stating flatly. No regulator asks members of the public to move funds anywhere. And no genuine account migration requires you to send crypto to a new address, share a , or hand over a seed backup. Those requests only exist in the fraudulent version.
Where the responsibility sits
The deadlines here were known years in advance, and the migration itself was reasonable: the whole point of MiCA is that customers of European crypto firms get supervised firms. But the industry sent enormous volumes of messages asking people to re-verify identity and log into unfamiliar entity names, which is precisely the shape of a phishing campaign, and left customers to work out on their own how to tell one from the other.
Firms and supervisors could have made verification easy: a single published list of the new entity names, the exact domains that would be used, and a plain statement that nothing would ever be requested by link. Some did some of that. Not consistently enough for it to be the default expectation, which is the gap the fraudsters are working in.
The UK position is different
MiCA doesn’t apply in the UK. British firms answer to the Financial Conduct Authority, and the UK’s own rules for crypto firms are on a separate timetable.
That matters practically, because a lot of UK holders use platforms licensed in the EU. They received the migration emails along with everyone else, but the register that confirms whether a firm is real is not the same one. For an EU-authorised platform, the licence is listed by the regulator in the country that granted it and appears on the register maintained by the European Securities and Markets Authority. For a UK-registered firm, it’s the FCA register, which also carries the FCA’s warning list of firms known to be operating without permission.
The checks that work
Never migrate from a link. Close the email, type the platform’s address yourself or open the app you already have installed, and see whether the same notice is waiting inside your account. If it isn’t there, it isn’t real.
Check the new entity name against the relevant register before entering anything, and look closely at the sending domain, since lookalikes usually differ by a character or a suffix. Turn on two-factor authentication using an app rather than SMS. Treat any follow-up phone call as a separate attempt, whoever the caller says they are.
If you’ve clicked something and entered details, change the password immediately, revoke active sessions and any API keys, and contact the platform directly. In England and Wales, report it to Action Fraud on 0300 123 2040 or through its website. In Scotland, report it to Police Scotland on 101. If a card or bank transfer was involved, tell your bank straight away.
What to watch
Whether the licensed platforms and national regulators start publishing plain verification pages listing the exact entity names and domains in use. That single step would take most of the ambiguity out of it, and it costs almost nothing.
And whether the impersonation moves on from migration once the transition is finished. The scripts tend to follow whatever official process people are currently expecting, so the next round is likely to attach itself to the UK’s own crypto authorisation deadlines when those arrive.