MFSA Warns: MiCA Transition Is Fuelling Crypto Impersonation Scams
Malta's financial regulator, the Malta Financial Services Authority (MFSA), has issued a public notice warning crypto-asset holders across the European Union about a growing wave of impersonation scams linked to the ongoing MiCA transition. Fraudsters are exploiting the uncertainty created as crypto-asset service providers (CASPs) restructure, close, or migrate customers to newly licensed entities, and the consequences for victims can be the permanent loss of their crypto assets. If you hold crypto, knowing how these scams work, and how to spot them, is no longer optional.
What MiCA Has to Do With It
The EU's Markets in Crypto-Assets Regulation (MiCA) requires all crypto-asset service providers operating within the European Union to hold the appropriate authorisations before they can legally serve customers. That process has created a transitional window during which some providers are winding down, others are rebuilding their corporate structure, and others are transferring customer accounts to a licensed successor entity.
All of that legitimate activity generates real, expected communications to customers: emails about account migrations, requests to re-verify identity, notifications about service changes. Scammers have noticed. They're crafting fraudulent messages that mimic exactly the kind of routine, compliance-driven correspondence that MiCA has made commonplace.
Why the transition period is a high-risk window
When a provider legitimately migrates customers, the process typically involves contacting those customers and asking them to take action. That action might be re-submitting KYC documents, acknowledging new terms, or following a link to a new platform. Fraudsters reproduce these exact patterns, inserting themselves into the flow. Because customers are already expecting to hear from exchanges about MiCA-related changes, they're less likely to pause and question an unexpected message.
The MFSA explicitly identifies this dynamic in its notice, stating that the uncertainty of the transition period creates opportunities for bad actors to exploit consumers through deceptive communications and impersonation schemes.
How the Scams Are Reaching People
The MFSA has received reports from across the EU describing fraudsters using a range of contact methods. These include email, telephone calls, messaging applications, and social media platforms. Fake websites closely replicating the appearance of legitimate CASPs or regulatory bodies have also been reported.
Common impersonation tactics
Reported schemes typically involve fraudsters claiming to be one of three types of entity:
- A crypto-asset service provider the victim already holds an account with, requesting an urgent account migration or KYC re-verification.
- A financial regulator or supervisory authority, including national competent authorities such as the MFSA itself, demanding the transfer of assets for so-called safekeeping or compliance reasons.
- A recovery service, contacting people who have previously been defrauded and offering to retrieve their lost assets, in exchange for an upfront fee or asset transfer.
The MFSA is explicit on one critical point: no legitimate regulator or supervisory authority will ever ask you to transfer your crypto assets. If any entity claiming to be a regulator requests a transfer, that request is fraudulent.
This pattern mirrors scams seen in other jurisdictions. Our earlier coverage of HMRC contacting crypto holders and how to verify it's real and fake IRS letters targeting crypto holders shows this is a global enforcement impersonation problem, not just a Maltese or EU-specific one.
What the MFSA Says You Should Do
The authority's guidance centres on two straightforward but important habits.
Always verify through official channels
If you receive any communication that claims to be from a crypto-asset service provider, a regulator, or a supervisory authority, do not respond using the contact details provided in that message. Instead, go directly to the official website of the entity in question, or use the customer service channels you already have on record. Type the URL into your browser manually rather than clicking a link in the message.
Check the MFSA register before acting
The MFSA maintains a public register of licensed entities and publishes warnings about unlicensed or fraudulent actors on its official website at mfsa.mt. Before taking any action requested in an unsolicited communication, check whether the entity that contacted you actually appears on that register. If it doesn't, or if its name is slightly different from a firm you recognise, stop and report the contact to the MFSA.
The Tax and Accounting Angle You Shouldn't Ignore
Beyond the immediate risk of asset loss, scam-related losses sit in an uncomfortable position when it comes to crypto tax. In most EU jurisdictions, a voluntary transfer of crypto to a fraudulent address is treated differently from a hack or theft. Whether a scam loss is deductible, and under what conditions, varies by member state and depends heavily on the circumstances of the transfer.
Why your records matter more than ever
If you do fall victim to an impersonation scam, having a complete record of your original acquisition costs, transaction history, and wallet addresses will be essential for any potential tax relief claim, insurance claim, or law enforcement report. A well-maintained crypto tax report showing your cost basis across all holdings is not just a filing tool: it's evidence.
Keeping your transaction history current through a reliable crypto tax calculator means that if an incident does occur, you already have documentation. You're not trying to reconstruct years of activity after the fact while simultaneously dealing with asset loss and a potential police report. The habit of calculating your crypto taxes regularly, and generating periodic reports, creates a paper trail that has real value outside of tax season.
For anyone who wants to understand how to file crypto taxes correctly and maintain records that will hold up to scrutiny, the starting point is always accurate, timely cost-basis tracking across every wallet and exchange you use.
Red Flags: A Quick Reference
The following behaviours should be treated as immediate warning signs, regardless of how official the communication appears:
- Any request to transfer crypto assets to a new wallet or address for compliance, safekeeping, or migration purposes.
- Urgency or time pressure: threats that your account will be closed or assets frozen unless you act immediately.
- Contact from someone claiming to represent a regulator and requesting asset transfers or confidential credentials.
- Unsolicited contact from a firm claiming to be able to recover previously lost or stolen crypto.
- A website URL that closely but not exactly matches a known provider or regulator (look for extra characters, hyphens, or domain variations).
- Contact details in the message that differ from those on the entity's official website.
Reporting a Suspected Scam
If you believe you've been contacted by a fraudulent actor impersonating a regulator or CASP, the MFSA asks that you report the incident via its official website. Doing so not only protects you: it helps the authority build an accurate picture of active schemes and issue timely public warnings that protect other holders across the EU.
If you've already transferred assets, contact your national police authority and your bank or payment provider as quickly as possible. Speed matters significantly when attempting to trace or recover funds.
Frequently Asked Questions
Will my crypto exchange ever ask me to send assets to a new wallet during a MiCA migration?
Legitimate migrations handled by licensed CASPs do not require you to send assets to an external wallet or address. If you're being asked to do that, it is a scam. A genuine provider will move your assets on its own infrastructure and notify you through your existing account interface, not through an unsolicited email asking for a transfer.
Can a regulator like the MFSA freeze or seize my crypto directly?
Regulators do not contact individual holders and ask them to transfer assets. Enforcement actions, where they occur, go through legal processes directed at service providers. Any message claiming to be from a national authority and demanding a direct asset transfer is fraudulent.
If I lose crypto to a scam, can I claim a tax deduction?
This depends on your country of residence and the specific circumstances of the loss. In some EU member states, losses from fraud may be claimable, but the classification of the loss and the evidence required varies. You should document everything immediately and seek advice from a qualified tax adviser who is familiar with crypto-asset treatment in your jurisdiction.
How do I verify whether a crypto firm is actually licensed under MiCA?
Visit the official website of your national competent authority (for Malta, that is mfsa.mt) and search the public register of authorised entities. The European Securities and Markets Authority (ESMA) also maintains a register of authorised CASPs at the EU level. Always navigate to these sites directly rather than using links provided in any unsolicited communication.
Does keeping a crypto tax report help if I become a scam victim?
Yes, in a practical sense. A current crypto tax report showing your full transaction history, wallet addresses, and cost basis creates contemporaneous evidence of your holdings before any incident. That documentation supports law enforcement reports, potential insurance claims, and any tax treatment of the loss. Using a crypto capital gains calculator regularly throughout the year means your records are already in order if you ever need them urgently.
