The short answer
Fraudsters are exploiting the implementation of the EU's Markets in Crypto-Assets (MiCA) regulation to trick users into transferring crypto to criminal-controlled wallets. These scammers pose as regulators or providers claiming your current account is unlicensed. Always verify migration requests directly through official provider channels. Never share private keys or transfer assets based on urgent, unsolicited requests from social media or email.
The implementation of the Markets in Crypto-Assets (MiCA) regulation has created a landscape of regulatory transition across the European Union. Unfortunately, bad actors are weaponizing this uncertainty to target crypto-asset holders in Malta and beyond.
By impersonating financial authorities or service providers, scammers are creating a false sense of urgency, pressuring victims to 'migrate' their assets to 'safe' or 'compliant' accounts. Understanding these tactics is vital for protecting your digital wealth during this transitional period.
01How MiCA Impersonation Works
Scammers leverage the public's awareness of MiCA to suggest that specific crypto-asset service providers are no longer authorized to operate. They may claim that a mandatory migration is required to maintain compliance with EU standards.
These messages often arrive via email, messaging apps, or social media, using copied branding and forged documents that appear highly legitimate to the untrained eye.
- Impersonation of national regulators or EU supervisory authorities.
- Falsely claiming a provider is losing its license.
- Use of forged documents and professional-looking emails.
- Creating high-pressure urgency to force impulsive decisions.
Source for this section[1] MFSA: MiCA-transition impersonation scams
02Verifying Official Communications
Legitimate regulatory updates regarding MiCA will be communicated through official channels, not via private messaging apps. If you receive a notice about your wallet, you should independently verify the information.
Check the provider’s official website or log into your account directly through their authorized application. Do not use links contained in the suspicious message.
- Treat unsolicited requests to move funds with extreme suspicion.
- Verify all instructions via the provider's official customer support channels.
- Check the MFSA Financial Services Register if you doubt an entity's legitimacy.
- Ignore pressure tactics designed to force a rapid transfer.
Source for this section[1] MFSA: MiCA-transition impersonation scams
03Risks of Unauthorized Transfers
The primary goal of these scams is to obtain control over your crypto-assets. Once you transfer your funds to an account controlled by a criminal, they are effectively impossible to recover.
It is vital to distinguish between a service provider update and an impersonation scam. If there is any uncertainty, simply refrain from acting.
- Transfers to criminal-controlled accounts result in permanent loss.
- No legitimate regulator will ask you to send crypto to a 'safe' account.
- Regulatory transition does not typically require users to manually migrate funds to unknown wallets.
Source for this section[1] MFSA: MiCA-transition impersonation scams
04Practical Security Checklist
Follow these steps when you receive a message regarding your account status or regulatory compliance.
Example: You receive an email stating, 'Due to MiCA, you must transfer your assets to this new wallet address by 5 PM to avoid account suspension'.
- Am I currently logged into my provider’s actual website?.
- Did the provider ever notify me through their internal dashboard?.
- Is the request asking me to transfer assets to a private or unknown wallet?.
- Have I ignored the sense of urgency created by the email?.
- Have I contacted the provider's support team using contact details from their verified website?.
- Am I avoiding clicking any links within the suspicious email?.
Source for this section[1] MFSA: MiCA-transition impersonation scams
05Staying Vigilant
While MiCA introduces a consistent supervisory regime across the EU, it does not change the core principle of self-custody security. Never share private keys, seed phrases, or one-time codes with anyone, even those claiming to be 'regulatory auditors'.
Remain updated on official MFSA and ESMA warnings regarding impersonation scams to protect yourself throughout the implementation phase.
- Never disclose confidential information like seed phrases.
- Monitor MFSA news releases for official warnings on scams.
- Check the ESMA website for broader EU-wide crypto-asset guidance.
- Use only official, verified apps to manage your digital assets.
Sources for this section[1] MFSA: MiCA-transition impersonation scams[2] European Supervisory Authorities: crypto risks and protections
Checklist
- Ignore all unsolicited requests to move crypto-assets.
- Check provider status on the official MFSA register.
- Contact your crypto exchange via their official, verified channels.
- Never use links provided in email or social media messages.
- Do not share account information or seed phrases with anyone.
- Report suspicious 'MiCA-related' emails to the MFSA.
- Review your account directly through an authorized app.
- Stay informed via official EU regulatory news sources.
Questions people ask
Is there a mandatory MiCA migration process that requires me to move funds?
No. While firms may restructure under MiCA, they will not demand you send crypto to a new, unsolicited address via email or private message.
How do I know if an email is from the MFSA?
The MFSA does not contact individuals via private, unsolicited emails to request crypto transfers. Official communications come through established, verifiable channels.
What should I do if I already sent funds to a 'migration' address?
Contact your bank and the Malta Police Force immediately to report the fraud. Unfortunately, on-chain transfers are generally irreversible.
Safety boundaries
- No legitimate helper needs your seed phrase, private key, password, one-time code, remote access to your device or a wallet connection.
- Nobody can promise that funds will be recovered. Treat any guarantee, or any fee demanded to release funds, with suspicion.
- Find official contact details yourself, through the regulator, bank or platform website, not through a message or advert you received.
- This guide is general education. It is not legal, financial or tax advice and does not assess your situation.
If you want to organise your facts, the initial claim outline on our homepage collects only a short summary and contact details. It creates no client relationship and promises no outcome. Do not send documents or credentials.
Official sources
- [1]MFSA: MiCA-transition impersonation scams
Checked 4 October 2026 - [2]European Supervisory Authorities: crypto risks and protections
Checked 4 October 2026
AI-assisted educational content published by Central Crypto Claim using the official sources listed below. No independent expert review is claimed. This is not legal, financial or tax advice.
