The EU MiCA Update landscape has shifted sharply since July 1, when the bloc's Markets in Crypto-Assets rules took full effect. Over 1,700 unlicensed platforms were pushed toward an exit, only 323 firms held valid authorization, and regulators say criminals are now using the migration itself as a scam vector, impersonating officials to steal user funds during the transition.
MiCA Migration: Key Numbers at a Glance
Figure/Status | |
MiCA full transitional deadline | July 1, 2026 |
MiCA-authorized firms in late-July snapshot | 323 |
Firms estimated by VASPnet to face EU exit | 1,700+ |
Unauthorized EEA firms identified by TRM | 1,062 |
Estimated users potentially needing migration | Up to 10 million |
Main verification source | ESMA MiCA Register |
Important: Clearly label the 1,700+ and 10 million figures as estimates, rather than presenting them as official ESMA figures. This makes the article more accurate.
This update reached a turning point on July 1, 2026, when the final transitional window under MiCA's Article 143 expired. Crypto-asset service providers that had continued operating under national licensing regimes were required to either secure MiCA authorization or wind down EU-facing services.
Data cited by CoinDesk put the number of newly authorized firms at just 323, while more than 1,700 other platforms faced restrictions or an exit from the bloc — one of the most consequential shifts since the framework became fully applicable in December 2024.

Media estimates suggest as many as 10 million users may need to relocate holdings from unauthorized platforms to licensed providers or self-hosted wallets.
Customers of firms without MiCA authorization no longer benefit from the regulation's consumer protections, giving them a genuine reason to act quickly. That urgency, paired with real account-closure and withdrawal notices from exiting platforms, has created fertile ground for fraud.
Regulators say fraudsters are copying legitimate migration communications almost exactly, sending fake notices that appear to come from regulators or licensed exchanges and directing recipients to fraudulent platforms or wallets.
Because millions of users already expect these kinds of messages, distinguishing real notices from fake ones has become unusually difficult — a pattern regulators are flagging as central to this EU MiCA Update.
France's Autorité des Marchés Financiers said criminals are posing as its staff to request upfront fees for supposedly recovering stolen funds. The European Securities and Markets Authority confirmed its name, logo and branding are being misused in forged documents and fake websites. The Netherlands' Authority for the Financial Markets said the migration process has itself become an attack surface, while Austria's Financial Market Authority urged customers of delisted firms to double-check any provider before moving assets.

The core problem is resemblance. Genuine providers are legitimately messaging customers about closures, transfers and new EU entities right now, so a convincing fake blends in easily. Scammers add pressure by framing transfers as urgent compliance steps, a classic social-engineering tactic this cycle has made newly effective.
ESMA points users to its official MiCA register as the authoritative check before transferring any assets. Verification should go beyond the brand name: authorization covers a specific legal entity, not every subsidiary under a global exchange's umbrella. Regulators also stress they never contact users personally to request fund transfers or fees, so unsolicited outreach warrants independent verification.
Figures vary by source. The widely cited "1,700 platforms" estimate comes from data provider VASPnet, while ESMA's late-July register listed 323 authorized firms. A separate analysis from TRM Labs identified 1,343 operating EEA crypto providers as of July 1, of which 281 were authorized and 1,062 were not. The gap reflects methodology — TRM counted firms actively providing services, while other estimates draw on broader historical registers.
EBA PDF
ESMA has told national regulators to scrutinize migration arrangements and act against unauthorized providers that continue operating past the deadline. Unauthorized firms are expected to complete an orderly wind-down, limiting activity to asset transfers and position closures rather than new business. This situation is likely to remain fluid as supervision intensifies and scam reports continue.
This EU MiCA regulation update marks a genuine regulatory milestone, but the migration it triggered has opened a fraud window regulators are actively trying to close. Verifying platforms against ESMA's register, checking the exact legal entity involved, and treating unsolicited transfer requests with skepticism remain the clearest ways users can protect themselves.
Disclaimer: This article is for informational purposes only and does not constitute financial, legal, or investment advice. Cryptocurrency markets and regulations carry inherent risks; readers should conduct their own research and consult a qualified professional before making financial decisions.