Skip to main content
Sign in

Audit log

Every state-changing event for MiCA Transition Impersonation Fraud Cluster (2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-28 12:20:22Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    EdovQUhm3hAs…jCU1BBB9sha256 → base58
    verifying row…
    canonical bytes (19254 B) ▸
    {"actor":"system:backfill","investigation_id":"24ab7b2a-bd46-4721-a4c9-4abeeb5966d5","kind":"publish","page_slug":"mica-transition-impersonation-fraud-cluster-2026","published_at":"2026-08-28T12:20:22.903Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"MiCA Transition Impersonation Fraud Cluster (2026)","sections":[{"content":"The Markets in Crypto-Assets Regulation (MiCA) is the EU's comprehensive crypto licensing framework. Its transitional grandfathering period — which allowed firms operating under pre-existing national rules to continue serving EU customers while awaiting authorization — expired on July 1, 2026. At the deadline, data provider VASPnet estimated that more than 1,700 crypto-asset service providers would need to cease EU operations. TRM Labs put the number of EEA firms operating without MiCA authorization at approximately 1,062 as of July 1, with 281 firms holding authorization at that point. By the end of July 2026, ESMA's official CASP register listed 323 authorized firms. Major licensed operators include Coinbase, Kraken, and OKX. Binance, the largest exchange by volume, did not hold a MiCA license at the deadline; it had withdrawn its application in Greece in June 2026. The dislocation affected an estimated 10 million retail users who simultaneously received legitimate migration notices from departing platforms, creating the conditions that fraud actors exploited.","heading":"Background: MiCA Deadline and the Displacement Window","severity":"medium","sources":[{"credibility":2,"name":"Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://decrypt.co/375034/scammers-pose-as-eu-regulators-to-prey-on-mica-deadline-fallout"},{"credibility":2,"name":"crypto.news: MiCA scam warnings rise as 1,000+ firms lose EU access","type":"news_article","url":"https://crypto.news/mica-scam-warnings-rise-as-firms-lose-eu-access/"},{"credibility":1,"name":"ESMA Public Statement: MiCA Transitional Period Ends (June 2026)","type":"regulatory","url":"https://www.esma.europa.eu/sites/default/files/2026-06/ESMA75-113276571-1710_Public_Statement_MiCA_transitional_period_ends.pdf"},{"credibility":2,"name":"AML Intelligence: Binance, MEXC and HTX remain accessible to EU users despite missing MiCA licences","type":"news_article","url":"https://www.amlintelligence.com/2026/07/binance-mexc-and-htx-accessible-eu-users-mica-licences/"}]},{"content":"Regulatory warnings describe a cluster of related tactics, not a single organized group. No named operators or criminal organizations had been publicly identified as of August 2026. The reported methods include: (1) Regulator impersonation — fraudsters falsely present themselves as staff of ESMA, France's AMF, the Dutch AFM, Belgium's FSMA, or Spain's securities regulator, using forged official letterhead and copied regulatory logos; (2) Licensed-exchange impersonation — fraudsters pose as employees of MiCA-authorized exchanges and contact customers of unlicensed departing platforms, directing them to criminal-controlled websites; (3) Fake migration notices — scammers copy the language and visual format of legitimate wind-down notifications to lend authenticity to phishing communications; (4) Screen-sharing attacks — according to MFSA and multiple national watchdogs, some actors deploy screen-sharing software to demonstrate fake account creation steps or show fabricated regulatory interfaces; (5) Recovery fraud — a secondary scheme in which prior victims are re-targeted by actors posing as recovery services or regulators offering to retrieve lost funds, on payment of an upfront administrative fee. Contact vectors include unsolicited email, telephone calls, messaging apps, and social media platforms. ESMA confirmed that criminals have misused its name, logo, and branding in fabricated documents.","heading":"Fraud Cluster: Tactics and Methods","severity":"critical","sources":[{"credibility":1,"name":"MFSA Notice: Crypto-Related Impersonation Scams During MiCA Transition","type":"regulatory","url":"https://www.mfsa.mt/news-item/mfsa-notice-crypto-related-impersonation-scams-during-mica-transition/"},{"credibility":2,"name":"CoinDesk: MiCA's Cleanup Is Creating a New Scam Wave Across the European Union","type":"news_article","url":"https://www.coindesk.com/business/2026/08/14/mica-s-cleanup-is-creating-a-new-scam-wave-across-the-european-union"},{"credibility":2,"name":"CryptoTimes: Scammers Pose as Regulators to Exploit EU's MiCA Wind-Down","type":"news_article","url":"https://www.cryptotimes.io/2026/08/06/scammers-pose-as-regulators-to-exploit-eus-mica-wind-down-watchdogs-warn/"},{"credibility":2,"name":"coin-turk: ESMA warns of MiCA scam surge","type":"news_article","url":"https://en.coin-turk.com/esma-warns-of-mica-scam-surge-as-fraudsters-impersonate-eu-crypto-regulators/"}]},{"content":"Multiple national competent authorities and ESMA itself issued public warnings beginning in early August 2026. ESMA stated it was aware of 'fraudulent practices involving the misuse of ESMA's logo and identity' and clarified that it does not contact investors to reclaim funds or request administrative fees. France's AMF documented cases in which criminals posed as AMF employees and instructed customers to transfer assets to fraudulent websites. AMF executive director Stéphane Pontoizeau stated publicly: 'This moment is an opportunity for scammers more than usual.' The AMF also indicated it would refer cases to law enforcement where criminals impersonate it or licensed companies. The Dutch AFM and Belgium's FSMA each issued parallel consumer warnings. Austria's FMA advised users to independently verify providers through the ESMA CASP register before transferring assets. The Malta Financial Services Authority (MFSA) published a formal notice describing the cluster of scams and the specific tactics in use. All authorities reiterated that no legitimate regulator will cold-contact consumers with instructions to send funds to a particular account.","heading":"Regulatory Warnings and Official Statements","severity":"high","sources":[{"credibility":1,"name":"MFSA Notice: Crypto-Related Impersonation Scams During MiCA Transition","type":"regulatory","url":"https://www.mfsa.mt/news-item/mfsa-notice-crypto-related-impersonation-scams-during-mica-transition/"},{"credibility":2,"name":"crypto.news: EU warns of crypto scams exploiting MiCA licensing transition","type":"news_article","url":"https://crypto.news/eu-warns-of-crypto-scams-exploiting-mica-licensing-transition/"},{"credibility":2,"name":"Yahoo Finance / Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/scammers-pose-eu-regulators-prey-124619269.html"},{"credibility":2,"name":"CoinMarketCap Academy: MiCA Deadline Triggers Fraud Wave","type":"news_article","url":"https://coinmarketcap.com/academy/article/mica-deadline-scams-eu-regulators-crypto"}]},{"content":"No enforcement body had published figures specific to MiCA-related impersonation losses as of August 2026. The following context figures are drawn from broader fraud tracking. Chainalysis estimated that global crypto scam and fraud losses reached $17 billion in 2025, up from approximately $6 billion five years earlier, and identified impersonation fraud as one of the fastest-growing categories. The UK's Financial Conduct Authority (FCA), a comparable market to the EU in scam typology, reported 4,465 reports of FCA impersonation in the first half of 2025 alone, with 480 confirmed victims losing money. Impersonation fraud losses in crypto grew approximately 1,400% year-over-year in 2025 per industry tracking, with average payments per incident rising from $782 to $2,764. The structural opportunity for the 2026 MiCA cluster is large: approximately 10 million EU retail users simultaneously received legitimate instructions to migrate assets, making fraudulent versions of those instructions difficult to distinguish at point of receipt. The absence of EU-specific loss totals for this cluster reflects the early stage of regulatory data collection, not the absence of harm.","heading":"Scale and Loss Estimates","severity":"high","sources":[{"credibility":2,"name":"Yahoo Finance / Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/scammers-pose-eu-regulators-prey-124619269.html"},{"credibility":2,"name":"crypto.news: EU warns of crypto scams exploiting MiCA licensing transition","type":"news_article","url":"https://crypto.news/eu-warns-of-crypto-scams-exploiting-mica-licensing-transition/"},{"credibility":2,"name":"CryptoTimes: Scammers Pose as Regulators to Exploit EU's MiCA Wind-Down","type":"news_article","url":"https://www.cryptotimes.io/2026/08/06/scammers-pose-as-regulators-to-exploit-eus-mica-wind-down-watchdogs-warn/"}]},{"content":"As of August 2026, no individual actors, criminal organizations, or specific fraud sites associated with this cluster had been publicly named by law enforcement or regulators. The AMF stated it would refer impersonation cases to law enforcement, but no publicly disclosed arrests or prosecutions had resulted from MiCA-specific impersonation fraud at the time of this investigation. The cluster is characterized by regulators as opportunistic and distributed rather than as a single coordinated operation. Tom Keatinge of the UK's Royal United Services Institute noted publicly that fraudsters routinely exploit moments of regulatory uncertainty and provider transitions. All claims about perpetrator identity in this section would require Tier 1 sourcing before being added to this page.","heading":"Known Actors and Attribution","severity":"medium","sources":[{"credibility":2,"name":"CryptoTimes: Scammers Pose as Regulators to Exploit EU's MiCA Wind-Down","type":"news_article","url":"https://www.cryptotimes.io/2026/08/06/scammers-pose-as-regulators-to-exploit-eus-mica-wind-down-watchdogs-warn/"},{"credibility":2,"name":"Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://decrypt.co/375034/scammers-pose-as-eu-regulators-to-prey-on-mica-deadline-fallout"}]},{"content":"All issuing authorities converge on the same protective measures. The ESMA CASP register, updated weekly and available at the official ESMA website, is the authoritative record of firms authorized to serve EU customers under MiCA. Regulators advise users to independently verify a provider against that register before transferring any assets. ESMA and all national competent authorities state they do not cold-contact consumers with instructions to send funds, do not request upfront administrative fees, and do not use screen-sharing software to guide users through account transfers. Users receiving unsolicited communications — by email, phone, messaging app, or social media — purporting to be from ESMA, the AMF, the AFM, the FSMA, or any other regulator, should treat those communications as suspected fraud and report them to their national competent authority. Links in unsolicited messages should not be clicked; users should navigate directly to the official ESMA CASP register URL.","heading":"Consumer Protection Guidance","severity":"low","sources":[{"credibility":1,"name":"MFSA Notice: Crypto-Related Impersonation Scams During MiCA Transition","type":"regulatory","url":"https://www.mfsa.mt/news-item/mfsa-notice-crypto-related-impersonation-scams-during-mica-transition/"},{"credibility":1,"name":"ESMA CASP Authorized List","type":"regulatory","url":"https://www.esma.europa.eu"},{"credibility":2,"name":"spaziocrypto: MiCA Crypto Scams in Europe — How to Spot Fake Exchanges","type":"news_article","url":"https://en.spaziocrypto.com/security/mica-crypto-scams-europe-fake-exchanges-how-to-protect-yourself/"}]}],"sources_used":[{"credibility":1,"name":"MFSA Notice: Crypto-Related Impersonation Scams During MiCA Transition","type":"regulatory","url":"https://www.mfsa.mt/news-item/mfsa-notice-crypto-related-impersonation-scams-during-mica-transition/"},{"credibility":1,"name":"ESMA Public Statement: MiCA Transitional Period Ends (June 2026)","type":"regulatory","url":"https://www.esma.europa.eu/sites/default/files/2026-06/ESMA75-113276571-1710_Public_Statement_MiCA_transitional_period_ends.pdf"},{"credibility":2,"name":"Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://decrypt.co/375034/scammers-pose-as-eu-regulators-to-prey-on-mica-deadline-fallout"},{"credibility":2,"name":"CoinDesk: MiCA's Cleanup Is Creating a New Scam Wave Across the European Union","type":"news_article","url":"https://www.coindesk.com/business/2026/08/14/mica-s-cleanup-is-creating-a-new-scam-wave-across-the-european-union"},{"credibility":2,"name":"crypto.news: MiCA scam warnings rise as 1,000+ firms lose EU access","type":"news_article","url":"https://crypto.news/mica-scam-warnings-rise-as-firms-lose-eu-access/"},{"credibility":2,"name":"crypto.news: EU warns of crypto scams exploiting MiCA licensing transition","type":"news_article","url":"https://crypto.news/eu-warns-of-crypto-scams-exploiting-mica-licensing-transition/"},{"credibility":2,"name":"CoinMarketCap Academy: MiCA Deadline Triggers Fraud Wave as Scammers Pose as EU Watchdogs","type":"news_article","url":"https://coinmarketcap.com/academy/article/mica-deadline-scams-eu-regulators-crypto"},{"credibility":2,"name":"CryptoTimes: Scammers Pose as Regulators to Exploit EU's MiCA Wind-Down","type":"news_article","url":"https://www.cryptotimes.io/2026/08/06/scammers-pose-as-regulators-to-exploit-eus-mica-wind-down-watchdogs-warn/"},{"credibility":2,"name":"coin-turk: ESMA warns of MiCA scam surge as fraudsters impersonate EU crypto regulators","type":"news_article","url":"https://en.coin-turk.com/esma-warns-of-mica-scam-surge-as-fraudsters-impersonate-eu-crypto-regulators/"},{"credibility":2,"name":"Yahoo Finance: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/scammers-pose-eu-regulators-prey-124619269.html"},{"credibility":2,"name":"AML Intelligence: Binance, MEXC and HTX remain accessible to EU users despite missing MiCA licences","type":"news_article","url":"https://www.amlintelligence.com/2026/07/binance-mexc-and-htx-accessible-eu-users-mica-licences/"},{"credibility":2,"name":"spaziocrypto: MiCA Crypto Scams in Europe — How to Spot Fake Exchanges","type":"news_article","url":"https://en.spaziocrypto.com/security/mica-crypto-scams-europe-fake-exchanges-how-to-protect-yourself/"},{"credibility":2,"name":"Tangem Learning Hub: How to Check If Your Exchange Is MiCA Licensed","type":"other","url":"https://tangem.com/en/learning-hub/post/check-exchange-mica-license/"},{"credibility":2,"name":"Wikipedia: Markets in Crypto-Assets","type":"other","url":"https://en.wikipedia.org/wiki/Markets_in_Crypto-Assets"}],"summary":"Following the July 1, 2026 expiry of the EU MiCA transitional licensing period, a cluster of fraud schemes emerged in which unidentified actors impersonated licensed crypto-asset service providers (CASPs), EU financial regulators — including ESMA, France's AMF, the Dutch AFM, and Belgium's FSMA — and the employees of those bodies. Fraudsters exploited the mass displacement of an estimated 10 million retail users from roughly 1,700 unlicensed platforms to redirect victims toward fake websites and criminal-controlled accounts. Multiple national regulators and ESMA issued public warnings beginning in early August 2026; no named arrests or completed prosecutions had been publicly reported as of the date of this investigation.","timeline":[{"date":"2024-12-01","event":"MiCA core regulations entered into force across the EU, with a transitional grandfathering period allowing pre-existing national-licensed firms to continue operating while applying for authorization.","source":"Wikipedia: Markets in Crypto-Assets","source_url":"https://en.wikipedia.org/wiki/Markets_in_Crypto-Assets"},{"date":"2026-06-01","event":"Binance withdrew its CASP application in Greece. Only approximately 194 firms had secured MiCA authorization by this point, well below the number needed to absorb displaced users.","source":"CoinMarketCap Academy: MiCA Deadline Triggers Fraud Wave","source_url":"https://coinmarketcap.com/academy/article/mica-deadline-scams-eu-regulators-crypto"},{"date":"2026-06-23","event":"ESMA published a public statement on the end of the MiCA transitional period, calling on unauthorized crypto-asset firms to wind down EU operations ahead of the July 1 deadline.","source":"ESMA Public Statement: MiCA Transitional Period Ends","source_url":"https://www.esma.europa.eu/sites/default/files/2026-06/ESMA75-113276571-1710_Public_Statement_MiCA_transitional_period_ends.pdf"},{"date":"2026-07-01","event":"MiCA grandfathering period expired. More than 1,700 unlicensed crypto platforms were required to cease serving EU customers. Approximately 10 million retail users began receiving legitimate migration notices from departing platforms, creating the displacement window exploited by fraudsters.","source":"crypto.news: MiCA scam warnings rise as 1,000+ firms lose EU access","source_url":"https://crypto.news/mica-scam-warnings-rise-as-firms-lose-eu-access/"},{"date":"2026-07-17","event":"ESMA's official CASP register listed 297 authorization records covering 293 firms across 26 EEA member states. The register would grow to 323 firms by end of July.","source":"Tangem Learning Hub: How to Check If Your Exchange Is MiCA Licensed","source_url":"https://tangem.com/en/learning-hub/post/check-exchange-mica-license/"},{"date":"2026-08-06","event":"Multiple national competent authorities — including France's AMF, the Dutch AFM, Belgium's FSMA, and ESMA — simultaneously issued public warnings about the impersonation fraud cluster. AMF executive director Stéphane Pontoizeau stated: 'This moment is an opportunity for scammers more than usual.'","source":"Decrypt: Scammers Pose as EU Regulators to Prey on MiCA Deadline Fallout","source_url":"https://decrypt.co/375034/scammers-pose-as-eu-regulators-to-prey-on-mica-deadline-fallout"},{"date":"2026-08-07","event":"TRM Labs released analysis confirming 1,062 EEA firms were operating without MiCA authorization as of July 1, providing the first third-party quantification of the displacement scale.","source":"crypto.news: MiCA scam warnings rise as 1,000+ firms lose EU access","source_url":"https://crypto.news/mica-scam-warnings-rise-as-firms-lose-eu-access/"},{"date":"2026-08-14","event":"CoinDesk published a detailed investigation into how MiCA's market cleanup was generating a scam wave, citing multiple national watchdogs and characterizing the fraud as distributed and opportunistic rather than a single coordinated operation.","source":"CoinDesk: MiCA's Cleanup Is Creating a New Scam Wave Across the European Union","source_url":"https://www.coindesk.com/business/2026/08/14/mica-s-cleanup-is-creating-a-new-scam-wave-across-the-european-union"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision e22c89f1-2cd0-4358-b732-5767c26f8f4c
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.