The most defensible conclusion is that MiCA sharply reduced the number of providers able to serve the European market under legacy arrangements. It did not establish that every unlicensed firm had already ceased all activity or that every affected user had completed a transfer.
The transition produced a credible reason for customers to receive urgent messages about their accounts. Fraudsters could imitate a real exchange, ESMA, a national regulator or a migration partner and tell users to “verify” an account, move funds, unlock a wallet or withdraw before a deadline.
European regulators reported an increase in impersonation scams after July 1. The reported tactics included fake regulator notices, counterfeit authorisation documents, cloned websites and messages directing users toward fraudulent platforms.
The danger is especially high because a legitimate provider may genuinely ask customers to withdraw or migrate assets. A real regulatory change does not make an unsolicited link trustworthy. Treat every message as unverified until it has been checked through a known official channel.
Reported examples of major exchanges with MiCA authorisations include Coinbase, Kraken, OKX, Crypto.com, Bitstamp and Bitpanda. Their permissions were obtained through particular EU member states, with the MiCA framework allowing authorised providers to offer permitted services across the single market through passporting.
These names should not be treated as a permanent substitute for checking the register. Authorisation belongs to a specific legal entity and may cover only particular services. ESMA’s investor guidance says users should confirm both the provider’s status and the scope of its permissions.
Binance did not have an equivalent MiCA authorisation at the July 1 deadline. Its European operations therefore could not rely on an EU-wide MiCA passport, and reporting said it would stop offering relevant new services while handling the orderly closure of user positions.
The available material does not provide reliable evidence for naming specific banks that “secured MiCA permissions.” That question also requires care: some financial entities may provide crypto-asset services through MiCA’s notification route rather than holding the same standalone CASP authorisation as an exchange.
Before the transition ended, eligible firms operating under national arrangements could continue temporarily while seeking MiCA authorisation. Those national systems were fragmented; MiCA introduced a common EU framework for authorisation and supervision of crypto-asset service providers.
The framework includes requirements covering:
Authorisation improves regulatory oversight, but it is not a guarantee against losses, volatility, hacks, operational failure or fraud.
Find the exact legal entity. Do not rely only on a brand name, app listing or search advertisement. Check the provider in ESMA’s register and confirm that its permissions cover the service you intend to use and your country. Check the relevant national regulator’s warning list as well.
Start from a known channel. Open the exchange’s established website or verified app yourself. Do not use links, QR codes, phone numbers or attachments in unsolicited emails, text messages, social posts or direct messages.
Reject requests for secrets. No legitimate regulator or exchange should need your seed phrase, private key, password or one-time authentication code to migrate an account.
Confirm transfer instructions independently. Check the destination address and network through a trusted channel. If appropriate, send a small test transaction first and preserve the relevant records.
Review what the new provider actually supports. Confirm that your assets, trading pairs, custody arrangements and withdrawal options remain available before moving a balance.
Limit exchange exposure. Keep only the balance needed for trading on a centralised platform. For long-term self-custody, protect recovery material offline and maintain a tested backup plan.
The key lesson from the MiCA deadline is not simply that many firms lost the ability to serve EU customers. It is that a genuine compliance transition can create highly convincing phishing conditions. Verify the legal entity and the communication independently before moving any asset.