MASTR 研究
The MiCA migration scam
A real regulatory transition gave impersonators a convincing reason to ask people to move their assets.
研究文章和参考条目以英语发布。导航提供七种语言。
人物与项目
本文目录
A credible story with a false destination
MASTR's article examined a specific social-engineering problem: people receiving genuine messages about crypto-provider authorisation were also receiving counterfeit migration instructions. The regulatory background was real. The destination account supplied by the impersonator was not.
The MFSA's 7 August 2026 warning describes criminals copying providers and regulators, contacting users across messaging channels and urging transfers to supposedly safe or regulated accounts. The practical failure is identity verification. A user may correctly understand that their provider is changing its services while still sending assets to the wrong party.
A licence belongs to an entity
A familiar global brand can operate through several legal companies. An authorisation for one entity does not authenticate every email, domain, account or product carrying the brand. A copied licence number can be accurate and still appear on a fraudulent website.
Check the legal entity and domain using the regulator's register, then contact the provider through a route you already trust. Do not use the support link inside the disputed message as its own verification. ESMA separately warns that its identity and logo are misused in fraud.
Read counts with their definitions
The original article's review of the ESMA dataset dated 5 August reported 329 CASP records representing 324 distinct legal names. It separately counted 167 records and 162 distinct entity names in the non-compliant-provider dataset. These are the author's historical dataset counts. They have not been presented here as today's register totals.
Several errors are easy to make: treating records as unique companies, counting firms that left a market as convicted scammers, or reading the country of a reporting authority as the location of every victim. The original article also noted that different national enforcement practices affect what appears in a shared register.
Where the investigation stops
The article did not identify a regulator-confirmed Telegram handle or a conclusive wallet cluster for the entire impersonation wave. Attaching an unrelated scam wallet would make the case less accurate. A future transaction-level case would need the actual receiving address, payment record and evidence connecting the communication to that destination.
If a message asks you to migrate funds, verify the instruction inside your existing provider account before acting. A regulatory logo and an urgent deadline are not enough. Continue with fake support and checking an authorisation.
来源
- MASTR: The MiCA Scam Gold Rush, 8 August 2026
- MFSA: MiCA-transition impersonation warning, 7 August 2026
- ESMA: MiCA register and regulatory resources
- ESMA: misuse of its name, logo and identity
资料核对日期:2026年9月5日. Historical cases retain the date and legal status of the cited record.