On December 30, 2024, the European Union's Markets in Crypto-Assets regulation (MiCA) came into full effect. After years of negotiation, drafts, and partial implementation, the EU now has the world's first comprehensive regulatory framework for cryptocurrency. MiCA affects every crypto business operating in the EU — exchanges, custodians, stablecoin issuers, and advisory services — and it has significant implications for anyone trying to recover stolen or frozen cryptocurrency. As a Swiss-based crypto compliance practice that serves clients across Europe, we have been closely tracking MiCA's implementation and its practical effects on recovery cases.
In this article, I explain what MiCA is, what it requires of crypto businesses, how it changes the landscape for crypto fraud recovery, and what it means for users who have lost cryptocurrency to scams, freezes, or exchange insolvencies. Whether you are a crypto user, an exchange operator, or a fraud victim, understanding MiCA is now essential.
What is MiCA?
The Markets in Crypto-Assets regulation (Regulation (EU) 2023/1114) is a comprehensive EU regulation that governs the issuance, trading, and custody of cryptocurrencies in the European Union. MiCA was proposed by the European Commission in September 2020, agreed upon by the EU institutions in June 2022, formally adopted in May 2023, and came into effect in stages: the stablecoin provisions took effect in June 2024, and the full regulation (including provisions for Crypto-Asset Service Providers, or CASPs) took effect in December 2024.
MiCA applies to:
- Crypto-Asset Service Providers (CASPs): This includes cryptocurrency exchanges, custodial wallet providers, trading platforms, and advisory services. Any entity that provides crypto-related services to EU customers must be authorized as a CASP under MiCA.
- Stablecoin issuers: Issuers of asset-referenced tokens (ARTs) and e-money tokens (EMTs) — which include major stablecoins like USDT, USDC, and others — must comply with MiCA's stablecoin provisions.
- Crypto-asset issuers: Entities that issue cryptocurrencies (other than stablecoins) must comply with MiCA's disclosure and transparency requirements.
Importantly, MiCA does not apply to decentralized finance (DeFi) protocols that operate without a central operator, nor to self-custody wallets. This means that users who hold their own private keys are not directly affected by MiCA — though the exchanges and services they interact with are.
Key MiCA provisions relevant to crypto recovery
1. Authorization and passporting
Under MiCA, any entity that provides crypto-asset services to EU customers must be authorized as a CASP by its home member state's national competent authority (NCA). Once authorized in one EU member state, the CASP can "passport" its authorization to other member states — providing services across the EU without needing separate authorization in each country.
This is a significant change. Before MiCA, crypto exchanges operated in the EU under a patchwork of national regulations. Some countries (Germany, France, Italy) had licensing regimes; others (Cyprus, Malta) had lighter-touch regimes. Exchanges could choose the most permissive jurisdiction and operate across the EU. Under MiCA, all CASPs must meet the same standards regardless of where they are authorized.
For fraud recovery, this matters because it means that every CASP operating in the EU is now a regulated entity with a known home member state and a supervising NCA. If you need to file a complaint or a legal request against an exchange, you know which regulator to approach. The NCA has supervisory authority over the CASP and can compel cooperation.
2. Travel Rule compliance
MiCA incorporates the FATF Travel Rule, requiring CASPs to collect and transmit sender and recipient information for crypto transactions above EUR 1,000. This is stricter than the FATF recommendation (which sets the threshold at USD/EUR 1,000) because MiCA applies the threshold uniformly across all EU member states. See our separate FATF Travel Rule article for how this affects tracing.
For fraud recovery, the Travel Rule means that when stolen funds are sent between EU-regulated exchanges, the sender and recipient information is transmitted with the transaction. This data can be obtained by law enforcement without the need for a Norwich Pharmacal order, significantly speeding up the identification of scammers.
3. Freeze and unfreeze procedures
MiCA requires CASPs to have procedures for freezing and unfreezing crypto assets in compliance with AML/CFT regulations and EU sanctions. Specifically, CASPs must:
- Implement systems to detect and freeze transactions involving sanctioned addresses
- Cooperate with law enforcement requests to freeze assets
- Provide a clear process for users to challenge freezes
- Report freeze actions to their supervising NCA
This is a significant improvement over the pre-MiCA landscape, where freeze procedures were ad hoc and varied by exchange. Under MiCA, every EU-regulated CASP must have a documented freeze/unfreeze process, and users have a clear right to challenge freezes. If a CASP refuses to unfreeze an address despite evidence that the freeze was unjustified, the user can complain to the NCA, which has the authority to order the CASP to act.
4. Stablecoin regulation
MiCA imposes strict requirements on stablecoin issuers. Issuers of significant tokens (defined as those with a market capitalization above a threshold) must:
- Maintain reserves that fully back the issued tokens
- Store reserves in segregated accounts at EU-authorized credit institutions
- Provide daily transparency reports on reserve composition
- Have procedures for freezing and unfreezing tokens
- Obtain authorization from the European Banking Authority (EBA) or a national NCA
For fraud recovery, this means that stablecoin issuers operating in the EU are now regulated entities with clear procedures for freezing tainted addresses. If your USDT or USDC is frozen by an EU-regulated issuer, you have a clear process for appealing the freeze — and if the appeal is denied, you can complain to the EBA or the national NCA. See our stablecoin freeze guide for the specific processes.
5. Custody and segregation of assets
MiCA requires CASPs that hold customer assets to segregate them from the CASP's own assets. Customer cryptocurrency must be held in separate accounts (or separate wallets) and must not be used for the CASP's own operations. This is a direct response to the FTX collapse, where customer deposits were commingled with the exchange's operational funds.
For fraud recovery, this is critical. If an EU-regulated CASP goes bankrupt, customer assets are segregated and cannot be claimed by the CASP's creditors. Customers have a priority claim on their own assets — they are not unsecured creditors. This is a fundamental change from the pre-MiCA landscape, where (as we saw in the FTX and Celsius cases) customer deposits could be treated as the exchange's property.
How MiCA affects different recovery scenarios
Scenario 1: Exchange account freeze
If your exchange account is frozen by an EU-regulated CASP, MiCA gives you rights that did not exist before:
- Right to information: The CASP must inform you of the reason for the freeze and the legal basis.
- Right to challenge: The CASP must provide a process for you to challenge the freeze and submit evidence.
- Right to complain to the NCA: If the CASP refuses to unfreeze your account despite evidence, you can complain to the NCA, which has the authority to order the CASP to act.
- Right to judicial review: You can challenge the NCA's decision in court.
In practice, this means that EU-regulated exchanges are more accountable for their freeze decisions. If your account is frozen unjustly — for example, because you received tainted funds through no fault of your own — you have a clear path to challenge the freeze, first through the CASP's internal process, then through the NCA, and finally through the courts. See our exchange freeze guide for the practical steps.
Scenario 2: Crypto fraud — tracing and recovery
If you have been scammed and the funds are sent to an EU-regulated exchange, MiCA improves your recovery chances in several ways:
- Travel Rule data: If the funds were sent from another EU-regulated exchange, the Travel Rule data (sender's identity) is already on file. Law enforcement can obtain this data quickly.
- Regulated freeze process: EU-regulated exchanges must have a documented freeze process. A properly formatted freeze request (with a police report and blockchain evidence) is more likely to be acted upon quickly.
- NCA involvement: If the exchange is slow to respond, you can involve the NCA, which has supervisory authority and can compel cooperation.
- Cross-border coordination: MiCA's passporting system means that an exchange authorized in one EU country can be compelled by the NCA of another EU country (through ESMA coordination). This simplifies cross-border recovery within the EU.
Scenario 3: Exchange insolvency
If an EU-regulated CASP goes bankrupt, MiCA's segregation requirement ensures that customer assets are not part of the bankruptcy estate. Customers have a priority claim on their own assets — they are not unsecured creditors. This is a fundamental improvement over the pre-MiCA landscape, where customer deposits could be treated as the exchange's property (as in the Celsius case).
In practice, this means that if you hold cryptocurrency on an EU-regulated exchange and the exchange goes bankrupt, you should be able to recover your crypto — it is segregated and cannot be claimed by the exchange's creditors. The process will still take time (the bankruptcy trustee must verify the segregation and distribute the assets), but the legal framework now clearly favors the customer.
What MiCA does not cover
While MiCA is comprehensive, it has important limitations:
- DeFi: MiCA does not apply to truly decentralized protocols that operate without a central operator. If you lose funds in a DeFi exploit, MiCA does not provide a regulatory framework for recovery. See our DeFi exploit article for the legal options in this scenario.
- Self-custody wallets: MiCA does not regulate self-custody wallets. If you hold your own private keys and lose them (through theft, hacking, or forgetting the seed phrase), MiCA does not provide a recovery mechanism.
- Non-EU exchanges: MiCA only applies to CASPs that serve EU customers. If your funds are on an exchange outside the EU (Binance's Seychelles entity, MEXC, or a DEX), MiCA does not apply, and you must rely on the local jurisdiction's laws.
- NFTs: MiCA's treatment of NFTs is limited. Most NFTs are excluded from MiCA's scope, though "crypto-asset" NFTs (those that function like cryptocurrencies) may be covered.
Practical implications for crypto users in the EU
If you are a crypto user in the EU, MiCA changes your relationship with exchanges and stablecoin issuers:
- Use EU-regulated exchanges: If you use an exchange that is authorized under MiCA, you have the protections described above. Check whether your exchange is authorized — the NCA of each member state maintains a public register of authorized CASPs.
- Keep records: MiCA requires CASPs to maintain records of transactions for 5 years. But you should also keep your own records — screenshots of deposits, transaction hashes, and correspondence. If a dispute arises, your records are essential.
- Know your rights: If your account is frozen, you have the right to information, the right to challenge, and the right to complain to the NCA. Exercise these rights. Do not accept a freeze without understanding the reason and challenging it if it is unjustified.
- Consider the jurisdiction: If you are choosing between exchanges, consider which EU member state the exchange is authorized in. Some NCAs (like BaFin in Germany and AMF in France) are more active and responsive than others. The quality of NCA supervision varies.
The MiCA transition period
MiCA includes a transition period (also called the "grandfathering" period) during which crypto businesses that were already operating in the EU under national law can continue to operate while applying for MiCA authorization. The transition period ends in mid-2026. During this period, some exchanges may be operating under national law rather than under MiCA, which can create uncertainty about which regulatory framework applies.
If you are dealing with an exchange during the transition period, ask whether the exchange is operating under MiCA authorization or under a national license. This affects your rights and the regulatory oversight that applies. After the transition period ends, all crypto businesses operating in the EU must be MiCA-authorized — any business that has not obtained authorization must cease operations.
How MiCA interacts with other regulations
MiCA is not the only regulation that affects crypto in the EU. It interacts with several other regulatory frameworks:
- AML Directive (AMLD6): The EU's Anti-Money Laundering Directive applies to CASPs alongside MiCA. CASPs must comply with both MiCA's provisions and AMLD6's KYC and reporting requirements.
- GDPR: The General Data Protection Regulation applies to CASPs' processing of customer data. CASPs must balance their AML/KYC obligations with GDPR's data protection requirements — a tension that is particularly relevant when sharing Travel Rule data across borders.
- Sanctions regulations: EU sanctions (including the EU's autonomous sanctions and UN sanctions) apply to CASPs. CASPs must screen addresses against sanctions lists and freeze sanctioned addresses.
- DORA (Digital Operational Resilience Act): DORA, which comes into effect in 2025, imposes cybersecurity and operational resilience requirements on financial entities, including CASPs. DORA requires CASPs to have incident response plans, conduct regular security testing, and report major incidents to regulators.
Case study: using MiCA to compel an exchange to unfreeze an account
In early 2025, a client's account at an EU-regulated exchange (authorized under MiCA in Germany, supervised by BaFin) was frozen after the client received 15 ETH from an address that had been flagged by the exchange's blockchain analytics provider. The client had sold a watch for ETH — the buyer sent the ETH from a self-custody wallet. The exchange's analytics tool flagged the buyer's wallet because it had previously transacted with an address connected to a known scam. The client had no knowledge of the buyer's wallet history.
Under MiCA, the exchange was required to: (1) inform the client of the reason for the freeze, (2) provide a process for challenging the freeze, and (3) respond to the challenge within a reasonable timeframe. The exchange initially provided only a generic reason ("your account has been flagged for suspicious activity") and did not respond to the client's challenge within 14 days.
We filed a complaint with BaFin, arguing that the exchange was not complying with MiCA's requirement to provide a clear challenge process. BaFin contacted the exchange and requested a detailed explanation of the freeze and the status of the client's challenge. Within 5 business days of BaFin's inquiry, the exchange provided a detailed explanation, including the specific transaction that triggered the flag and the blockchain analytics report that identified the tainted source.
We then submitted a formal appeal with supporting documentation: (1) the watch sale agreement, (2) correspondence with the buyer, (3) a blockchain forensics report showing that the client's address had no prior connection to the flagged address, and (4) a legal analysis demonstrating that the client was a victim of tainted funds, not a participant in illicit activity. The exchange reviewed the appeal and unfroze the account within 7 business days.
The entire process — from freeze to unfreeze — took 26 days. Without MiCA's regulatory framework, the process would likely have taken much longer, and the client would have had no recourse to BaFin. The MiCA framework gave us a clear path: exchange challenge process first, then NCA complaint, then (if necessary) judicial review. This structured approach is a significant improvement over the pre-MiCA landscape, where exchanges could freeze accounts with minimal explanation and no clear appeal process.
The NCA landscape: which regulators are most effective?
Under MiCA, each EU member state designates a National Competent Authority (NCA) to supervise CASPs. The effectiveness of the NCA varies significantly across member states:
- BaFin (Germany): One of the most active and well-resourced NCAs. BaFin has a dedicated crypto supervision unit and has been proactive in enforcing MiCA's requirements. Complaints to BaFin are typically acknowledged within 5-10 business days.
- AMF (France): The Autorite des Marches Financiers is another active NCA, particularly strong on investor protection. AMF has experience with crypto regulation (France was one of the first EU countries to implement a crypto licensing regime) and is effective at compelling exchanges to respond to user complaints.
- Banca d'Italia / CONSOB (Italy): Italy's dual-regulator approach (Banca d'Italia for AML, CONSOB for market conduct) can be slower than single-regulator jurisdictions, but both regulators are responsive to serious complaints.
- CNMV (Spain): The Spanish regulator has been building its crypto supervision capacity and is becoming more active, though it is less experienced than BaFin or AMF.
- Central Bank of Ireland: Ireland's NCA is relatively small and less experienced with crypto, but it is obligated to enforce MiCA and will respond to complaints.
- CySEC (Cyprus): Cyprus was a popular jurisdiction for crypto businesses before MiCA due to its lighter-touch regime. Under MiCA, CySEC must meet the same standards as other NCAs, but its enforcement capacity is more limited.
If you are filing a complaint against an exchange, the NCA that has jurisdiction is the NCA of the member state where the exchange is authorized (its home member state). You cannot choose which NCA to complain to — but you can influence the choice by choosing which EU-regulated exchange to use in the first place. If you have the option, prefer exchanges authorized in jurisdictions with active, well-resourced NCAs (Germany, France, Netherlands).
The bottom line
MiCA is a landmark regulation that brings cryptocurrency into the EU's regulatory perimeter. For crypto fraud recovery, MiCA provides several important improvements: regulated freeze/unfreeze processes, Travel Rule data, asset segregation in insolvency, and NCA oversight. These improvements make it easier to recover stolen or frozen cryptocurrency from EU-regulated exchanges. However, MiCA does not cover DeFi, self-custody wallets, or non-EU exchanges — so the recovery toolkit must still include the full range of forensic and legal tools for cases that fall outside MiCA's scope.
If you are dealing with a crypto fraud or freeze case involving an EU-regulated exchange, contact us. We can navigate MiCA's framework to maximize your recovery chances, from filing freeze requests to complaining to the NCA to coordinating cross-border legal action. MiCA has given EU crypto users real rights for the first time — but exercising those rights effectively requires understanding the framework and knowing which levers to pull and in what order. The combination of NCA complaints, Travel Rule data requests, and regulated freeze processes creates a toolkit that simply did not exist before 2024.