ExchangesAugust 5, 2026

ESMA will examine how licensed exchanges actually hold your coins

Supervisors across every member state will jointly review how CASPs store their keys, handle incidents and manage outside providers. The exercise runs until mid-2027 and targets exactly the part customers see least of.

Article image for: ESMA will examine how licensed exchanges actually hold your coins

Anyone who leaves coins on an exchange is trusting something they cannot check: the way that company stores its keys. ESMA is now going to look at that specifically for the first time.

What a Common Supervisory Action is

A Common Supervisory Action is not an enforcement sweep, nor an inspection of a single firm. It is a coordinated review in which the national supervisors, meaning AFM, FSMA, BaFin, AMF, CNMV, CMVM, CONSOB, KNF and Finanstilsynet, use the same questionnaire and the same yardstick. That makes it visible whether an authorisation granted in one country means the same in practice as one granted in another.

This is the first time ESMA has used that instrument on crypto. The trigger is the combination of MiCA and DORA, the European rules on the digital resilience of financial institutions, which have applied since 17 January 2025.

Exactly what is being examined

ESMA lists seven topics: the risks inherent to DLT, governance arrangements, key and storage management, transaction controls, incident detection and response, smart contract risks, and dependence on third-party providers.

That last point is quieter than it sounds. Many authorised providers do not hold assets themselves but outsource custody to a specialist firm. If ten exchanges use the same subcontractor, that is one point of failure for ten authorisations at once.

A sample, not a full sweep

An important detail: supervisors will take a risk-based sample of authorised CASPs, not everyone. So the fact that your preferred exchange is not in the review says nothing about the quality of its custody. And the reverse holds too: a firm being reviewed is not an indication that something is wrong.

The timeline

The review runs from the second half of 2026 through the first half of 2027. The final report goes to ESMA's Board of Supervisors in the second half of 2027 and will set out the findings, the good practices found in the industry, the weak spots and the recommendations.

In concrete terms: before 2028, little visible changes for you as a customer. What is happening already is that providers are tidying up their documentation, because they know the questionnaire is coming.

What this means for you

Two things worth remembering. First: a MiCA authorisation says a firm meets the rules on paper, and this review is the first to check whether that also works in the engine room. That gap exists, and it is now officially acknowledged.

Second: as long as that report is not out, the old rule of thumb still applies. What you leave on an exchange is held by someone else. What you hold yourself, you hold yourself, with all the advantages and drawbacks that brings.

Sources: ESMA press release of 8 July 2026 on the Common Supervisory Action into CASPs' digital operational resilience for custody. Last checked: 5 August 2026.

#ESMA#MiCA#CASP#toezicht#bewaring