RegulationAugust 25, 2026

EU crypto warning register: 165 of 167 from Italy

Europe keeps a public register of crypto firms without authorisation. Three supervisors fill it. What ‘not on the list’ does and does not tell you.

Article image for: EU crypto warning register: 165 of 167 from Italy

Since MiCA came into force, Europe has kept a single public register of firms offering crypto-asset services without the authorisation the law requires. At the last count it held 167 entries, and 165 of them came from one competent authority: Italy's CONSOB. The AFM added one, the National Bank of Slovakia one. The rest of Europe: nothing. Which makes ‘not on the list’ a worthless safety check.

What this register is

ESMA publishes it under article 110 of MiCA: a list of firms that, according to a national competent authority, provide crypto-asset services in breach of article 59 or 61 — the articles that say you need an authorisation. The file is called NCASP.csv and sits alongside the register of authorised providers (CASPS.csv) in the Interim MiCA Register section on esma.europa.eu. Both were last updated on 21 August 2026.

So it is a notification register, not the result of an investigation. ESMA does not fill it in; the national competent authorities do.

Who fills it, and who does not

Competent authorityEntries
CONSOB (Italy)165
AFM (Netherlands)1
Národná banka Slovenska1
The other 27 EU and EEA jurisdictions combined0

Germany's BaFin stands at zero. That same authority had granted 69 of the 324 European authorisations at the start of August, more than any other country. France's AMF is also at zero.

Two things say something about the quality of what is in there. Of the 167 entries, one contained a concrete explanation in the field for the legal reason. And of the 242 web addresses listed in the file, fewer than a fifth still responded: 47 out of 242, or 19.4%.

Why an empty list is not a clean bill of health

This is where the easy mistake sits. You look up a provider, do not find it in the warning register, and conclude that all is well.

That does not follow. A firm is missing from this file if no competent authority has reported it — and 27 of the 30 jurisdictions examined have never reported anything. Absence here measures a supervisor's willingness to file, not a company's conduct.

The reverse does hold: if a firm is in there, a competent authority has made a concrete finding. A register almost nobody appears in is useful for those who do appear, and says nothing about everyone else.

What to check instead

The check that does close is the positive one: is the provider in the authorisation register? Same source, same file location, just the other list — and that one is complete by definition, because without an entry there is no authorisation.

Two things worth knowing:

  • An authorisation does not cover everything. MiCAR defines ten separate services, from custody (a) to advice (i). A provider can be authorised to execute orders and not to hold your assets. "Regulated" without saying what for is half a statement.
  • The authorisation attaches to the entity, not to the brand. The EU entity of a global platform may hold a different set of services than its parent. Read the name in the register, not the logo on the website.

We keep the authorisation register in readable form, per provider and per service letter, straight from CASPS.csv. The wider MiCA file sets out what the regulation covers section by section. And the seven platforms we compare side by side all hold a European authorisation — with the supervising authority named for each, because that differs.

Why we name no names here

The 167 entries contain company names. We do not publish them, and that is a deliberate rule: absence from a register and presence in a half-filled register are both poor evidence. We write down who does hold an authorisation, with the source and the date next to it. Anyone who wants the names will find them in ESMA's own file.

Frequently asked questions

Does "not in the warning register" mean a provider is safe?

No. 27 of the 30 EU and EEA jurisdictions examined have no entry in this file at all. Absence therefore says more about the supervisor than about the firm.

Where is the official register?

On esma.europa.eu, in the Interim MiCA Register section, as two CSV files: NCASP.csv for notifications and CASPS.csv for authorisations. They are republished weekly.

Why is Italy so far ahead?

The file does not tell you. The register records what has been reported, not why a supervisor does or does not report.

Will the MiCA review change this?

Brussels is revising MiCA right now; the consultation closes on 31 August 2026. Whether the notification regime is tightened as part of it is not yet known.

Sources: ESMA, Interim MiCA Register (NCASP.csv and CASPS.csv, esma.europa.eu), updated 21 August 2026 — read by us on 25 August 2026. The count of 167 entries and the 165/1/1 split comes from CryptoTicker, which read the file on 16 August 2026; the three-country pattern was independently confirmed by Crypto Benelux (23 August 2026) and also appears in our own reading of the file. We did not recount the total ourselves. Authorisations per country: ESMA CASPS.csv. Last checked: 25 August 2026.

This is not investment advice and not legal advice. Crypto is risky and you can lose the money you put in.

#esma#mica#regulatie#toezicht#vergunning