MiCA can help people in the EU assess a crypto-asset service provider’s duties and make a formal complaint. It does not create an automatic route to retrieve cryptocurrency sent to a scammer or stolen from a private wallet. When funds have moved, the practical questions are still where they went, who controls them now, and what legal or operational action is available at that point.
The distinction matters because “MiCA protection” is often treated as if it were a reimbursement promise. The EU’s supervisory authorities warn that crypto protections remain limited and that MiCA does not provide an investor compensation scheme. A regulated provider may have duties to its own clients, but those duties do not make it liable for every loss involving a crypto-asset.
What does MiCA actually cover?
The EU’s Markets in Crypto-Assets Regulation sets rules for certain crypto-assets and for businesses providing covered crypto-asset services in the Union. Those businesses are usually called crypto-asset service providers, or CASPs. The rules address authorisation, conduct, client information, custody and complaints, among other matters. The scope depends on the asset, the service and the provider involved; an EU resident’s loss does not automatically bring every wallet, token or offshore website under MiCA.
One useful first check is the provider’s legal identity. A familiar trading name, app design or EU-looking website is not proof of authorisation. The ESMA MiCA register and the relevant national regulator can help establish whether the actual provider is authorised, and for which services. ESMA has warned clients to verify provider authorisation as MiCA’s transitional periods ended.
When can MiCA matter after a loss?
MiCA matters most when the loss involves a covered provider’s own conduct or custody of a client’s assets. Under Article 71, a CASP must maintain a transparent complaints procedure, allow clients to complain free of charge, keep complaint records and investigate complaints fairly. That gives a client a defined channel for challenging the provider’s handling of a transfer, account restriction or security incident. It is a complaints process, not a guarantee of repayment.
There is a more specific rule for custody. Article 75 requires a CASP that holds crypto-assets for clients to safeguard them and says the provider can be liable for a loss caused by an incident attributable to it, subject to the article’s conditions and liability cap. An account compromise or transfer from a custodial platform may therefore raise different questions from a scam in which a person instructed a transfer from their own wallet. The facts, service agreement and cause of loss need to be examined before drawing a liability conclusion.
What if the crypto was sent to a scammer’s wallet?
MiCA cannot reverse an on-chain transaction simply because it was fraudulent. If the recipient controls a self-hosted wallet, there may be no CASP holding the assets at that address. If the assets later reach an exchange, the exchange may be able to assess a documented alert and, where appropriate, restrict an account or respond to a lawful order. A stablecoin issuer may have separate technical controls. Those are different mechanisms, with different decision makers; none should be described as automatic recovery under MiCA.
This is why the evidence trail matters. A transaction hash proves that a transfer occurred, but it does not by itself establish who controlled the receiving address, whether the transfer was unauthorised, or where the assets are now. A useful case file connects wallet addresses and transaction IDs with the payment route, platform records, communications and a dated account of what happened. For more on the operational distinction between locating, freezing and returning funds, see Recoveris’s guide to freezing crypto assets.
What should an EU victim or adviser do first?
Stop further payments and preserve the original evidence: transaction IDs, wallet addresses, account statements, platform URLs, messages and screenshots. If an account or wallet may still be compromised, secure remaining assets and credentials. Contact the relevant provider through a verified channel and report the incident to local police. Where a regulated provider’s conduct is in question, use its formal complaint procedure and consider the relevant national financial supervisor. The EU supervisory authorities’ fraud factsheet gives similar immediate steps and warns about follow-on “recovery” scams.
The route then depends on where the assets went. A CASP complaint can address a CASP’s conduct. A police report can start a criminal investigation. Blockchain tracing can identify where funds moved and whether they touched a service that may be able to act. A lawyer may assess civil remedies or orders under the relevant national law. These routes can reinforce one another, but a complaint, account hold, seizure and return to the victim are separate outcomes. Recoveris explains the broader investigation-to-recovery process here.
Does ESMA’s proposed freeze power change the answer?
Not yet. In September 2026, ESMA recommended stronger EU capacity to block fraudulent websites and freeze crypto-assets where market abuse or terrorist financing is suspected. This was a recommendation in the review of MiCA, not an enacted EU-wide power that lets victims freeze any alleged scam wallet. Even if the proposal advances, freezing assets would still be different from proving ownership and returning them.
MiCA is therefore useful as a framework for examining a covered provider’s obligations. It is not a substitute for an evidence-led investigation and a lawful route to restitution. If you are assessing a cross-border crypto loss, schedule a confidential consultation with Recoveris to discuss the transaction trail and the next practical steps.