The App Still Works After MiCA's Deadline. That Does Not Show Your Exchange Is Authorized.
The European Union's transition period for crypto-asset service providers ended on July 1, 2026. If you live in the EU and your exchange app still opens, bal...
The European Union's transition period for crypto-asset service providers ended on July 1, 2026. If you live in the EU and your exchange app still opens, balances still load and trades still go through, it is natural to assume the company is cleared to serve you. The European Securities and Markets Authority (ESMA) says that assumption needs a check.
This article explains what ESMA has said and how a reader can look up the company behind an app. It does not assess any named exchange.
Why a working app is not proof
ESMA's public statement of June 23, 2026 says the transition under the Markets in Crypto-Assets Regulation (MiCA) ends on July 1. It expects crypto-asset service providers without authorization to wind down in an orderly way. In ESMA's description, that means they should:
- stop onboarding new EU clients and stop marketing to them
- limit services to selling, transferring or closing positions
- hold client assets only as long as strictly necessary for an orderly exit
- tell clients clearly what is happening, including a deadline for closing remaining positions
So an app that still works could belong to an authorized provider. It could also be a provider in a wind-down, or one that ESMA says should not be serving EU clients at all. The app itself does not tell you which.
What "reverse solicitation" means
ESMA says providers based outside the EU "cannot provide MiCA services to EU clients or solicit EU clients," with one exception. They may serve a client who comes to them entirely on the client's "own exclusive initiative," under what MiCA calls reverse solicitation.
ESMA's guidelines on reverse solicitation describe that exception narrowly. They are addressed to national authorities and non-EU firms, and they say:
- Solicitation is read broadly. It covers websites, apps, social media, ads, emails, invitations to events, influencers, affiliate campaigns and general brand advertising.
- "Own exclusive initiative" is read narrowly.
- The question is one of fact. Contracts or disclaimers cannot override contrary facts.
- A firm may market only the same type of service, in the context of the original transaction. ESMA's example is that a firm may not market further transactions a month later.
The guidelines list examples likely to count as solicitation, including EU-specific domains or search optimization, geo-targeted ads, EU-language websites, EU sponsorships, paid EU influencers, and push notifications days or months after a first trade. They treat geo-blocking or refusing new EU accounts as a precaution.
In short, reverse solicitation is not a general exemption, and the guidelines do not decide any individual customer's case.
How to check the company behind your app
These steps are a reading suggestion, not a legal test.
- Find the legal entity. The company named in the app's terms of service, legal notice or user agreement is the one that matters. The brand name on the app may belong to a group of companies, and the one contracting with you can differ by country.
- Search ESMA's register. ESMA's MiCA page, last updated Sept. 30, 2026, hosts the Interim MiCA Register as downloadable CSV files. One lists authorized crypto-asset service providers. Another lists non-compliant entities.
- Check your national regulator. ESMA says the register is published at weekly intervals, so national registers may be ahead of it. ESMA also publishes a list of national competent authorities.
- Read the dates. ESMA says a withdrawn authorization stays in the file with its withdrawal date, so an entry alone is not enough. Also confirm that the entry covers the entity and services you actually use.
One caution on the register. ESMA says the records reflect what national authorities have reported. Its separate file of crypto white papers is described as "not reviewed or approved" by any authority, so a listing there is not an endorsement.
What ESMA tells clients of unauthorized providers
ESMA's statement includes a warning for consumers. Clients of unauthorized providers, whether based in the EU or outside it, "do not benefit from MiCA safeguards, including protections for client assets."
ESMA invites clients to check in the ESMA register whether their provider is authorized. It says they should "act promptly where this is not the case," including by moving assets to an authorized provider or a self-hosted wallet. Clients who run into difficulties are told to contact their provider first.
The statement also says ESMA and national authorities may take coordinated action after the transition period. This article does not report any such action against a specific company.
Limits to keep in mind
ESMA's guidance applies to services offered to clients in the EU. Rules in the UK, the US and other countries differ. The register has gaps by design: it is a weekly snapshot of national reports. CryptoWorkPro could not confirm from ESMA's pages whether the register lists the specific services each entity may offer, so verify that with the national regulator.
A registry entry shows the status of a legal entity. It does not show how safe the entity is, whether it has been audited, or how it treats customers.
Disclosure: This article is based on ESMA's June 2026 statement, its reverse solicitation guidelines and its MiCA page as they appeared on Oct. 2, 2026. It does not evaluate any named exchange, and the featured image is a generated illustration, not documentary evidence. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.


