AMF Crypto Warnings: Why Domain Checks Matter Under MiCA
One familiar brand, one copied domain, and a customer’s money can end up in the wrong hands. The AMF’s warning lists help—but they are no substitute for checking who operates a crypto site, what it is authorised to do, and whether the web address is genuinely theirs before acting.

Paris, France
Oct 5, 2026
A crypto platform’s name is not enough to establish that it is authorised. For firms serving French investors, the Autorité des Marchés Financiers’ public warning lists make website identity a necessary part of due diligence: the legal entity, its regulatory permissions and the domain soliciting customers must all match.
The AMF’s blacklists and warnings identify websites and operators flagged by the regulator, including offers made without the necessary authorisation. They are a useful screening tool, but not a complete register of misconduct—or a certification system for websites that do not appear on them.
The practical distinction is important. A fraudulent website can copy the name and registration details of a genuine provider. Conversely, a warning concerning an impersonating domain does not mean the legitimate company whose identity has been copied is itself operating unlawfully.
Check the permission, not just the name
The first question is what service the website actually offers.
Under the EU’s Markets in Crypto-Assets Regulation, or MiCA, services such as crypto-asset custody, exchange and operating a trading platform fall within a defined regulatory framework. Authorisation is service-specific: permission to provide one activity should not be treated as permission to provide every crypto-related product. Certain existing regulated financial institutions can also provide specified services through MiCA’s notification route rather than obtaining a separate crypto-asset service provider authorisation.
A provider authorised in another EU member state may serve French customers through MiCA’s cross-border framework. The relevant check therefore extends beyond whether a business appears to hold a French licence. It must establish the entity’s regulatory status, the services covered and its entitlement to operate across borders.
Crypto derivatives require a separate analysis. Where a product qualifies as a financial instrument, it falls outside MiCA’s scope and into the EU’s financial-services framework, including MiFID II. A MiCA authorisation alone does not establish permission to offer derivatives trading.
The ESMA databases and registers, alongside records maintained by the relevant national authority, provide starting points for checking those claims.
A genuine registration can still lead to a false website
An authorisation search establishes something about a legal entity. It does not, by itself, prove that the website displaying that entity’s name belongs to it.
Clone websites exploit this gap. They may reproduce a genuine firm’s address, registration number or regulatory disclosures while directing customers to unrelated payment accounts or wallets. Small spelling changes, additional words and misleading subdomains can make the substitution difficult to notice.
A proportionate review should connect three elements:
- The entity: the exact legal name and identifying details in the official record.
- The permission: the services the entity is entitled to provide and any relevant restrictions.
- The channel: the domain, contact details and payment instructions actually presented to the customer.
Where there is uncertainty, confirmation should come through independently established official contact channels—not a telephone number or link supplied by the suspect website.
The same caution applies to claims of an AMF endorsement. A regulator’s logo, a purported certificate or copied official wording is not evidence that the regulator has approved a platform or its products.
Turn a warning into a documented review
For compliance teams, a blacklist match should trigger assessment rather than an unsupported conclusion about fraud.
The review should preserve the exact URL, the date of the search, the wording of the warning and the authorisation records consulted. Teams should distinguish an exact domain match from a similar name and determine whether the alert concerns an unauthorised operator, identity misuse or another issue.
Those distinctions affect the response. A prospective partner may need enhanced verification; a customer report may require escalation to fraud specialists; an impersonated provider may need to publish a clear notice identifying its genuine website and support channels.
Evidence preservation also matters. Dated screenshots, messages and payment instructions can support reports to authorities, hosting providers and domain registrars. Customers who have disclosed credentials or transferred assets should contact their financial provider promptly and preserve records of the interaction.
Warning lists complement supervision
Public warnings offer a rapid way to communicate identified risks, but they cannot replace clear authorisation records or predictable supervisory decisions. Legitimate providers need to be distinguishable from unauthorised operators without requiring customers to interpret several regulatory regimes unaided.
The central lesson is straightforward: check the operator, check the permission and independently verify the domain. None of those checks is sufficient alone.
Verification note: The supplied material describes AMF updates dated 10–28 September 2026 and names individual domains. Those specific entries have not been independently verified here and are not presented as established findings. A warning-list entry is not, by itself, a court finding of fraud; absence from a list does not establish that a service is authorised or safe.