Maëlle Vautrin
Paris, France
Oct 5, 2026

Reported BaFin warnings concerning bitbucks.space and fintresor.online highlight two distinct risks in Germany’s digital-asset market: businesses offering regulated services without permission, and websites claiming a connection to an authorized financial institution.

Verification note: The supplied account dates the warnings to September 30, 2026, but the individual BaFin notices have not been independently verified for this article. The allegations concerning these websites, the reported identity misuse and the cited legal basis should therefore be treated as unconfirmed pending publication or confirmation by BaFin.

The regulatory question is nevertheless concrete. Under the EU’s Markets in Crypto-Assets Regulation, known as MiCA or MiCAR, authorization depends on the service being provided and the legal entity providing it—not on whether a website describes itself as a technology platform, investment portal or crypto business.

What the reported warnings concern

According to the supplied account, Germany’s Federal Financial Supervisory Authority said the operators of both websites were offering banking, financial and crypto-asset services without the necessary authorization.

The account also says fintresor.online purported to act under the name of Fintresor Vermögensverwaltung GmbH, described as a supervised asset-management company. If confirmed, that would raise a separate identity-misuse concern. It would not establish that the legitimate company operated the website or participated in its activities.

The distinction matters. A regulated firm’s name can be copied; its authorization cannot simply be borrowed by an unrelated operator.

The account identifies Section 10(7) of Germany’s Crypto Markets Supervision Act, or KMAG, as the basis for the notices. Their exact wording would need to be checked before describing the authority’s findings or the scope of any action.

A public warning should also not be described as a cease-and-desist order unless BaFin has actually issued such an order. Alerting customers to suspected unauthorized activity and formally directing a business to stop are different supervisory actions.

MiCA creates a common licensing framework—not a single license for every activity

MiCA’s rules for crypto-asset service providers became applicable on December 30, 2024. Article 59 of the regulation generally requires providers to obtain authorization, while Article 60 allows certain already-regulated financial institutions to provide specified services through a notification route, subject to its conditions.

Covered activities include custody and administration, operating a crypto-asset trading platform, exchanging crypto-assets, executing or transmitting orders, and providing advice or portfolio management.

The perimeter is not determined by branding. Supervisors must examine what the operator actually does: whether it safeguards assets or private keys, arranges transactions, executes customer instructions or makes discretionary investment decisions.

Nor does every digital asset fall under MiCA. Assets qualifying as financial instruments are excluded from its scope and remain subject to the relevant securities framework. An offering involving banking or investment services may therefore raise authorization questions beyond MiCA.

That is why a warning referring to banking, financial and crypto-asset services should not automatically be reduced to a single alleged MiCA breach.

Transitional permissions have limits

MiCA allowed member states to permit qualifying providers operating under previous national rules to continue temporarily. Under Article 143, that continuation could last no later than July 1, 2026, or until authorization was granted or refused, whichever came first. Member states could shorten the period or decline to use it.

If the reported September 2026 date is correct, the EU’s maximum transitional period would already have ended. Even before that deadline, a provider could not assume that a transitional arrangement in one country authorized unrestricted activity throughout the EU.

For an authorized provider, cross-border access follows MiCA’s procedures. For a customer or counterparty, the practical question remains whether the particular entity is entitled to deliver the particular service in the relevant market.

Check the entity, not just the website

The reported identity allegation illustrates why checking a company name is insufficient. Customers and compliance teams should compare the legal entity in the contractual terms with the entity receiving payments and the firm recorded in official registers.

BaFin’s official website provides access to its supervisory warnings and company information. ESMA’s MiCA resources provide access to relevant European registers. An apparent affiliation should be confirmed through independently sourced contact details—not through a telephone number or email address supplied only by the website under review.

Even a genuine authorization must be checked for scope. Permission to provide one service does not necessarily cover another, and a supervised company’s existence does not authenticate every website using its name.

Enforcement needs a clear explanation

Public warnings can help customers avoid potentially unauthorized offerings and protect legitimate firms from impersonation. But they are most useful when they distinguish the operator under scrutiny, the services involved and the authorization believed to be missing.

The broader test for Germany’s MiCA supervision is therefore not simply whether BaFin issues warnings. It is whether enforcement makes the regulatory boundary easier to understand.

Credible supervision can strengthen the legitimate crypto industry. To do so, it must pair intervention with clear, proportionate and predictable explanations—while keeping allegations, administrative orders and final judicial findings separate.