BaFin Warns on Decapitalus: Unauthorised Services and Fake Certificates
Polished certificates, a Brussels address and borrowed Australian names: none proves regulatory permission. BaFin says Decapitalus offered unauthorised financial and crypto services and displayed counterfeit credentials. Explore what the warning means, how to verify a provider’s identity, and why registers matter more than the paperwork a platform puts before customers.

Ljubljana, Slovenia
Oct 9, 2026
For customers weighing whether to entrust money or crypto-assets to Decapitalus, the central question is not how convincing its certificates look, but whether the business behind the website has permission to provide the services it advertises. Germany’s financial supervisor says the operator of de-capitalus(.)com was offering financial, investment and crypto-asset services in Germany without the required authorisation.
In a warning dated October 7, 2026, the Federal Financial Supervisory Authority, BaFin, identifies the platform by its commercial name, “Decapitalus,” and says it claims a place of business in Brussels, Belgium. The supervisor also alleges that the website displayed counterfeit regulatory certificates referring to Australian financial companies and regulators—documents that could give prospective customers a misleading impression of official oversight.
Australian names, no connection
According to BaFin, the certificates invoked Capital Finance Australia Limited and the Australian Prudential Regulation Authority, or APRA, as well as Hmc Capital Investments Limited and the Australian Securities and Investments Commission, or ASIC. BaFin says neither of the Australian companies is connected with the platform.
That distinction is important for anyone checking a provider’s credentials. Finding a genuine company in a regulator’s register does not establish that a website using its name belongs to that company. A certificate can borrow the credibility of a real institution without demonstrating any relationship between that institution and the business seeking a customer’s money.
The same applies to Decapitalus’s claimed Brussels address. An overseas address is not evidence of regulatory authorisation, and a provider’s right to serve German customers depends on the legal entity, the activity involved and the applicable permissions—not simply where it says it is based.
What the regulatory warning establishes
BaFin cites Section 37(4) of the German Banking Act and Section 10(7) of the German Crypto Markets Supervision Act as the legal bases for its notice. The warning concerns both conventional financial activities and crypto-asset services, rather than cryptocurrency alone.
The notice communicates the supervisor’s position on the platform’s authorisation and its use of purported credentials. It does not establish who ultimately controls the website, whether customers have lost money or how extensive its activities have been. Nor should a public regulatory warning be confused with a court judgment finding criminal fraud.
For consumers, the practical issue is the gap between a displayed credential and a verifiable permission. ASIC’s professional registers and APRA’s register of authorised deposit-taking institutions can help check particular Australian regulatory claims. Their scope matters: an entry in one register is not blanket approval for every financial activity, and it does not authenticate a separate website claiming an affiliation.
Anyone considering a transfer should verify the exact legal entity, website and relevant authorisation through official regulatory records rather than relying on documents supplied by the provider. Customers who have already transferred funds should preserve payment records and communications and contact their bank or crypto-asset service provider promptly to ask what options remain.
The claims about Decapitalus and the certificates are attributed to BaFin, not presented as findings by a court. The linked October 7, 2026 notice has not been independently verified.