CONSOB Website Blocks and MiCA: The Legal Test for Italy’s Crypto Enforcement
Italy’s reported move to block six websites raises a sharper question than headlines suggest: what does a domain ban prove under MiCA? The answer depends on the missing orders, the services allegedly offered and the legal authority invoked. Until those documents emerge, enforcement claims remain reports—not precedent for Italian regulators.

Milan, Italy
Oct 5, 2026
An order blocking access to a crypto website is an enforcement measure, not a complete account of the case against its operator. That distinction matters in assessing a reported CONSOB action against six websites, two of which allegedly provided unauthorized crypto-asset services.
The supplied account cites a CONSOB announcement dated September 17, 2026. That announcement and the individual blocking orders have not been independently verified for this article. The account therefore provides a starting point—not sufficient evidence to identify the operators, establish which services they offered or assess their possible defenses.
The legal framework nevertheless allows a clearer distinction between three questions: whether a provider may serve Italian customers, whether CONSOB can restrict access to its website, and what a blocking order actually proves.
MiCA authorization is the substantive question
The EU’s Markets in Crypto-Assets Regulation, or MiCA, generally became applicable on December 30, 2024. Its rules for asset-referenced and e-money tokens began applying earlier, on June 30, 2024.
Article 59 establishes the central rule for crypto-asset service providers: a business must have the appropriate authorization or qualify to provide the services through the route available to certain already-regulated financial institutions under Article 60. The analysis turns on the activity performed, not simply whether a website describes itself as a crypto platform.
Custody, exchange, execution of orders, operation of a trading platform and crypto-asset advice are among the services covered. Different activities can raise different authorization questions. Conversely, the presence of crypto-related content on a website does not by itself establish that its operator is providing a regulated service.
Italy’s Legislative Decree No. 129/2024 adapts domestic law to MiCA and allocates supervisory responsibilities between CONSOB and the Bank of Italy.
Authorization also has a cross-border dimension. A properly authorized provider in another EU member state can serve Italian customers through MiCA’s passporting framework, subject to the applicable notification procedure. The relevant question is therefore not merely whether a company holds an Italian license, but whether it has a lawful basis to provide the particular services in Italy.
The blocking power needs a precise citation
The supplied draft attributes CONSOB’s blocking power to “Law Decree No. 58/2019.” That citation should be corrected.
CONSOB’s established website-blocking power is commonly cited by reference to Article 36, paragraph 2-terdecies, of the Growth Decree, Decree-Law No. 34/2019, as converted with amendments by Law No. 58 of June 28, 2019.
This is more than a drafting detail. MiCA supplies the EU rules governing crypto-asset services; domestic legislation supplies supervisory responsibilities and enforcement mechanisms. A legally sound account must identify both the alleged breach and the provision empowering the particular remedy.
Without the individual orders, it is not possible to assess the complete legal basis used against either crypto-related website.
A blocked website is not a closed business
An access restriction can disrupt a website’s ability to reach customers through Italian internet service providers. It does not necessarily shut down the operator, remove the website globally or recover customer funds.
Nor should an administrative blocking decision be presented as a criminal conviction or a judicial precedent. Its significance depends on the regulator’s reasoning, the evidence supporting its findings and any subsequent challenge or court ruling.
The supplied material does not identify the six domains or include the operators’ responses. It also does not establish whether alternative domains remained accessible, whether customers suffered losses or whether further proceedings followed. Those gaps prevent a case-specific assessment of proportionality, effectiveness or wider legal significance.
Authorization, identity and white papers are separate checks
The supplied account also attributes warnings about cloned websites and misleading promotions to CONSOB. Those risks require investors to check more than a familiar company name.
A register entry can help establish a provider’s regulatory status. It does not establish that a particular website belongs to that provider. Investors should compare the legal entity, authorized services and official contact details with the claims made by the site they are using.
White papers answer another question. Where MiCA requires one, its notification and publication concern disclosures about a crypto-asset; they do not substitute for a service provider’s authorization. For crypto-assets other than asset-referenced or e-money tokens, MiCA expressly provides that competent authorities must not require prior approval of the white paper before publication. Publication should therefore not be marketed as regulatory endorsement.
The reported six-site action may illustrate how access restrictions support crypto supervision. But the stronger legal conclusion requires the underlying orders: what service was provided, why authorization was required, which enforcement power applied and whether the operator contested the findings. Until those documents are available, this is a reported enforcement action—not an established precedent for Italy’s application of MiCA.