EU Crypto Asset Recovery: What an Anti-Corruption Push Would Change
Finding a crypto wallet is not the same as freezing its contents. Europe’s anti-corruption debate turns on that distinction. Explore how MiCA, transfer rules and confiscation powers fit together—and why private keys, cross-border cooperation and operational capacity could determine whether tougher policy actually recovers criminal proceeds rather than adding paperwork.

Brussels, Belgium
Oct 9, 2026
Bringing crypto-assets more explicitly into the European Union’s anti-corruption agenda would test a distinction that often disappears in Brussels policy debates: regulating a financial business is not the same as recovering criminal proceeds. Europe already has rules for crypto service providers, information accompanying transfers and confiscation. The harder question is whether those rules allow investigators to establish control over digital assets—and preserve them before they move.
A European Parliament resolution urging the Commission to strengthen that framework would be a political intervention, not a new enforcement power. It would not amend the Markets in Crypto-Assets Regulation, impose an immediate compliance deadline or authorise the seizure of a wallet. Its significance would depend on the Commission’s response: legislative proposals, supervisory guidance, operational support or some combination of the three.
The institutional test is therefore more demanding than whether Brussels promises tougher oversight. It is whether any initiative identifies a demonstrable gap, assigns responsibility to actors capable of meeting it and improves recovery without duplicating existing obligations.
Three legal frameworks, three different jobs
The first distinction is between market regulation and financial-crime controls. MiCA, Regulation (EU) 2023/1114, establishes requirements for certain crypto-asset issuers and crypto-asset service providers, including authorisation, governance, disclosure and customer protection. Its principal service-provider provisions have applied since 30 December 2024, subject to national transitional arrangements.
MiCA is not, however, a comprehensive code for tracing corrupt payments or confiscating criminal property. Nor does an activity falling outside its scope necessarily mean that it falls outside every other relevant law. Anti-money-laundering duties, criminal law and asset-recovery powers have their own definitions and conditions.
The second framework concerns identifying customers and preserving information about transfers. The Transfer of Funds Regulation, Regulation (EU) 2023/1113, has applied since 30 December 2024 and extends the “travel rule” to covered crypto-asset transfers. Providers must obtain and transmit specified information about originators and beneficiaries, with procedures for dealing with missing or incomplete information.
Transfers involving self-hosted addresses are not simply excluded. Where a regulated provider is involved, the regulation imposes information requirements; for transfers exceeding €1,000, it also requires adequate measures to assess whether the relevant self-hosted address is owned or controlled by the provider’s customer. That is not a general prohibition on self-hosted wallets, nor a requirement that every blockchain transaction pass through an authorised intermediary.
The EU’s newer Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, adds a directly applicable framework for covered businesses, including crypto-asset service providers. Most of its provisions apply from 10 July 2027. That timetable matters: policymakers should distinguish obligations already in force from requirements adopted but not yet generally applicable.
The third framework concerns the property itself. The Asset Recovery and Confiscation Directive, Directive (EU) 2024/1260, strengthens rules on tracing, freezing, confiscating and managing criminal assets. Its definition of property expressly encompasses crypto-assets. Member states must transpose the directive by 23 November 2026.
These measures serve related purposes, but they are not interchangeable. Customer information can help identify a suspect. Transaction records can help establish a money trail. Neither automatically gives an authority the practical ability—or the legal basis—to take control of the assets at the end of that trail.
Finding a wallet is not securing its contents
A public blockchain can provide a durable transaction record while leaving investigators uncertain about who controls an address. Even when control can be established, recovery may depend on access to private keys, cooperation from a custodian or assistance from authorities in another jurisdiction.
A supervised exchange may be able to respond to a lawful freezing order. A decentralised protocol may have no operator with equivalent control over a user’s assets. Those differences are central to designing enforceable obligations: requiring a business to preserve assets it holds is not the same as requiring a software developer to immobilise assets it cannot access.
Cross-border coordination creates another constraint. A payment may pass through several services and jurisdictions before investigators obtain the information needed to act. Better tracing tools can help, but they do not replace timely legal cooperation, admissible evidence or secure arrangements for managing recovered crypto-assets.
An effective anti-corruption initiative would therefore need to address operational capacity alongside legal coverage. Specialist investigators, rapid communication between competent authorities and clear procedures for handling digital assets may be as consequential as another reporting requirement.
What would constitute a meaningful change?
The Commission’s first task would be to separate gaps in legislation from gaps in implementation. If a regulated provider is failing to meet an existing duty, the answer may be supervision or enforcement. If authorities cannot cooperate quickly enough, another customer questionnaire is unlikely to solve the problem.
Any proposal extending duties beyond established intermediaries would also need precise definitions. The relevant questions are whether an actor has a customer relationship, possesses useful identifying information or exercises control over assets. A broad reference to activity “outside MiCA” would not settle those questions.
Industry objections deserve the same scrutiny as institutional promises. Claims that compliance is technically impossible should be tested against what a service actually controls. Conversely, requirements should not assume that every developer or infrastructure provider has the capabilities of a custodian.
The measure of success is not the number of additional checks. It is whether authorities can lawfully identify and preserve proceeds more effectively, while maintaining proportionality, procedural safeguards and routes to challenge a freezing or confiscation decision.
For firms, the immediate priority remains implementing the rules that already exist and preparing for those with defined application dates. A parliamentary call for further action would shape the policy agenda; binding changes would require the relevant legal or supervisory steps to follow.
Verification note: The reported resolution dated 8 October 2026 and its stated vote of 390–86 have not been verified against an identifiable adopted text or official voting record. Parliament’s adopted-texts register is the appropriate source for that check; its homepage does not substantiate the reported adoption. The analysis above is grounded in the EU legislation linked directly in the text.