BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
The BaFin has warned about a website offering crypto-asset services without authorisation and speaks of a presumed identity theft at the expense of a real US company. The case shows why the advice to look a provider up in the register does not carry on its own.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
The BaFin published a consumer notice on the website nova-c-solutions(.)com on 28 September 2026. According to its findings, financial and securities services as well as crypto-asset services are offered there without the required authorisation. What makes the case interesting is less the warning itself than the route by which the site acquires an air of respectability: the operators give a business address in Pompano Beach in the United States, and at that address, on the BaFin's account, a company called Nova Capital Solutions, LLC is indeed registered with the US Securities and Exchange Commission.
The regulator states explicitly that it has no indications whatsoever that this company or the people responsible for it are connected to the website. Instead, it says, this is presumably a case of identity theft at the expense of Nova Capital Solutions, LLC and its executives. For you as an investor, an uncomfortable conclusion follows: a genuine registration number proves nothing so long as it does not belong to the counterparty addressing you. That is precisely where the standard advice to “look it up in the register” breaks down.
What the BaFin notice on nova-c-solutions.com says
The notice is a consumer communication about a website operating without authorisation, not a charge and not a verdict. Its legal basis is section 37(4) of the German Banking Act and section 10(7) of the German Crypto Markets Supervision Act. The substance in brief: the site offers financial, securities and crypto-asset services; the BaFin has granted no authorisation for them.
Anyone offering such services in Germany needs that authorisation. It is no formality: capital requirements, rules on the safekeeping of client funds, reporting duties and supervision itself all hang on it. Where it is missing, so is the entire apparatus that would take hold in a dispute.
One point matters for context. With a notice of this kind the BaFin is not saying that any particular investor has suffered a loss. What it establishes is that an offer is being made without authorisation — and the regulator makes that public so that nobody else falls for it.
Identity theft: why the US company named is the presumed victim, on the BaFin's account
This point deserves care, because it is easily misread. Nova Capital Solutions, LLC appears in the notice not as an accused party but as a presumed injured one. The BaFin cites the company in order to explain why the address given on the website survives an initial inspection, and makes clear in the same paragraph that it has no indications of any link between that company and the site.
The suspicion of identity theft is likewise a suspicion, and it comes from the regulator rather than from us: the BaFin phrases it with the word “presumably”. Whether a third party's identity was in fact used here, and by whom, is therefore not conclusively established.
A note on what can be substantiated, which we disclose rather than smooth over: we were unable to confirm the SEC registration of Nova Capital Solutions, LLC independently, because a query of the SEC's EDGAR database returned nothing usable. The statement stands here as what it is, an account given by the BaFin.
The same blueprint as watermarkinvestments.com
In its notice the BaFin points out that nova-c-solutions(.)com bears strikingly strong similarities to the site watermarkinvestments(.)com, which it had already warned about on 8 July 2026. That is the real news for the reader: this is a template in repeated use rather than an isolated case.
When a template runs more than once, the name and the domain change while the structure, the boilerplate and the manner of legitimation stay the same. Anyone who knows the structure once will recognise the next version, whatever it is called. That is where the value of such a warning lies beyond the individual case.

A register entry alone does not separate real company names from borrowed ones
The common advice runs: establish whether the provider is registered or licensed. The advice is sound and remains the first step, but this case exposes its gap. That enquiry answers the question “Does this company exist?”. The question that matters, however, is a different one: “Is the company that exists the same one writing to me here?”
A register entry is an entry about a company, not about a website. It says nothing about who operates a domain, who sends an email or who is on the telephone. Where a genuine company address is used on somebody else's site, the enquiry adds up formally and misses the substance.
What makes the difference is reversing the direction of the enquiry: instead of typing the details from the website into a register, work back from the official site of the registered company. Is the domain that approached you named there? Is the telephone number the same? Does the official site carry this offer at all? If any of those answers comes back negative, the register entry is worthless, however genuine it may be.
Regulated crypto exchanges comparedSection 10 of the Crypto Markets Supervision Act: how to spot a BaFin crypto warning
The BaFin publishes warnings about providers operating without authorisation on a rolling basis, and only a small share of them concern crypto-assets. There is, however, a reliable marker: the legal basis cited. The reference to section 10(7) of the Crypto Markets Supervision Act (KMAG) does not appear under every notice; it is set deliberately where an offer covers crypto-asset services.
By way of comparison, warnings about leasing offers or interest-rate portals from the same days do not carry that line, only the basis drawn from the Banking Act. For anyone who looks through the BaFin warning list from time to time and wants the crypto cases alone, that line serves as a usable filter.
The KMAG is the German statute that accompanies the European regulation on markets in crypto-assets and gives the BaFin its supervisory powers over crypto-asset service providers. It is the reason the regulator can act at all today against a crypto platform without authorisation.
The BaFin company database and its limits
For the question of whether a provider is licensed in Germany, the BaFin maintains a public company database. It shows whether an institution holds an authorisation, and for which business.
The limits of that database are the limits of any register. The database tells you which company holds an authorisation. What it does not answer is whether the website that approached you belongs to that company. A provider can sit in the database and still turn up on a forged site, which is exactly the process at issue here, only with a German rather than a US register.
That is why the order matters: first look in the database, then open the official presence of the company you found and work onward from there, never through a link somebody has sent you. Anyone who would rather stay with providers whose EU licensing is documented will find them in the overview of regulated crypto exchanges.
MiCA authorisation: what a licence in the EU actually covers
MiCA is the EU regulation on markets in crypto-assets, in force in stages since 2024, which requires providers of crypto-asset services to hold an authorisation. Such an authorisation means a provider is supervised, has to meet organisational requirements and must keep client assets segregated.
What it does not mean: that your market losses would be insured, that a provider cannot become insolvent, or that every service the provider offers is covered by the authorisation. A licence applies to particular business, not across the board to everything a company sells.
For the nova-c-solutions(.)com case the position is simpler. There, on the BaFin's account, no authorisation exists at all, so the question of its scope never arises.
How a borrowed company profile shows up in conversation
The patterns that recur in this kind of operation can be named without knowing who is behind it:
- The approach comes from outside. A regulated institution rarely contacts you unprompted through messenger apps, social networks or phone calls.
- The legitimation is supplied for you. Registration number, address and screenshots all come from the other side. Only what you have found yourself, by your own route, can be tested.
- A second channel is missing. The official main switchboard of the supposed company does not lead to your contact person.
- Withdrawals require a payment first. Fees, taxes or an “unlocking” charge payable before a withdrawal are not standard practice.
- Time pressure stands in for documents. An offer with a deadline that leaves no room for scrutiny is built as a sales argument, not as information.
None of these features proves anything on its own. Several together are the point at which it pays to transfer nothing and let a day pass instead. Anyone holding their balance in their own custody shrinks the attack surface considerably: the comparison of hardware wallets shows what that costs and what responsibility it brings.

Hardware wallets comparedWhen money has already moved: which routes are still open
Where a transfer has already gone out, much depends on the payment method and on time. With a classic bank transfer it is worth calling your own bank immediately to attempt a recall, and the chances fall with every hour. With a card payment, a chargeback procedure through the card issuer comes into consideration.
With a transfer in crypto-assets the position is different: a transaction on a blockchain cannot be recalled. What remains is the documentation, meaning the transaction hash, the recipient address, the timestamp, the entire correspondence and a screen capture of the website with its date. Those records are the basis for a report to the police and for a notification to the BaFin, which accepts information on unauthorised business.
Stay realistic: the prospect of recovering funds in cases like this is slim. That makes the part you can influence all the more important, namely making no further payment. The demand for an additional fee to release a supposedly blocked withdrawal is the most common pattern by which one loss becomes a larger one.
Four cases in six weeks: the pattern these BaFin warnings share
This case is not the first we have traced this year, and set side by side the pattern becomes clear. In August there was a warning in which another company's name was likewise used, and the analysis of it appears in the piece on identity misuse at a crypto platform. Alongside it came the warning about a wallet application, the survey of entire platform series, and the compilation of how to place a crypto provider before the first euro changes hands.
Across all the cases the same construction repeats: a professional presence, a verifiable but borrowed legitimation, no evidence of authorisation for the business on offer, and an approach that comes from the other side. The names change faster than a warning list can absorb them. The construction does not.
From that follows the practical consequence for how to handle such lists. A warning list is a rear-view mirror. It reliably shows what has come to notice, but never the full picture of what is running right now. That a name is not on the list is therefore no certificate of good standing, an inference drawn surprisingly often in practice.
BaFin warning: How to proceed now
- Work in the reverse direction before money moves. Instead of typing the provider's details into a register, start from the official presence of the registered company and see whether the domain is named there at all. Anyone who would rather begin with providers holding documented EU authorisation will find them in the comparison of regulated crypto exchanges.
- Shrink the attack surface. A balance that does not sit on somebody else's platform cannot be frozen there either. What self-custody costs and demands is set out in the comparison of hardware wallets.
- Document everything you pay and receive. That holds for the worst case as much as for your tax return, because complete transaction data are the basis in both. Tools for it appear in the overview of crypto tax software.
And the most important sentence from this case, because it carries over to every next one: a genuine register entry proves that a company exists. It does not prove that you are talking to it.
(As of September 28, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Frequently asked questions about the BaFin warning on nova-c-solutions.com
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- BaFin Warning: What Happens When You Enter Your Data on an AI Crypto Platform
- BaFin Warnings in September: How to Check in Three Minutes Whether a Crypto Provider Holds Authorisation
- BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
- BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
- BaFin Warnings 2026: 24 Crypto Platform Series With 639 Domains, and How to Check Your Provider
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 26, 2026 4:21 AM

Operation Herakles disconnects 13,888 phone numbers: what to check on crypto investment calls
Six authorities have disconnected 13,888 phone numbers used by investment fraudsters to call their victims in Operation Herakles, 9,304 of them in the past three months alone. What the Federal Network Agency now requires of telecoms providers and which three checks protect you from the scheme.
September 29, 2026 10:33 AM

ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
ESMA presented its work programme for 2027 on September 28, 2026 and made reverse solicitation a supervisory priority. What that means if your coins sit with a provider without EU authorisation, and which three steps make sense now.
October 1, 2026 7:32 AM

Starting a crypto company in Germany: legal form, BaFin licence and capital
Setting up a crypto company in Germany: which business models need BaFin authorisation under MiCA, GmbH or UG, how much capital is required and where public support is available.
August 21, 2026 7:46 AM

Crypto Job Offers Using Your Own Bank Account: How the Money Mule Scheme Works and Why Money Laundering Starts With Negligence
On August 18, 2026 BaFin warned about job offers in which applicants are to pass third-party payments through their own account and exchange them into crypto-assets. Anyone taking part risks criminal proceedings for money laundering, and gross negligence is already enough.
August 19, 2026 10:26 PM

EU warning list for crypto providers: 167 entries, 165 of them from Italy, none from BaFin
ESMA maintains a Europe-wide register of non-compliant crypto providers. We counted it on August 16, 2026 and called up every web address stored in it. Three of 30 supervisory authorities supply any entries at all, and BaFin is not among them.
September 1, 2026 4:12 AM

USDT cashback and 7 percent on stablecoins: what the MiCA interest ban means for you
A new payment card advertises up to 10 percent cashback in USDT and up to 7 percent a year on the balance. Article 50 MiCAR explains why a provider licensed in the EU is not allowed to pay you exactly that.
May 15, 2024 12:04 PM

Crypto Scams: How to Protect Your Cryptos?
With the rise of crypto scams, and while international efforts are still working to combat these threats and protect investors, some recent tactics have been identified, and here is your full guide.
September 19, 2026 4:11 PM

MiCA Consultation Closes September 30: What to Check and Submit Before Then
The European Commission is reviewing the MiCA crypto regulation and will accept submissions until September 30, 2026 at 23:59 CEST. Staking, DeFi, lending, stablecoins and custody are all under examination, and you can take part without a lawyer.
September 1, 2026 10:13 AM

BaFin Crypto Knowledge Survey: Four Assumptions Owners Believe Are True
BaFin has measured what crypto owners know about their products: 57 percent of the answers were correct, 31 percent wrong. Four false assumptions come up especially often, and each of them changes your own investment decision.
January 22, 2025 11:31 AM

How to Identify Fake TRUMP tokens: A Guide to Staying Safe in the Crypto World
The rise of fake TRUMP and MELANIA tokens is alarming crypto enthusiasts. Learn how to distinguish the official tokens from scams and protect your investments with this essential guide.
August 22, 2026 4:16 PM

Stolen Crypto: Where You Actually File a Report and What Counts in the First Hours
After a theft most people google first and preserve the evidence last, when the right order is the other way round. What you have to record in the first hours, where private individuals actually turn, and where the limit of what is possible lies.
September 8, 2026 7:23 AM

Compensation After an Exchange Hack: What Twelve Crypto Providers Really Promise German Customers
After $322 million in losses in a single September week, the question is who replaces stolen coins. On September 8, 2026 we retrieved the security and legal pages of twelve providers and evaluated what is promised there.
September 5, 2026 10:24 PM

Fake German Finance Ministry Letters: Why Nobody May Demand 19 Percent VAT on Your Crypto Purchase
Since September 1, 2026, Germany's Federal Ministry of Finance has been warning about forged letters that demand 19 percent VAT on cryptocurrency purchases while citing real transactions. That tax does not exist, and this is how to spot the forgery.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
September 29, 2026 10:40 AM

“We have created the essential conditions …”: bitcoin.de has stood still for three months, the MiCAR licence is missing
Bitcoin Group SE published its half-year report on September 29, 2026: trading on bitcoin.de has been idle since the end of June because the MiCAR authorisation is missing. The new platform is finished, but no launch date is set.
September 26, 2026 7:29 PM

Coins Stolen in an Exchange Hack: What the German Tax Office Accepts as a Loss
After the attack on Bitget on September 24, a question the reports leave out arises for those affected in Germany: can a stolen balance be written off against tax? The answer hangs on a single term in the Income Tax Act, and it is decided by your records.
September 19, 2026 1:14 AM

Crypto investment fraud: when the tax office taxes phantom gains and what to check now
Between September 11 and 16, 2026, BaFin published thirteen consumer notices, seven of them on crypto-assets. Anyone who has paid into such a platform risks not only the loss but, in some circumstances, a tax demand on gains that never existed.
August 21, 2026 10:27 AM

Complaining About a Crypto Exchange: the Deadlines Article 71 MiCAR Sets and Why BaFin Will Not Decide Your Case
Authorised crypto providers have to run a formal complaints procedure, and Delegated Regulation (EU) 2025/294 sets a hard limit of two months for it. Our own analysis of the ESMA list shows at the same time that no complaints link is on file for Germany to this day.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
October 2, 2026 10:28 PM

GENIUS Act stablecoin rules: what applies today and what stays open until 2027
The GENIUS Act creates the US framework for payment stablecoins. Which proposals are already on the table, why the OCC matters and what stays open until January 2027.
September 25, 2026 7:24 PM

Bitcoin Forecast: What to Check on Levels, Holding Period and Buying Route Before the Quarter Ends
Bitcoin stands at $83,877 at 16:40 UTC on September 25, 2026, and the measured volatility of the past 30 days spans a band of $73,600 to $94,200 for the coming month. More important than that band before the quarter ends are three checks: holding period, buying route under MiCA and the reporting duty in force since January 2026.
September 22, 2026 4:33 PM

Three of the 25 Largest Coins Have No Euro Pair: How to Check Your Buying Route Before the Order
Our own survey of five trading venues active in the EU, taken on September 22, 2026, shows that three of the 25 largest cryptocurrencies have no euro pair there at all, and four more only one. What that means for your next order and what the detours cost.
September 20, 2026 4:15 PM

Crypto Phishing After a Data Breach: The Warning Signs in a Fake Exchange Email
After every major data breach, the number of phishing emails sent in the name of crypto exchanges and wallet manufacturers rises. This article shows you how to recognise such a message, which data a reputable provider never requests by email, and what to do in the first hour after a click.
September 15, 2026 3:53 PM

Waltio Confirms Brevo Breach Touched Its User Emails: Here Is What To Do Now
Waltio has told users its Brevo account was accessed during the September breach that also hit Trezor and BitBox. Here is what was exposed.
August 19, 2026 10:37 AM

Who Regulates Crypto in the US? CFTC and SEC Compared
On 20 August 2026 the new innovation advisory committee of the US derivatives regulator CFTC meets for the first time, staffed with the chief executives of Coinbase, Kraken, Gemini and Ripple. What separates the two US agencies, and why MiCA and BaFin still count for your portfolio.
May 19, 2024 1:23 PM

Will Tether (USDT) Get Delisted In Europe?
With growing concerns revolving around the reliability and compliance regulations of stablecoins, some crypto exchanges opt to delist some of them. Will this be the case for Tether in Europe?
September 13, 2026 4:33 AM

Your Volksbank's Crypto Licence: Why You Have to Check Custody Separately
14 of the 16 newest CASP entries in the ESMA register were German cooperative banks, and each one carries order execution only. Our count of the BaFin database shows that not one of the 21 cooperative institutions is registered as a crypto custodian.
More from CryptoTicker
