BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
BaFin has been warning since August 24, 2026 about a crypto website that, according to the regulator's findings, misuses the identity of a real German company. Why the commercial register and the imprint are worthless as proof, and how to check a provider yourself in a few minutes.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Germany's financial regulator BaFin issued a warning on August 24, 2026 about offerings on the website tresorbit(.)com. What is new in this notice is the addition: according to the regulator's findings, the case involves identity misuse at the expense of a real German company. The short answer for you is therefore this. A German company name, a German address and a clean legal form on a crypto website prove nothing at all. A provider is only verified once you have found it yourself in BaFin's company database.
According to BaFin, crypto-asset services are offered through the website without authorisation, specifically trading in crypto-assets. The regulator also names whose identity was used for this: Gesellschaft für Kryptoregisterführung mbH, based in Willich. BaFin states that this company has no connection to the operators of the website. Anyone who googles the company name and finds a genuine German commercial register entry has found the wrong confirmation.
The BaFin Warning of August 24, 2026: What the Regulator Said About tresorbit(.)com
The notice itself is short and consists of three statements, and every one of them matters for your own check. First: crypto-asset services are offered through the website without the authorisation required for them. Second: what is offered is specifically trading in crypto-assets. Third: there is identity misuse at the expense of the named Willich company, which has nothing to do with the operators.
BaFin bases the publication on section 10 subsection 7 of the German Crypto Markets Supervision Act. This is the provision that allows the regulator to inform the public about unauthorised crypto offerings and to name names and addresses in doing so. Such a notice is not a court decision and not a criminal conviction. It is official information about what the regulator has established. For you as an investor it is the most solid source available on an unknown provider.
What the notice does not contain is just as much part of the picture: no loss figure, no number of affected customers, no indication of how long the website has been running. Anyone quoting you such numbers on this case did not get them from BaFin.
Identity Misuse Explained: What the Term Means in Supervisory Law
Identity misuse in this context means that unknown operators use the name, the address or the register details of a genuinely existing company in order to give their own offering a respectable appearance, without that company knowing about it or being involved in it. In these cases the affected company is itself an injured party.
The difference from a freely invented shell company matters in practice. An invented company gives itself away as soon as you search for the name and find nothing. A misused name survives that first search: the company really exists, there is a commercial register entry, there is an address in Germany, and if in doubt there is even a website with a correct imprint. All of that belongs to a different firm from the one that would like to receive your money.
Why Crypto Offerings Are Particularly Exposed
The European MiCA regulation has applied in full since December 30, 2024, and anyone offering crypto-asset services in Germany needs authorisation to do so. German investors have grown used to looking for licences, and it is exactly that habit which is being exploited. An offering that lists a German company in its imprint looks more credible today than one with an address overseas. Misusing a real name is thus the answer to a regulation that works in principle.
Commercial Register, Imprint, Licence Number: Why These Three Documents Prove Nothing
The commercial register is a directory of merchants and companies registered in Germany and states that a firm legally exists. It says nothing about whether that firm holds a BaFin authorisation, and even less about whether the website using the name actually belongs to it.
The imprint works in a similar way. An imprint is a self-declaration by the website operator. Nobody checks before publication whether the company named there belongs to the operator. The same applies to licence or register numbers printed on a page: a number is a string of characters for as long as you do not look it up in the register itself.
The reliable route therefore always runs in the other direction. You do not look on the website for evidence of its own respectability. You look for the provider in the register, and then check whether the details held there match what is in front of you. Anyone using a regulated crypto exchange with verifiable EU authorisation largely avoids this problem, because the authorisation there is publicly documented and easy to find.

Crypto-Asset Service: What Requires Authorisation From 2026
A crypto-asset service is a commercial service around crypto-assets provided to a customer, such as operating a trading platform, exchanging crypto-assets for euros, executing orders or holding crypto-assets in custody for others. Anyone offering that in Germany needs authorisation from BaFin.
What you do for yourself does not fall under it. If you hold Bitcoin in your own wallet whose keys only you know, nobody is providing a service to you and nobody needs a permit for it. That distinction is also the reason why some wallet providers rightly operate without a licence and others do not; we covered the dividing line in detail in a separate piece on when wallet apps require authorisation.
The BaFin Company Database and the MiCA Register: How to Check a Provider
The BaFin company database is the public directory of all institutions and providers to which the regulator has granted a permit or authorisation. Access is free and requires no registration, and it is the only place where you genuinely verify a German permit.
The search is unspectacular and takes a few minutes. You open BaFin's company database and search for the exact name of the company given in the imprint. If you find no match, the matter is already settled. If you find a match, you compare the address and legal form with the details on the website, character by character: a differing legal form or a different city is not a detail but the actual finding.
For providers from other EU countries, the MiCA register of the European securities regulator ESMA takes the same role. It lists authorised crypto-asset service providers from all member states, each with the authority that granted the authorisation. A provider claiming a European licence and not appearing in that register does not have one.
Three Details That Have to Match
A register hit alone is not enough. The company name in the imprint, the register entry and the domain you are currently on all have to match. The case BaFin warned about on August 24 works through precisely that gap: the name exists, the company exists, the website does not belong to it. Reputable providers therefore state their domain in official documents and actively point out imitators.
Our Own Count: Five of 24 BaFin Consumer Notices Concern Crypto
cryptoticker.io compiled this analysis itself on August 25, 2026. Method: we retrieved BaFin's “News & Warnings” overview page, loaded every consumer notice from 2026 listed there individually, and assessed for each notice whether the text itself concerns a crypto offering and whether it names an identity misuse. The general explanatory block at the end of each notice, which lists the terms as a matter of routine, was cut off for this purpose.
Objects examined: 24 consumer notices, all retrieved with HTTP status 200. Result: five of them concern crypto offerings, dated August 18, August 19 (two notices), August 24 and August 25, 2026, and therefore all within a window of eight days. Exactly one of these notices, the one on tresorbit(.)com, expressly names an identity misuse.
The overview page shows only a section of the year. The oldest entry listed there dates from May 4, 2026; notices from the months before that were not reachable through this page. The 24 are the state of that page on the day of the survey and not the annual total. The classification by notice text also has an edge to it: the warning of August 19 about the “NC Wallet” app concerns a wallet application, but its notice heading speaks only of financial services and it therefore does not fall into the crypto group under our rule.
Four More Warnings on August 24 and 25: What Sets the Cases Apart
On the same two days BaFin published four further consumer notices, and the comparison shows how different the patterns are. On auvelion(.)com the regulator states that financial and securities services as well as crypto-asset services are offered there without a permit; the operator merely appears under the designation Auvelion, with no legal form, no stated place of business and no imprint. That is the obvious case: quite simply everything is missing.
On rivolifinances(.)com the operators use the designations Rivoli S.A. and Rivoli Finances Sàrl according to BaFin and state a supposed place of business in France; the regulator's suspicion here concerns unauthorised banking business through the granting of loans. On navigatorpf(.)com the notice says the operators offer banking business and financial services without a permit and are not supervised by BaFin. The fourth notice, of August 25, concerns helvetickeystone(.)com together with emails from a similarly spelled sender address and revolves around overnight and fixed-term deposit offers.
Between the obvious case and the misused name lies a third level, which BaFin described on August 19 in connection with the “Crendel” app. A US company is named there as the developer according to the app's own statement, and by its own account the regulator has no findings as to whether that registered company actually has any connection to the app. The regulator words this more cautiously than in the Willich case, where it establishes the misuse.

How to Spot Identity Misuse on a Crypto Website
There is no reliable indicator to be drawn from the text of the website itself, because the details are correct precisely for the reason that they come from somebody else. What can be checked are the breaks between the details.
- The company name in the imprint has nothing to do with the platform's presentation in substance, for example a register-keeping or administration company behind a trading interface.
- The domain appears nowhere on the website of the company named, and conversely the platform never points to that company's original address.
- Email addresses run through a domain that resembles the official one without being identical to it. BaFin described exactly this constellation on August 25 in the case of helvetickeystone(.)com, where the sender address sat on a differing domain.
- The company is entered in the commercial register but is not listed in BaFin's company database as a provider of crypto-asset services.
- Withdrawals are tied to an additional payment, for example to a supposed tax, fee or unlocking charge. You know this pattern from our analysis of faked withdrawal demands.
The last point is the most important, because it works independently of any register check. An authorised platform never demands an advance payment in order to release your own balance.
Self-custody: hardware wallets comparedMoney Already Transferred: The Steps That Count Now
If you have deposited with a provider that BaFin now warns about, the order of steps is decisive. First you secure evidence: bank statements, transfer receipts, transaction hashes, screenshots of the platform and all correspondence. These documents are later the basis for every criminal complaint and every attempt at reimbursement, and they disappear as soon as access to the platform is switched off.
Then comes the route to your bank. With a SEPA transfer made only a few days ago, a recall can occasionally still work; with card payments a chargeback is conceivable. Both depend on deadlines, and both deadlines run from the day of payment, not from the day you become suspicious. In parallel you file a criminal complaint with the police, which is also possible online.
What regularly achieves nothing: a message to the platform's support, a demand for the money to be sent back, and above all every offer that promises recovery against an advance payment. Such offers are a business model of their own, and BaFin already warned about a website of this kind in 2026. If crypto-assets were moved in your own wallet, one more thing applies. As soon as you are under suspicion of having disclosed your access details, you move any remaining holdings to a freshly generated wallet whose keys have never been on a third-party device. Which devices are suitable for that is shown in our hardware wallet comparison.
What You Can Report to BaFin
BaFin is not an authority that recovers your money, and it does not represent individual investors. The regulator does accept tips about unauthorised business, however, and such tips are the basis for exactly the consumer notices at issue here. Reporting is therefore worthwhile even if you have suffered no loss yourself.
Distinguishing It From Phishing and Platform Series: Why This Is a Different Attack
In phishing the attacker targets your access details or your recovery phrase, that is, a secret you already possess. That applies to faked emails just as it does to the letters with a QR code that were warned about in August and that we described in our piece on wallet phishing by post. Identity misuse, by contrast, is about trust before the first deposit: you are meant to transfer voluntarily because the provider looks orderly.
The case also differs from the so-called platform series. There, many almost identical websites are operated under changing names and can be recognised by their wording and structure; we counted that structure in a separate analysis of the BaFin warnings on crypto platform series. Misusing a real company name is the more laborious route, because it works only once per victim company, but in exchange it survives a superficial check. A third variant is the plainly unlicensed app, as in the case of the BaFin warning on NC Wallet.
What the Case Means for Choosing a Provider
The practical consequence is uncomfortable but manageable: the check has to happen before the first deposit, because afterwards it prevents nothing. Two minutes in the company database cost less than any attempt at reimbursement.
Anyone who does not want to start from scratch with every new name reduces the problem through their choice of provider. A handful of trading venues authorised in the EU covers by far the greatest part of what private investors need; our comparison of the larger crypto exchanges ranks the common providers by fees and range of functions. And anyone who documents their movements cleanly anyway, for example with one of the tools from our overview of crypto tax and portfolio tools, already has the records together in the event of a loss that otherwise have to be gathered laboriously.
A final point concerns the opposite direction. Job offers are also used for unauthorised crypto business, when applicants are asked to forward payments through their own account and exchange them into crypto-assets; BaFin warned about this on August 18, and we described the pattern under the heading of the money mule trap. Anyone falling for it loses money and additionally comes into the sights of the prosecuting authorities.
BaFin Warning Over Identity Misuse: Your Key Takeaways
- Check the provider in the register before you deposit. Search for the exact company name from the imprint in BaFin's company database and compare legal form and address character by character. If you want to save yourself the search, choose a regulated crypto exchange with documented EU authorisation from the outset.
- Treat a German company name as a claim, not as proof. The case of August 24 shows that a commercial register entry and an imprint can be genuine and still belong to a different company. Compare providers by verifiable terms instead, for example through our crypto exchange comparison.
- Keep holdings you are not trading in your own custody. What sits in a wallet whose keys only you know cannot be taken from you by any unauthorised provider. Which devices are suitable and what they cost is set out in our hardware wallet comparison.
(As of August 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- BaFin Warnings 2026: 24 Crypto Platform Series With 639 Domains, and How to Check Your Provider
- EU warning list for crypto providers: 167 entries, 165 of them from Italy, none from BaFin
- BaFin Warnings in September: How to Check in Three Minutes Whether a Crypto Provider Holds Authorisation
- BaFin warns over nova-c-solutions.com: What is behind a genuine registration number
- Crypto investment fraud: when the tax office taxes phantom gains and what to check now
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 21, 2026 7:46 AM

Crypto Job Offers Using Your Own Bank Account: How the Money Mule Scheme Works and Why Money Laundering Starts With Negligence
On August 18, 2026 BaFin warned about job offers in which applicants are to pass third-party payments through their own account and exchange them into crypto-assets. Anyone taking part risks criminal proceedings for money laundering, and gross negligence is already enough.
August 11, 2026 9:18 AM

Your Crypto Exchange Is Telling You to Withdraw: How to Spot Phishing After the MiCA Deadline
Unauthorised crypto providers now have to tell their EU customers to withdraw, which leaves fraudsters an easy run with faked requests. Here is how to check in two minutes whether the message is genuine.
August 21, 2026 10:27 AM

Complaining About a Crypto Exchange: the Deadlines Article 71 MiCAR Sets and Why BaFin Will Not Decide Your Case
Authorised crypto providers have to run a formal complaints procedure, and Delegated Regulation (EU) 2025/294 sets a hard limit of two months for it. Our own analysis of the ESMA list shows at the same time that no complaints link is on file for Germany to this day.
August 21, 2026 7:17 AM

Checking a MiCAR White Paper: What the First Published MiCA Penalty Against Bitpanda Means for Investors
Austria's FMA has fined Bitpanda GmbH 70,000 euros because a crypto-asset white paper was filed late and advertised before it had been published. We explain what rights this mandatory document gives you, and called up all 972 white papers held in the ESMA register to see whether they can be reached at all.
September 15, 2026 4:12 AM

Using Hyperliquid from Germany: What Applies to Your Funds Without a MiCA Licence
Hyperliquid is not entered in any EU register as an authorised crypto-asset service provider, and for perpetual futures a MiCA licence would be the wrong paperwork anyway. Here is what that means in concrete terms for your funds, your keys and your tax return.
August 20, 2026 10:24 PM

MiCA Review: What the European Commission Could Change About the EU Crypto Rules
The European Commission has reopened MiCA for review after barely two years and is asking 86 questions covering the stablecoin interest ban, staking, lending and DeFi. Brussels is taking responses until September 30, 2026.
September 25, 2026 10:31 AM

BaFin Warning: What Happens When You Enter Your Data on an AI Crypto Platform
On September 23, 2026 BaFin warned about 39 near-identical websites presenting themselves as AI-powered crypto trading platforms. On its findings these pages take no money but pass the data left in their contact form on to unauthorized trading platforms.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
September 19, 2026 4:11 PM

MiCA Consultation Closes September 30: What to Check and Submit Before Then
The European Commission is reviewing the MiCA crypto regulation and will accept submissions until September 30, 2026 at 23:59 CEST. Staking, DeFi, lending, stablecoins and custody are all under examination, and you can take part without a lawyer.
August 6, 2026 3:05 PM

MiCA Register 2026: Only 21 of 329 Licences Are Real Exchanges
ESMA publishes the register of MiCA-authorised providers as an open file. We worked through all of it — and the result is not what the phrase “licensed crypto exchange” suggests.
July 2, 2026 8:59 PM

Binance Is Out of the EU: How to Move to a MiCA-Regulated Exchange
Binance has left the EU market. Which exchanges hold a MiCA licence, how to verify an authorisation is real, and how to move your holdings across step by step.
September 29, 2026 10:33 AM

ESMA puts reverse solicitation on its 2027 watch list: what investors need to know about exchanges without an EU licence
ESMA presented its work programme for 2027 on September 28, 2026 and made reverse solicitation a supervisory priority. What that means if your coins sit with a provider without EU authorisation, and which three steps make sense now.
August 22, 2026 10:13 AM

BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
On August 19, 2026, BaFin issued a warning about the NC Wallet app and two websites: on the regulator's findings, the unknown operators offer financial services there without authorisation. Because the wallet is custodial, it is the provider and not you who holds the key to your balance.
February 24, 2025 6:22 PM

German DekaBank Introduces Cryptocurrency Trading and Custody Services for Institutional Clients
DekaBank, managing $395 billion in assets, launches cryptocurrency trading and custody services for institutional clients, marking a significant step in integrating traditional finance with digital assets.
August 18, 2026 7:13 AM

Bitcoin Tax Reporting in Austria 2026: What Applies
Bitcoin tax reporting in Austria: which data investors can request from crypto exchanges in 2026, and when the report matters for the tax return.
October 1, 2026 7:32 AM

Starting a crypto company in Germany: legal form, BaFin licence and capital
Setting up a crypto company in Germany: which business models need BaFin authorisation under MiCA, GmbH or UG, how much capital is required and where public support is available.
September 24, 2026 1:13 AM

Solana DEX Trades Overtake the NYSE: What to Check on Swaps, Tax and Oversight
Solana's decentralised exchanges settled roughly 208 million trades in a single week and overtook the New York Stock Exchange for the first time. The figure is real, but it measures something other than the comparison suggests, and for German investors it carries tax duties that no provider takes on.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
February 18, 2024 11:00 PM

Bitget Report Unveils 250% Surge in Crypto Custodial Assets
A Bitget report recently unveiled a report showcasing a remarkable 250% surge in assets within third-party custodial accounts.
September 24, 2026 1:34 PM

Cardano Slides Below $0.24: What ADA Holders Should Check on Leverage, Liquidation and Holding Period
Cardano has given back its move above $0.25 and trades around seven percent below the high of the past 24 hours. What that means for leveraged positions, the holding period of your tranches and the buying route under MiCA.
September 24, 2026 1:24 PM

NEAR Falls Almost 8 Percent After a 62 Percent Week: What to Check on Perps, Buying Route and Holding Period
NEAR Protocol loses up to 7.9 percent on September 24, 2026 and is still more than 55 percent higher over the week. The rally was carried by a confidential perp offering via Hyperliquid, which raises questions of its own on buying route, leverage and holding period in Germany.
September 13, 2026 4:33 AM

Your Volksbank's Crypto Licence: Why You Have to Check Custody Separately
14 of the 16 newest CASP entries in the ESMA register were German cooperative banks, and each one carries order execution only. Our count of the BaFin database shows that not one of the 21 cooperative institutions is registered as a crypto custodian.
August 19, 2026 10:37 AM

Who Regulates Crypto in the US? CFTC and SEC Compared
On 20 August 2026 the new innovation advisory committee of the US derivatives regulator CFTC meets for the first time, staffed with the chief executives of Coinbase, Kraken, Gemini and Ripple. What separates the two US agencies, and why MiCA and BaFin still count for your portfolio.
September 26, 2026 10:23 AM

Trive: Client Funds Frozen - What Holders of Crypto CFDs Can Check Now
The Maltese supervisor MFSA has instructed Trive Financial Services Europe to freeze client funds; BaFin speaks of numerous affected clients in Germany. Why a crypto CFD is treated differently from a coin in your own wallet, and which steps are possible now.
September 25, 2026 4:11 AM

Bitget Hack of $351 Million: What to Check at Your Crypto Exchange Now
Bitget reports unauthorised outflows of around $351.6 million and has suspended withdrawals. For existing customers in Europe, that closes the one route MiCA had left them.
September 1, 2026 4:12 AM

USDT cashback and 7 percent on stablecoins: what the MiCA interest ban means for you
A new payment card advertises up to 10 percent cashback in USDT and up to 7 percent a year on the balance. Article 50 MiCAR explains why a provider licensed in the EU is not allowed to pay you exactly that.
January 14, 2020 12:26 AM

Can Ethereum be Converted to Cash?
Ethereum (ETH) is a prominent crypto-asset. It is a project with high trading volume and thus liquidity. It is traded across almost all exchanges – whether major or minor or centralized or not. All cryptocurrencies have a trading pair against […]
More from CryptoTicker

