The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

BaFin Warnings in September: How to Check in Three Minutes Whether a Crypto Provider Holds Authorisation

Twelve consumer notices in ten days, five of them on crypto-asset services and two with the entry point in WhatsApp or Telegram. We evaluated all twelve notices ourselves and show the check that takes you three minutes.

Golden Bitcoin coin on a stone parapet in front of a floodlit neoclassical government building with a columned portico at night
12 min read
Share:

BaFin published twelve consumer notices on unauthorised business between September 2 and September 11, 2026. Five of them explicitly name crypto-asset services, and five of the twelve appeared on a single day, September 11. If a trading platform reached you through an advertisement, a chat group or a direct message, you can check for yourself in about three minutes whether that provider is allowed to operate in Germany at all. This article shows how, and sets out what the twelve notices actually say.

A BaFin warning is an official notice issued under the German Banking Act and the Crypto Markets Supervision Act. Its core message is almost always the same: the regulator has findings, or a suspicion, that a provider is conducting business requiring authorisation without holding that authorisation. No court ruling is attached to it.

BaFin warnings in September 2026: twelve notices in ten days

For this article we retrieved BaFin's "News & Warnungen" overview page, loaded every 2026 consumer notice linked there individually, and evaluated the opening paragraph of each one. Twelve notices were listed at the time of retrieval, and all twelve responded with HTTP status 200. cryptoticker.io compiled this evaluation itself on September 12, 2026.

The distribution by publication date: one notice on September 2, one on September 3, two on September 4, one on September 7, two on September 9 and five on September 11. September 11 is by far the densest day in the window. The notices give no reason for that, and we do not attribute one either: publication backlogs and the processing rhythms of a regulator are not visible from the outside.

The composition matters more than the timing. Seven of the twelve notices concern classic financial and securities services, fixed-term deposit offers or credit agreements. Five concern crypto-asset services, which is exactly the area this page deals with.

Crypto-asset services: five of twelve warnings concern your subject

Crypto-asset service is a legal term taken from the EU's MiCAR regulation and the German Crypto Markets Supervision Act. It covers, among other things, trading in crypto-assets on behalf of others, exchanging them for euros, holding crypto-assets belonging to others in custody, and operating a trading platform. Anyone offering one of these services commercially in Germany needs authorisation.

These five notices in the window name crypto-asset services explicitly in their first paragraph:

  • 37mh(.)com, September 2. According to BaFin's findings, the operators there offer crypto-asset services without authorisation. The regulator also notes that the website carries no valid imprint and that the supervision by BaFin claimed there does not exist.
  • rheinbridge(.)capital, September 4. There is a suspicion that unknown operators are offering financial services and crypto-asset services without the required authorisation.
  • Telegram channel "Sophia Hoffmann" and sophiahoffmann(.)icu, September 9. Here BaFin warns explicitly about a messenger channel and the bot run inside it, not only about a website.
  • schelhammer-systems(.)com, September 11. Same wording as rheinbridge: suspected financial services and crypto-asset services without authorisation.
  • sogmbh(.)com, September 11. Suspected financial and securities services as well as crypto-asset services, combined with alleged identity misuse.

Five out of twelve sounds like a minority. Measured against the fact that crypto is only one slice of the entire financial market BaFin supervises, the share is remarkably high. Anyone active in this market should treat a look at the register as routine rather than as an exception reserved for suspicious cases. If you are weighing up where to buy anyway, it helps to look at regulated crypto exchanges authorised for the European market before you open an account anywhere.

Smartphone on a dark wooden table showing a glowing group chat interface without text, a Bitcoin coin next to it
Two of the twelve notices begin not on a website but in a chat group.

BaFin company database: how to check an authorisation in three minutes

BaFin points to the same place in every one of its notices: the company database. It records which companies hold authorisation in Germany and for exactly what. Access is free and requires no account.

Step one: take the exact company name from the imprint

Search for the legal entity named in the imprint, not for the brand name shown on the home page. This is exactly where many checks fail, because brand and legal entity do not match. If an imprint is missing altogether, as BaFin notes for 37mh(.)com, the check ends there: a provider without a traceable legal entity cannot be verified by you.

Step two: check the authorisation against the right service

A hit in the database is not enough on its own. What counts is which authorisation is recorded there. An authorisation for investment broking does not cover crypto trading, and registration as a financial investment broker under the German Trade Regulation Act is no BaFin authorisation at all. So read the scope of the entry and do not settle for its mere existence.

Step three: cross-check the warning list

Finally, look at the section holding consumer notices on unauthorised business. If the name or the domain appears there, the matter is settled. If it does not appear, that means little: BaFin issues a warning only once a specific case has come to its attention. A missing warning is no seal of approval.

Identity misuse: when a real company serves as camouflage

Three of the twelve notices cite alleged identity misuse. By this BaFin means that a website uses the details of a genuinely existing, often reputable company without having any connection to it.

In the case of cptvertex(.)com, BaFin says the imprint lists a company called Vertex AG, and the register number given there belongs to Vertex Treuhand AG in the Swiss commercial register. By its own account, the regulator has no information whatsoever that this company actually has anything to do with the website. For capitalparadigm(.)com, BaFin states explicitly that there is no connection with Paradigm Capital AG, based in Grünwald. For sogmbh(.)com the same applies to Strategic Opportunities GmbH, based in Offenburg.

This finding has a practical consequence for you. The reasoning "the company is in the commercial register, so everything is in order" no longer holds. The register number can be genuine and still belong to someone who knows nothing about the website. The check only becomes reliable once you reverse the contact and call the supposed parent company on the number from its own, independently found web presence.

WhatsApp group and Telegram bot: the entry point moves into the messenger

In two of the twelve notices the starting point lies in a messenger rather than on a website. On September 9, BaFin warned about a Telegram channel and the bot "Sophia Hoffmann" run inside it, together with the associated website. A second notice on offers made in WhatsApp groups appeared the same day.

That second notice is the most detailed in the entire window, and it describes a sequence. According to BaFin, the initiators of such groups present themselves as a US company called "Pinney Investment Lab" or as the "PISI Investment Forum" and promote a supposed AI project under the name "Dual-Track Transformation Plan". The associated website claims that an application for authorisation has already been filed with BaFin and that the operation complies with German and European supervisory law. The regulator addresses this in one sentence: that does not correspond to the facts. After recruitment, those interested are asked to fill in a registration form to gain access to an external trading platform under further domains.

Two details here are useful for your own assessment. First, the claimed legitimacy rests on an invented pending application instead of an invented authorisation. An application cannot be looked up in any public register, and that is precisely what makes it so convenient as a claim. Second, the recruitment takes place in a space with no reviews, no search engine and no history. A supervisory authority never approaches investors of its own accord in a chat group.

If you want to understand the mechanics behind such approaches in more detail, our analysis of fake AML checks for crypto wallets covers a related scheme that ends with the release of a wallet instead of a bank transfer.

Crypto Markets Supervision Act and Banking Act: what BaFin bases its warnings on

The legal basis appears in the footer of each notice, and it is a useful indication of what the individual case is about. Notices on financial and securities services invoke section 37(4) of the German Banking Act. Notices on crypto-assets cite section 10(7) of the Crypto Markets Supervision Act. For sogmbh(.)com and for the Telegram channel, both provisions stand side by side, because both areas are affected.

The Crypto Markets Supervision Act is the German legislation accompanying the European MiCAR regulation. Among other things, it governs who may act as a provider of crypto-asset services in Germany and what powers the supervisor holds in doing so. The warning power in section 10(7) is interesting because it allows the regulator to inform the public on the basis of suspicion alone, that is, before proceedings have concluded. That explains the cautious language in the texts. Where BaFin has established findings, it writes "according to BaFin's findings". Where it does not, it writes "there is a suspicion".

Four of the five crypto notices in the window are phrased as suspicion, one as a finding. This gradation is more than a formality: it shows how far supervision has already progressed in each case.

Steel vault door open by a crack with massive locking bolts, darkness behind it and a single Bitcoin coin in front
Once the money has been transferred, the practical influence of the supervisor ends very quickly.

What a BaFin warning does not achieve: the limits of the list

The warning list is a rear-view mirror. It records cases that have been reported to the regulator or have come to its attention, and it does so with a delay. Between the launch of a website and a notice there are usually weeks or months in which money has already changed hands.

There is also a limit of jurisdiction. BaFin supervises the German market. For providers authorised in another EU state, the European securities regulator ESMA maintains its own register, and for crypto-asset service providers under MiCAR the European passport applies. A provider can therefore operate legally in Germany without being listed in the BaFin database as a German institution. In that case it appears in the register of its home state. Anyone who searches in only one place and finds nothing easily draws the wrong conclusion.

And finally, an authorisation says nothing about prices, service quality or creditworthiness. All it proves is that a supervisor is responsible and that rules for complaints exist. How to file such a complaint and which deadlines apply is something we described in our article on complaining about a crypto exchange under Article 71 MiCAR.

Money already transferred: which steps still help

When the check comes too late, speed counts. For a classic transfer to an account in the SEPA area, it is worth calling your own bank immediately and asking for a recall of the payment. This rarely succeeds, but it costs nothing and has a chance only in the first few hours. For a card payment, the route runs through the card issuer's chargeback procedure.

For a transfer in Bitcoin or a stablecoin there is no recall. What remains is documentation: transaction hashes, recipient addresses, chat histories, screenshots of the platform and of every payment request. These records are the basis for a report to the police and for a notification to BaFin through its consumer service. The notification will not bring your money back, but it is how a case makes it onto the warning list that others read later.

One point is easily overlooked. After such an incident, a second approach often follows, offering help in recovering the money and demanding an advance payment for it. BaFin, the Federal Criminal Police Office and the state criminal police offices point to exactly this pattern in their joint guidance on financial fraud on the internet.

Self-custody as a consequence: what should change after an incident

A more general lesson can be drawn from the twelve notices. Every one of the cases described requires money or crypto-assets to pass into the control of a third party. That is where the damage occurs, regardless of how convincing the interface looked.

Anyone holding larger amounts reduces this attack surface through self-custody. Trading then still takes place with an authorised provider, but the holdings afterwards sit on a device nobody else can access. Which devices are suitable for this and how they differ is shown in our comparison of hardware wallets. For day-to-day use, the remainder stays with an exchange whose authorisation you have checked.

Limits of this BaFin survey: what we could not check

Three things were beyond our reach. First, BaFin's overview page lists only the most recent notices; older 2026 notices sit in the archive, so the twelve notices represent a time window and no annual total. Second, we deliberately did not open the websites named, which is why we cannot say whether they were still reachable at the time of the survey. Third, we did not verify ourselves whether the operators are in fact acting without authorisation; BaFin explicitly labels this as suspicion in ten of the twelve notices.

Checking a crypto provider: what you take away

  1. Check before your first deposit, not after your first withdrawal delay. Take the legal entity from the imprint, look it up in BaFin's company database and see which service the authorisation covers. If you are still looking anyway, start with regulated crypto exchanges.
  2. Treat every approach in a messenger as a warning sign in its own right. Two of the twelve September notices began in a WhatsApp group or a Telegram channel. A claimed application for authorisation cannot be looked up anywhere and is therefore worthless as evidence. Where you can buy instead is set out in our overview of regulated trading venues.
  3. Shrink the attack surface for the next case. Keep on the exchange only what you need for trading, and move the remainder into self-custody. Our hardware wallet comparison provides the starting point.

The two original notices on the messenger cases are available from BaFin itself: the warning about the Telegram channel of September 9, 2026 and the more detailed warning about offers made in WhatsApp groups.

(As of September 12, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

More from CryptoTicker