BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
BaFin has been warning since August 24, 2026 about a crypto website that, according to the regulator's findings, misuses the identity of a real German company. Why the commercial register and the imprint are worthless as proof, and how to check a provider yourself in a few minutes.

Germany's financial regulator BaFin issued a warning on August 24, 2026 about offerings on the website tresorbit(.)com. What is new in this notice is the addition: according to the regulator's findings, the case involves identity misuse at the expense of a real German company. The short answer for you is therefore this. A German company name, a German address and a clean legal form on a crypto website prove nothing at all. A provider is only verified once you have found it yourself in BaFin's company database.
According to BaFin, crypto-asset services are offered through the website without authorisation, specifically trading in crypto-assets. The regulator also names whose identity was used for this: Gesellschaft für Kryptoregisterführung mbH, based in Willich. BaFin states that this company has no connection to the operators of the website. Anyone who googles the company name and finds a genuine German commercial register entry has found the wrong confirmation.
The BaFin Warning of August 24, 2026: What the Regulator Said About tresorbit(.)com
The notice itself is short and consists of three statements, and every one of them matters for your own check. First: crypto-asset services are offered through the website without the authorisation required for them. Second: what is offered is specifically trading in crypto-assets. Third: there is identity misuse at the expense of the named Willich company, which has nothing to do with the operators.
BaFin bases the publication on section 10 subsection 7 of the German Crypto Markets Supervision Act. This is the provision that allows the regulator to inform the public about unauthorised crypto offerings and to name names and addresses in doing so. Such a notice is not a court decision and not a criminal conviction. It is official information about what the regulator has established. For you as an investor it is the most solid source available on an unknown provider.
What the notice does not contain is just as much part of the picture: no loss figure, no number of affected customers, no indication of how long the website has been running. Anyone quoting you such numbers on this case did not get them from BaFin.
Identity Misuse Explained: What the Term Means in Supervisory Law
Identity misuse in this context means that unknown operators use the name, the address or the register details of a genuinely existing company in order to give their own offering a respectable appearance, without that company knowing about it or being involved in it. In these cases the affected company is itself an injured party.
The difference from a freely invented shell company matters in practice. An invented company gives itself away as soon as you search for the name and find nothing. A misused name survives that first search: the company really exists, there is a commercial register entry, there is an address in Germany, and if in doubt there is even a website with a correct imprint. All of that belongs to a different firm from the one that would like to receive your money.
Why Crypto Offerings Are Particularly Exposed
The European MiCA regulation has applied in full since December 30, 2024, and anyone offering crypto-asset services in Germany needs authorisation to do so. German investors have grown used to looking for licences, and it is exactly that habit which is being exploited. An offering that lists a German company in its imprint looks more credible today than one with an address overseas. Misusing a real name is thus the answer to a regulation that works in principle.
Commercial Register, Imprint, Licence Number: Why These Three Documents Prove Nothing
The commercial register is a directory of merchants and companies registered in Germany and states that a firm legally exists. It says nothing about whether that firm holds a BaFin authorisation, and even less about whether the website using the name actually belongs to it.
The imprint works in a similar way. An imprint is a self-declaration by the website operator. Nobody checks before publication whether the company named there belongs to the operator. The same applies to licence or register numbers printed on a page: a number is a string of characters for as long as you do not look it up in the register itself.
The reliable route therefore always runs in the other direction. You do not look on the website for evidence of its own respectability. You look for the provider in the register, and then check whether the details held there match what is in front of you. Anyone using a regulated crypto exchange with verifiable EU authorisation largely avoids this problem, because the authorisation there is publicly documented and easy to find.

Crypto-Asset Service: What Requires Authorisation From 2026
A crypto-asset service is a commercial service around crypto-assets provided to a customer, such as operating a trading platform, exchanging crypto-assets for euros, executing orders or holding crypto-assets in custody for others. Anyone offering that in Germany needs authorisation from BaFin.
What you do for yourself does not fall under it. If you hold Bitcoin in your own wallet whose keys only you know, nobody is providing a service to you and nobody needs a permit for it. That distinction is also the reason why some wallet providers rightly operate without a licence and others do not; we covered the dividing line in detail in a separate piece on when wallet apps require authorisation.
Authorised and verifiable: regulated crypto exchanges comparedThe BaFin Company Database and the MiCA Register: How to Check a Provider
The BaFin company database is the public directory of all institutions and providers to which the regulator has granted a permit or authorisation. Access is free and requires no registration, and it is the only place where you genuinely verify a German permit.
The search is unspectacular and takes a few minutes. You open BaFin's company database and search for the exact name of the company given in the imprint. If you find no match, the matter is already settled. If you find a match, you compare the address and legal form with the details on the website, character by character: a differing legal form or a different city is not a detail but the actual finding.
For providers from other EU countries, the MiCA register of the European securities regulator ESMA takes the same role. It lists authorised crypto-asset service providers from all member states, each with the authority that granted the authorisation. A provider claiming a European licence and not appearing in that register does not have one.
Three Details That Have to Match
A register hit alone is not enough. The company name in the imprint, the register entry and the domain you are currently on all have to match. The case BaFin warned about on August 24 works through precisely that gap: the name exists, the company exists, the website does not belong to it. Reputable providers therefore state their domain in official documents and actively point out imitators.
Our Own Count: Five of 24 BaFin Consumer Notices Concern Crypto
cryptoticker.io compiled this analysis itself on August 25, 2026. Method: we retrieved BaFin's “News & Warnings” overview page, loaded every consumer notice from 2026 listed there individually, and assessed for each notice whether the text itself concerns a crypto offering and whether it names an identity misuse. The general explanatory block at the end of each notice, which lists the terms as a matter of routine, was cut off for this purpose.
Objects examined: 24 consumer notices, all retrieved with HTTP status 200. Result: five of them concern crypto offerings, dated August 18, August 19 (two notices), August 24 and August 25, 2026, and therefore all within a window of eight days. Exactly one of these notices, the one on tresorbit(.)com, expressly names an identity misuse.
What we could not check belongs here too. The overview page shows only a section of the year. The oldest entry listed there dates from May 4, 2026; notices from the months before that were not reachable through this page. The 24 are the state of that page on the day of the survey and not the annual total. The classification by notice text also has an edge to it: the warning of August 19 about the “NC Wallet” app concerns a wallet application, but its notice heading speaks only of financial services and it therefore does not fall into the crypto group under our rule.
Four More Warnings on August 24 and 25: What Sets the Cases Apart
On the same two days BaFin published four further consumer notices, and the comparison shows how different the patterns are. On auvelion(.)com the regulator states that financial and securities services as well as crypto-asset services are offered there without a permit; the operator merely appears under the designation Auvelion, with no legal form, no stated place of business and no imprint. That is the obvious case: quite simply everything is missing.
On rivolifinances(.)com the operators use the designations Rivoli S.A. and Rivoli Finances Sàrl according to BaFin and state a supposed place of business in France; the regulator's suspicion here concerns unauthorised banking business through the granting of loans. On navigatorpf(.)com the notice says the operators offer banking business and financial services without a permit and are not supervised by BaFin. The fourth notice, of August 25, concerns helvetickeystone(.)com together with emails from a similarly spelled sender address and revolves around overnight and fixed-term deposit offers.
Between the obvious case and the misused name lies a third level, which BaFin described on August 19 in connection with the “Crendel” app. A US company is named there as the developer according to the app's own statement, and by its own account the regulator has no findings as to whether that registered company actually has any connection to the app. The regulator words this more cautiously than in the Willich case, where it establishes the misuse.

How to Spot Identity Misuse on a Crypto Website
There is no reliable indicator to be drawn from the text of the website itself, because the details are correct precisely for the reason that they come from somebody else. What can be checked are the breaks between the details.
- The company name in the imprint has nothing to do with the platform's presentation in substance, for example a register-keeping or administration company behind a trading interface.
- The domain appears nowhere on the website of the company named, and conversely the platform never points to that company's original address.
- Email addresses run through a domain that resembles the official one without being identical to it. BaFin described exactly this constellation on August 25 in the case of helvetickeystone(.)com, where the sender address sat on a differing domain.
- The company is entered in the commercial register but is not listed in BaFin's company database as a provider of crypto-asset services.
- Withdrawals are tied to an additional payment, for example to a supposed tax, fee or unlocking charge. You know this pattern from our analysis of faked withdrawal demands.
The last point is the most important, because it works independently of any register check. An authorised platform never demands an advance payment in order to release your own balance.
Self-custody: hardware wallets comparedMoney Already Transferred: The Steps That Count Now
If you have deposited with a provider that BaFin now warns about, the order of steps is decisive. First you secure evidence: bank statements, transfer receipts, transaction hashes, screenshots of the platform and all correspondence. These documents are later the basis for every criminal complaint and every attempt at reimbursement, and they disappear as soon as access to the platform is switched off.
Then comes the route to your bank. With a SEPA transfer made only a few days ago, a recall can occasionally still work; with card payments a chargeback is conceivable. Both depend on deadlines, and both deadlines run from the day of payment, not from the day you become suspicious. In parallel you file a criminal complaint with the police, which is also possible online.
What regularly achieves nothing: a message to the platform's support, a demand for the money to be sent back, and above all every offer that promises recovery against an advance payment. Such offers are a business model of their own, and BaFin already warned about a website of this kind in 2026. If crypto-assets were moved in your own wallet, one more thing applies. As soon as you are under suspicion of having disclosed your access details, you move any remaining holdings to a freshly generated wallet whose keys have never been on a third-party device. Which devices are suitable for that is shown in our hardware wallet comparison.
What You Can Report to BaFin
BaFin is not an authority that recovers your money, and it does not represent individual investors. The regulator does accept tips about unauthorised business, however, and such tips are the basis for exactly the consumer notices at issue here. Reporting is therefore worthwhile even if you have suffered no loss yourself.
Distinguishing It From Phishing and Platform Series: Why This Is a Different Attack
In phishing the attacker targets your access details or your recovery phrase, that is, a secret you already possess. That applies to faked emails just as it does to the letters with a QR code that were warned about in August and that we described in our piece on wallet phishing by post. Identity misuse, by contrast, is about trust before the first deposit: you are meant to transfer voluntarily because the provider looks orderly.
The case also differs from the so-called platform series. There, many almost identical websites are operated under changing names and can be recognised by their wording and structure; we counted that structure in a separate analysis of the BaFin warnings on crypto platform series. Misusing a real company name is the more laborious route, because it works only once per victim company, but in exchange it survives a superficial check. A third variant is the plainly unlicensed app, as in the case of the BaFin warning on NC Wallet.
What the Case Means for Choosing a Provider
The practical consequence is uncomfortable but manageable: the check has to happen before the first deposit, because afterwards it prevents nothing. Two minutes in the company database cost less than any attempt at reimbursement.
Anyone who does not want to start from scratch with every new name reduces the problem through their choice of provider. A handful of trading venues authorised in the EU covers by far the greatest part of what private investors need; our comparison of the larger crypto exchanges ranks the common providers by fees and range of functions. And anyone who documents their movements cleanly anyway, for example with one of the tools from our overview of crypto tax and portfolio tools, already has the records together in the event of a loss that otherwise have to be gathered laboriously.
A final point concerns the opposite direction. Job offers are also used for unauthorised crypto business, when applicants are asked to forward payments through their own account and exchange them into crypto-assets; BaFin warned about this on August 18, and we described the pattern under the heading of the money mule trap. Anyone falling for it loses money and additionally comes into the sights of the prosecuting authorities.
BaFin Warning Over Identity Misuse: Your Key Takeaways
- Check the provider in the register before you deposit. Search for the exact company name from the imprint in BaFin's company database and compare legal form and address character by character. If you want to save yourself the search, choose a regulated crypto exchange with documented EU authorisation from the outset.
- Treat a German company name as a claim, not as proof. The case of August 24 shows that a commercial register entry and an imprint can be genuine and still belong to a different company. Compare providers by verifiable terms instead, for example through our crypto exchange comparison.
- Keep holdings you are not trading in your own custody. What sits in a wallet whose keys only you know cannot be taken from you by any unauthorised provider. Which devices are suitable and what they cost is set out in our hardware wallet comparison.
(As of August 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.





























