The information provided in this article is for informational purposes only and does not constitute financial advice. Cryptocurrency investments carry a high degree of risk. Always conduct your own research.

“Not an official EBA register and appears to be forged”, BaFin says of a rebuilt EU registry

BaFin has warned about a supposed bank that pointed customers to a self-run EU register to verify its authorisation. That shifts the question for investors: no longer only whether a provider is in the register, but whether the register is real.

A brass seal stamp engraved with the Bitcoin symbol beside a red wax seal impression on laid paper
12 min read
Share:

The EBA register is the directory listing the credit and payment institutions authorised in the European Economic Area. Anyone who wants to know whether a provider really holds an authorisation looks there. That very act of looking is what a scheme targets, one the German financial regulator BaFin warned about on October 9, 2026: the operators of a supposed European bank directed prospective customers to check their authorisation in a register that sat under their own domain.

BaFin's wording is this: "The register displayed on this website is not an official EBA register and appears to be forged." It also names the address where the genuine directory sits: euclid.eba.europa.eu. The lesson is an uncomfortable one, because it demands one step more than before. Searching for a provider in the register is no longer enough. You first have to know whether the register you are looking at is real.

The BaFin Warning of October 9: a Rebuilt Register Under the Operator's Own Domain

BaFin published two consumer notices on unauthorised business that day. The first concerns offers on the websites vantex-bank(.)com and vantex-bank(.)net. According to the regulator, no credit institution by the name of Vantex Bank exists in either Germany or France. The unknown operators claimed, BaFin says, that the supposed authorisation could be verified in the "public register" of the European Banking Authority on the website euclide-eba(.)com.

That domain name is the actual trick. It sits close enough to the real address to pass at a glance, and far enough away to have been freely available for registration. Follow the provider's link and you land in a directory the provider controls, where you find, as expected, an entry. The check then confirms not the authorisation, but only that somebody can build a web page.

The second notice of the same day concerns the website vaulttrades(.)co. According to BaFin's findings, its operators offer crypto-asset services without authorisation and are not supervised by it. That information rests on Section 10(7) of the Crypto Markets Supervision Act. Both are findings by the regulator, not judgments tested in court.

Euclid, the Real EBA Register: What an EEA Entry Actually Says

The European Banking Authority, or EBA, is the EU's supervisory authority for the banking sector. Under the name Euclid it maintains a central directory to which national supervisors report the credit and payment institutions they have authorised. EEA stands for European Economic Area, meaning the EU plus Iceland, Liechtenstein and Norway. An entry there means that some national supervisor within that area has granted the institution an authorisation and passes it on to Brussels.

That directory is public and free of charge, and it sits at exactly one address. The safest way to open it is therefore the most inconvenient one: type the address into the address bar by hand instead of clicking a link a provider has sent you. A bookmark you set yourself once serves the same purpose.

An illuminated wooden door between the tall stone columns of a neoclassical government portal at night in fog
A supervisory authority has exactly one address. Type it yourself and you cannot confuse it.

Bank Register and Crypto Supervision: Two Directories That Do Not Prove the Same Thing

Here lies the second error of reasoning, and it is older than the current warning. Even a genuine entry in the EBA register says nothing about whether a house may offer crypto-asset services in Germany. The directory lists credit and payment institutions. Authorisation for the crypto business is a separate authorisation, granted nationally or under the European MiCA Regulation, and it sits in other directories.

Anyone offering banking, financial, securities or crypto-asset services in Germany needs BaFin's authorisation to do so. The obligations attached to it and the deadlines applying to providers in the EU are set out at length in our overview of the MiCA licensing obligations for crypto companies. For an investor, the reverse is what counts above all: a provider advertising a banking licence has not thereby demonstrated any crypto authorisation, and the same holds the other way round.

If you want to avoid the detour through registers altogether, the direct route remains: houses whose authorisation is established in any case. Which platforms operate under supervision in Germany is set out in our comparison of regulated crypto exchanges.

For Germany there is exactly one competent body, and that is BaFin's company database. It lists the institutions to which the German regulator has granted an authorisation. Three steps are enough, and none of them runs through a page belonging to the provider.

First: open the database through an address you typed yourself or saved as a bookmark. Second: search for the full company name, not the brand name of the app or the domain. Third: compare what is listed there with what the provider claims. Registered office, legal form and the type of permitted business all have to match. If a house is not listed, that does not automatically mean something is wrong, because providers from other EU states can operate under the European passport. It does mean the authorisation does not come from Germany and that you have to keep looking.

What that comparison looks like in practice, and how a missing authorisation can be spotted in a few minutes, we worked through in September against the warnings of the time: how to check in three minutes whether a crypto provider holds an authorisation. The procedure still applies unchanged. All that is new is the step before it, namely the question of whether the checking body itself is genuine.

Seven of Thirteen Warnings Concern Crypto Assets: the Figures From Eleven Days

How often the crypto business features in these warnings can be counted. Between September 29 and October 9, 2026, BaFin published thirteen consumer notices on unauthorised business. Seven of them explicitly name crypto-asset services, five rest on the Crypto Markets Supervision Act and ten on the Banking Act. The first nine days of October alone account for nine of the thirteen notices.

More interesting than the total is how the methods are distributed. Five of the thirteen notices involve identity abuse: somebody poses as a real, genuinely supervised company and uses its name or registration number. In exactly one of the thirteen, by contrast, a forged register appears, and that is the Vantex notice of October 9. On the pattern where the registration number is real and the sender is false, we described the nova-c-solutions.com case: what lies behind it when the registration number is genuine.

From the Borrowed Company Name to the Rebuilt Register: the Next Stage of the Method

Between those two variants lies a difference that changes everything about the check. Borrow somebody else's identity and you stay vulnerable: the number belongs to another firm, the name does not match the website, the registered office is wrong. Rebuild the register yourself and you escape that very comparison. What stands there is then the name the website carries, with the registered office the website names, and with a number nobody else ever issued.

A forgery that supplies the verification step along with itself is therefore harder to detect than one that merely makes an assertion. Our assessment: for readers, this shifts attention from the question "is the provider in the register?" to the question "how did I get into this register?". The evidence sits in the notice itself, in which BaFin classifies the displayed directory as apparently forged and places the genuine address beside it. Against that stands the fact that this case is so far an isolated one: one of thirteen matters in eleven days. It only becomes a method once the blueprint is repeated. That it is cheap argues it will be.

A brass balance scale with two near-identical paper documents bearing embossed seals in its two pans
Two directories can look identical. Only one of them is run by an authority.

Recovery Scam: the Method Involving Recovered Crypto Holdings

In the same notice, BaFin records that the supposed bank may also be used for what is known as a recovery scam. In it, perpetrators approach previous victims of fraud again and hold out the prospect of recovering lost money or crypto holdings. For crypto investors this is the most dangerous variant, because it targets precisely those people who have already lost money and whose loss is publicly traceable on a blockchain.

The sequence follows a fixed pattern, according to the regulator. First a copy of an identity document is demanded, supposedly for identification. The perpetrators then use those copies for further offences. Next, payment of supposed fees or taxes is made a condition of the payout. No payout follows. BaFin reports that people who have lost no money at all are now being approached too, in that case under the pretext of a gift or a grant. A genuine authority demands no advance payment for the recovery of assets, and a reputable body does not ask for a copy of your ID by email.

That BaFin may publish such notices at all is set out in law. For the Vantex notice it relies on Section 37(4) of the Banking Act, and for vaulttrades(.)co on Section 10(7) of the Crypto Markets Supervision Act. The KMAG is the German act that supplements the European MiCA Regulation and governs the supervision of crypto-asset service providers. What role it plays in the warnings of recent weeks we broke down here: five of nine BaFin warnings rest on the Crypto Markets Supervision Act.

In practice that means a BaFin publication is not a criminal verdict but information for the market. Such a notice records that the regulator does not supervise a company and that, according to its findings, the company conducts business requiring authorisation. For practical purposes that is entirely sufficient, because without an authorisation none of the protective mechanisms attached to one exist either.

Money With an Unauthorised Provider: Deposit Guarantee Does Not Apply Here

That is where the actual damage lies. At an authorised institution in the EU, bank deposits are protected by law up to 100,000 euros per customer. That protection attaches to the authorisation, not to the company name, and certainly not to an entry in a directory somebody runs themselves. A house without an authorisation belongs to no protection scheme.

For crypto assets there is the added point that they fall outside deposit guarantee in any case, even with an authorised provider. There, supervision protects differently, through requirements on custody and on the segregation of client holdings. Where the authorisation is missing, those requirements are missing too. What then remains is the civil route against operators who are regularly listed as unknown in BaFin's notices. A total loss is the normal outcome in such cases, not a risk at the margin.

The same logic will meet you in other methods wearing other disguises, incidentally. How fraudsters invent a supposed mandatory check in order to obtain wallet approvals is shown in our piece on the fake AML check for crypto wallets.

EBA Register: Two Addresses Decide Whether a Licence Is Real

In the end it takes no long checklist, but two self-typed addresses and the willingness not to follow a convenient link.

  1. Check the authorisation where you went yourself. For Germany that is BaFin's company database, and for the EEA the register at euclid.eba.europa.eu. If you would rather save yourself the search, start with houses whose authorisation is established: comparison of regulated crypto exchanges.
  2. Withdraw your balance while you still can. With a provider that has no authorisation, every day is a day too many. If you do not want to leave your coins with a third party, hold them yourself: hardware wallets compared.
  3. Never pay in advance to get at your own money. Fees, taxes or deposits as a condition of a payout are the hallmark of the recovery scam. For a fresh start with an authorised provider, the exchange comparison helps.

The two notices in question can be read at the regulator itself: the warning about the supposed Vantex Bank.

(As of October 9, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)

Frequently asked questions about the EBA register

Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.

Related articles

Which topics should we dive deeper into?

Select what genuinely interests you. Your picks feed directly into our editorial planning.

Crypto news that's actually worth your time.

Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.

Subscribe

More on this topic

View All

More from CryptoTicker