Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
On 19 August 2026 Germany’s financial regulator BaFin published two consumer notices on the same day about offerings that present themselves as wallets. One concerns a website, the other a website together with an app that appears under its own product name in the usual stores. In both cases the supervisor writes that, on its findings, the operators are active without the required authorisation and are not supervised by it. In one of the two cases it is investigating operators who are unknown.
Both notices rest on the same provision, namely Section 10(7) of the German Crypto Markets Supervision Act (KMAG). And both raise the same question, which reporting on such warnings almost always passes over: at what point does a wallet need an authorisation at all? The answer is not obvious, because millions of people use wallet software with no authorised company behind it, and that is entirely in order. The difference sits at a point you cannot see on an app from the outside.
Two BaFin warnings in one day: what was published on 19 August 2026 about wallet offerings
The first notice concerns a website on which, on the supervisor’s findings, crypto-asset services are offered without authorisation. The second concerns two websites and an app; there, according to the notice, the operators hold themselves out as a company carrying the legal-form designation LLC that is said to operate the app. Names and addresses appear in the supervisor’s own notices, which are freely accessible and linked here. This piece does not name them, because its subject is the pattern and not the individual case.
What matters for placing this in context is what such a notice means legally. Section 10(7) KMAG allows BaFin to inform the public, naming the company, where facts justify the assumption, or where it is established, that a company is conducting unauthorised business. The wording expressly covers both, the suspicion and the finding. The company must be heard before the decision, and where a publication later turns out to be wrong, the supervisor has to correct the public record by the same route. A warning is therefore neither a judgment nor a taking of evidence, but a protective measure with a built-in retraction mechanism.
Sentence 2 of the same provision is the more interesting part. It also bites where a company does not provide the unauthorised business at all but creates the public impression that it does. For wallet offerings that is the more frequent case in practice: an app promising to hold and grow a balance need not even actually hold that balance to fall within the provision.
Article 3(17) MiCAR: custody is control over the means of access
The Crypto Markets Supervision Act is not a free-standing body of rules. Its Section 1 states that it serves to implement Regulation (EU) 2023/1114, that is, MiCA. The substantive definitions sit there, and one of them decides the whole question.
Article 3(1)(17) of the regulation defines the custody and administration of crypto-assets on behalf of clients as the safekeeping or controlling of crypto-assets, or of the means of access to such crypto-assets, on behalf of clients, where applicable in the form of private cryptographic keys. That sentence contains three switches, and each one repays reading closely.
The first switch is the word controlling. It is enough that a provider has control over the means of access; it does not have to keep the crypto-assets itself. The second switch is the means of access. The point of attachment is not the coins but what gets you to them. The third switch sits in the words on behalf of clients. Anyone holding only their own balances keeps custody of nothing for a client and therefore provides no service within the meaning of the regulation.
From those three switches follows the dividing line this piece is about. A wallet where you alone hold the keys and the maker only supplies software does not fall under custody on the wording, because nobody is controlling on your behalf. As soon as somebody else can hold or restore the means of access, the condition is met.
Custodial or non-custodial: how to tell who controls your keys
The terms custodial and non-custodial appear in neither provision. As industry shorthand, though, they capture exactly the distinction the regulation draws. Custodial means the provider holds the means of access; non-custodial means you hold them alone.
In practice you spot the difference at setup. A wallet that shows you a recovery phrase on first use and prompts you to write it down away from the device is handing you the means of access with that step. An application where you log in with an email address and a password and never see such a phrase has kept the means of access. Vocabulary is no reliable guide here, because the word wallet is not protected and is used for both. Anyone wanting an overview of the designs will find one in the software wallet comparison.
The recovery question: why a forgotten-password function gives the authorisation away
There is a single test that brings immediate clarity in the vast majority of cases, and it costs less than a minute. Ask yourself what happens if you lose your password.
If the provider can give you back access, then it must hold the means of access or be able to reconstruct them. That is precisely the control in Article 3(17). If it cannot and points you to your recovery phrase, then the means of access sit with you and the provision does not bite to that extent. A provider advertising convenient recovery while stressing that it has no access whatsoever to your balances is asserting two things that are hard to hold at once. That tension is the point at which asking questions pays off.

Article 3(16) MiCAR: the ten crypto-asset services at a glance
Custody is only the first of ten items. Article 3(1)(16) lists exhaustively what counts as a crypto-asset service: the custody and administration of crypto-assets on behalf of clients, the operation of a trading platform, the exchange of crypto-assets for funds, the exchange for other crypto-assets, the execution of orders on behalf of clients, the placing of crypto-assets, the reception and transmission of orders on behalf of clients, advice on crypto-assets, portfolio management and the provision of transfer services on behalf of clients.
That list matters more for judging a wallet app than it first appears. An application can be clean on custody and still need an authorisation because it offers one of the other nine activities. Every one of the ten items triggers the authorisation requirement in its own right.
Hardware wallets comparedSwapping inside the wallet app: why a built-in swap is a service in its own right
The most frequent case in practice is the exchange function. Many wallets that correctly leave the keys with the user display a button that swaps one token directly for another. Depending on how that is structured technically and contractually, it touches items (c), (d), (e) or (g) from the Article 3 list.
For you as a user that means one thing above all: the authorisation question is not a question about the app as a whole but about each function individually. A wallet can be unproblematic at its core and still offer something at the checkout that would require an authorised company behind it. At the large trading venues the position is different, because there the authorisation covers the entire operation from the outset.
Article 59 MiCAR: who may offer crypto-asset services in the EU
Article 59(1) of the regulation frames the prohibition subject to authorisation. A person shall not offer crypto-asset services in the Union unless that person has either been authorised as a crypto-asset service provider under Article 63 or is one of the institutions named in Article 60, that is, a credit institution, investment firm or electronic money institution permitted to provide the services on the basis of that authorisation.
There are therefore two lawful routes and no third. Anyone standing on neither of them and nonetheless offering one of the ten activities is acting without authorisation. That holds regardless of how carefully the software is built or how convincing the website looks.
Registered office and management in the Union: the condition in Article 59(2)
Paragraph 2 of the same provision is rarely quoted but works as a quick plausibility test. Authorised providers must have a registered office in a Member State in which they carry out at least part of their business. Their place of effective management must be in the Union, and at least one of the directors must be resident in the Union.
Where a wallet provider’s legal notice shows only a company in a third country and gives no address in the Union, that does not fit the conditions Article 59(2) attaches to an authorisation. It is not yet proof of anything, but it is reason to check the registers rather than rely on the presentation.

Section 9 KMAG: what BaFin can order in cases of unauthorised business
German enforcement sits in Section 9 of the Crypto Markets Supervision Act, headed there as intervention against unauthorised business. Under paragraph 1, first sentence, item 3, BaFin can order the immediate cessation of business operations and their prompt winding up where crypto-asset services are offered without the authorisation required by Article 59(1)(a) of the regulation.
Two details of that provision matter to those affected. First, the powers under paragraph 1 extend beyond the company itself to its shareholders, to the members of its governing bodies and to undertakings involved in the initiation, conclusion or settlement of such business. Second, the supervisor can order cessation as soon as facts justify the assumption of unauthorised business. It does not have to wait for proof. Section 10(8) additionally allows it to prohibit the business provisionally pending clarification.
For you as a user that carries something uncomfortable which the warning notices rarely spell out: where the supervisor intervenes and appoints a liquidator, your balance is part of a winding up. That is a drawn-out process with an uncertain outcome, and it begins the moment the provider has to cease operating.
Why a warning appears only after the hearing, and what that means for the timeline
Section 10(7), third sentence, KMAG requires the company to be heard before publication. That hearing takes time. Between the moment an offering appears on the market and the moment a warning is published there is therefore necessarily a stretch in which the supervisor already knows and the public does not.
From that follows the most important caveat about any warning list. It can contain only what has already been investigated and heard. An offering not on the list is merely not the subject of a completed publication. That is a long way from having been examined and found sound. How incomplete such lists are in practice is shown by a look at the European level, where the ESMA register of non-compliant providers is overwhelmingly filled by a single national authority. For the German side, the analysis of the BaFin warnings on crypto platform series produced the same picture.
Regulated crypto exchanges comparedThe company database has a gap: why a missing entry means nothing for self-custody
The standard advice with any provider is to check BaFin’s company database. It is sound advice, but with wallets it runs into a peculiarity that can blunt it.
A database of authorised companies lists companies holding an authorisation. The maker of a pure self-custody wallet needs no authorisation and is therefore routinely absent from it. Its absence is in that case the expected consequence of its doing nothing requiring authorisation, and does not work as a warning signal. Conversely, the absence of a provider offering custody or exchange is a very clear signal indeed.
The database query alone therefore does not answer the question. It only becomes meaningful once you have decided beforehand which of the two categories the offering falls into. That order is the real yield of this piece: determine the design first, then check. Do it the other way round and an empty search result buys you either false reassurance or false alarm.
An app store listing is not an authorisation: what publishing an app proves
That an app is available in one of the large stores says nothing about its regulatory position. The store operators check technical guidelines and formal details; they grant no authorisation under Article 59 of the regulation and are not competent to do so. One of the two notices of 19 August expressly concerns an app and not merely a website.
The same goes for ratings, download counts and a cleanly designed appearance. None of those features has any counterpart in the provisions at issue here. Authorisation is a property of the company, not of the product.
Distinguishing the security question: authorisation is no protection against key loss
A closing boundary this piece should not cross. The authorisation requirement is a regulatory category and not a statement about the technical security of an application. An authorised custodian can be attacked, and a self-custody wallet requiring no authorisation can be superbly built.
The two questions run across each other, and both have to be answered. Whoever holds the keys themselves carries sole responsibility for keeping them safe. Whoever hands them over trades that risk for the risk that things go badly for the custodian. Authorisation says something about the second case and nothing about the first.
Checking whether a wallet needs authorisation: what to take away
- Determine the design first, then check. Ask the password question: if the provider can give you back access, it holds the means of access and custody under Article 3(17) of the regulation is in play. If it shows you a recovery phrase and points to you in case of loss, the means of access sit with you. Which designs exist and how they differ is set out in the software wallet comparison.
- Check each function individually, not the app as a whole. Article 3(1)(16) lists ten services, and each triggers the authorisation requirement in its own right. A built-in swap function is the most frequent case. With providers whose authorisation covers the entire operation from the outset this item-by-item check falls away; the regulated crypto exchanges offer an overview.
- Read an empty search result correctly. If a provider is absent from the company database, that means nothing for a pure self-custody wallet and a great deal for a custody or exchange offering. Check additionally whether the registered office and management sit in the Union, as Article 59(2) requires. If you hold the keys yourself, secure them along the designs from the hardware wallet comparison.
The two notices of 19 August 2026 can be retrieved from the supervisor’s portal; one of them is published here. What is described there are suspected cases under Section 10(7) KMAG and not facts established by a court.
(As of August 19, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
- Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
- Complaining About a Crypto Exchange: the Deadlines Article 71 MiCAR Sets and Why BaFin Will Not Decide Your Case
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
September 13, 2026 1:13 PM

Sparkasse Crypto Custody: Why You Get No Key to Your Bitcoin and What to Check First
From October, Sparkasse customers are to be able to buy Bitcoin and Ether inside their own banking app, with DekaBank acting as custodian. What you get is a custody position rather than a private key. What that means in practice and what you should settle before your first purchase.
September 1, 2026 10:13 AM

BaFin Crypto Knowledge Survey: Four Assumptions Owners Believe Are True
BaFin has measured what crypto owners know about their products: 57 percent of the answers were correct, 31 percent wrong. Four false assumptions come up especially often, and each of them changes your own investment decision.
September 29, 2026 10:40 AM

“We have created the essential conditions …”: bitcoin.de has stood still for three months, the MiCAR licence is missing
Bitcoin Group SE published its half-year report on September 29, 2026: trading on bitcoin.de has been idle since the end of June because the MiCAR authorisation is missing. The new platform is finished, but no launch date is set.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 21, 2026 7:17 AM

Checking a MiCAR White Paper: What the First Published MiCA Penalty Against Bitpanda Means for Investors
Austria's FMA has fined Bitpanda GmbH 70,000 euros because a crypto-asset white paper was filed late and advertised before it had been published. We explain what rights this mandatory document gives you, and called up all 972 white papers held in the ESMA register to see whether they can be reached at all.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
September 27, 2026 4:32 AM

Hester Peirce Leaves the SEC: What Now Applies to Your Custody in Germany
The most crypto-friendly voice at the US securities regulator goes on October 2, 2026, and the commission shrinks to two members. For investors in Germany it is still the European rulebook that decides, and there a deadline falls in July 2027.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
September 15, 2026 4:12 AM

Using Hyperliquid from Germany: What Applies to Your Funds Without a MiCA Licence
Hyperliquid is not entered in any EU register as an authorised crypto-asset service provider, and for perpetual futures a MiCA licence would be the wrong paperwork anyway. Here is what that means in concrete terms for your funds, your keys and your tax return.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
September 1, 2026 4:12 AM

USDT cashback and 7 percent on stablecoins: what the MiCA interest ban means for you
A new payment card advertises up to 10 percent cashback in USDT and up to 7 percent a year on the balance. Article 50 MiCAR explains why a provider licensed in the EU is not allowed to pay you exactly that.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
August 22, 2026 10:13 AM

BaFin Warns Against NC Wallet and ncwallet.net: What Users of the Wallet App Must Check Now
On August 19, 2026, BaFin issued a warning about the NC Wallet app and two websites: on the regulator's findings, the unknown operators offer financial services there without authorisation. Because the wallet is custodial, it is the provider and not you who holds the key to your balance.
August 26, 2026 7:15 AM

BaFin Warning Over Identity Misuse: When a Crypto Platform Borrows a Real German Company's Name
BaFin has been warning since August 24, 2026 about a crypto website that, according to the regulator's findings, misuses the identity of a real German company. Why the commercial register and the imprint are worthless as proof, and how to check a provider yourself in a few minutes.
February 18, 2024 11:00 PM

Bitget Report Unveils 250% Surge in Crypto Custodial Assets
A Bitget report recently unveiled a report showcasing a remarkable 250% surge in assets within third-party custodial accounts.
August 18, 2026 7:13 AM

Bitcoin Tax Reporting in Austria 2026: What Applies
Bitcoin tax reporting in Austria: which data investors can request from crypto exchanges in 2026, and when the report matters for the tax return.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
October 1, 2026 7:32 AM

Starting a crypto company in Germany: legal form, BaFin licence and capital
Setting up a crypto company in Germany: which business models need BaFin authorisation under MiCA, GmbH or UG, how much capital is required and where public support is available.
September 28, 2026 10:26 AM

Phantom Wallet and Solscan: What a Solana Transfer Really Costs and Where It Fails
A transfer on Solana costs 0.000005 SOL, a new token account ties up 0.00148844 SOL once — both values measured on-chain by us today. This practical guide shows how to set up Phantom, how to get there from the exchange, how to read Solscan and what applies for tax in Germany.
September 19, 2026 1:14 AM

Crypto investment fraud: when the tax office taxes phantom gains and what to check now
Between September 11 and 16, 2026, BaFin published thirteen consumer notices, seven of them on crypto-assets. Anyone who has paid into such a platform risks not only the loss but, in some circumstances, a tax demand on gains that never existed.
September 29, 2026 10:14 AM

387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Bitget has disclosed how the attackers reached its withdrawal systems on September 24: through a previously unknown flaw in a security product it had bought in. The second stage of the withdrawal schedule opens today at 08:00 UTC, and for the balance you keep on any exchange the case changes the arithmetic.
September 24, 2026 1:34 PM

Cardano Slides Below $0.24: What ADA Holders Should Check on Leverage, Liquidation and Holding Period
Cardano has given back its move above $0.25 and trades around seven percent below the high of the past 24 hours. What that means for leveraged positions, the holding period of your tranches and the buying route under MiCA.
More from CryptoTicker
