Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.

On 19 August 2026 Germany’s financial regulator BaFin published two consumer notices on the same day about offerings that present themselves as wallets. One concerns a website, the other a website together with an app that appears under its own product name in the usual stores. In both cases the supervisor writes that, on its findings, the operators are active without the required authorisation and are not supervised by it. In one of the two cases it is investigating operators who are unknown.
Both notices rest on the same provision, namely Section 10(7) of the German Crypto Markets Supervision Act (KMAG). And both raise the same question, which reporting on such warnings almost always passes over: at what point does a wallet need an authorisation at all? The answer is not obvious, because millions of people use wallet software with no authorised company behind it, and that is entirely in order. The difference sits at a point you cannot see on an app from the outside.
Two BaFin warnings in one day: what was published on 19 August 2026 about wallet offerings
The first notice concerns a website on which, on the supervisor’s findings, crypto-asset services are offered without authorisation. The second concerns two websites and an app; there, according to the notice, the operators hold themselves out as a company carrying the legal-form designation LLC that is said to operate the app. Names and addresses appear in the supervisor’s own notices, which are freely accessible and linked here. This piece does not name them, because its subject is the pattern and not the individual case.
What matters for placing this in context is what such a notice means legally. Section 10(7) KMAG allows BaFin to inform the public, naming the company, where facts justify the assumption, or where it is established, that a company is conducting unauthorised business. The wording expressly covers both, the suspicion and the finding. The company must be heard before the decision, and where a publication later turns out to be wrong, the supervisor has to correct the public record by the same route. A warning is therefore neither a judgment nor a taking of evidence, but a protective measure with a built-in retraction mechanism.
Sentence 2 of the same provision is the more interesting part. It also bites where a company does not provide the unauthorised business at all but creates the public impression that it does. For wallet offerings that is the more frequent case in practice: an app promising to hold and grow a balance need not even actually hold that balance to fall within the provision.
Article 3(17) MiCAR: custody is control over the means of access
The Crypto Markets Supervision Act is not a free-standing body of rules. Its Section 1 states that it serves to implement Regulation (EU) 2023/1114, that is, MiCA. The substantive definitions sit there, and one of them decides the whole question.
Article 3(1)(17) of the regulation defines the custody and administration of crypto-assets on behalf of clients as the safekeeping or controlling of crypto-assets, or of the means of access to such crypto-assets, on behalf of clients, where applicable in the form of private cryptographic keys. That sentence contains three switches, and each one repays reading closely.
The first switch is the word controlling. It is enough that a provider has control over the means of access; it does not have to keep the crypto-assets itself. The second switch is the means of access. The point of attachment is not the coins but what gets you to them. The third switch sits in the words on behalf of clients. Anyone holding only their own balances keeps custody of nothing for a client and therefore provides no service within the meaning of the regulation.
From those three switches follows the dividing line this piece is about. A wallet where you alone hold the keys and the maker only supplies software does not fall under custody on the wording, because nobody is controlling on your behalf. As soon as somebody else can hold or restore the means of access, the condition is met.
Custodial or non-custodial: how to tell who controls your keys
The terms custodial and non-custodial appear in neither provision. As industry shorthand, though, they capture exactly the distinction the regulation draws. Custodial means the provider holds the means of access; non-custodial means you hold them alone.
In practice you spot the difference at setup. A wallet that shows you a recovery phrase on first use and prompts you to write it down away from the device is handing you the means of access with that step. An application where you log in with an email address and a password and never see such a phrase has kept the means of access. Vocabulary is no reliable guide here, because the word wallet is not protected and is used for both. Anyone wanting an overview of the designs will find one in the software wallet comparison.
The recovery question: why a forgotten-password function gives the authorisation away
There is a single test that brings immediate clarity in the vast majority of cases, and it costs less than a minute. Ask yourself what happens if you lose your password.
If the provider can give you back access, then it must hold the means of access or be able to reconstruct them. That is precisely the control in Article 3(17). If it cannot and points you to your recovery phrase, then the means of access sit with you and the provision does not bite to that extent. A provider advertising convenient recovery while stressing that it has no access whatsoever to your balances is asserting two things that are hard to hold at once. That tension is the point at which asking questions pays off.

Article 3(16) MiCAR: the ten crypto-asset services at a glance
Custody is only the first of ten items. Article 3(1)(16) lists exhaustively what counts as a crypto-asset service: the custody and administration of crypto-assets on behalf of clients, the operation of a trading platform, the exchange of crypto-assets for funds, the exchange for other crypto-assets, the execution of orders on behalf of clients, the placing of crypto-assets, the reception and transmission of orders on behalf of clients, advice on crypto-assets, portfolio management and the provision of transfer services on behalf of clients.
That list matters more for judging a wallet app than it first appears. An application can be clean on custody and still need an authorisation because it offers one of the other nine activities. Every one of the ten items triggers the authorisation requirement in its own right.
Hardware wallets comparedSwapping inside the wallet app: why a built-in swap is a service in its own right
The most frequent case in practice is the exchange function. Many wallets that correctly leave the keys with the user display a button that swaps one token directly for another. Depending on how that is structured technically and contractually, it touches items (c), (d), (e) or (g) from the Article 3 list.
For you as a user that means one thing above all: the authorisation question is not a question about the app as a whole but about each function individually. A wallet can be unproblematic at its core and still offer something at the checkout that would require an authorised company behind it. At the large trading venues the position is different, because there the authorisation covers the entire operation from the outset.
Article 59 MiCAR: who may offer crypto-asset services in the EU
Article 59(1) of the regulation frames the prohibition subject to authorisation. A person shall not offer crypto-asset services in the Union unless that person has either been authorised as a crypto-asset service provider under Article 63 or is one of the institutions named in Article 60, that is, a credit institution, investment firm or electronic money institution permitted to provide the services on the basis of that authorisation.
There are therefore two lawful routes and no third. Anyone standing on neither of them and nonetheless offering one of the ten activities is acting without authorisation. That holds regardless of how carefully the software is built or how convincing the website looks.
Registered office and management in the Union: the condition in Article 59(2)
Paragraph 2 of the same provision is rarely quoted but works as a quick plausibility test. Authorised providers must have a registered office in a Member State in which they carry out at least part of their business. Their place of effective management must be in the Union, and at least one of the directors must be resident in the Union.
Where a wallet provider’s legal notice shows only a company in a third country and gives no address in the Union, that does not fit the conditions Article 59(2) attaches to an authorisation. It is not yet proof of anything, but it is reason to check the registers rather than rely on the presentation.

Section 9 KMAG: what BaFin can order in cases of unauthorised business
German enforcement sits in Section 9 of the Crypto Markets Supervision Act, headed there as intervention against unauthorised business. Under paragraph 1, first sentence, item 3, BaFin can order the immediate cessation of business operations and their prompt winding up where crypto-asset services are offered without the authorisation required by Article 59(1)(a) of the regulation.
Two details of that provision matter to those affected. First, the powers under paragraph 1 extend beyond the company itself to its shareholders, to the members of its governing bodies and to undertakings involved in the initiation, conclusion or settlement of such business. Second, the supervisor can order cessation as soon as facts justify the assumption of unauthorised business. It does not have to wait for proof. Section 10(8) additionally allows it to prohibit the business provisionally pending clarification.
For you as a user that carries something uncomfortable which the warning notices rarely spell out: where the supervisor intervenes and appoints a liquidator, your balance is part of a winding up. That is a drawn-out process with an uncertain outcome, and it begins the moment the provider has to cease operating.
Why a warning appears only after the hearing, and what that means for the timeline
Section 10(7), third sentence, KMAG requires the company to be heard before publication. That hearing takes time. Between the moment an offering appears on the market and the moment a warning is published there is therefore necessarily a stretch in which the supervisor already knows and the public does not.
From that follows the most important caveat about any warning list. It can contain only what has already been investigated and heard. An offering not on the list is merely not the subject of a completed publication. That is a long way from having been examined and found sound. How incomplete such lists are in practice is shown by a look at the European level, where the ESMA register of non-compliant providers is overwhelmingly filled by a single national authority. For the German side, the analysis of the BaFin warnings on crypto platform series produced the same picture.
Regulated crypto exchanges comparedThe company database has a gap: why a missing entry means nothing for self-custody
The standard advice with any provider is to check BaFin’s company database. It is sound advice, but with wallets it runs into a peculiarity that can blunt it.
A database of authorised companies lists companies holding an authorisation. The maker of a pure self-custody wallet needs no authorisation and is therefore routinely absent from it. Its absence is in that case the expected consequence of its doing nothing requiring authorisation, and does not work as a warning signal. Conversely, the absence of a provider offering custody or exchange is a very clear signal indeed.
The database query alone therefore does not answer the question. It only becomes meaningful once you have decided beforehand which of the two categories the offering falls into. That order is the real yield of this piece: determine the design first, then check. Do it the other way round and an empty search result buys you either false reassurance or false alarm.
An app store listing is not an authorisation: what publishing an app proves
That an app is available in one of the large stores says nothing about its regulatory position. The store operators check technical guidelines and formal details; they grant no authorisation under Article 59 of the regulation and are not competent to do so. One of the two notices of 19 August expressly concerns an app and not merely a website.
The same goes for ratings, download counts and a cleanly designed appearance. None of those features has any counterpart in the provisions at issue here. Authorisation is a property of the company, not of the product.
Distinguishing the security question: authorisation is no protection against key loss
A closing boundary this piece should not cross. The authorisation requirement is a regulatory category and not a statement about the technical security of an application. An authorised custodian can be attacked, and a self-custody wallet requiring no authorisation can be superbly built.
The two questions run across each other, and both have to be answered. Whoever holds the keys themselves carries sole responsibility for keeping them safe. Whoever hands them over trades that risk for the risk that things go badly for the custodian. Authorisation says something about the second case and nothing about the first.
Checking whether a wallet needs authorisation: what to take away
- Determine the design first, then check. Ask the password question: if the provider can give you back access, it holds the means of access and custody under Article 3(17) of the regulation is in play. If it shows you a recovery phrase and points to you in case of loss, the means of access sit with you. Which designs exist and how they differ is set out in the software wallet comparison.
- Check each function individually, not the app as a whole. Article 3(1)(16) lists ten services, and each triggers the authorisation requirement in its own right. A built-in swap function is the most frequent case. With providers whose authorisation covers the entire operation from the outset this item-by-item check falls away; the regulated crypto exchanges offer an overview.
- Read an empty search result correctly. If a provider is absent from the company database, that means nothing for a pure self-custody wallet and a great deal for a custody or exchange offering. Check additionally whether the registered office and management sit in the Union, as Article 59(2) requires. If you hold the keys yourself, secure them along the designs from the hardware wallet comparison.
The two notices of 19 August 2026 can be retrieved from the supervisor’s portal; one of them is published here. What is described there are suspected cases under Section 10(7) KMAG and not facts established by a court.
(As of August 19, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.






























