Austria’s FMA fined Bitpanda in first MiCA enforcement action

News Team
Written by News Team

Austria’s Financial Market Authority (FMA) has fined cryptocurrency platform Bitpanda €70,000 (approx. $81,023) for breaches of the EU’s Markets in Crypto-Assets Regulation (MiCA).

The violations involved crypto-asset white paper and marketing requirements. Bitpanda reportedly failed to submit a required white paper to the FMA at least 20 working days before publication and circulated marketing material before the white paper was published.

The FMA also found that a marketing communication lacked mandatory information, including a disclaimer stating that the material had not been reviewed or approved by an EU competent authority.

The case is the first publicly disclosed MiCA enforcement action by a national EU regulator and highlights regulatory requirements for crypto firms operating under the framework.

What happened

The Austrian regulator reportedly found that Bitpanda failed to submit a required crypto-asset white paper to the FMA at least 20 working days before publication. The authority also said a marketing communication was published before the related white paper and that another communication did not include all required information.

According to the reported enforcement findings, Bitpanda distributed marketing material before the related white paper was published. In a separate communication, the company also failed to include required wording and contact information. Under MiCA, marketing communications must be clearly identifiable, fair, clear and not misleading. They must be consistent with the relevant white paper, include specified information and contain the required statement on regulatory review and responsibility for the content.

For crypto-assets covered by Title II, MiCA requires this information to be notified to the relevant authority before publication. Article 8 sets a 20-working-day notification period before publication. The FMA has also issued guidance stating that submission of a white paper starts the relevant publication and public-offering timeline.

The purpose of the timing requirement is to allow regulators enough time to receive and review the necessary data before it is released onto the market. Regulators are not required by the system to approve each standard crypto white paper prior to publishing. In pertinent circumstances, MiCA separates notification from prior regulatory clearance. Rather, the procedure produces a supervisory record that is documented.

Bitpanda’s MiCA licensing status

On 9 April 2025, the FMA issued a MiCA licence to Bitpanda GmbH under which the latter will be able to offer a variety of services related to crypto-assets, like: custodial and management services, exchange services between cryptocurrencies and fiat currencies, crypto-to-crypto exchangs, order execution in addition to crypto-transfer services. Currently, Bitpanda GmbH still remains in the FMA’s register of approved companies.

In addition, the firm was granted MiCA authorisation by Germany’s BaFin back in January 2025. According to the company spokesman, the German licence would allow Bitpanda to conduct its activities across the EU under a single regulatory framework.

By definition, an enforcement action does not imply that the business has lost its ability to operate according to the relevant regulations. In developed markets, regulators usually detect violations, impose fines and require corrective measures without ceasing business activity.

End of MiCA’s transitional period

MiCA became fully applicable on 30 December 2024; the regulator said it would assume a central role in regulating and supervising Austria’s crypto sector. It also stressed the importance of a “compliance-first” approach among supervised firms. European Securities and Markets Authority (ESMA) has been clear about the consequences after that deadline. In June 2026, it said unauthorised crypto-asset service providers must wind down their EU activities in an orderly manner after the transition period while protecting clients and reducing risks to market integrity.

In a separate statement issued in April 2025, ESMA said that any entity providing crypto-asset services to EU clients without a MiCA licence after 1 July 2026 would be in breach of EU law and would have to stop offering those services.

Next phase of EU crypto regulation

The next phase of MiCA is likely to be influenced by lessons learned during its early rollout. The European Commission’s ongoing review consultation shows policymakers are already assessing whether changes are needed. Areas such as stablecoins, cross-border supervision, market integrity, consumer protection and the regulation of new crypto business models are expected to remain key issues as the sector evolves.

For crypto companies, compliance is not a task that ends once a licence is granted. Regulatory frameworks continue to evolve through updates, interpretations and refinements as new issues emerge. Firms with governance systems that can adapt to those changes are likely to be better prepared.