Two warnings were issued on the same day in August 2026: Why do wallet services need authorization?
On August 19, 2026, German financial regulator BaFin issued a consumer warning on the same day against two self-proclaimed wallet products. One involves a website, and the other involves a website and an application that appears in mainstream app stores under its own product name. In both cases, regulators pointed out that based on the investigation results, the operator conducted business without the necessary authorization and was not subject to its supervision. In one case, the identity of the operator was unknown and was under investigation.
Both warnings are based on the same legal basis, namely Article 10 (7) of the German Crypto Market Regulation Act (KMAG). They also raise the same question-one that such warnings rarely delve into: Under what circumstances do wallets need authorization? The answer is not obvious, because the wallet software used by millions of users is not backed by any authorized company, which is completely legal. The difference is a node that is invisible from outside the application.
Two BaFin warnings on the same day: Information about wallet products released on August 19, 2026
The first warning involved a website that, according to a regulatory investigation, provided unauthorized cryptographic asset services. The second alert involved two websites and an application; according to the notice, the operator claimed to be a company established as a limited liability company (LLC) and claimed to operate the application. Names and addresses are listed in regulators 'own notices, which are freely available, and this article provides links here, but does not list specific names because this article focuses on patterns rather than individual cases.
To put this warning in the correct context, its legal significance needs to be understood. KMAG Article 10 (7) allows BaFin to publicly name a company when facts support relevant assumptions or it has been confirmed that the company is engaged in unauthorized business. The wording clearly covers both cases of suspicion and confirmation. The company's opinions must be listened to before making a decision. If the public information is subsequently discovered to be incorrect, the regulatory agency must correct the public record through the same channels. Therefore, warning is neither a verdict nor evidence collection, but a protective measure with a built-in withdrawal mechanism.
The second sentence of the same clause is even more noteworthy. It also applies to situations where the company does not actually engage in unauthorized business, but gives the public the impression that it is engaged in that business. For wallet products, this is more common in practice: an application that promises to hold and add value to a balance may fall within the scope of the clause even if it does not actually hold the balance.
MiCAR Article 3 (17): Custody means control of access
The Crypto Market Regulation Act is not an independent legal system. Its article 1 stipulates that the law aims to implement EU Regulation 2023/1114 (MiCA). Substantive definitions are all in the regulation, and one of them determines the core of the entire issue.
Article 3, paragraph 1, item 17 of the regulation defines "custody and management of cryptographic assets on behalf of customers" as: custody or control of cryptographic assets on behalf of customers, or control of access to such cryptographic assets (if applicable, in the form of a private key). This sentence contains three key points, each of which is worth reading carefully.
The first key point is the word "control". As long as the provider can control access, it is enough, and it does not need to hold crypto assets itself. The second key point is "access channels". The connection point is not the cryptocurrency itself, but the way to obtain it. The third key point is "representing customers". Persons who only hold their own balances do not keep any assets for their customers and therefore do not provide services within the meaning of this regulation.
These three key points lead to the dividing lines discussed in this article. In a wallet, if you hold the key alone and the manufacturer only provides the software, then based on the wording, this is not managed because no one is controlling it on your behalf. Conditions are met once others are able to hold or restore access.
Custody vs. unmanaged: How to tell who controls your key
The terms "trusteeship" or "non-trusteeship" do not appear in either legal article. However, as industry shorthand, they capture the differences drawn by regulations. Hosted means the provider holds access; unmanaged means you hold access alone.
In practice, you can see the difference when setting up. The first time you use it, your wallet displays a string of recovery phrases and prompts you to write them away from your device-a step that effectively puts access in your hands. Applications that simply need to log in with email and password and have never seen such phrases retain access. Words are unreliable here because the word "wallet" is unprotected and is used in both types. If you want to understand different designs, refer to the Software Wallet Comparison Guide.
Recovery Question: Why the "Forget Password" feature exposes authorization requirements
There is a simple test that clarifies the issue immediately in the vast majority of cases and takes less than a minute: Ask yourself what happens if you lose your password.
If the provider can help you restore access, then it must have access or be able to rebuild them-this is what Article 3 (17) refers to as "control". If the provider cannot and instead lets you use the recovery phrase, then the access is in your hands and the clause does not apply to this extent. A provider that emphasizes that it "has no access to your balance at all" while providing convenient recovery features is actually advocating two difficult things at the same time. This contradiction is the key point that needs to be questioned.
Article 3 of the regulation lists ten crypto asset services; custody is just one of them.
MiCAR Article 3 (16): A list of ten crypto asset services
Custody is only the first of ten services. Item 16 of Article 3, paragraph 1, details what behaviors constitute crypto asset services: custody and management of crypto assets on behalf of customers; operating trading platforms; converting crypto assets into funds; converting crypto assets into other crypto assets; executing orders on behalf of customers; placing crypto assets; receiving and delivering orders on behalf of customers; crypto asset consulting; portfolio management; and providing transfer services on behalf of customers.
This list is far more important to judging wallet applications than it appears. An application may have no problems hosting, but authorization may still be required if it provides any of the other nine activities. Each of the ten services itself triggers an authorization requirement.
In-wallet redemption: Why built-in redemption is a service in itself
The most common situation in practice is the redemption function. Many wallets that properly leave the key to the user display a button for direct redemption of a token. Depending on its technology and contract structure, this may touch on items (c),(d),(e) or (g) in the article 3 list.
For users, this means one thing: authorization issues are not for the entire application, but for each individual feature. A wallet may have no problems with its core functions, but its settlement link may provide services that require endorsement by an authorized company. At large trading platforms, the situation is different, where authorizations cover the entire operation from the beginning.
MiCAR Article 59: Who can provide crypto asset services in the EU
Article 59 (1) of the regulation stipulates an "unauthorized prohibition" clause. No person may provide crypto asset services in the EU unless that person has been authorized by a crypto asset service provider in accordance with Article 63 or is an institution listed in Article 60 (i.e. a credit institution, investment company or electronic money institution) and is allowed to provide services based on that authorization.
Therefore, there are only two legal paths and no third. Anyone who does not satisfy either of these two avenues but still provides any of the ten services is acting without authorization. No matter how carefully the software is built or how convincing the website looks, this holds true.
Registered offices and regulatory bodies in the EU: Conditions for Article 59 (2)
Paragraph 2 of the same article is rarely cited, but can be used as a quick test of reasonableness. Authorized providers must have registered offices in the Member State where at least part of their business is carried out. Its effective management must be in the EU and at least one director must reside in the EU.
If the wallet provider's legal statement only shows its company in a third country and does not provide an EU address, the conditions for authorization under Article 59 (2) are not met. This doesn't prove anything, but it's enough for people to check registration information rather than just on the surface.
Authorization depends on the joint satisfaction of multiple conditions; it is not enough to satisfy only some conditions.
Article 9 of KMAG: Measures that BaFin may take in unauthorized business
German law enforcement measures are found in Article 9 of the Crypto Market Regulation Act, titled "Interference with Unauthorized Business." According to paragraph 1, sentence 1, item 3, if crypto asset services are provided without obtaining the authorization required by paragraph 1 (a) of Article 59 of the regulation, BaFin may order the immediate cessation of business operations and prompt liquidation.
There are two details of this clause that are important to those affected. First, the powers under paragraph 1 apply not only to the company itself, but also to its shareholders, members of its governing bodies and enterprises involved in the initiation, conclusion or settlement of such business. Second, regulators can order a stop immediately when the facts are sufficient to support the assumption of unauthorized business, without waiting for evidence. Article 10, paragraph 8, also allows it to temporarily ban the business during the clarification period.
For users, this includes a disturbing but rarely explicit situation: When regulators step in and appoint a liquidator, your balance will be part of the liquidation. This is a long and uncertain process and starts from the moment the provider must stop operating.
Why warnings are issued after hearings and what this means for the timeline
KMAG Article 10, paragraph 7, sentence 3 requires companies to be heard before issuing. This hearing takes time. Therefore, there must be a period of time between the time a product appears on the market and the warning is issued that is known to regulators but unknown to the public.
This leads to the most important warning about any warning list: It can only contain what has been investigated and opinions listened to. Products that are not on the list simply mean that the release process has not yet been completed and are far from being reviewed and deemed safe. How incomplete these lists are in practice can be seen at the European level: the vast majority of ESMA's register of non-compliant providers is filled out by a single national regulatory agency. For Germany, an analysis of the BaFin encryption platform warning series also reached the same conclusion.
Gaps in corporate databases: Why missing entries don't make sense for unmanaged wallets
The standard recommendation for any provider is to consult BaFin's corporate database. This is wise advice, but there is a particularity for wallets that may weaken their effectiveness.
The Authorized Company Database lists companies that hold authorizations. Manufacturers of purely unmanaged wallets do not require authorization and therefore usually do not appear in the database. Their absence in this case is the expected result of their unauthorized activities and does not constitute a warning sign. Conversely, the absence of providers providing hosting or redemption services is a very clear signal.
Therefore, authorization questions cannot be answered based on database queries alone. A query is meaningful only if you determine in advance which category the product belongs to. This order is the true value of this article: determine the design first, check it later. The order is reversed, and blank search results can only bring you false peace of mind or false alarms.
App store listings are not authorized: Releasing apps proves what
apps are available in mainstream stores does not explain their regulatory status. Store operators check technical guidelines and formal details, which do not grant authorization under Article 59 of the Regulation and are not qualified bodies. One of the two warnings issued on August 19 explicitly involved apps, not just websites.
The same goes for ratings, downloads and a clean design look. None of these characteristics is relevant to the legal provisions discussed here. Authorization is an attribute of the company, not the product.
Distinguish security issues: Authorization is not a protection against key loss
This article should draw a line. Authorization requirements are a regulatory area rather than a statement of application technical security. Authorized custodians can be attacked, and unmanaged wallets that do not require authorization can be extremely well built.
These two questions intersect and both need to be answered. The person who holds the key is solely responsible for protecting the key. The person who handed over the key used this risk in exchange for the risk of something wrong with the custodian. Authorization concerns the second situation and has nothing to do with the first situation.
Check whether the wallet requires authorization: Summary of key points
Determine the design first and then check.
Ask the password issue: If the provider can help you restore access, it holds access channels, and escrow under Article 3, paragraph 17 is established. If it displays the recovery phrase and points to you when you lose it, the access path is in your hands. See the Software Wallet Comparison Guide for what designs exist and how to distinguish them.
Examine each feature one by one, rather than the entire application.
Article 3, paragraph 1, item 16 lists ten services, each of which itself triggers an authorization requirement. Built-in redemption is the most common situation. For providers whose authorization covers the entire operation from the beginning, this item-by-item check can be skipped; regulated crypto exchanges provide an overview.
Correctly interpret blank search results.
If the provider is not in the company database, this does not make sense for purely unmanaged wallets, but it does make sense for hosting or redemption service providers. Also check whether the registered office and regulatory body are located in the European Union as required by Article 59, paragraph 2. If you own the key, please protect it according to the design in the Hardware Wallet Comparison Guide.
Two warnings dated August 19, 2026 are available from the regulator portal, and one of them is published here. What is described there is a suspected case under Article 10, paragraph 7, of KMAG, rather than facts confirmed by the court.
(As of August 19, 2026. This article does not constitute investment advice. Price and fee structures may change; check provider terms before purchasing.)

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following