The German Federal Financial Supervisory Authority (BaFin) issued twelve consumer warnings: Risks of unauthorized business and crypto asset services
From September 2 to September 11, 2026, the German Federal Financial Supervisory Authority (BaFin) issued twelve consumer warnings about unauthorized business. Five of them explicitly mention crypto asset services, and five of these twelve were released on September 11. If you reach a trading platform through advertisements, chat groups or private messages, you can verify for yourself whether the provider is allowed to operate in Germany in approximately three minutes. This article will introduce specific operating methods and elaborate on the specific contents of these twelve warnings.
Nature and Release of BaFin Alerts
BaFin Alerts are official notices issued under the German Banking Act and the Crypto Market Supervision Act. Its core message is almost always the same: regulators have discovered or suspected that a provider is conducting business that requires authorization without authorization. Such warnings are not accompanied by court decisions.
Warning Statistics for September 2026
This article searched BaFin's "News and Warnings" overview page, individually loaded all content linked to the 2026 consumer warnings, and evaluated the opening paragraph of each warning. A total of twelve warnings were listed during the search, and all returned an HTTP status code of 200. Cryptoticker.io completed this evaluation on September 12, 2026.
Distribution by release date: 1 case on September 2, 1 case on September 3, 2 case on September 4, 1 case on September 7, 2 case on September 9, and 5 case on September 11. September 11th is the most intensive day for releases during this period. The warning does not explain the reason, and we have no intention of attributing it: the regulatory body's publishing backlog and processing rhythm cannot be seen from the outside.
Composition content is more important than release time. Of the twelve warnings, seven involve traditional financial and securities services, time deposit discounts or credit agreements. The fifth involves cryptographic asset services, which is the area of focus of this article.
Crypto asset services: Five of the twelve warnings focus on your topic
"Crypto asset services" is a legal term derived from the EU MiCAR regulations and the German Crypto Market Supervision Act. It includes trading crypto assets on behalf of others, converting them into euros, hosting crypto assets belonging to others, and operating trading platforms. Anyone providing one of these services commercially in Germany requires authorization.
The following five warnings explicitly name crypto asset services in the first paragraph:
- 37mh (.) com, September 2: According to BaFin's findings, operators there used crypto asset services without authorization. The regulator also pointed out that the website does not have a valid imprint (legal statement/ Impressum) and that there is no claim to be supervised by BaFin.
- rheinbridge(.) Capital, September 4: There are doubts that unknown operators are providing financial services and crypto asset services without the necessary authorizations.
- Telegram channels "Sophia Hoffmann" and sophiahoffmann(.) icu, September 9:BaFin expressly warns a telegram channel and the robots running within it, not just websites.
- schelhammer-systems(.) com, September 11: Worded the same as Rheinbridge: Suspected of providing financial services and crypto asset services without authorization.
- sogmbh(.) com, September 11: Suspected of financial and securities services and crypto asset services, accompanied by identity theft charges.

Five of the twelve sounds like a minority. But considering that crypto assets are only part of the overall financial market that BaFin supervises, this proportion is quite high. Anyone active in this market should view checking the registry as a routine practice rather than just an exception for suspicious situations. If you are still weighing where to buy, it is recommended to check the regulated crypto exchanges for European markets before opening any account.
Two alerts start in chat groups rather than websites
BaFin's corporate database: Three-minute verification of authorizations
BaFin points to the same place in all of its alerts: the company database. The database records which companies have authorizations in Germany and the specific scope of business. Access is free and no account registration is required.
Step 1: Get the exact company name from Imprint
Search for the legal entities listed in the seal, not the brand names displayed on the home page. Many inspections fail precisely because brand names do not match legal entities. If Imprint is completely missing (such as BaFin for 37mh(.) com), verification terminates: providers without a traceable legal entity cannot be verified by you.
Step 2: Check authorization for the correct service
Critical hits in the database are not enough. The key is what kind of authorization is recorded. The investment broker authorization does not cover crypto transactions, and registering as a financial investment broker under German trade regulations does not constitute a BaFin authorization. Therefore, please read the scope of the entry and don't just settle for its existence.
Step 3: Cross-check the list of warnings
Finally, review the section that contains warnings for unauthorized business consumers. If the name or domain name appears there, the problem is resolved. If it doesn't appear, it doesn't mean much: BaFin only issues warnings when a specific case comes to its attention. Missing warnings are not seals of approval.
Identity theft: When real companies act as cover
Three of the twelve warnings cite so-called identity theft. BaFin defines this as: the website uses details of a real, usually reputable company, but has no connection to that company.
In cptvertex(.) In the case of. com, BaFin stated that Imprint listed a company named Vertex AG and the registration number given belonged to Vertex Treuhand AG in the Swiss Commercial Register. According to regulators, they have no information at all to suggest that the company actually has any relationship with the site. For capitalparadigm(.) com, BaFin made it clear that it has no affiliation with Paradigm Capital AG in Grünwald. For sogmbh(.) com, also applies to Strategic Opportunities GmbH in Offenburg.
This finding has practical consequences for you. The reasoning that "the company is in the business register, so everything is normal" no longer holds true. The registration number may be real, but it still belongs to someone who knows nothing about the site. Verification becomes reliable only when you contact back and dial the so-called parent company's phone number obtained from an independently found network presence.
WhatsApp groups and Telegram bots: Portal moved to instant messaging software
Among the twelve warnings, two start from the instant messaging software rather than the website. On September 9, BaFin warned a Telegram channel and the robot "Sophia Hoffmann" running inside it, as well as related websites. There was a second warning on the same day regarding quotes provided in WhatsApp groups.
The second alert is the most detailed in the entire window and describes a sequence. According to BaFin, the initiators of such groups call themselves an American company called "Pinney Investment Lab" or "PISI Investment Forum" and promote a so-called AI project under the name of a "dual-track transformation plan." The relevant website claims that it has submitted an authorization application to BaFin and that its operations comply with German and European regulatory laws. Regulators responded with one sentence: This is inconsistent with the facts. After recruitment, interested people are required to fill out a registration form in order to gain access to external trading platforms under other domain names.
Here are two details that will help you assess yourself. First, the claimed legitimacy is based on fictitious pending applications rather than fictitious authorizations. Applications cannot be found in any public registry, which is what makes them so convenient as a declaration. Second, hiring takes place in a closed space with no reviews, search engines and history. Regulators will never proactively reach out to investors in chat groups.
If you want to understand in more detail the mechanisms of such methods, our analysis article AML checks for counterfeit cryptocurrency wallets covers related scenarios that lead to wallet release rather than bank transfers.
Crypto Market Supervision Law and Banking Law: Legal Basis for BaFin Warnings
The legal basis appears in the footer of each warning, which is a useful indication of the nature of the case. The warning regarding financial and securities services invokes Section 37(4) of the German Banking Act. The warning about crypto assets invokes Article 10(7) of the Crypto Market Supervision Act. For sogmbh(.) com and Telegram channels, these two regulations exist side by side because both areas are affected.
The Crypto Market Supervision Act is German legislation that complements European MiCAR regulations. These include who can act as a crypto asset service provider in Germany and the powers regulators have in the process. The right of warning in section 10(7) is interesting because it allows regulators to inform the public based solely on suspicion, i.e. before the end of the process. This explains the cautious language in the text. Where BaFin has made discoveries, it will write "Based on BaFin's discoveries." If not, it will write "Suspicion exists."
Four of the five encrypted warnings in the window are expressed in the language of suspicion and one is expressed in the language of discovery. This ranking is not just formal: it shows the extent to which regulatory progress has been made in each case.

Once funds are transferred, the actual influence of regulators quickly wanes
What BaFin warnings fail to achieve: Limitations of lists
The warning list is a rear-view mirror. It records cases that have been reported to or brought to the attention of regulators, with delays. There are usually weeks or months between the launch of a website and the issuance of an alert, during which time funds have changed hands.
Jurisdiction also has limitations. BaFin regulates the German market. For providers authorized in other EU countries, the European Securities Market Regulation Authority (ESMA) maintains its own registry, while for crypto asset service providers subject to MiCAR, the European passport system applies. Therefore, providers can legally operate in Germany without being listed as German institutions in the BaFin database. In this case, it appears in the registry of the country. Anyone who searches in one place and cannot find anything can easily draw wrong conclusions.
Finally, authorization does not indicate price, service quality or credit status. It only proves that regulatory bodies are responsible and complaints rules exist. How to file such complaints and the applicable deadlines are described in our article on complaints against crypto exchanges under MiCAR Article 71.
Funds have been transferred: What steps are still in effect
When verification is too late, speed is crucial. For classic SEPA regional account transfers, it is worth calling your bank immediately and requesting a recall payment. This is rarely successful, but the cost is zero and the opportunity is only available in the first few hours. For card payments, the route is through the issuing bank's refusal process.
There is no recall function for Bitcoin or stablecoin transfers. What remains is documentation: transaction hashes, receiving addresses, chat history, platform and screenshots of each payment request. These records are the basis for reporting cases to the police and notifying BaFin through its consumer service. A notice does not allow you to withdraw funds, but it is a way to put the case on a warning list that others will later read.
One point is easy to overlook. After such incidents, the second method is often followed, providing assistance in recovering funds and requiring up-front fees. BaFin, the Federal Criminal Police Office and the State Criminal Police Offices point out this pattern in their joint guide on Internet financial fraud.
Self-custody as a consequence: What changes should be made after an incident
A more general lesson can be drawn from the twelve warnings. Each case described requires funds or crypto assets to flow under the control of a third party. No matter how convincing the interface may seem, the damage occurs there.
People who hold large amounts of assets can reduce this attack surface by self-hosting. Transactions are still conducted with authorized providers, but subsequent positions are stored on devices that no one can access. Which devices are suitable for this purpose and how they differ are shown in our hardware wallet comparison. For daily use, the rest remains at the exchange where you have checked for authorization.
Limitations of this BaFin investigation: What we failed to verify
There are three things that are beyond our capabilities. First, BaFin's overview page only lists recent warnings; older 2026 warnings are on file, so these twelve warnings represent a time window rather than an annual total. Secondly, we deliberately did not open the named websites, so we cannot say whether they would still be accessible at the time of the investigation. Third, we did not personally verify whether the operator was indeed acting without authorization;BaFin clearly marked this as suspicion in ten of the twelve warnings.
Checking crypto providers: Points you should take away
Check before the first deposit, not after the first withdrawal is delayed.
Get the legal entity from Imprint, look it up in the BaFin company database, and check the scope of services covered by the authorization. If you are still looking, start with an overview of regulated trading venues.
Treat each method in instant messaging software as a separate warning sign.
Two of the two warnings in September started in WhatsApp groups or Telegram channels. The purported authorization application is nowhere to be traced and is therefore of no value as evidence.
Narrow down the attack area for the next case.
Keep only the funds needed for the transaction on the exchange and transfer the rest to self-custody. Our hardware wallet comparison provides a starting point.
Two original warnings about instant messaging cases are available from BaFin itself: a warning about the Telegram channel on September 9, 2026, and a more detailed warning about quotes provided in WhatsApp groups.
(As of September 12, 2026. This article does not constitute investment advice. Price and fee structures are subject to change; please check terms with your provider before purchasing.)

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following