Skip to content

MiCA Crypto Blacklist: 165 of 167 ESMA Records Come From Italy's Consob

165 of 167 entries in ESMA's MiCA non-compliant register come from Italy's Consob. The figure exposes fragmented EU enforcement, not a map of where illegal…

3 min read How we work

165 of 167 entries in ESMA's non-compliant crypto provider register, or 98.8%, were submitted by Italy's Consob, according to the official NCASP.csv file updated on August 21, 2026. That figure does not mean 99% of Europe's illegal crypto operators are Italian. What it reveals is a striking asymmetry in how MiCA is being enforced across EU member states.

The register, sometimes called the “MiCA crypto blacklist,” is formally established under Article 110 of the MiCA regulation. ESMA collects notifications from national competent authorities and updates the file periodically. Appearing in the register means a national authority has submitted a report. Not appearing does not mean a platform is authorized or safe.

What the ESMA Register Actually Contains

The official NCASP.csv file, last updated August 21, 2026, contains 167 rows. Breaking down entries by reporting authority reveals an extreme distribution: 165 records are attributable to Italy's Consob, one to the Netherlands Authority for the Financial Markets (AFM), and one to the National Bank of Slovakia. Only three national authorities appear in the current dataset out of the 30 EEA jurisdictions.

The legal scope is more precise than the generic phrase “unlicensed operators.” Article 59 of MiCA prohibits providing crypto-asset services in the EU without authorization or without qualifying as a financial entity permitted under Article 60. Article 61 covers reverse solicitation: a third-country firm may serve a European client only when the client initiates contact entirely on their own, without any prior promotion or solicitation directed at EU residents.

What That 98.8% Figure Does Not Measure

The biggest editorial risk is treating this count as a geographic ranking of illegal crypto activity. The CSV file records which authority submitted each entry, not where the flagged entities are actually established. Across the 30 EEA jurisdictions, entries from only three countries appear. Germany, France, and 24 other national authorities do not feature as reporting authorities in this version of the dataset.

That absence does not prove those markets have no abusive operators or that their supervisors are inactive. ESMA itself notes the register is non-exhaustive, updated weekly, and reflects only what national authorities have transmitted. To read these records correctly, it helps to distinguish this non-compliant file from the ESMA register of authorized operators, which answers a different question entirely.

MiCA Blacklist: Snapshot as of August 21, 2026
Source: ESMA, NCASP.csv; analysis by SpazioCrypto
  • 167 total records
    in the register of non-compliant crypto-asset service providers.
  • 165 submitted by Consob
    98.8% of the entire ESMA file.
  • Three authorities represented
    Consob, the Dutch AFM, and the National Bank of Slovakia.

Why Consob Dominates the Register

The ESMA file doesn't explain why the distribution is so skewed. The data is consistent, though, with an Italian regulator that has been exceptionally active in using its powers against online financial abuse. By August 11, 2026, Consob had declared 1,805 financial websites blocked since July 2019, according to the regulator's own published figures. That total spans multiple categories and cannot be compared directly to the 165 MiCA CSV records, since the CSV counts entities and may attach multiple domains to a single row.

What the blocking tally does show is an active national monitoring and enforcement machine. It does not, on the other hand, mean other European regulators are idle. Procedural differences, transmission timelines, and classification methods all affect how each authority's activity is represented in the final dataset.

How to Verify Whether a Crypto Provider Is Authorized

For users, the blacklist should never function as a reverse certificate of safety. Not finding a brand in the non-compliant register provides no guarantee whatsoever. Positive verification must start from the list of MiCA-authorized CASPs, checking the legal entity name, the authority that granted the license, and the specific services that entity is permitted to offer.

You'll also need to confirm that the domain you're using actually belongs to the authorized entity, and check for any communications from your national regulator. A license obtained in one EU country can be passported across the bloc, but that doesn't remove every local obligation, as our analysis of crypto market obligations that go beyond MiCA makes clear.

The Wider Picture

MiCA created a common rulebook, but the 165-out-of-167 figure shows that enforcement visibility still depends heavily on what individual national authorities choose to report. A European register fed almost entirely by a single supervisor risks being highly informative about one jurisdiction while remaining nearly silent on the rest of the market.

The conclusion here isn't that Italy hosts almost all of Europe's illegal crypto operators. The real finding is that Europe's notification system doesn't yet deliver a consistent picture. The blacklist is useful for knowing who has been flagged. It's a weak instrument for inferring who is safe. For that, you need the positive register of authorized entities, read alongside national authority enforcement actions and checked against the most recent data available.

Consent Preferences