The Austrian Financial Markets Authority (FMA) imposed a fine of Euro70,000 on the encryption platform Bitpanda for violating white paper disclosure and marketing rules under the EU Regulation on the Regulation of Encrypted Asset Markets (MiCA). This was also the first case of final penalties for the MiCA that was made public by the FMA, indicating that the relevant law enforcement was in the landing phase after the end of the EU transition period.

The White Paper was not submitted on time

According to the FMA bulletin, Bitpanda did not submit the required white paper on encrypted assets to the competent authority at least 20 working days before the white paper was made public. This time requirement is part of the MICA disclosure system.

The regulator also noted that Bitpanda had distributed relevant marketing materials prior to the White Paper, which constituted another violation.

Lack of required explanation for marketing materials

FMA states that another marketing material involved did not state that the content had not been reviewed or approved by the competent authority, nor did it state explicitly that the responsibility for the content lay with the encrypted asset service provider.

The contact information for this material is also incomplete and lacks telephone numbers and e-mails. All of the above issues were found to be incompatible with the requirements of the MiCA for marketing communication.

  • Fine: Euro70,000
  • Type of procedure: accelerated procedure
  • Status of penalties: decision in force

MiCA law enforcement into a new phase

The penalty was issued shortly after the end of the final EU MiCA transition period. As of 1 July, encryption companies that had previously relied on the old registration systems of member States had to be transferred to the EU Unified Delegation Framework.

MICA places governance, customer asset protection, information technology security and information disclosure requirements on the services providers of encrypted assets, such as exchanges, brokers and custodians. Once an enterprise is authorized in a member State, the relevant services can be provided in other EU countries through the Passport Mechanism.

TRM Labs had previously indicated that, as of 1 July, only 281 of the 1343 recognized encryption service providers in the European Economic Area had completed the MiCA authorization and 1062 had not been approved. The introduction of public penalties by regulatory bodies also means that compliance reviews are shifting from the licensing phase to continuous enforcement.

Bitpanda has a MiCA license plate.

It is worth noting that Bitpanda had previously obtained a licence for MiCA. Reports indicate that the company, which is based in Vienna, was authorized by the German Federal Financial Supervisory Authority in January 2025 to operate in the region through the EU passport regime.

By May 2026, Bitpanda had also held MiCA licences in Germany and Malta and provided encryption infrastructure services to other financial companies. This Austrian sanction is directed at compliance with the white paper and marketing materials identified by FMA and does not change the fact that it has been authorized.

Additional information:The new MiCA application is also currently being processed by the FMA of Austria. Bitget EU submitted its application to the Agency on 17 June, and plans to use Vienna as the European headquarters.