CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Bitpanda Fined Under MiCA: What Austria's First Published Penalty Means for Crypto Firms

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Bitpanda Fined Under MiCA: WhatAustria's First Published Penalty Meansfor Crypto Firms

Austria's Financial Market Authority (FMA) has fined Bitpanda €70,000 (approximately $82,000) for breaching the EU's Markets in Crypto-Assets Regulation, marking the regulator's first publicly issued final decision under MiCA. The penalty is procedural in nature, covering white paper notification timing and marketing disclosure failures, but its significance extends well beyond the fine amount. It demonstrates that national competent authorities are now actively publishing MiCA enforcement decisions, setting a precedent that compliance teams across the EU cannot ignore.

Bitpanda Fined Under MiCA: What Austria's First Published Penalty Means for Crypto Firms

What the FMA Found

The Austrian regulator identified three distinct breaches, all relating to MiCA's disclosure and marketing obligations rather than to any underlying financial misconduct or customer harm.

White paper notification failure

MiCA requires crypto-asset issuers to submit their white paper to the relevant national competent authority at least 20 working days before publication. The FMA concluded that Bitpanda did not meet this advance notification deadline. The requirement exists so regulators have a structured window to review disclosures before they reach the public, even though MiCA does not require prior approval of white papers in the way a securities prospectus requires approval.

Marketing communications published prematurely

Bitpanda also distributed a marketing communication before the required white paper had been published. Under MiCA, marketing materials must not precede or substitute for the white paper. The sequencing rule is explicit: the white paper comes first, and any accompanying promotional content must be consistent with it and follow its publication.

Missing mandatory disclosures

A separate marketing communication omitted several disclosures that MiCA mandates. Specifically, it did not state that the material had not been reviewed or approved by a competent authority, and it did not make clear that the crypto-asset provider bore sole responsibility for the contents. The communication also lacked a required telephone number and email address. These are not optional formalities; they are prescribed disclosure items whose absence constitutes a direct breach of the regulation.

Bitpanda's Response

Bitpanda confirmed to media that the issues were limited to the timing and formal requirements around white paper and information document publication. The company stated that customer funds and platform security were unaffected and that no customers suffered financial harm as a result. Bitpanda said it corrected the issues after receiving notice from the FMA and chose a swift, consensual resolution of the proceedings. The decision is now final.

The cooperative approach likely contributed to the outcome. A consensual conclusion is a recognised procedural path in Austrian administrative law, and regulators across the EU have indicated that prompt remediation and transparency are factors they weigh when determining penalties.

Why This Enforcement Action Matters for MiCA Compliance

The fine amount, €70,000, is modest relative to the potential penalties MiCA allows. What matters is the publication. National competent authorities are not obliged to publish every decision, and the FMA's choice to do so sends a clear signal that procedural MiCA breaches will become part of the public record. Published decisions create reputational exposure and, in some cases, can affect a firm's ability to passport services across EU member states.

MiCA's white paper regime is not self-certifying

A common misconception among issuers is that MiCA's white paper regime is lighter than a traditional prospectus regime because it does not require prior regulatory approval. That is true in the narrow sense: the regulator does not formally sign off on the document before it is published. But the 20-working-day advance notification requirement is mandatory, and failure to observe it is a breach regardless of the quality of the white paper itself. The FMA's decision makes that unambiguous.

Marketing materials carry their own compliance obligations

The finding that a marketing communication was distributed before the white paper is a reminder that marketing sign-off cannot be treated as a separate, informal process. Under MiCA, the sequencing between white paper publication and marketing distribution is a regulatory requirement, not a best-practice recommendation. Similarly, the specific disclosure text that must appear in marketing materials is prescribed, and its omission is an independent breach.

The first published decision will not be the last

Austria has now established a public enforcement record. Other national competent authorities, including those in larger markets such as France, Germany, and the Netherlands, are running their own MiCA supervisory programmes. The likelihood is that more published decisions will follow, potentially covering a wider range of MiCA obligations including own funds requirements, custody rules, and conflict-of-interest policies. Compliance teams should treat this Austrian decision as the opening marker of an active enforcement landscape, not an isolated event.

Accounting and Reporting Implications

For accounting firms and CFOs advising crypto-asset businesses, the Bitpanda penalty creates several immediate considerations.

Provisions and contingent liabilities

Any EU-regulated crypto firm that has not completed a formal MiCA compliance gap assessment should consider whether a provision or contingent liability disclosure is warranted in its financial statements. Under IAS 37, a provision is recognised when a present obligation exists, an outflow of resources is probable, and a reliable estimate can be made. Where a firm knows of a procedural gap, that threshold can be closer than many finance teams assume. The FMA decision provides a concrete benchmark for calibrating what an authority considers a sanctionable breach.

Internal controls and the compliance calendar

The white paper notification deadline is a dated, trackable obligation. It belongs in the compliance calendar alongside other regulatory deadlines, with ownership assigned and evidence retained. Digital asset accounting software and broader compliance management tools used by firms should be configured to flag white paper submission windows well in advance, not on the day of intended publication. The same applies to the marketing review process: a documented sign-off checklist confirming that mandatory disclosures are present should be a standard step before any MiCA-regulated marketing material is distributed.

Audit and assurance considerations

External auditors reviewing crypto-asset businesses operating under MiCA should now treat white paper notification timelines and marketing disclosure completeness as areas warranting specific inquiry. The FMA decision establishes that these are live supervisory concerns, which shifts them from theoretical risk to documented precedent. Engagement teams may wish to request evidence of advance notification submissions as part of their regulatory compliance testing.

Passporting risk

MiCA allows authorised crypto-asset service providers to passport their services across EU member states. A published enforcement record in one jurisdiction can attract scrutiny from host-state regulators in others. CFOs and compliance officers at firms with cross-border EU operations should factor reputational and regulatory spillover risk into their ongoing risk assessments. The same logic applies to firms seeking new authorisations: a history of published enforcement decisions is likely to feature in the scrutiny applied by any national competent authority reviewing an application.

Practical Steps for Compliance and Finance Teams

The FMA's action against Bitpanda points to a short list of concrete actions that compliance and finance teams at EU crypto firms should address now.

Audit your white paper workflow

Map the end-to-end process from the decision to issue a crypto asset to the publication of its white paper. Identify where the 20-working-day notification window is tracked, who owns the submission, and what evidence is retained. If this workflow does not exist as a formal documented process, create one.

Review all live marketing materials

Check every current marketing communication associated with MiCA-regulated crypto assets against the prescribed disclosure requirements. Confirm that the mandatory text about competent authority review, issuer responsibility, and contact details is present and correctly worded. Archive evidence of the review.

Establish a sequencing control

Implement a control that prevents any marketing material from being distributed until the corresponding white paper has been published and the advance notification period has elapsed. This is a sequencing gate, not a content gate, and it needs to be operationalised in whatever workflow system governs marketing approvals.

Update your risk register

Add MiCA procedural compliance, specifically white paper timing, marketing sequencing, and disclosure completeness, as named risks in the firm's regulatory risk register. Assign likelihood and impact ratings informed by the Bitpanda precedent, and document the controls in place to mitigate each risk.

For broader context on how EU regulators are approaching crypto licensing and AML obligations, see our analysis of what Ireland's AML strategy means for crypto accounting firms and CFOs and the MFSA warning against DistributeX and what unlicensed crypto activity means for compliance teams.

Bitpanda Fined Under MiCA: What Austria's First Published Penalty Means for Crypto Firms

Frequently Asked Questions

What specific MiCA rules did Bitpanda breach?

The FMA identified three breaches: failing to notify the regulator of its white paper at least 20 working days before publication, distributing a marketing communication before the white paper was published, and omitting mandatory disclosures from a marketing communication, including statements about regulatory review status, issuer responsibility, and required contact details.

Does the fine mean Bitpanda's licence or authorisation is at risk?

Based on the published information, no. The FMA's decision is final and the case has been concluded consensually. The breaches were procedural, and Bitpanda confirmed it remediated the issues after receiving notice. There is no indication from the regulator that authorisation has been suspended or that further action is pending.

What is the 20-working-day notification requirement under MiCA?

MiCA requires that before a crypto-asset white paper is published, the issuer must notify the relevant national competent authority at least 20 working days in advance. The regulator uses this period to review the document and may request changes. It is not a formal approval process, but the notification deadline is mandatory and its breach is sanctionable, as this case confirms.

Should our firm's financial statements reflect potential MiCA compliance risk?

Potentially, yes. Under IAS 37, where a firm has a present obligation arising from a past event, where an outflow is probable, and where the amount can be reliably estimated, a provision should be recognised. Where the conditions for a provision are not fully met but a material outflow is possible, a contingent liability disclosure is required. Any known MiCA procedural gap warrants a careful assessment against these criteria, with legal and compliance input.

Is this fine relevant to firms operating in EU member states other than Austria?

Yes. MiCA is an EU-wide regulation and the obligations breached by Bitpanda apply in every member state. The FMA's published decision sets a public precedent that other national competent authorities can reference. Firms passporting services across the EU face the additional risk that a published enforcement record in one jurisdiction may attract scrutiny from host-state regulators in others.

Source: Cointelegraph

EUATGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Bybit's Austrian EMI License: Dual-Entity EU Structure and What Accounting Firms Must Assess Now
AML/KYC & Licensing
ESMA MiCA Register Reaches 309 CASPs as BNY Mellon Unit and 14 Others Join in Third Update
AML/KYC & Licensing
Binance, Russia, and User Data: What the Belenkiy Case Means for AML and KYC Compliance
AML/KYC & Licensing
The A7 Leaks: What $8 Billion in Stablecoin Flows Mean for Crypto Accounting and AML Compliance