CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MFSA Warns Against Unlicensed DistributeX in Malta

CryptaCount Editorial · · 8 min read
AML / KYC / LICENSING MFSA Warns Against UnlicensedDistributeX in Malta

The Malta Financial Services Authority has issued a public notice warning that an entity trading under several names, including DistributeX, distributex, DistributeX Limited, DX Distribute and DX, is operating in Malta without any form of authorisation. The MFSA confirms that none of these names correspond to a company registered in Malta and that the entity has never held a licence, approval or any other form of regulatory recognition from the Authority. For accounting firms, auditors and CFOs with Maltese operations or clients exposed to the local market, this notice carries direct compliance, AML and client-risk implications worth unpacking carefully.

MFSA Warns Against Unlicensed DistributeX in Malta

What the MFSA Has Found

The Authority's notice sets out a detailed picture of how DistributeX presents itself and operates on the ground.

Physical and Digital Footprint

The entity maintains an active online presence through a dedicated website and at least one mobile application, DX-Plus, available for download via the Apple App Store. Beyond its digital channels, it appears to operate from multiple physical locations across Malta, including Birkirkara, Hamrun, Mosta and Hal Tarxien. The MFSA also notes that the entity has been organising in-person gatherings across the island, promoted internally as official employee meetings. This combination of a credible-looking app, a website and on-the-ground activity is precisely the kind of profile that creates a false impression of legitimacy among retail participants.

Regulatory Status: Unauthorised on Every Count

The MFSA is explicit: DistributeX, under any of its trading names or variations, is not registered as a company in Malta. No individual, representative or promoter group associated with it has ever been licensed, authorised, regulated or otherwise approved by the Authority. Under Maltese law, providing financial services without the requisite authorisation is prohibited, and the MFSA makes clear that the entity is not permitted to carry out any activity requiring such authorisation.

MLM and Pyramid Scheme Characteristics Identified

Beyond the bare licensing question, the MFSA's notice goes further by identifying specific structural features in the entity's business model that raise serious concern.

The Three Red Flags

The Authority identified three characteristics that it considers significant. First, participation requires an upfront financial contribution from members. Second, members are incentivised to recruit new participants through referral-based commissions. Third, the platform promotes the prospect of returns through a tiered or structured membership programme. The MFSA is careful to note that the presence of these features alone does not legally establish that the operation is an illegal pyramid scheme. However, these are precisely the hallmarks that the Authority has previously highlighted in its own public guidance on pyramid schemes that present themselves as legitimate multi-level marketing businesses.

Why the Distinction Matters for Due Diligence

The legal qualification may ultimately be a matter for prosecutors or courts, but the practical risk is immediate and real. Unlicensed entities are not subject to the capital adequacy rules, segregation of client funds requirements, AML and KYC obligations, or conduct-of-business standards that apply to MFSA-authorised firms. Any funds placed with such an entity have none of the protections that regulated financial services carry. Recruitment-driven return structures also raise questions about the sustainability of the model and the source of funds used to pay early participants, both of which are relevant to any financial crime assessment.

Accounting and AML Implications for Firms and CFOs

For professionals using crypto bookkeeping software or digital asset accounting software to manage client portfolios and produce compliant financial statements, a public warning of this kind triggers several practical obligations and risk considerations.

Client Exposure Screening

Any accounting firm or CFO with clients based in Malta, or with Maltese-resident employees or directors, should consider whether any exposure to DistributeX has found its way into accounts. Given the entity's use of physical offices and recruitment meetings, participation could involve individuals across a wide range of client organisations. If funds have been transferred to or received from this entity, those transactions will need to be assessed under the firm's AML procedures, and possibly reported under Malta's Prevention of Money Laundering Act if the required thresholds and conditions are met.

Financial Statement and Audit Considerations

From an accounting standpoint, any assets held with an unlicensed operator are subject to heightened recoverability risk. Where a client has recorded a receivable or investment balance linked to participation in the DistributeX scheme, auditors and preparers will need to assess whether that balance is impaired. Given the regulator's public warning and the absence of any legal registration, a case for full impairment is easy to construct. IFRS 9 expected credit loss considerations, or equivalent national GAAP provisions, apply from the moment it becomes apparent that recovery is uncertain.

AML Risk Rating and Enhanced Due Diligence

The MFSA warning is a public regulatory notice, which means it becomes part of the documented risk landscape for any AML risk assessment covering Malta. Accounting firms acting as subject persons under Maltese AML regulations must update their risk assessments to reflect new public warnings as they emerge. DistributeX and its associated trading names should be added to internal negative-news and entity screening lists immediately. If any client relationship involves individuals who have participated in or promoted DistributeX schemes, enhanced due diligence is warranted.

Director and Officer Liability

CFOs advising businesses whose employees or associated individuals have been promoting DistributeX at what the entity calls employee meetings should also consider whether any corporate facilitation risk arises. Where a company's premises or resources have been used to host or promote an unauthorised financial scheme, even informally, legal advice on potential liability exposure is prudent.

The Broader Malta Regulatory Context

This notice does not emerge in isolation. Malta has been a significant jurisdiction for digital asset licensing since the introduction of the Virtual Financial Assets Act in 2018, and the MFSA has increasingly used public warnings as a proactive enforcement tool against unlicensed activity. The territory's status as an EU member state also means that MiCA, which is now fully in force across the bloc, provides an additional layer of authorisation requirements for any crypto-asset service provider targeting Maltese residents. Any entity wishing to offer crypto-asset services lawfully in Malta must either hold an MFSA authorisation or passport into Malta under MiCA from another EU competent authority.

The ESMA MiCA register reaches 309 CASPs, and that publicly available list is now the definitive starting point for verifying whether any entity operating across the EU has the regulatory standing it claims. Checking that register takes minutes and should be a standard step in any onboarding or counterparty check process.

Equally, the FATF VASP targeted update July 2026 reinforces that global standard-setters expect supervisors to take prompt action against unlicensed virtual asset service providers, and that financial institutions and professional advisers are expected to support that effort through robust counterparty screening.

Practical Steps for Accounting Firms and CFOs

Given the above, the following steps are appropriate now rather than on a deferred basis.

Immediate Actions

Screen current and prospective clients for any connection to DistributeX, DX Distribute, DX-Plus or associated trading names. Update internal negative-news databases and AML monitoring lists with all known variants of the entity name. Review any open balances that could represent participation in this scheme and assess recoverability. Where the firm acts as a subject person under Maltese AML legislation, document the review and the outcome in the client file. If any suspicious activity indicators are present, consider obligations under the relevant reporting framework.

Ongoing Monitoring

The MFSA maintains a public register of licensed entities on its official website. Firms should ensure that counterparty verification procedures include a routine check against that register for any Malta-domiciled or Malta-facing financial services provider. This is especially relevant where digital asset accounting software is used to record transactions involving Maltese counterparties, since the automated audit trail will capture the transaction but will not flag the regulatory status of the counterparty unless a manual screening step is built into the workflow.

MFSA Warns Against Unlicensed DistributeX in Malta

Frequently Asked Questions

Is DistributeX a licensed crypto-asset service provider in Malta?

No. The MFSA has confirmed that none of the entities operating under the DistributeX name, or any variation of it, are registered as a company in Malta or hold any licence, authorisation or approval from the MFSA. They are not permitted to provide financial services in Malta.

Does the MFSA warning mean DistributeX is definitely a pyramid scheme?

The MFSA stops short of making a definitive legal determination in its notice. It identifies structural features consistent with MLM and pyramid scheme arrangements, namely upfront contributions, recruitment-based commissions and structured membership returns, but notes that the presence of those features alone does not legally establish an illegal pyramid scheme. The warning is nonetheless a strong regulatory red flag.

What should an accounting firm do if a client has funds with DistributeX?

The firm should assess the balance for impairment given the regulator's public warning and the entity's unregistered status. AML screening obligations should be reviewed, and if the circumstances meet the threshold for a suspicious activity report under Maltese law, the firm's MLRO should be notified. Document the review thoroughly in the client file.

How does MiCA affect this situation?

MiCA is now fully in force across the EU, including Malta. Any entity offering crypto-asset services to Maltese residents must either hold an MFSA authorisation or be passported from another EU competent authority and appear on the ESMA CASP register. DistributeX appears on neither list.

Where can I verify whether a Malta-facing financial services provider is authorised?

The MFSA publishes a live register of all licensed entities on its official website at mfsa.mt. For crypto-asset service providers specifically, the ESMA MiCA register of authorised CASPs is also a primary reference point for EU-wide verification.

Source: Malta Financial Services Authority

MTGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
MFSA CFT/CPF/TFS Thematic Review: What Firms Must Do
AML/KYC & Licensing
MFSA Thematic Review on Financial Crime Risks: Compliance Implications for Crypto Firms
AML/KYC & Licensing
MFSA DORA 2025 Authorisation Lessons: ICT Gaps Accounting Firms Must Close
AML/KYC & Licensing
MFSA Opens Consultation on EU AML Directive 2025/1: What Firms Must Know