CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

MFSA Fines Everest Network €40,560 for VFA Breaches

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING MFSA Fines Everest Network€40,560 for VFA Breaches

Malta's financial regulator has settled enforcement proceedings against a licensed crypto firm, imposing a penalty of €40,560 on Everest Network Ltd for two distinct failures under the country's Virtual Financial Assets framework. The action, concluded on 10 July 2026, signals that the Malta Financial Services Authority is prepared to pursue firms that treat shareholding approvals and regulatory reporting as optional formalities, even where those firms subsequently demonstrate goodwill. For accounting firms, auditors, and CFOs serving VFA-licensed entities, this settlement is a clear calibration point for how the MFSA prices compliance failures.

MFSA Fines Everest Network €40,560 for VFA Breaches

What the MFSA Found

The authority's supervisory engagement with Everest Network Ltd uncovered two separate categories of breach, each tied to specific provisions of Malta's VFA legislation.

Unapproved Shareholding Changes

The first breach relates to Article 28(1)(c) of the Virtual Financial Assets Act, read alongside Rule R3-2.3.4.4.2(iii) of Chapter 3 of the VFA Rulebook. Taken together, these provisions require a VFA service provider to seek and obtain the MFSA's prior approval before any change is made to its shareholding structure, even where the transfer takes place among existing shareholders rather than new external parties.

This is a detail that traps many operators. A common assumption is that movements of equity between people who already hold shares in the company are an internal matter, not a regulatory event. Malta's framework rejects that assumption entirely. Any redistribution of ownership within a licensed VFA entity triggers the prior-approval requirement. The rationale sits in the MFSA's need to maintain continuous fitness-and-propriety oversight over the persons who, in practice, control a licensed firm. A shift in the relative weighting of existing shareholders can alter effective control, even without a new face on the cap table.

Missed Regulatory Reporting Deadlines

The second category of failure is more operational. The MFSA found that Everest Network Ltd did not submit certain regulatory reporting documents within the deadlines prescribed by the VFA Rulebook. The gap in timely submission spanned three financial years: 2022, 2023, and 2024. The notice does not specify which individual reports were late, but the VFA Rulebook requires service providers to submit a range of periodic documents including financial statements, compliance reports, and returns covering business activity.

A failure that persists across three consecutive reporting cycles is not an isolated oversight. It points to either a structural weakness in the firm's internal reporting calendar or, in some cases, a deliberate deprioritisation of regulatory obligations. From a bookkeeping and internal-controls perspective, a three-year gap suggests that no effective monitoring mechanism was in place to flag overdue submissions before they accumulated.

How the Settlement Was Reached

The MFSA's notice states that the authority took account of the goodwill demonstrated by Everest Network Ltd in deciding to settle rather than escalate the matter further. The settlement agreement was executed on 10 July 2026, and the administrative penalty was fixed at €40,560. No suspension or revocation of the firm's VFA licence is mentioned in the published notice.

Settlement processes of this kind are not uncommon in EU financial regulation. They allow regulators to resolve matters efficiently, particularly where a firm cooperates fully and remedies the underlying failings before formal proceedings are concluded. The commercial benefit for the firm is a defined, finite penalty rather than the reputational and operational uncertainty of a contested enforcement process. For the regulator, settlement preserves supervisory resources for higher-risk cases.

The published figure of €40,560 is therefore a negotiated outcome, not necessarily the ceiling that the MFSA could have imposed under its penalty powers. Accounting and legal advisers should read it as a floor-level reference rather than a cap.

Implications for Accounting Firms and CFOs

This settlement contains two distinct compliance signals that advisers and finance leads should carry back to any client operating under a VFA licence, or applying for one.

Shareholding Changes Require a Regulatory Workflow, Not Just a Legal One

When clients restructure their cap tables, the instinct is to engage corporate lawyers and, where relevant, tax advisers. That is necessary but not sufficient for a VFA-licensed entity. The MFSA approval process must run in parallel, and it must complete before the transaction closes. Accountants supporting M&A or restructuring work for crypto clients licensed in Malta should build MFSA prior-approval as a hard prerequisite in every transaction checklist. Any crypto bookkeeping software or entity management tool used to track ownership changes should flag VFA-licensed entities for regulatory pre-clearance.

The same principle extends to entities that may be operating in other EU jurisdictions under MiCA. As MiCA authorisation becomes the primary licensing route across the bloc, most competent authorities apply analogous fit-and-proper requirements to ownership changes. The MFSA's action under the VFA framework is a preview of the enforcement posture that national competent authorities across the EU are likely to adopt for MiCA-licensed crypto-asset service providers. Firms advising on MFSA authorisation and compliance cycles should factor this into their client onboarding checklists.

Reporting Calendars Must Be Enforced, Not Just Maintained

A VFA service provider's regulatory reporting obligations are not self-executing. The VFA Rulebook prescribes specific submission windows for each category of return. A firm that misses one deadline in isolation may argue an operational hiccup. A firm that misses deadlines across 2022, 2023, and 2024 has demonstrated a systemic absence of controls. The MFSA noticed.

For accounting firms acting as outsourced compliance or finance functions for VFA licensees, this settlement reinforces the need for dedicated regulatory calendars that are maintained separately from standard financial reporting schedules. The two cycles often diverge: a firm's financial year-end may not align with every regulatory submission window, and the two should not be tracked in the same spreadsheet without explicit reconciliation logic. Digital asset accounting software that integrates regulatory deadline management alongside financial close processes reduces the risk of this kind of multi-year accumulation.

CFOs of VFA-licensed entities should also consider whether their current reporting infrastructure would surface a missed regulatory submission quickly enough to allow remediation before the MFSA's own monitoring systems flag it. If the answer is uncertain, that gap is the next item on the internal audit agenda.

The Broader VFA and MiCA Enforcement Landscape

The Everest Network Ltd settlement is one data point in a pattern of increased supervisory assertiveness across EU crypto licensing frameworks. The transition from Malta's domestic VFA regime to the pan-EU MiCA framework is ongoing, and firms operating under transitional arrangements should not infer that the MFSA's supervisory attention is diminished during that window. If anything, the authority is demonstrating that it will use settlement mechanisms actively to resolve legacy matters before the MiCA regime fully crystallises.

The penalty amount, while modest relative to the scale of penalties that MiCA's own provisions allow for larger infractions, carries a compliance cost well beyond the €40,560 figure. Legal fees, management time, remediation costs, and reputational exposure to counterparties and banking partners collectively dwarf the fine itself. Firms that treat crypto licensing obligations as back-office administration rather than front-line risk items routinely underestimate this total cost of non-compliance.

For context, MiCA Article 111 empowers national competent authorities to impose administrative penalties of up to €700,000 on natural persons and up to 5% of total annual turnover on legal persons for certain breaches. The VFA framework's penalty architecture is different, but the direction of travel in EU crypto enforcement is clearly toward larger, more visible sanctions. As we have covered in relation to AMF enforcement actions and blacklist outcomes, regulators across the EU are sharpening their tools and using them with increasing frequency.

Practical Steps for Advisers

Accounting firms, auditors, and CFOs advising VFA-licensed or MiCA-licensed entities should act on the following practical points in the near term.

Cap Table Review and Regulatory Pre-Clearance

Conduct a review of any shareholding changes that have occurred since the firm's VFA or MiCA licence was granted. If any transfers among existing shareholders were completed without prior MFSA or competent authority approval, that gap should be assessed and, where necessary, disclosed to the relevant regulator proactively. Self-disclosure, combined with remediation, is consistently treated more favourably than a finding made through supervisory inspection.

Regulatory Reporting Audit

Produce a complete schedule of all regulatory submissions required under the VFA Rulebook or the applicable MiCA regulatory technical standards. Cross-reference that schedule against actual submission dates held on file. Any late or missing submissions should be triaged by severity and materiality, and a remediation plan prepared before the next supervisory contact. This is precisely the kind of structured review that robust digital asset accounting software should support, by maintaining an auditable record of submission timestamps alongside the underlying financial data.

Internal Controls Documentation

The Everest Network Ltd settlement is the kind of outcome that auditors cite when assessing the adequacy of a client's internal controls environment. If your firm is auditing a VFA or MiCA licensee, confirm that the client's compliance function maintains written procedures for both regulatory-event approvals and periodic reporting submissions, and that those procedures are tested at least annually. An absence of documented procedures is itself a finding under most audit frameworks.

MFSA Fines Everest Network €40,560 for VFA Breaches

Frequently Asked Questions

What did Everest Network Ltd do wrong?

The MFSA found two failures: the company changed its shareholding structure among existing shareholders without first obtaining regulatory approval, as required by Article 28(1)(c) of the Virtual Financial Assets Act and the VFA Rulebook; and it failed to submit certain regulatory reporting documents on time across financial years 2022, 2023, and 2024.

Why does an intra-shareholder transfer require MFSA approval?

Malta's VFA framework requires prior approval for any change to a licensed firm's shareholding structure, regardless of whether new investors are involved. The MFSA needs to maintain continuous oversight of those who control a licensed entity, and a shift in relative ownership among existing shareholders can alter effective control just as a transfer to a new party can.

How large was the penalty, and how was it calculated?

The MFSA imposed an administrative penalty of €40,560 on Everest Network Ltd. The settlement notice indicates that the authority took the company's demonstrated goodwill into account. The exact methodology behind the figure is not publicly detailed, but settlement amounts typically reflect the nature and duration of the breach, any remediation taken, and the degree of cooperation shown by the firm.

Does this case have implications for firms operating under MiCA rather than the VFA framework?

Yes. While the specific provisions cited are from Malta's domestic VFA Act, analogous fit-and-proper and ownership-change requirements exist under MiCA for crypto-asset service providers. National competent authorities across the EU are empowered to supervise and penalise similar failures. The MFSA's enforcement posture under the VFA regime signals the kind of supervisory behaviour that MiCA licensees should anticipate.

What should an accounting firm do if a VFA-licensed client has missed regulatory reporting deadlines?

The first step is to identify the scope of the gap: which reports, covering which periods, were late or absent. The next step is to assess whether proactive disclosure to the MFSA or relevant competent authority is appropriate. In most cases, voluntary disclosure combined with a credible remediation plan is treated more favourably than a finding made during a supervisory inspection. Legal counsel with regulatory expertise in the relevant jurisdiction should be involved before any disclosure is made.

Source: Malta Financial Services Authority

EUGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
CSSF Flags consulting-mla.com as Unlicensed: What Accounting Firms and CFOs Must Act On
AML/KYC & Licensing
EU Sanctions 'Stern': Trickbot Boss and the $300M Ransom Trail
AML/KYC & Licensing
MiCA Licensing Is Just the Start: ESMA Puts Crypto Custodians Under the Microscope
AML/KYC & Licensing
Binance's MiCA Setback and the Race for New Licenses