MFSA Flags Nuverex Ltd as Unlicensed Crypto Entity in Malta
On 25 August 2026, the Malta Financial Services Authority (MFSA) issued a formal public warning against an entity trading as Nuverex Ltd and operating at nuverex.net. The entity falsely claims to be incorporated under Maltese law and purports to hold a Markets in Crypto-Assets Regulation (MiCA) authorisation as a Crypto-Asset Service Provider (CASP). Neither claim is true. The MFSA has confirmed the entity is not registered in Malta, holds no licence from the Authority, and has no permission to provide investment or financial services under Maltese law. For accounting firms, auditors, and CFOs who touch digital assets, this warning carries direct due-diligence obligations that cannot be deferred.
What the MFSA Warning Says
The MFSA warning covers three distinct, compounding concerns that together make Nuverex Ltd a high-risk counterparty under any standard AML or third-party risk framework.
False claims of MiCA authorisation
Nuverex Ltd claims to operate as a CASP under Regulation (EU) 2023/1114, citing a specific authorisation reference. The MFSA has explicitly rejected that claim. MiCA, which is directly applicable across all EU member states, requires CASPs to obtain authorisation from a national competent authority before providing services such as custody, exchange, or transfer of crypto assets to the public. Presenting a fabricated reference number is not merely a regulatory technicality: it is the kind of misrepresentation that regulators across the EU are specifically trained to detect and that AML frameworks classify as a red flag for fraud.
Misappropriation of a legitimate company's identity
The MFSA notes that Nuverex Ltd is making unauthorised use of the registration details of a genuine Maltese-incorporated company. This tactic, sometimes called clone fraud, is designed to add credibility to an entity that has none. Firms that rely on company name searches alone, rather than checking the MFSA's live register of authorised entities, are exposed to being deceived by exactly this method.
No authorisation under Maltese statute
Malta's financial services framework relevant to digital assets rests on two statutes: the Investment Services Act (Chapter 370 of the Laws of Malta) and the Virtual Financial Assets Act (Chapter 590 of the Laws of Malta). The MFSA has confirmed that Nuverex Ltd holds no authorisation under either piece of legislation. Any firm or individual transacting with Nuverex Ltd is therefore doing so with an entity that operates entirely outside the regulated perimeter.
Why This Matters for Accounting Firms and CFOs
A regulator naming an unlicensed crypto entity is not simply a consumer-protection notice. It creates a concrete compliance burden for professional services firms and corporate treasury functions that interact with the digital asset sector.
AML counterparty risk
Under the EU's Anti-Money Laundering Directives and Malta's transposing legislation, obliged entities, including accountants, auditors, and tax advisers in many circumstances, must perform customer due diligence and ongoing monitoring on relationships that involve financial services activity. Transacting with or recording financial flows to an entity that a national competent authority has publicly identified as unlicensed creates an immediate red flag that must be addressed in a firm's risk assessment. Ignoring a published MFSA warning would be very difficult to defend before a supervisor. For a deeper look at why ongoing monitoring matters beyond the initial onboarding screen, see our coverage of how continuous monitoring closes post-screening AML gaps.
Accounting records and financial statements
If a client of an accounting firm has transacted with Nuverex Ltd, those transactions need careful scrutiny before they are reflected in financial statements or tax returns. Payments to or receipts from an unlicensed CASP may represent funds at risk of loss, potential involvement in a fraud, or both. Under IFRS and UK/Maltese GAAP, assets and liabilities must be recognised faithfully: a balance held with an entity that has no legal right to accept or hold those assets is likely to require a specific disclosure or impairment assessment. The crypto bookkeeping software used to record those transactions should allow enough granularity to flag the counterparty's regulatory status alongside the transaction itself.
Director and officer liability
CFOs at entities that have approved treasury activity involving unregulated crypto service providers face personal exposure under corporate governance frameworks. Maltese company law, like its EU equivalents, places a duty of care on directors to ensure the company transacts with authorised counterparties where the law requires authorisation. The MFSA warning, once published, makes any subsequent engagement with Nuverex Ltd a deliberate choice rather than an oversight, which significantly raises the legal and reputational risk for individuals who approved the relationship.
The MiCA Authorisation Landscape in Malta and the EU
MiCA entered into force progressively across 2024 and 2025, with the CASP authorisation regime fully live from December 2024. Under MiCA, a CASP authorised in one EU member state benefits from a passport to provide services across the bloc, subject to notification requirements. That passporting mechanism makes Malta, with its established virtual financial assets framework, an attractive jurisdiction for genuine CASPs seeking EU-wide access.
How to verify a CASP's authorisation status
The MFSA maintains a public register of all entities licensed or otherwise authorised by the Authority, accessible directly from mfsa.mt. At the EU level, the European Securities and Markets Authority (ESMA) is building a central register of authorised CASPs across member states. Checking both sources, and not relying on documentation supplied by the entity itself, is the minimum standard for any professional conducting due diligence on a crypto-asset service provider. For context on how that EU-level register is developing, our article on Germany's expanding MiCA-authorised CASP register sets out the current state of play.
Red flags the MFSA specifically highlights
The MFSA's warning explicitly calls out unsolicited approaches via telephone and social media as channels commonly used by unlicensed entities. For firms that receive cold approaches from crypto-asset service providers, a three-step check is the practical minimum: confirm legal name and registration number against the MFSA register, verify authorisation status through ESMA's CASP register, and request a copy of the authorisation letter directly from the regulator rather than from the entity. Where any element cannot be verified, the relationship should not proceed.
Practical Steps for Firms and Finance Teams
Immediate actions if you have dealt with Nuverex Ltd
The MFSA's guidance is direct: stop all transactions immediately and contact the Authority. For firms that have processed payments, recorded receivables, or provided professional services in connection with Nuverex Ltd, additional steps are needed. These include a suspicious activity report where AML obligations apply, a review of any financial statements that include balances or revenue linked to the entity, and a client notification if the firm's professional duties require it. The digital asset accounting software used to manage those records should be capable of attaching compliance notes to specific transaction lines, creating an audit trail that demonstrates the firm acted promptly on the MFSA warning.
Strengthening counterparty checks going forward
The Nuverex Ltd case illustrates a pattern that compliance teams should build into their standard onboarding workflow for any crypto-asset counterparty. The clone fraud element in particular, using a real Maltese company's details, would defeat a simple company name check. The verification process needs to go a step further: confirm that the specific registration number cited by the entity matches the name and address on the MFSA register, and that the authorisation reference number, if provided, actually appears in the regulator's published records. No crypto bookkeeping software or digital asset accounting software can substitute for that manual regulatory check, but the two work best in combination, with the software flagging counterparties whose regulatory status has not been confirmed in the onboarding file.
Client communication for accounting practices
Accounting firms advising clients who hold or trade crypto assets should consider whether the Nuverex Ltd warning triggers a proactive client communication. If any client has mentioned the entity, or if the firm has seen transaction data referencing nuverex.net, a prompt advisory note, flagging the MFSA warning and recommending the client cease dealings and seek legal advice, is both good professional practice and a reasonable risk-management measure for the firm itself.
Frequently Asked Questions
Is Nuverex Ltd regulated anywhere in the EU?
The MFSA has confirmed that Nuverex Ltd is not licensed by the Authority and is not a registered company in Malta. The MFSA has not indicated any other EU national competent authority has authorised the entity. Firms should check the ESMA CASP register for the current full EU picture.
What is the Virtual Financial Assets Act and why does it matter here?
Malta's Virtual Financial Assets Act (Chapter 590) established a licensing regime for virtual financial asset services before MiCA was agreed at EU level. It covers a range of crypto-asset activities directed at the Maltese market. Nuverex Ltd holds no authorisation under this act, meaning it has no legal basis to solicit or accept Maltese clients for crypto-asset services.
Does a MiCA passport mean I don't need to check the Maltese register?
No. A genuine MiCA passport originates from authorisation in a home member state, which is then notified to host-state regulators. The home-state authorisation still appears on the home NCA's register and, progressively, on ESMA's central CASP register. If an entity claims a MiCA passport but does not appear on either register, the claim should be treated as unverified until confirmed directly with the relevant NCA.
What are the AML obligations for an accountant who discovers a client dealt with Nuverex Ltd?
The specific obligations depend on whether the accountant is a designated person under Malta's or another EU member state's AML transposition. Where they are, discovering a link to a publicly identified unlicensed entity is likely to constitute a suspicious circumstance requiring internal escalation and potentially a suspicious transaction report. The firm's MLRO should be consulted immediately.
How should this MFSA warning be treated in a client's audit file?
Auditors should document the MFSA warning as a known fact relevant to any balance or transaction involving Nuverex Ltd. Under ISA 240 (fraud risk) and ISA 250 (laws and regulations), the existence of a public regulatory warning about a counterparty is directly relevant to audit risk assessment. Any balance with Nuverex Ltd should be subject to heightened scrutiny and may require a specific audit procedure to establish its recoverability.
