Poland Upholds Crypto Veto as Zondacrypto Scandal Widens
Poland's parliament has again failed to override President Karol Nawrocki's veto of national crypto legislation, leaving the country without a designated supervisory authority for digital assets even as the European Union's Markets in Crypto-Assets Regulation (MiCA) is already in force. The vote came the same week that Zondacrypto's Estonian operating entity was formally declared bankrupt, a scandal that is now drawing in allegations of political corruption and is intensifying pressure on Warsaw to establish functioning oversight infrastructure. For accounting firms, auditors, and CFOs serving Polish or broader EU-regulated crypto clients, the situation creates a concrete compliance gap that needs immediate attention.
The Parliamentary Vote: What Happened and Why It Matters
On Friday 5 September 2026, Poland's lower house of parliament, the Sejm, voted 241 to 198 in favour of overriding the presidential veto, with three abstentions. Overturning a veto requires a three-fifths majority, which translates to 266 votes in the full chamber. The pro-override side fell 25 votes short.
What the vetoed bill would have done
The legislation was designed to build Poland's national implementation framework for MiCA. Its central provision would have placed supervisory responsibility for the domestic crypto-asset market with the Polish Financial Supervision Authority, known by its Polish acronym KNF. Without that designation, no single body is currently empowered to enforce MiCA at the national level inside Poland.
The KNF itself confirmed this gap on the same day as the vote, stating publicly that Poland still lacks a formally designated authority responsible for supervising the crypto-asset market, despite MiCA applying across all EU member states. That is an unusual situation: an EU regulation is technically in force, but the national supervisory machinery needed to act on it is absent.
The president's objection
President Nawrocki has not opposed crypto regulation in principle. His stated concern is proportionality: he has argued that the proposed rules go further than MiCA requires and that the bill's provisions allowing authorities to block websites set a standard he considers excessive. That distinction matters for practitioners advising clients, because the political impasse is not simply about whether to regulate but about where the boundary of national discretion under MiCA should sit.
The Zondacrypto Scandal: A Parallel Crisis
The regulatory deadlock is unfolding alongside a deepening criminal investigation into Zondacrypto, a crypto exchange formerly known as BitBay. Polish prosecutors are investigating suspected fraud and money laundering connected to the platform. In July, the case was widened to include a probe into the exchange's founder. As of April, prosecutors assessed losses linked to Zondacrypto at no less than 350 million Polish zlotys, equivalent to roughly 95 million US dollars at prevailing rates.
Bankruptcy of the Estonian operator
Zondacrypto's operating entity, BB Trade Estonia, was formally declared bankrupt by an Estonian court in August 2026. The first creditors' meeting was scheduled for 17 September 2026. For creditors, counterparties, and any firm that maintained business relationships with the exchange, the bankruptcy filing triggers standard insolvency obligations: debt crystallisation, potential clawback exposure for payments made in the preference period, and the need to lodge proofs of claim ahead of the creditors' meeting.
Political corruption allegations
Prime Minister Donald Tusk used the parliamentary debate to present excerpts from what he described as testimony by a key witness in the Zondacrypto investigation. According to Tusk, the witness alleged a payment arrangement of 2 million Polish zlotys, approximately 550,000 US dollars, involving a foundation linked to former Justice Minister Zbigniew Ziobro. Separate testimony cited by the Prime Minister alleged that an unnamed individual had promised to arrange a presidential pardon if the witness were convicted.
Whether or not these allegations are eventually substantiated, the fact that a major crypto exchange investigation is being linked to political actors from a previous government dramatically raises the political stakes around Poland's crypto regulatory framework. Tusk has explicitly used the Zondacrypto case to argue for tighter oversight, framing the regulatory gap as a direct enabler of the alleged misconduct.
The MiCA Compliance Gap in Poland
MiCA has direct effect across all EU member states. However, member states retain responsibility for designating national competent authorities, and several MiCA provisions require those authorities to be operational before they can be enforced in practice. Poland's failure to enact enabling legislation means there is currently no KNF-equivalent empowered to issue or refuse crypto-asset service provider licences, conduct supervisory examinations, or impose sanctions under MiCA's domestic enforcement chapter.
Implications for VASPs operating in Poland
Any virtual asset service provider currently active in Poland sits in an ambiguous position. MiCA obligations apply, but the supervisory counterpart on the Polish side does not yet legally exist in the form the regulation anticipates. Firms cannot obtain a Polish MiCA authorisation, cannot be subject to Polish supervisory review, and cannot benefit from the EU passporting regime as a Polish-authorised entity. Practically, this means firms seeking EU passporting rights may need to consider authorisation in another member state where the national framework is fully operational, a decision with material cost and structural implications.
What accounting and audit teams should check now
Firms providing audit, advisory, or crypto accounting software services to clients with Polish crypto exposure should undertake a targeted review across several dimensions. First, confirm whether any client holds or has applied for a Polish virtual asset service provider registration that was expected to transition into a MiCA authorisation: those transition timelines are now uncertain. Second, assess whether any client's financial statements carry a contingent liability or asset relating to Zondacrypto creditor claims. Third, review AML controls: the Zondacrypto investigation involves alleged money laundering, and firms with any historic transaction exposure to the exchange should satisfy themselves that the relevant customer due diligence files are complete and defensible.
On the audit side, going-concern assessments for any Polish crypto entity should now explicitly address the supervisory vacuum. If a client's business model depends on obtaining a Polish MiCA licence within a specific timeframe, that dependency is a material uncertainty that warrants disclosure under IAS 1 or the applicable reporting framework.
AML Implications: Lessons from the Zondacrypto Case
The scale of alleged losses, 350 million zlotys as a floor estimate, and the specific mention of money laundering in the prosecutorial investigation make this case a practical reference point for AML risk discussions. A few structural points are worth drawing out.
Exchange-linked AML exposure
When a major exchange enters bankruptcy under a criminal cloud, the transactional history of that exchange becomes a risk factor for every counterparty in the chain. Firms using digital asset accounting software to record client positions should verify that on-chain tracing tools are flagging any wallet addresses associated with Zondacrypto in current screening workflows. The EU's AML framework, reinforced by the recently adopted AMLR, requires obliged entities to conduct ongoing monitoring: a bankrupt exchange under criminal investigation is precisely the kind of event that should trigger a retrospective review of transaction history involving that entity.
Politically exposed person considerations
The allegations linking payments to a foundation associated with a former government minister introduce a politically exposed person dimension to the Zondacrypto case. Any firm that conducted business with Zondacrypto or its affiliates and did not at the time screen for PEP connections should now review those files. Enhanced due diligence requirements apply retrospectively where new information emerges that changes the risk profile of an existing or former client relationship.
What Comes Next for Poland's Crypto Framework
Friday's vote does not permanently close the door. Parliament could attempt another override vote, or the government could draft revised legislation that addresses Nawrocki's stated objections on website-blocking powers and proportionality. However, the political dynamics are complicated. The government controls the parliamentary majority but has so far been unable to persuade enough additional members to reach the three-fifths threshold. The Zondacrypto scandal may change the political calculus: several commentators have noted that the criminal investigation has made it harder for opposition members to publicly argue against tighter oversight.
In the meantime, the European Commission could, in theory, pursue infringement proceedings against Poland for failing to designate a national competent authority under MiCA. No such proceedings have been announced, but the KNF's own public statement acknowledging the gap suggests the authority is aware of the exposure and may be signalling to legislators that the current situation is unsustainable.
For practitioners advising clients on EU crypto strategy, the practical message is straightforward: do not plan a Polish MiCA authorisation timeline around a legislative resolution that has no confirmed date. Build contingency into any regulatory roadmap that currently depends on KNF becoming operational as a MiCA competent authority. For EU-wide context on how crypto monitoring frameworks are developing across member states, the ESMA data and crypto monitoring agenda provides useful background on the direction of travel at the supranational level.
Frequently Asked Questions
Does MiCA apply in Poland right now?
MiCA has direct applicability across all EU member states, including Poland. However, several practical enforcement mechanisms require a designated national competent authority. Poland has not yet passed the legislation needed to designate the KNF in that role, which means some MiCA provisions cannot be enforced domestically in the way the regulation envisages.
Can a crypto firm obtain a Polish MiCA licence at the moment?
Not currently. Without enabling legislation formally designating KNF as the competent authority, there is no legal basis for KNF to issue MiCA-compliant authorisations. Firms seeking an EU licence with passporting rights would need to pursue authorisation in a different member state where the national framework is fully operational.
What should firms with Zondacrypto exposure do now?
Firms that held positions on, transacted through, or have creditor claims against Zondacrypto should review their AML files for completeness, consider whether retrospective screening for PEP and sanctions connections is warranted, and if they have creditor claims, ensure those are lodged before the September 17 creditors' meeting of BB Trade Estonia.
Does the Zondacrypto bankruptcy affect financial statement disclosures?
Potentially yes. If a client holds a receivable from Zondacrypto or BB Trade Estonia, impairment under IFRS 9 or equivalent provisions should be assessed given the bankruptcy. Any contingent liability arising from historical transactions with the exchange should be evaluated for disclosure under IAS 37. Auditors should also consider whether Zondacrypto-related uncertainty affects their going-concern assessment for clients materially dependent on the exchange.
Could the European Commission take action against Poland over the supervisory gap?
The Commission has the power to open infringement proceedings against member states that fail to comply with EU law obligations, including designating competent authorities under MiCA. No proceedings have been announced, but the KNF's public acknowledgement of the gap suggests the issue is live. Practitioners should monitor for any Commission communication on this point.
Source: Cointelegraph
