Europe now has its first publicly named MiCA enforcement case.
On 14 August 2026, Austria’s Financial Market Authority (FMA, Finanzmarktaufsicht) published a legally final administrative penalty of €70,000 against Bitpanda GmbH for breaches of the EU’s Markets in Crypto-Assets Regulation (MiCAR). The FMA describes it as the first penalty decision under MiCAR that it has published.
What the FMA found
The case is not about lost client money or a hack. According to the FMA’s own announcement, the breaches were procedural and centred on how a crypto-asset was brought to market:
- Bitpanda did not submit the required crypto-asset whitepaper to the FMA at least 20 business days before publication, as required by Article 8 of MiCAR.
- It disseminated a marketing communication before publishing the whitepaper, contrary to Article 7 of MiCAR.
- The marketing communication omitted a mandatory disclosure: a clear statement that no competent authority has reviewed or approved the whitepaper and that responsibility for its content rests with the offeror.
The matter was concluded through an accelerated procedure under section 22(2b) of the Austrian Financial Market Authority Act (FMABG), and the penalty is legally final. Importantly, the FMA made no findings about customer funds, custody or a data breach, and Bitpanda’s MiCA authorisation, granted by the FMA itself, is unaffected.
This case is about notification and marketing rules, not the safety of client assets.
A small fine with an outsized signal
Bitpanda is one of Europe’s most established crypto brokers, and the company has reported around 7.4 million registered users and adjusted revenue of around €371 million. Against that scale, the fine is secondary; the real significance is a national competent authority shifting from transposing the Markets in Crypto-Assets (MiCA) framework to actively enforcing it on the public record.
National regulators routinely name public enforcement notices to establish supervisory precedent across the market. By placing this action in the public domain, the Financial Market Authority (FMA) has drawn an unambiguous line regarding how it intends to police MiCA’s white paper publication and marketing communication mandates.
For crypto-asset service providers (CASPs) operating across the European Union, the compliance takeaway is stark: the formal, disclosure-driven, and timing-specific requirements under MiCAR are enforceable day-one obligations.
Why It Matters: The MiCAR Compliance Checklist
- The 20-Day Notification Gate: white papers are not launch day filings, and missing the mandatory 20 business day regulatory notification window before publication directly invites financial penalties.
- Synchronised marketing rules: promotional campaigns cannot precede the published white paper and must display the statutory disclaimer confirming no competent authority has approved the document.
- Timing-driven exposure: allowing commercial or marketing launches to outpace the compliance calendar is precisely the procedural breach the FMA has now moved to sanction.
The action also fits a broader pattern of European supervisors turning MiCA and its sister regimes from text into practice, from the joint push by the EBA, EIOPA and ESMA to contain systemic and ICT risk in the sector to national authorities testing the operational and disclosure rules firm by firm.
Bitpanda’s €70,000 penalty is small, but as the first published MiCAR decision, it is the one the rest of the industry will read closely. The primary source is the FMA’s own announcement of the decision.
