ESMA tells EU crypto firms to end services for unauthorised stablecoins

Nick Sawinyh on 08 Oct 2026

On October 8, 2026, the European Securities and Markets Authority published Opinion ESMA75-113276571-1742, telling national regulators that EU-authorised crypto-asset service providers should stop providing services involving stablecoins that do not meet the Markets in Crypto-Assets Regulation. The opinion gives regulators three months from publication to remediate remaining legacy exposures.

The direction covers asset-referenced tokens and e-money tokens. ESMA defines a non-compliant token as one for which the conditions for a lawful EU public offer or admission to trading under MiCA are not met, including applicable exemptions or transitional arrangements. The regulator uses ART and EMT as the legal categories for the assets commonly called stablecoins.

ESMA addressed the opinion primarily to national competent authorities. It asks them to assess whether authorised providers in their jurisdictions maintain or facilitate EU client access to affected tokens. ESMA will monitor application of the opinion with those national regulators.

What providers must stop

The scope reaches far beyond exchange listings. ESMA’s announcement names trading platforms, exchange services, order execution, token placement, reception and transmission of orders, investment advice, transfers, custody and administration, and portfolio management. The opinion says the expectation applies to those services individually or in combination.

National regulators should examine whether a provider lets an EU client acquire, trade, exchange, subscribe for, increase exposure to, access or maintain a non-compliant stablecoin. Providers should not introduce these tokens, preserve access to them or facilitate their availability through another service. They should put technical, contractual and organisational controls in place to prevent affected assets from remaining available in the EU. Those controls must also stop clients from buying or increasing positions.

This interpretation closes a gap between issuance rules and service rules. Earlier European Commission and ESMA guidance addressed when a service could itself amount to a public offer, admission to trading or placement. The new opinion says the outcome no longer turns on that classification for each service. An authorised provider may breach its own MiCA duties by keeping a non-compliant token usable or liquid for EU clients even when its particular service is not itself an offer or admission to trading.

ESMA grounds that view in Article 66(1), which requires providers to act honestly, fairly and professionally in the best interests of clients and prospective clients. The regulator says non-compliant tokens expose clients to risks created by missing issuer-level safeguards. A provider cannot adequately identify, manage or mitigate those risks with the measures available at service level. Facilitating the exposure therefore creates a presumption that the provider is acting incompatibly with Article 66(1).

The missing safeguards may include redemption rights, reserve or safeguarding requirements, governance obligations, disclosures and continuing supervision. MiCA-compliant issuers bear those duties and costs. ESMA says allowing unauthorised alternatives to remain accessible would produce different regulatory standards for assets in the same category and an uneven market between compliant and non-compliant issuers.

ESMA gives three reasons for requiring the same approach across the Union. Continued service would let token issuers circumvent the requirements that apply to public offers and trading admission. It would distort competition because compliant issuers bear obligations that unauthorised issuers avoid. It would also leave investors facing different protections and enforcement standards for assets in the same regulatory category. In ESMA’s view, that variation weakens confidence in the integrity and reliability of the EU crypto-asset market. The service restriction is therefore intended to preserve the issuer rules as well as protect an individual provider’s clients.

Warnings do not cure non-compliance

A risk warning or client acknowledgement is not enough. ESMA says disclosures cannot replace issuer safeguards or fully communicate the consequences when several protections are absent together. It also rejects the idea that providers can solve the issue by making their own assessment and explaining it to users. Those assessments require legal, regulatory and operational judgments that could vary in scope, method and conclusion.

The opinion also points to an enforcement problem. Continued access makes it harder for national regulators to check white-paper information, marketing communications and whether trading harms token holders, particularly retail users. ESMA’s answer is to remove service-level access rather than rely on warnings around it.

For users, the immediate effect depends on how a provider implements the required controls. New purchases and position increases should stop. Products that use an affected token as collateral, a settlement asset, a portfolio holding or a transfer rail may also fall within scope because the opinion covers services in combination, not just direct spot trading. Providers will need to identify which tokens qualify and which client locations count as EU access.

Custody is covered, but ESMA allows a narrow exit route for existing holdings. A national regulator may permit residual services needed for an orderly wind-down and to avoid client harm. Those services can include liquidation, conversion, withdrawal, transfer or safekeeping. They must be time-limited, clearly communicated, risk-based and closely supervised. They cannot support new acquisitions, promotion, active trading, distribution or continued market availability.

The implementation deadline

National regulators should require remediation as soon as possible and no later than three months after the opinion’s publication. That puts the outside date on January 8, 2027. The opinion does not name particular stablecoins, prescribe one technical implementation or publish a common EU list of affected assets. Each national authority must assess the providers it supervises and the compliance status of the tokens they support.

The unresolved operational question is whether national regulators will classify the same stablecoins consistently and require the same treatment for custody, transfers and DeFi-facing products. ESMA says it will monitor implementation with those authorities, while providers have until January 8, 2027 at the latest to remediate legacy exposure.

DeFi is coming. Don't get left behind

About the author
Nick Sawinyh founded DeFiprime in 2019 and has edited it ever since. His current editorial focus is stablecoin infrastructure, real-world assets on-chain, DeFi yield and risk, and crypto regulation. Based on the East Coast, US. He holds small positions across a range of crypto assets; nothing he publishes is investment advice.

More from the blog