Austria Fines Bitpanda €70,000 in First Published MiCA Penalty

Austria has issued its first published, legally binding penalty under the European Union’s Markets in Crypto-Assets Regulation, or MiCA, fining crypto platform Bitpanda GmbH €70,000 over breaches involving a crypto-asset white paper and marketing communications.
The Austrian Financial Market Authority announced the penalty on August 14, 2026, saying Bitpanda failed to meet several disclosure and timing requirements under MiCA. The regulator said the decision is final.
The case is important not because of the size of the fine, which is relatively small for a company of Bitpanda’s scale, but because it demonstrates that Europe’s new crypto rulebook has moved beyond licensing and into active enforcement.
It also shows that receiving a MiCA licence does not end a company’s regulatory obligations.
Bitpanda itself received authorization from Austria’s FMA as a crypto-asset service provider in April 2025.
What Did Bitpanda Do Wrong?
According to Austria’s FMA, the violations centered on how Bitpanda handled the documentation and marketing of a crypto asset.
The regulator said Bitpanda failed to submit a required crypto-asset white paper to the FMA at least 20 working days before publishing it.
Under Article 8 of MiCA, issuers and other parties covered by the rule are required to notify the relevant competent authority of a crypto-asset white paper before publication.
The FMA said Bitpanda did not meet that timeline.
The regulator did not publicly identify the crypto asset involved.
Bitpanda Also Marketed the Asset Before Publishing the White Paper
The white-paper timing issue was not the only violation.
The FMA also found that Bitpanda distributed a marketing communication before publishing the required crypto-asset white paper.
MiCA places specific restrictions on how crypto assets can be marketed to consumers.
Under Article 7 of the regulation, marketing communications relating to covered crypto assets must meet disclosure requirements and must be consistent with the information contained in the relevant white paper.
The FMA said Bitpanda breached those requirements by circulating marketing material before the required white paper had been made public.
Some Mandatory Disclosures Were Also Missing
Austria’s regulator identified additional problems with another marketing communication.
According to the FMA, Bitpanda failed to include a mandatory statement explaining that the communication had not been reviewed or approved by a competent authority and that responsibility for its contents remained with the provider.
The marketing material also failed to include a required telephone number and email address.
These requirements may sound administrative, but they form part of MiCA’s broader investor-protection framework.
The idea is that consumers should know who is responsible for a crypto promotion, how they can contact that entity and whether regulators have reviewed the material they are seeing.
The FMA said these omissions contributed to the €70,000 penalty.
The Fine Is Final
The FMA said the proceedings were concluded through an expedited procedure under Austria’s Financial Market Authority Act.
The €70,000 penalty is therefore legally binding and final.
The regulator described MiCA as a framework intended to create uniform rules for crypto assets throughout the European Union while protecting investors and safeguarding the integrity of crypto markets.
Austria is effectively signalling that MiCA is no longer simply about companies preparing applications or regulators handing out licences.
Enforcement has begun.
Bitpanda Remains MiCA-Authorised
The fine does not mean Bitpanda has lost its permission to operate.
Austria’s FMA authorised Bitpanda GmbH as a crypto-asset service provider in April 2025 under Article 63 of MiCA.
The authorization allows Bitpanda to provide services including:
- custody and administration of crypto assets on behalf of clients;
- exchanging crypto assets for funds;
- exchanging one crypto asset for another;
- executing crypto orders on behalf of clients; and
- placing crypto assets.
Bitpanda had previously operated under Austria’s virtual-asset-service-provider regime, but that registration lapsed once its MiCA authorization took effect.
That makes the enforcement case particularly noteworthy.
The company being fined is not an unauthorized offshore exchange.
It is a regulated European crypto business that already went through the MiCA authorization process.
A MiCA Licence Is Not a Free Pass
This is perhaps the biggest lesson from the case.
A MiCA licence allows a crypto company to provide certain regulated services across the European market.
It does not mean regulators stop examining what the company does afterward.
Authorization is only the beginning.
Once licensed, companies must continue meeting requirements covering areas such as:
- governance;
- customer protection;
- conflicts of interest;
- custody;
- operational controls;
- marketing;
- disclosure;
- capital requirements; and
- regulatory reporting.
The Bitpanda case shows that even relatively procedural requirements such as the timing of a white-paper submission can lead to enforcement action.
That matters for every crypto company hoping to operate under MiCA.
What Is a Crypto-Asset White Paper?
The term “white paper” has existed in crypto long before MiCA.
Historically, anyone launching a token could publish a document explaining what the project did, how the token worked and what it was supposed to be used for.
The quality of those documents varied enormously.
Some contained detailed technical information.
Others were little more than marketing documents.
MiCA changes that approach for crypto assets falling within its scope.
Under the EU’s regulatory framework, white papers have become formal disclosure documents subject to specific legal requirements.
Among other things, they can be required to contain information about:
- the issuer or offeror;
- the crypto asset;
- the project;
- associated rights and obligations;
- technology;
- risks; and
- environmental considerations.
The purpose is similar in principle to disclosure documents used in traditional financial markets.
Investors should receive important information before deciding whether to buy.
MiCA Is Now Fully in the Enforcement Era
The timing of the penalty is also important.
MiCA entered into full application for crypto-asset service providers on December 30, 2024, although qualifying businesses in some countries were allowed to continue operating temporarily under transitional arrangements.
That EU-wide transitional period ultimately ended by July 1, 2026.
The European Securities and Markets Authority explained that entities operating under national regimes could continue under certain grandfathering provisions until July 1, 2026, or until they were granted or refused MiCA authorization, whichever came first.
Ahead of that deadline, ESMA warned that unauthorized crypto-asset service providers would need to stop serving EU customers once the transition ended.
The Bitpanda penalty arrived only weeks after that transition ended.
That makes it a useful signal of what the next phase of MiCA could look like.
The regulatory conversation in Europe is shifting from:
Who has received a licence?
to:
Are licensed companies actually following the rules?




