← Research library

Regulation / regulatory guide

How to Verify a Crypto Exchange License: Entity, Scope and Domain Checks

Verify a crypto exchange license by matching the legal entity, regulator record, status, permitted services, jurisdiction, official domain and payment path.

Published 2026-08-16Updated 2026-08-1617 min read

Verifying a crypto exchange licence is not the same as finding a licence number.

A number can be:

  • Genuine but attached to another company
  • Genuine but limited to another jurisdiction
  • Genuine but valid only for a different service
  • Part of an AML registration rather than a broader financial-services authorisation
  • Suspended, withdrawn or expired
  • An application or in-principle approval rather than an active licence
  • Copied onto a clone website with no connection to the regulated company

The reliable approach is to connect the regulatory record to the business that will actually hold or service your account.

Use this chain:

brand → legal entity → regulator → record type → status → jurisdiction → activity → customer scope → domain → payment path

If one of those links is missing, the regulatory claim has not yet been fully verified.

The short answer

To verify a crypto exchange licence:

  1. Find the legal entity in the customer agreement.
  2. Identify the regulator and record type being claimed.
  3. Open the regulator's official database independently.
  4. Search the exact legal entity and regulatory reference.
  5. Check whether the status is active, authorised or only pending.
  6. Read the permitted services and geographic scope.
  7. Match the official domain, app and contact details.
  8. Confirm that the account agreement names the same entity.
  9. Check that the deposit and payment route fits the regulated structure.
  10. Save the record with the date you verified it.

A licence badge, PDF certificate or regulator logo on the exchange's own website should be treated as a lead—not as final proof.

Crypto exchanges are usually marketed as brands.

Regulators license or register legal entities.

Those are different things.

A global exchange group can have a structure like:

Exchange Brand
├── European company
├── Dubai company
├── Hong Kong company
├── US money-transmitter entity
├── derivatives company
└── offshore global entity

Each company can have:

  • A different regulator
  • A different record type
  • Different permitted services
  • Different customer eligibility
  • Different complaint routes
  • Different custody arrangements

This means the question:

“Is Exchange X licensed?”

is often too broad.

The more useful question is:

Which company will serve my account, and what exactly is that company permitted to do?

Cexvia applies this same entity-level approach in its Regulatory Atlas and Exchange Passport research.

Explore Cexvia Regulatory Atlas

The Cexvia licence-verification model

Cexvia separates ten fields that are frequently compressed into a single “regulated” badge.

FieldWhat to verify
BrandThe trading platform users recognise
Legal entityThe company named in the customer agreement
RegulatorThe official authority maintaining the record
Record typeLicence, authorisation, registration, approval, etc.
Reference numberThe regulator's unique identifier
StatusActive, suspended, withdrawn, pending, restricted, etc.
JurisdictionCountry, state or regulatory territory
ActivitySpot trading, custody, exchange, derivatives, payments, etc.
Customer scopeRetail, professional, institutional or other limitations
DomainWebsite or service actually connected to the regulated entity

Cexvia's methodology treats regulatory standing as one evidence dimension. A regulatory record is not automatically converted into a global safety conclusion.

Read Cexvia Methodology

Step 1 — Find the company that actually serves the account

Start with the exchange's legal documents.

Check:

  • Terms of service
  • User agreement
  • Account-opening terms
  • Privacy notice
  • Legal / regulatory page
  • Fiat deposit instructions
  • Account footer

Record:

Brand:
Legal entity:
Company number:
Registered address:
Governing law:
Account country:
Relevant product:

Do not search only the brand name.

Why the user agreement matters

A press release may say:

“Exchange X receives European authorisation.”

But the account agreement may place a specific customer under:

Exchange X Global Ltd

instead of the regulated European affiliate.

The licence held by one group company does not automatically cover another.

A platform that accepts customer money or crypto but does not clearly identify the contracting company creates a major verification problem.

Before depositing, the user should be able to answer:

Who legally owes me the account balance?

If that cannot be established, a licence search will be unreliable.

Step 2 — Identify what kind of regulatory record is being claimed

Do not assume every regulatory number is a “licence.”

Common record types include:

Record typeTypical meaning
Company incorporationConfirms legal existence
AML registrationPlaces the entity under AML / CTF obligations
MSB registrationUS money-services registration under applicable federal rules
VASP registrationScope varies significantly by jurisdiction
CASP authorisationMiCA authorisation for specified EU crypto-asset services
VASP licenceActivity-specific virtual-asset authorisation in some jurisdictions
Money-transmitter licenceState or jurisdiction-specific money-transmission permission
Broker / dealer authorisationFinancial-services activity within defined scope
Derivatives licenceRelevant futures, options or derivatives activity
In-principle approvalConditional stage before full authorisation in some regimes

The regulator's terminology should be preserved.

Do not rewrite:

Registered Money Services Business

as:

Fully licensed US crypto exchange

unless the broader statement is independently supported.

For the distinction between registration and authorisation, see:

Registered, Licensed or Regulated? How to Verify a Crypto Exchange

Step 3 — Open the regulator's website independently

Do not verify a licence through a link supplied only by:

  • A recruiter
  • A trading mentor
  • Telegram support
  • WhatsApp support
  • A relationship contact
  • A private investment group
  • A suspicious exchange website

Fraudsters can build fake regulator websites as well as fake exchanges.

Use the known official authority or government domain.

Examples of official starting points include:

European Union

ESMA MiCA Register

ESMA maintains a central register that includes authorised crypto-asset service providers and non-compliant entities based on information from national competent authorities.

ESMA — Markets in Crypto-Assets Regulation

Dubai

VARA Public Register

Dubai's Virtual Assets Regulatory Authority publishes its VASP register, including licence status and licensed activities.

VARA — Public Register

United Kingdom

FCA

The UK currently requires in-scope cryptoasset businesses to comply with the applicable MLR registration framework while the new FSMA authorisation regime is introduced.

FCA — Cryptoassets

United States

The US does not have one universal federal crypto-exchange licence.

Relevant checks can include:

  • FinCEN MSB registration
  • State money-transmitter records
  • New York virtual-currency authorisation
  • SEC records for securities-related activity
  • CFTC records for derivatives-related activity

FinCEN — Money Services Business Registration

Australia

AUSTRAC maintains regulatory registration for virtual-asset service providers under Australia's AML / CTF framework.

In 2026, Australia updated the terminology from digital currency exchange providers toward the internationally recognised VASP terminology and made a searchable public register available.

AUSTRAC — Virtual Asset Service Providers

The correct database always depends on what activity is being claimed.

Search using:

  1. Full legal name
  2. Regulatory reference number
  3. Company number
  4. Former company name
  5. Trading name, if the register supports it

Do not accept a close spelling as automatically equivalent.

Example

The exchange claims:

Entity:
Alpha Digital Markets Ltd

Licence:
123456

The official register returns:

Alpha Digital Holdings Ltd
Reference: 123456

That is not a match merely because the names look similar.

Investigate:

  • Whether one is a former name
  • Whether the companies are affiliates
  • Whether the record has been copied
  • Whether the exchange's claim is inaccurate

Licence cloning

A common fake-platform technique is to copy a genuine reference number.

The number resolves to a real regulated company, which can make the fake site appear legitimate.

The correct conclusion is not:

“The number is real, therefore the website is real.”

It is:

Does the company in the official record match the company and domain I am using?

Step 5 — Check the status before reading the marketing claim

Finding the company is not enough.

Read the current status.

Possible statuses include:

  • Active
  • Authorised
  • Registered
  • Licensed
  • Restricted
  • Suspended
  • Revoked
  • Withdrawn
  • Expired
  • Cancelled
  • Pending
  • Applied
  • In-principle approval
  • In liquidation

These do not mean the same thing.

Application is not authorisation

A platform may announce:

“We have applied for a MiCA licence.”

That does not mean the application has been granted.

Likewise:

Application submitted
≠
authorised

In-Principle Approval is not a full VARA licence

VARA's public register explicitly distinguishes fully licensed VASPs from firms holding an In-Principle Approval (IPA).

VARA states that an IPA is a conditional stage and that firms holding only an IPA are prohibited from initiating operations, conducting virtual-asset activities or servicing clients until the full VASP licence is obtained.

Therefore:

VARA IPA
≠
VARA VASP Licence

This is exactly why the status field matters more than a screenshot saying “approved by VARA.”

Step 6 — Check dates and regulatory transitions

A regulatory record can be genuine and still be outdated for the current service.

Record:

Issue date:
Effective date:
Expiry date:
Withdrawal date:
Last register update:
Verification date:

EU MiCA transition

Older national VASP registrations should not automatically be treated as current MiCA authorisation.

The EU's MiCA transition has changed the regulatory basis for crypto-asset service providers, and current verification should use the relevant MiCA / competent-authority record.

UK transition

The United Kingdom provides another example of why date matters.

As of August 2026, in-scope cryptoasset firms remain subject to the current MLR registration framework while the FCA prepares the new FSMA cryptoasset regime.

The FCA states that:

  • The FSMA authorisation gateway opens on 30 September 2026.
  • The new regime is expected to begin on 25 October 2027.
  • Existing MLR registration does not automatically become FSMA authorisation.
  • Being registered under the MLRs does not guarantee future FSMA authorisation.

Therefore, a UK regulatory claim should record the actual regime:

FCA MLR registration

rather than prematurely describing it as:

FSMA-authorised cryptoasset firm

Official reference:

FCA — Registration under the MLRs ahead of the new FSMA regime

Step 7 — Read the permitted activities line by line

The existence of a licence does not mean every product offered by the wider exchange group is covered.

Check the authorised activity.

Examples include:

  • Custody
  • Exchange of crypto-assets for funds
  • Exchange of crypto-assets for other crypto-assets
  • Operating a trading platform
  • Execution of orders
  • Transfer services
  • Brokerage
  • Advisory services
  • Lending
  • Staking
  • Derivatives
  • Payment services

MiCA example

Under MiCA, crypto-asset services are authorised by service category.

An EU CASP authorisation should therefore be checked against the user's intended activity.

If the user wants:

BTC/EUR spot trading
+
custody
+
withdrawal

verify that the relevant services are within the entity's authorisation.

Do not assume:

MiCA authorised
=
every crypto product offered by the global brand

VARA example

VARA's public register includes specific licensed activities such as:

  • Broker-Dealer Services
  • Custody Services
  • Exchange Services
  • Management and Investment Services
  • Lending and Borrowing Services
  • Advisory Services

A company licensed for one activity should not automatically be described as licensed for all of them.

Step 8 — Check jurisdiction and customer scope

A valid licence can still be irrelevant to a specific user.

Verify:

  • Country
  • State
  • EEA / EU route
  • Retail eligibility
  • Professional-client restrictions
  • Institutional-only restrictions
  • Residency exclusions

Jurisdiction mismatch example

Suppose an exchange has a genuine Dubai VARA licence.

A customer lives in Germany.

The correct conclusion is not:

“The exchange is licensed, therefore my German account is covered by the Dubai licence.”

The relevant question is:

Which entity serves the German customer, and what EU regulatory basis applies to that account?

Licences should never be stretched across borders without evidence.

Step 9 — Match the official domain

A regulatory record can be real while the website is fake.

This is one of the most important scam-prevention checks.

Compare:

Regulator record
        ↓
Legal entity
        ↓
Official domain
        ↓
Website being used

Clone-site example

Official licensed company:

Alpha Digital Markets Ltd
Official domain: alphadigital.com
Licence: 123456

User is visiting:

alpha-digitalvip.com

The clone can copy:

  • Company name
  • Licence number
  • Logo
  • Address
  • Certificate
  • Terms

The licence remains genuine.

The connection between the licence and the clone website is not.

If the regulator does not publish a domain

Not every register includes approved URLs.

In that case:

  1. Match the legal entity and reference.
  2. Use independently verified corporate contact information.
  3. Check whether the regulated company links to the exchange domain.
  4. Contact the regulator if necessary.
  5. Do not let the disputed website provide both sides of the verification.

For fake-platform verification, see:

How to Spot a Fake Crypto Exchange: 12 Red Flags and Verification Checks

Step 10 — Match the mobile app

The mobile app is another identity layer.

Check:

  • App publisher
  • Developer name
  • Linked website
  • Privacy-policy domain
  • Store listing
  • Whether the verified exchange website links to the same app

A genuine regulatory record does not protect a user who installs an impersonating app.

Be particularly cautious with:

  • APK files sent through messaging apps
  • Enterprise distribution profiles
  • Test builds
  • Configuration profiles
  • Remote-access software
  • Apps installed through links from investment mentors

The app should map back to the same verified operating business.

Step 11 — Compare the account agreement with the regulatory record

This is where many superficial licence checks fail.

The exchange may have a valid licence somewhere in its corporate group, but the customer agreement may name another company.

Compare:

Account documentRegulator record
Legal entityLicence holder
AddressRegistered address
CountryJurisdiction
ProductAuthorised service
Customer typeEligible client category
DomainApproved / official domain
Complaint routeRelevant regulated entity

If these do not align, investigate before depositing.

Example

Marketing page:

“Licensed in Europe under MiCA.”

User agreement:

Contracting entity:
Example Global Ltd
Jurisdiction:
Offshore jurisdiction

Regulator:

MiCA entity:
Example Europe S.A.

The existence of the MiCA entity does not by itself prove the user's account is provided by it.

Step 12 — Compare the deposit and payment path

The final verification should include how money or crypto actually enters the account.

For fiat deposits, record:

  • Beneficiary name
  • Bank or payment partner
  • IBAN / account
  • Reference
  • Legal relationship disclosed by the exchange

For crypto deposits, record:

  • Asset
  • Network
  • Address
  • Memo / tag
  • Whether the address is generated inside the authenticated account

Why this matters

A platform can pass the company-name test but fail at the payment stage.

Warning signs include:

  • Payment to an individual's bank account
  • Beneficiary unrelated to the exchange with no disclosed explanation
  • Deposit wallet supplied only through Telegram
  • “Account manager” replacing the in-app address
  • Instructions to lie to the bank about payment purpose
  • A different company appearing on every transfer

Payment partners can be legitimate.

The relationship should be identifiable and consistent with the platform's documentation.

Worked example 1 — MiCA: Kraken in the EEA

Cexvia's current exchange records map Kraken's Ireland / EEA crypto-service route to:

Brand:
Kraken

Legal entity:
Payward Europe Solutions Limited

Jurisdiction:
Ireland / European Economic Area

Record type:
MiCA Crypto-Asset Service Provider

Regulator:
Central Bank of Ireland

Reference:
C468360

Cexvia status:
Active

The relevant lesson is not that the Kraken brand has one global licence.

It is that a specific legal entity is mapped to a specific European regulatory record.

A user should still verify that the account agreement and intended service correspond to that entity.

Cexvia — Kraken Risk Profile

Worked example 2 — Hong Kong: HashKey Exchange

Cexvia maps the Hong Kong HashKey Exchange route to:

Brand:
HashKey Exchange

Legal entity:
Hash Blockchain Limited

Jurisdiction:
Hong Kong

Regulator:
Securities and Futures Commission

Record type:
Licensed virtual asset trading platform operator

Reference:
CE No. BPL992

Cexvia status:
Active

Again, the licence applies to the identified entity and regulatory perimeter.

HashKey also has other entities in other jurisdictions, which Cexvia evaluates separately.

Cexvia — HashKey Exchange Risk Profile

Worked example 3 — US MSB record is not a universal exchange licence

Cexvia's US Regulatory Atlas includes records that combine federal MSB evidence with state money-transmitter scope.

For example, its current Trek Labs, Inc. record identifies:

FinCEN:
31000315905825

NMLS:
2665675

Cexvia classification:
MSB and state money-transmitter scope

The important point is the classification.

Cexvia does not convert the FinCEN number into:

US federal crypto exchange licence

because that would overstate the record.

Cexvia — United States Regulatory Framework

Worked example 4 — VARA: licence status and activity both matter

VARA's public register provides fields including:

VASP name
Licence type
Reference
Licensed activities
Licence issue date
Status

It also separates fully licensed firms from entities holding only In-Principle Approval.

A proper verification should therefore capture:

Entity:
Reference:
Status:
Licensed activity:
Date:

—not only “VARA regulated.”

Cexvia — Dubai Regulatory Framework

Different countries require different interpretations

A single template can be used globally, but the legal meaning of the record must remain jurisdiction-specific.

MarketExample recordKey verification issue
EUMiCA CASP authorisationEntity + authorised crypto services
DubaiVARA VASP licenceFull licence vs IPA + activity
UKFCA MLR registration / future FSMA regimeDo not confuse current registration with future authorisation
USFinCEN + state records + product-specific regulationNo single universal federal crypto-exchange licence
AustraliaAUSTRAC VASP registration + other financial-services rules where applicableAML / CTF registration is not automatically every financial-services permission
Hong KongSFC virtual asset trading platform licensingExact licensed operator + scope
JapanRegistered Crypto-Asset Exchange Service ProviderExact entity and registration number

The field names may change.

The logic does not:

entity → regulator → record → scope → status → customer

How Australia illustrates record-type risk

Australia provides another useful example of why a regulator entry needs context.

AUSTRAC regulates virtual-asset service providers under the AML / CTF framework.

In 2026, AUSTRAC:

  • Expanded the virtual-asset regulatory perimeter
  • Moved from older DCE terminology toward VASP terminology
  • Made a searchable public VASP register available
  • Continued to take registration action against inactive or unsuitable entities

A valid AUSTRAC registration is meaningful regulatory evidence.

It should still be classified according to what the AUSTRAC regime establishes rather than described as a universal licence for every financial product.

Other Australian financial-services or market licensing obligations can apply depending on the product or service.

Official reference:

AUSTRAC — Public VASP Register Update

Red flags during licence verification

Stop and investigate when you see:

Identity mismatch

Website company ≠ regulator company

Domain mismatch

Official domain ≠ website being used

Status inflation

Applied → marketed as licensed

Approval inflation

In-Principle Approval → marketed as fully authorised

Scope inflation

Custody licence → marketed as permission for derivatives

Jurisdiction inflation

Dubai licence → marketed as global authorisation

Registration inflation

FinCEN MSB registration → marketed as US government approval

Group-company inflation

Entity A licensed → Entity B presented as licensed

Stale evidence

Old certificate → current status not checked

Payment mismatch

Licensed company → deposit requested to unrelated person

Any one issue may have a legitimate explanation.

The explanation should be independently verifiable before funds are sent.

What a regulator logo does not prove

The following are not substitutes for an official register check:

  • Regulator logo
  • Certificate image
  • Screenshot
  • Licence badge
  • News article
  • Exchange press release
  • Affiliate marketing page
  • Search-engine snippet
  • Social-media verification badge
  • Customer-support statement

The exchange itself can tell you what to investigate.

The regulator's record tells you what is officially recorded.

Those two sources should be compared, not treated as interchangeable.

How Cexvia should store licence evidence

For each regulatory record, Cexvia should preserve structured evidence.

Recommended fields:

brand:
legal_entity:
jurisdiction:
regulator:
record_type:
reference_number:
status:
authorised_activities:
customer_scope:
official_domain:
issue_date:
effective_date:
expiry_or_withdrawal_date:
source_url:
verified_at:
cexvia_interpretation:

Example interpretation

record_type: "Money Services Business registration"
status: "Registered"
cexvia_interpretation: >
  Federal US MSB / AML registration.
  Does not by itself establish nationwide permission
  for every crypto exchange product.

Or:

record_type: "VARA In-Principle Approval"
status: "IPA"
cexvia_interpretation: >
  Conditional licensing stage.
  Not a full VASP licence and does not authorise
  the applicant to begin servicing clients.

This makes Cexvia's regulatory data more useful than a simple:

Licensed: Yes

Cexvia verification checklist

Before describing an exchange as licensed or authorised, confirm:

Identity

  • [ ] Brand identified
  • [ ] Legal entity identified
  • [ ] Company number matched
  • [ ] Account agreement reviewed

Regulator

  • [ ] Official regulator identified
  • [ ] Official register used
  • [ ] Regulatory number matched
  • [ ] Current record saved

Status

  • [ ] Active / authorised / registered status confirmed
  • [ ] Application not confused with authorisation
  • [ ] IPA / conditional status identified
  • [ ] Suspension / restriction checked

Scope

  • [ ] Jurisdiction confirmed
  • [ ] Product / service scope confirmed
  • [ ] Customer type checked
  • [ ] Regional restrictions checked

Digital identity

  • [ ] Domain matched
  • [ ] App publisher matched
  • [ ] Official contact details matched
  • [ ] Contracting entity matches record
  • [ ] Deposit route is explainable
  • [ ] Payment partner is identified
  • [ ] Complaint route matches the entity

If a material field cannot be verified, Cexvia should record it as unverified or scope unclear, not guess.

That aligns with Cexvia's methodology: missing evidence lowers coverage or confidence rather than being silently filled in.

Frequently asked questions

How do I verify a crypto exchange licence?

Find the legal entity in the exchange's account terms, then search that entity in the regulator's official database.

Confirm the record type, reference number, status, jurisdiction, authorised services and domain before linking the licence to the account.

Can I trust a licence certificate on an exchange website?

Use it only as a starting point.

Certificates can be copied, altered, outdated or displayed by a clone website.

The live regulator record is more important.

What if the licence number is real but the company name is different?

Do not treat the licence as verified for the exchange.

Investigate whether the company changed names or whether the number belongs to an unrelated entity.

Licence cloning is a known fake-platform pattern.

Does an MSB number mean a crypto exchange is licensed in the United States?

Not as a universal federal crypto-exchange licence.

FinCEN MSB registration relates to the money-services and AML / BSA framework. State permissions and product-specific federal regulation can also be relevant.

Is a MiCA application the same as MiCA authorisation?

No.

An application means the company has applied.

Use the ESMA and relevant national-authority records to confirm whether authorisation has actually been granted.

Is a VARA In-Principle Approval a full licence?

No.

VARA states that an IPA is a conditional stage. An entity with only an IPA is not permitted to begin virtual-asset operations or service clients until it obtains the full VASP licence.

Does one licence cover every company in an exchange group?

No.

Regulatory records attach to specific legal entities.

Each entity, jurisdiction and service should be checked separately.

Does one licence cover spot trading, custody and derivatives?

Not necessarily.

Licences and authorisations can be activity-specific.

Read the permitted services rather than assuming one permission covers the entire product catalogue.

Does a valid licence mean the exchange is safe?

No.

Regulatory standing is one risk dimension.

Users should separately assess:

  • Corporate transparency
  • Reserves and liabilities
  • Custody
  • Security incidents
  • Withdrawal reliability
  • Operational controls

Cexvia evaluates those dimensions separately.

What if the regulator does not publish the website domain?

Match the legal entity, reference number, address and other identifiers.

Then verify the domain through independently obtained corporate or regulator contact details.

Do not let the disputed exchange supply both sides of the confirmation.

How often should a licence be checked?

Check before opening or materially funding an account and again when:

  • The exchange migrates users to another entity
  • Terms of service change
  • The user moves country
  • A major regulatory announcement occurs
  • A licence approaches expiry
  • A regulator publishes enforcement action
  • Product availability changes

Regulatory status is time-sensitive evidence.

Conclusion

Crypto exchange licence verification is an identity-and-scope exercise.

The correct workflow is not:

Find a licence number
→ assume regulated

It is:

Brand
→ Legal entity
→ Regulator
→ Record type
→ Reference
→ Status
→ Jurisdiction
→ Activity
→ Customer scope
→ Domain
→ Account agreement
→ Payment path

A licence claim is only as strong as the connection between those records.

A genuine regulatory number attached to the wrong company is not verification.

A genuine company registration presented as a financial licence is not verification.

An application described as an active authorisation is not verification.

And a full licence held by one affiliate does not automatically cover every website or product operated by the wider brand.

Cexvia's Regulatory Atlas is built around the same principle: map the licence to the entity.

For exchange research:

  • [Cexvia Regulatory Atlas](/regulators)
  • [Cexvia Exchange Risk Profiles](/exchanges)
  • [Cexvia Methodology](/methodology)
  • [Cexvia Exchange Safety Checklist](/exchange-safety-checklist)

Primary sources and Cexvia resources


*Cexvia evaluates centralized exchanges using publicly verifiable evidence across regulatory standing, corporate transparency, asset and solvency transparency, security history, and operations and user protection. Regulatory records are mapped to the relevant legal entity, jurisdiction and documented activity. Ratings are evidence-based assessments, not guarantees of safety or recommendations to deposit or trade.*