Verifying a crypto exchange licence is not the same as finding a licence number.
A number can be:
- Genuine but attached to another company
- Genuine but limited to another jurisdiction
- Genuine but valid only for a different service
- Part of an AML registration rather than a broader financial-services authorisation
- Suspended, withdrawn or expired
- An application or in-principle approval rather than an active licence
- Copied onto a clone website with no connection to the regulated company
The reliable approach is to connect the regulatory record to the business that will actually hold or service your account.
Use this chain:
brand → legal entity → regulator → record type → status → jurisdiction → activity → customer scope → domain → payment path
If one of those links is missing, the regulatory claim has not yet been fully verified.
The short answer
To verify a crypto exchange licence:
- Find the legal entity in the customer agreement.
- Identify the regulator and record type being claimed.
- Open the regulator's official database independently.
- Search the exact legal entity and regulatory reference.
- Check whether the status is active, authorised or only pending.
- Read the permitted services and geographic scope.
- Match the official domain, app and contact details.
- Confirm that the account agreement names the same entity.
- Check that the deposit and payment route fits the regulated structure.
- Save the record with the date you verified it.
A licence badge, PDF certificate or regulator logo on the exchange's own website should be treated as a lead—not as final proof.
Why licence verification starts with the legal entity
Crypto exchanges are usually marketed as brands.
Regulators license or register legal entities.
Those are different things.
A global exchange group can have a structure like:
Exchange Brand
├── European company
├── Dubai company
├── Hong Kong company
├── US money-transmitter entity
├── derivatives company
└── offshore global entityEach company can have:
- A different regulator
- A different record type
- Different permitted services
- Different customer eligibility
- Different complaint routes
- Different custody arrangements
This means the question:
“Is Exchange X licensed?”
is often too broad.
The more useful question is:
Which company will serve my account, and what exactly is that company permitted to do?
Cexvia applies this same entity-level approach in its Regulatory Atlas and Exchange Passport research.
Explore Cexvia Regulatory Atlas
The Cexvia licence-verification model
Cexvia separates ten fields that are frequently compressed into a single “regulated” badge.
| Field | What to verify |
|---|---|
| Brand | The trading platform users recognise |
| Legal entity | The company named in the customer agreement |
| Regulator | The official authority maintaining the record |
| Record type | Licence, authorisation, registration, approval, etc. |
| Reference number | The regulator's unique identifier |
| Status | Active, suspended, withdrawn, pending, restricted, etc. |
| Jurisdiction | Country, state or regulatory territory |
| Activity | Spot trading, custody, exchange, derivatives, payments, etc. |
| Customer scope | Retail, professional, institutional or other limitations |
| Domain | Website or service actually connected to the regulated entity |
Cexvia's methodology treats regulatory standing as one evidence dimension. A regulatory record is not automatically converted into a global safety conclusion.
Step 1 — Find the company that actually serves the account
Start with the exchange's legal documents.
Check:
- Terms of service
- User agreement
- Account-opening terms
- Privacy notice
- Legal / regulatory page
- Fiat deposit instructions
- Account footer
Record:
Brand:
Legal entity:
Company number:
Registered address:
Governing law:
Account country:
Relevant product:Do not search only the brand name.
Why the user agreement matters
A press release may say:
“Exchange X receives European authorisation.”
But the account agreement may place a specific customer under:
Exchange X Global Ltdinstead of the regulated European affiliate.
The licence held by one group company does not automatically cover another.
Stop if no legal entity is identifiable
A platform that accepts customer money or crypto but does not clearly identify the contracting company creates a major verification problem.
Before depositing, the user should be able to answer:
Who legally owes me the account balance?
If that cannot be established, a licence search will be unreliable.
Step 2 — Identify what kind of regulatory record is being claimed
Do not assume every regulatory number is a “licence.”
Common record types include:
| Record type | Typical meaning |
|---|---|
| Company incorporation | Confirms legal existence |
| AML registration | Places the entity under AML / CTF obligations |
| MSB registration | US money-services registration under applicable federal rules |
| VASP registration | Scope varies significantly by jurisdiction |
| CASP authorisation | MiCA authorisation for specified EU crypto-asset services |
| VASP licence | Activity-specific virtual-asset authorisation in some jurisdictions |
| Money-transmitter licence | State or jurisdiction-specific money-transmission permission |
| Broker / dealer authorisation | Financial-services activity within defined scope |
| Derivatives licence | Relevant futures, options or derivatives activity |
| In-principle approval | Conditional stage before full authorisation in some regimes |
The regulator's terminology should be preserved.
Do not rewrite:
Registered Money Services Businessas:
Fully licensed US crypto exchangeunless the broader statement is independently supported.
For the distinction between registration and authorisation, see:
Registered, Licensed or Regulated? How to Verify a Crypto Exchange
Step 3 — Open the regulator's website independently
Do not verify a licence through a link supplied only by:
- A recruiter
- A trading mentor
- Telegram support
- WhatsApp support
- A relationship contact
- A private investment group
- A suspicious exchange website
Fraudsters can build fake regulator websites as well as fake exchanges.
Use the known official authority or government domain.
Examples of official starting points include:
European Union
ESMA MiCA Register
ESMA maintains a central register that includes authorised crypto-asset service providers and non-compliant entities based on information from national competent authorities.
ESMA — Markets in Crypto-Assets Regulation
Dubai
VARA Public Register
Dubai's Virtual Assets Regulatory Authority publishes its VASP register, including licence status and licensed activities.
United Kingdom
FCA
The UK currently requires in-scope cryptoasset businesses to comply with the applicable MLR registration framework while the new FSMA authorisation regime is introduced.
United States
The US does not have one universal federal crypto-exchange licence.
Relevant checks can include:
- FinCEN MSB registration
- State money-transmitter records
- New York virtual-currency authorisation
- SEC records for securities-related activity
- CFTC records for derivatives-related activity
FinCEN — Money Services Business Registration
Australia
AUSTRAC maintains regulatory registration for virtual-asset service providers under Australia's AML / CTF framework.
In 2026, Australia updated the terminology from digital currency exchange providers toward the internationally recognised VASP terminology and made a searchable public register available.
AUSTRAC — Virtual Asset Service Providers
The correct database always depends on what activity is being claimed.
Step 4 — Search the exact legal entity
Search using:
- Full legal name
- Regulatory reference number
- Company number
- Former company name
- Trading name, if the register supports it
Do not accept a close spelling as automatically equivalent.
Example
The exchange claims:
Entity:
Alpha Digital Markets Ltd
Licence:
123456The official register returns:
Alpha Digital Holdings Ltd
Reference: 123456That is not a match merely because the names look similar.
Investigate:
- Whether one is a former name
- Whether the companies are affiliates
- Whether the record has been copied
- Whether the exchange's claim is inaccurate
Licence cloning
A common fake-platform technique is to copy a genuine reference number.
The number resolves to a real regulated company, which can make the fake site appear legitimate.
The correct conclusion is not:
“The number is real, therefore the website is real.”
It is:
Does the company in the official record match the company and domain I am using?
Step 5 — Check the status before reading the marketing claim
Finding the company is not enough.
Read the current status.
Possible statuses include:
- Active
- Authorised
- Registered
- Licensed
- Restricted
- Suspended
- Revoked
- Withdrawn
- Expired
- Cancelled
- Pending
- Applied
- In-principle approval
- In liquidation
These do not mean the same thing.
Application is not authorisation
A platform may announce:
“We have applied for a MiCA licence.”
That does not mean the application has been granted.
Likewise:
Application submitted
≠
authorisedIn-Principle Approval is not a full VARA licence
VARA's public register explicitly distinguishes fully licensed VASPs from firms holding an In-Principle Approval (IPA).
VARA states that an IPA is a conditional stage and that firms holding only an IPA are prohibited from initiating operations, conducting virtual-asset activities or servicing clients until the full VASP licence is obtained.
Therefore:
VARA IPA
≠
VARA VASP LicenceThis is exactly why the status field matters more than a screenshot saying “approved by VARA.”
Step 6 — Check dates and regulatory transitions
A regulatory record can be genuine and still be outdated for the current service.
Record:
Issue date:
Effective date:
Expiry date:
Withdrawal date:
Last register update:
Verification date:EU MiCA transition
Older national VASP registrations should not automatically be treated as current MiCA authorisation.
The EU's MiCA transition has changed the regulatory basis for crypto-asset service providers, and current verification should use the relevant MiCA / competent-authority record.
UK transition
The United Kingdom provides another example of why date matters.
As of August 2026, in-scope cryptoasset firms remain subject to the current MLR registration framework while the FCA prepares the new FSMA cryptoasset regime.
The FCA states that:
- The FSMA authorisation gateway opens on 30 September 2026.
- The new regime is expected to begin on 25 October 2027.
- Existing MLR registration does not automatically become FSMA authorisation.
- Being registered under the MLRs does not guarantee future FSMA authorisation.
Therefore, a UK regulatory claim should record the actual regime:
FCA MLR registrationrather than prematurely describing it as:
FSMA-authorised cryptoasset firmOfficial reference:
FCA — Registration under the MLRs ahead of the new FSMA regime
Step 7 — Read the permitted activities line by line
The existence of a licence does not mean every product offered by the wider exchange group is covered.
Check the authorised activity.
Examples include:
- Custody
- Exchange of crypto-assets for funds
- Exchange of crypto-assets for other crypto-assets
- Operating a trading platform
- Execution of orders
- Transfer services
- Brokerage
- Advisory services
- Lending
- Staking
- Derivatives
- Payment services
MiCA example
Under MiCA, crypto-asset services are authorised by service category.
An EU CASP authorisation should therefore be checked against the user's intended activity.
If the user wants:
BTC/EUR spot trading
+
custody
+
withdrawalverify that the relevant services are within the entity's authorisation.
Do not assume:
MiCA authorised
=
every crypto product offered by the global brandVARA example
VARA's public register includes specific licensed activities such as:
- Broker-Dealer Services
- Custody Services
- Exchange Services
- Management and Investment Services
- Lending and Borrowing Services
- Advisory Services
A company licensed for one activity should not automatically be described as licensed for all of them.
Step 8 — Check jurisdiction and customer scope
A valid licence can still be irrelevant to a specific user.
Verify:
- Country
- State
- EEA / EU route
- Retail eligibility
- Professional-client restrictions
- Institutional-only restrictions
- Residency exclusions
Jurisdiction mismatch example
Suppose an exchange has a genuine Dubai VARA licence.
A customer lives in Germany.
The correct conclusion is not:
“The exchange is licensed, therefore my German account is covered by the Dubai licence.”
The relevant question is:
Which entity serves the German customer, and what EU regulatory basis applies to that account?
Licences should never be stretched across borders without evidence.
Step 9 — Match the official domain
A regulatory record can be real while the website is fake.
This is one of the most important scam-prevention checks.
Compare:
Regulator record
↓
Legal entity
↓
Official domain
↓
Website being usedClone-site example
Official licensed company:
Alpha Digital Markets Ltd
Official domain: alphadigital.com
Licence: 123456User is visiting:
alpha-digitalvip.comThe clone can copy:
- Company name
- Licence number
- Logo
- Address
- Certificate
- Terms
The licence remains genuine.
The connection between the licence and the clone website is not.
If the regulator does not publish a domain
Not every register includes approved URLs.
In that case:
- Match the legal entity and reference.
- Use independently verified corporate contact information.
- Check whether the regulated company links to the exchange domain.
- Contact the regulator if necessary.
- Do not let the disputed website provide both sides of the verification.
For fake-platform verification, see:
How to Spot a Fake Crypto Exchange: 12 Red Flags and Verification Checks
Step 10 — Match the mobile app
The mobile app is another identity layer.
Check:
- App publisher
- Developer name
- Linked website
- Privacy-policy domain
- Store listing
- Whether the verified exchange website links to the same app
A genuine regulatory record does not protect a user who installs an impersonating app.
Be particularly cautious with:
- APK files sent through messaging apps
- Enterprise distribution profiles
- Test builds
- Configuration profiles
- Remote-access software
- Apps installed through links from investment mentors
The app should map back to the same verified operating business.
Step 11 — Compare the account agreement with the regulatory record
This is where many superficial licence checks fail.
The exchange may have a valid licence somewhere in its corporate group, but the customer agreement may name another company.
Compare:
| Account document | Regulator record |
|---|---|
| Legal entity | Licence holder |
| Address | Registered address |
| Country | Jurisdiction |
| Product | Authorised service |
| Customer type | Eligible client category |
| Domain | Approved / official domain |
| Complaint route | Relevant regulated entity |
If these do not align, investigate before depositing.
Example
Marketing page:
“Licensed in Europe under MiCA.”
User agreement:
Contracting entity:
Example Global Ltd
Jurisdiction:
Offshore jurisdictionRegulator:
MiCA entity:
Example Europe S.A.The existence of the MiCA entity does not by itself prove the user's account is provided by it.
Step 12 — Compare the deposit and payment path
The final verification should include how money or crypto actually enters the account.
For fiat deposits, record:
- Beneficiary name
- Bank or payment partner
- IBAN / account
- Reference
- Legal relationship disclosed by the exchange
For crypto deposits, record:
- Asset
- Network
- Address
- Memo / tag
- Whether the address is generated inside the authenticated account
Why this matters
A platform can pass the company-name test but fail at the payment stage.
Warning signs include:
- Payment to an individual's bank account
- Beneficiary unrelated to the exchange with no disclosed explanation
- Deposit wallet supplied only through Telegram
- “Account manager” replacing the in-app address
- Instructions to lie to the bank about payment purpose
- A different company appearing on every transfer
Payment partners can be legitimate.
The relationship should be identifiable and consistent with the platform's documentation.
Worked example 1 — MiCA: Kraken in the EEA
Cexvia's current exchange records map Kraken's Ireland / EEA crypto-service route to:
Brand:
Kraken
Legal entity:
Payward Europe Solutions Limited
Jurisdiction:
Ireland / European Economic Area
Record type:
MiCA Crypto-Asset Service Provider
Regulator:
Central Bank of Ireland
Reference:
C468360
Cexvia status:
ActiveThe relevant lesson is not that the Kraken brand has one global licence.
It is that a specific legal entity is mapped to a specific European regulatory record.
A user should still verify that the account agreement and intended service correspond to that entity.
Worked example 2 — Hong Kong: HashKey Exchange
Cexvia maps the Hong Kong HashKey Exchange route to:
Brand:
HashKey Exchange
Legal entity:
Hash Blockchain Limited
Jurisdiction:
Hong Kong
Regulator:
Securities and Futures Commission
Record type:
Licensed virtual asset trading platform operator
Reference:
CE No. BPL992
Cexvia status:
ActiveAgain, the licence applies to the identified entity and regulatory perimeter.
HashKey also has other entities in other jurisdictions, which Cexvia evaluates separately.
Cexvia — HashKey Exchange Risk Profile
Worked example 3 — US MSB record is not a universal exchange licence
Cexvia's US Regulatory Atlas includes records that combine federal MSB evidence with state money-transmitter scope.
For example, its current Trek Labs, Inc. record identifies:
FinCEN:
31000315905825
NMLS:
2665675
Cexvia classification:
MSB and state money-transmitter scopeThe important point is the classification.
Cexvia does not convert the FinCEN number into:
US federal crypto exchange licencebecause that would overstate the record.
Cexvia — United States Regulatory Framework
Worked example 4 — VARA: licence status and activity both matter
VARA's public register provides fields including:
VASP name
Licence type
Reference
Licensed activities
Licence issue date
StatusIt also separates fully licensed firms from entities holding only In-Principle Approval.
A proper verification should therefore capture:
Entity:
Reference:
Status:
Licensed activity:
Date:—not only “VARA regulated.”
Cexvia — Dubai Regulatory Framework
Different countries require different interpretations
A single template can be used globally, but the legal meaning of the record must remain jurisdiction-specific.
| Market | Example record | Key verification issue |
|---|---|---|
| EU | MiCA CASP authorisation | Entity + authorised crypto services |
| Dubai | VARA VASP licence | Full licence vs IPA + activity |
| UK | FCA MLR registration / future FSMA regime | Do not confuse current registration with future authorisation |
| US | FinCEN + state records + product-specific regulation | No single universal federal crypto-exchange licence |
| Australia | AUSTRAC VASP registration + other financial-services rules where applicable | AML / CTF registration is not automatically every financial-services permission |
| Hong Kong | SFC virtual asset trading platform licensing | Exact licensed operator + scope |
| Japan | Registered Crypto-Asset Exchange Service Provider | Exact entity and registration number |
The field names may change.
The logic does not:
entity → regulator → record → scope → status → customer
How Australia illustrates record-type risk
Australia provides another useful example of why a regulator entry needs context.
AUSTRAC regulates virtual-asset service providers under the AML / CTF framework.
In 2026, AUSTRAC:
- Expanded the virtual-asset regulatory perimeter
- Moved from older DCE terminology toward VASP terminology
- Made a searchable public VASP register available
- Continued to take registration action against inactive or unsuitable entities
A valid AUSTRAC registration is meaningful regulatory evidence.
It should still be classified according to what the AUSTRAC regime establishes rather than described as a universal licence for every financial product.
Other Australian financial-services or market licensing obligations can apply depending on the product or service.
Official reference:
AUSTRAC — Public VASP Register Update
Red flags during licence verification
Stop and investigate when you see:
Identity mismatch
Website company ≠ regulator companyDomain mismatch
Official domain ≠ website being usedStatus inflation
Applied → marketed as licensedApproval inflation
In-Principle Approval → marketed as fully authorisedScope inflation
Custody licence → marketed as permission for derivativesJurisdiction inflation
Dubai licence → marketed as global authorisationRegistration inflation
FinCEN MSB registration → marketed as US government approvalGroup-company inflation
Entity A licensed → Entity B presented as licensedStale evidence
Old certificate → current status not checkedPayment mismatch
Licensed company → deposit requested to unrelated personAny one issue may have a legitimate explanation.
The explanation should be independently verifiable before funds are sent.
What a regulator logo does not prove
The following are not substitutes for an official register check:
- Regulator logo
- Certificate image
- Screenshot
- Licence badge
- News article
- Exchange press release
- Affiliate marketing page
- Search-engine snippet
- Social-media verification badge
- Customer-support statement
The exchange itself can tell you what to investigate.
The regulator's record tells you what is officially recorded.
Those two sources should be compared, not treated as interchangeable.
How Cexvia should store licence evidence
For each regulatory record, Cexvia should preserve structured evidence.
Recommended fields:
brand:
legal_entity:
jurisdiction:
regulator:
record_type:
reference_number:
status:
authorised_activities:
customer_scope:
official_domain:
issue_date:
effective_date:
expiry_or_withdrawal_date:
source_url:
verified_at:
cexvia_interpretation:Example interpretation
record_type: "Money Services Business registration"
status: "Registered"
cexvia_interpretation: >
Federal US MSB / AML registration.
Does not by itself establish nationwide permission
for every crypto exchange product.Or:
record_type: "VARA In-Principle Approval"
status: "IPA"
cexvia_interpretation: >
Conditional licensing stage.
Not a full VASP licence and does not authorise
the applicant to begin servicing clients.This makes Cexvia's regulatory data more useful than a simple:
Licensed: YesCexvia verification checklist
Before describing an exchange as licensed or authorised, confirm:
Identity
- [ ] Brand identified
- [ ] Legal entity identified
- [ ] Company number matched
- [ ] Account agreement reviewed
Regulator
- [ ] Official regulator identified
- [ ] Official register used
- [ ] Regulatory number matched
- [ ] Current record saved
Status
- [ ] Active / authorised / registered status confirmed
- [ ] Application not confused with authorisation
- [ ] IPA / conditional status identified
- [ ] Suspension / restriction checked
Scope
- [ ] Jurisdiction confirmed
- [ ] Product / service scope confirmed
- [ ] Customer type checked
- [ ] Regional restrictions checked
Digital identity
- [ ] Domain matched
- [ ] App publisher matched
- [ ] Official contact details matched
Operational link
- [ ] Contracting entity matches record
- [ ] Deposit route is explainable
- [ ] Payment partner is identified
- [ ] Complaint route matches the entity
If a material field cannot be verified, Cexvia should record it as unverified or scope unclear, not guess.
That aligns with Cexvia's methodology: missing evidence lowers coverage or confidence rather than being silently filled in.
Frequently asked questions
How do I verify a crypto exchange licence?
Find the legal entity in the exchange's account terms, then search that entity in the regulator's official database.
Confirm the record type, reference number, status, jurisdiction, authorised services and domain before linking the licence to the account.
Can I trust a licence certificate on an exchange website?
Use it only as a starting point.
Certificates can be copied, altered, outdated or displayed by a clone website.
The live regulator record is more important.
What if the licence number is real but the company name is different?
Do not treat the licence as verified for the exchange.
Investigate whether the company changed names or whether the number belongs to an unrelated entity.
Licence cloning is a known fake-platform pattern.
Does an MSB number mean a crypto exchange is licensed in the United States?
Not as a universal federal crypto-exchange licence.
FinCEN MSB registration relates to the money-services and AML / BSA framework. State permissions and product-specific federal regulation can also be relevant.
Is a MiCA application the same as MiCA authorisation?
No.
An application means the company has applied.
Use the ESMA and relevant national-authority records to confirm whether authorisation has actually been granted.
Is a VARA In-Principle Approval a full licence?
No.
VARA states that an IPA is a conditional stage. An entity with only an IPA is not permitted to begin virtual-asset operations or service clients until it obtains the full VASP licence.
Does one licence cover every company in an exchange group?
No.
Regulatory records attach to specific legal entities.
Each entity, jurisdiction and service should be checked separately.
Does one licence cover spot trading, custody and derivatives?
Not necessarily.
Licences and authorisations can be activity-specific.
Read the permitted services rather than assuming one permission covers the entire product catalogue.
Does a valid licence mean the exchange is safe?
No.
Regulatory standing is one risk dimension.
Users should separately assess:
- Corporate transparency
- Reserves and liabilities
- Custody
- Security incidents
- Withdrawal reliability
- Operational controls
Cexvia evaluates those dimensions separately.
What if the regulator does not publish the website domain?
Match the legal entity, reference number, address and other identifiers.
Then verify the domain through independently obtained corporate or regulator contact details.
Do not let the disputed exchange supply both sides of the confirmation.
How often should a licence be checked?
Check before opening or materially funding an account and again when:
- The exchange migrates users to another entity
- Terms of service change
- The user moves country
- A major regulatory announcement occurs
- A licence approaches expiry
- A regulator publishes enforcement action
- Product availability changes
Regulatory status is time-sensitive evidence.
Conclusion
Crypto exchange licence verification is an identity-and-scope exercise.
The correct workflow is not:
Find a licence number
→ assume regulatedIt is:
Brand
→ Legal entity
→ Regulator
→ Record type
→ Reference
→ Status
→ Jurisdiction
→ Activity
→ Customer scope
→ Domain
→ Account agreement
→ Payment pathA licence claim is only as strong as the connection between those records.
A genuine regulatory number attached to the wrong company is not verification.
A genuine company registration presented as a financial licence is not verification.
An application described as an active authorisation is not verification.
And a full licence held by one affiliate does not automatically cover every website or product operated by the wider brand.
Cexvia's Regulatory Atlas is built around the same principle: map the licence to the entity.
For exchange research:
- [Cexvia Regulatory Atlas](/regulators)
- [Cexvia Exchange Risk Profiles](/exchanges)
- [Cexvia Methodology](/methodology)
- [Cexvia Exchange Safety Checklist](/exchange-safety-checklist)
Primary sources and Cexvia resources
- ESMA — Markets in Crypto-Assets Regulation (MiCA)
- ESMA — Databases and Registers
- VARA — Public Register
- VARA — Licence Applications
- FCA — Cryptoassets
- FCA — Registration under the MLRs ahead of the new FSMA regime
- FCA — Cryptoasset Regime Policy Statements
- FinCEN — Money Services Business Registration
- AUSTRAC — Virtual Asset Service Providers
- AUSTRAC — Public VASP Register Update
- Cexvia — Regulatory Atlas
- Cexvia — United States Regulatory Framework
- Cexvia — Dubai Regulatory Framework
- Cexvia — Kraken Risk Profile
- Cexvia — HashKey Exchange Risk Profile
- Cexvia — Exchange Risk Profiles
- Cexvia — Methodology
*Cexvia evaluates centralized exchanges using publicly verifiable evidence across regulatory standing, corporate transparency, asset and solvency transparency, security history, and operations and user protection. Regulatory records are mapped to the relevant legal entity, jurisdiction and documented activity. Ratings are evidence-based assessments, not guarantees of safety or recommendations to deposit or trade.*