Binance has continued to onboard European customers and route their trades months after failing to secure a licence under the bloc’s crypto asset regime, using structures that keep the activity formally outside the regulated entity. The exchange remains the largest venue in the market by volume, and a meaningful share of that volume is European.
The Design of the Rule
MiCA was built to solve a specific European problem: a single market in which a firm authorised in one member state can serve all of them, and in which national regulators had been competing on leniency to attract crypto business. Authorisation in one country, supervision to a common standard, and a passport to the rest. The regime came with a transition window, and firms that failed to obtain a licence were supposed to wind down.
The gap is not in the drafting. It is in what happens when a firm declines to wind down.
The Workarounds
The techniques are familiar to anyone who has watched offshore financial services operate under a compliance regime, and each has a plausible legal argument attached.
- Reverse solicitation. If the customer approached the firm rather than the reverse, the argument runs, no local authorisation is needed. The doctrine exists for a reason and it was never meant to cover systematic onboarding, but proving intent at scale is slow work.
- Non-EU entities of record. The customer contracts with an offshore company, and the European-facing surface is presented as marketing rather than a regulated service.
- Order routing. Matching happens outside the bloc, so the position is that no European venue is being operated at all.
- Group separation on paper. A licensed or licence-seeking European entity handles the compliant slice while the volume sits elsewhere, with shared branding and shared technology across both.
Why This Is an Intelligence Question, Not Only a Regulatory One
Exchange licensing determines who can see the flow. A licensed venue keeps identity records a European authority can compel, runs transaction monitoring to a supervised standard, and files suspicious activity reports into a system that connects to national financial intelligence units. An offshore entity serving the same customers does none of that in a form any EU authority can reach quickly.
That matters for sanctions enforcement above all. Ruble-denominated flows, evasion networks moving value out of restricted jurisdictions, and ransomware proceeds all pass through large exchanges at some point in their lifecycle. The value of a licensing regime to a sanctions authority lies precisely in the compulsion, and every workaround that moves the entity offshore removes a subpoena target.
The Test That Is Coming
MiCA’s credibility now rests on enforcement rather than drafting, and enforcement is fragmented across national regulators with uneven capacity and uneven appetite. If the largest firm in the sector can operate at scale without the licence, the regime becomes a tax on the compliant. Watch which national authority moves first, and whether it moves with a fine or with a payment-rail cutoff. Only one of those changes behaviour.