Why Italy has 162 of MiCA's non-compliant crypto entities

Of the 164 entities flagged as non-compliant across the EU, 162 come from a single regulator: Italy's CONSOB. It looks like Italy is the continent's crypto-fraud capital. It isn't. The real explanation is a specific legal power, and a pattern hiding in the flagged web addresses themselves.

Published: July 2026 · Data as of 16 July 2026 · Reading time: ~6 minutes

Key Takeaways

  • 162 of the 164 entries on the MiCA non-compliant register we track come from Italy's CONSOB. The Netherlands' AFM and Slovakia's NBS account for one each.
  • This is an artefact of enforcement method, not fraud geography. CONSOB holds a power most EU regulators lack: it can order internet providers to block abusive financial websites for Italian users — and it has blocked more than 1,500 sites since 2019.
  • The flagged addresses are not 162 separate operations. Nearly half (47%) carry a domain-rotation signature — trailing digits or an inserted "it" — the fingerprint of operators respawning a blocked site under a new address.
  • Clear clusters recur: one brand appears across five or six near-identical domains (`ofuyc.com`, `ofuyc-32516it.com`, `ofuyc-55337it.com`…), and 91 short, disposable `.it` domains follow a throwaway `abc123.it` pattern.
  • Read correctly, the register measures which regulator is most actively hunting and publishing, not where the crime concentrates.

One register, effectively one regulator

The MiCA framework gives every member state's national competent authority the job of naming firms that provide crypto-asset services without authorisation. In principle, 30 authorities feed the list. In practice, one dominates it completely.

AuthorityCountryEntries
CONSOBItaly162
AFMNetherlands1
NBSSlovakia1

The Italian entries span decisions from 12 February 2025 to 8 July 2026 — 100 flagged in 2025 and 62 more in the first half of 2026 alone. The list is not a historical archive; it grows almost every week. (For the full growth curve and the standout AFM action against MEXC, see our MiCA enforcement watch.)

MiCA non-compliant entities flagged by CONSOB per quarter, 2025–2026

Why Italy dominates: CONSOB's site-blocking power

The instinct is to read the table as a fraud map: Italy must be where the scams are. That reading is wrong, and the reason is a single Italian law.

Under the 2019 "Growth Decree" (Law 58/2019, Article 36, paragraph 2-terdecies), CONSOB can order internet service providers to black out — block access from Italy to — the websites of intermediaries offering financial services without authorisation. Most EU regulators can only publish a warning and refer the matter onward. CONSOB can publish a warning and switch the site off at the network level. Since it received the power in July 2019, it has ordered the blocking of more than 1,500 sites across all abusive financial services.

That single capability changes the incentive to publish. When blocking a site is your primary tool, every blocked domain becomes a public, dated, individually listed decision. A regulator that mainly issues periodic press warnings produces a handful of entries a year; a regulator that blocks sites one by one produces hundreds. The register is not measuring how much unlicensed crypto activity exists in each country. It is measuring how each authority chooses to act on it.

What the flagged entities have in common

The more revealing question is the one buried in the data: are these 162 genuinely distinct operations? The web addresses say no.

Cleaned of duplicates, the Italian entries point to 231 domains. Of those, 47% carry a rotation signature — a run of trailing digits, or an inserted "it" tag aimed at Italian visitors. This is the classic footprint of block-evasion: when CONSOB darkens one address, the operator brings up a fresh one that differs by a few characters.

The clusters are hard to miss once you look:

Brand rootRotation variants observed
ofuyc`ofuyc.com`, `ofuyc-32516it.com`, `ofuyc-55337it.com`, `ofuyc-23166it.com`, `ofuyc-33111it.com`, `ofuyc-83255it.com`
jzmor`jzmor.com`, `jzmor-it33583.com`, `jzmor-it52337.com`, `jzmor-it57659.com`, `jzmor-it99518.com`
oxelvian`oxelvian.it`, `oxelvian.net`, `oxelvian.io`, `oxelvian.tech`, `oxelvian-it.net`
fameex`fameexn.com`, `fameexn.top`, `fameexe.top`, `fameexj.top`
lucrumia`lucrumiaofficial.co`, `lucrumiamode.co`, `lucrumiagroup.co`

Alongside these sit 91 short, disposable `.it` domains — `tnt882.it`, `78def.it`, `dfh258.it`, `rye026.it` and dozens more — random three-to-four-letter stems with a numeric tail. These are not brands anyone is building; they are cheap, throwaway addresses, registered to be blocked and replaced. The `.it` ending is itself a tell: 106 of the 231 domains use it, because the target audience is explicitly Italian retail investors.

The trading names reinforce the picture. Of 162 entries, most names are single invented words — Dobibo, Fameexn, Oxelvian, AKQ — with no corporate history behind them, rather than the "X Capital Ltd" style of a firm trying to look established.

None of this proves a fixed number of operators in a courtroom sense; CONSOB's data doesn't attribute ownership. But the pattern is unambiguous: the register is inflated by rotation. A meaningful share of its length reflects the same handful of operations reappearing under new addresses, not 162 independent schemes.

How to read the non-compliant register correctly

For anyone using MiCA data — journalists, compliance teams, researchers — the Italian dominance carries two lessons.

Don't rank countries by warning count. A country low on the list may simply have a regulator that warns rarely, not a cleaner market. Absence of entries is absence of this kind of enforcement action, nothing more.

Don't equate rows with operators. Because block-evasion multiplies domains, the register's length overstates the number of distinct bad actors. The right unit of analysis is the operation, not the row.

What the register does reliably tell you: which brands and domains Italian authorities have judged to be operating unlawfully, and when. That is genuinely useful — it is the single largest public, structured feed of crypto-related enforcement actions in the EU. It just has to be read as what it is: a window onto one regulator's method, not a league table of national crime.

Frequently Asked Questions

Does Italy have more crypto fraud than other EU countries? The data doesn't support that conclusion. Italy dominates the non-compliant register because CONSOB has an unusual site-blocking power and uses it prolifically, producing far more individual published decisions than authorities that only issue occasional warnings.

What lets CONSOB block websites? Italy's 2019 "Growth Decree" (Law 58/2019, Article 36, paragraph 2-terdecies) empowers CONSOB to order internet providers to block access to sites offering financial services without authorisation. It has ordered more than 1,500 such blocks since 2019.

Why do so many flagged domains look almost identical? Because operators rotate them. When a site is blocked, a near-identical replacement appears — a new numeric suffix, an added "it", or a different top-level domain. Roughly 47% of the flagged Italian domains show this signature.

Are the other EU regulators simply not doing anything? Not necessarily. They act through different tools — licensing conditions, criminal referrals, one-off public warnings — that don't generate a long list of individually dated website entries. The MiCA non-compliant register captures CONSOB's method especially well and others' hardly at all.

Sources