Germany's financial regulator BaFin published a consumer notice on August 18, 2026 addressed to a group that rarely features in crypto coverage: people applying for a job. The warning concern
Germany's financial regulator BaFin published a consumer notice on August 18, 2026 addressed to a group that rarely features in crypto coverage: people applying for a job. The warning concerns job advertisements for a position described as «back office and administration support, home office». According to the regulator, there are grounds to suspect that crypto-asset services are being provided behind the offer without the required authorisation.
The point at which this job advertisement becomes dangerous for you personally sits in the second sentence of the notice. According to BaFin, the work consists of receiving third-party payments through your own domestic bank account and forwarding them on instruction or exchanging them into crypto-assets. Anyone doing that is not working in a company's back office. They are making their current account available as a transit station, for money that the regulator assesses as probably originating from victims of criminal acts, fraud in particular.
This piece explains how the pattern is built, which provisions apply and how you can check in a few minutes whether a provider is authorised at all. It is no substitute for legal advice; anyone who has already forwarded payments belongs in a lawyer's office, not in a forum.
The BaFin Warning of August 18, 2026: What the Regulator Says About Crypto Job Offers
The notice is short and unambiguous on the substance. It names the website through which the positions are advertised, and the suspicion: unauthorised crypto-asset services. As the legal basis for publication, BaFin cites Section 10(7) of the Crypto Markets Supervision Act. That is the provision which, since the German legislation accompanying the EU regulation on markets in crypto-assets, allows the regulator to inform the public and name the company before proceedings have concluded.
What stands out is BaFin's express note that it has warned about this activity several times before. It used to run frequently under the label «work as a trust assistant». The packaging changes, then, while the pattern behind it stays the same. Lay the warnings of recent years side by side and the same description reappears under different job titles.
A consumer notice of this kind has nothing to do with a court judgment. What it records is a suspicion the regulator considers sufficiently substantiated to inform the public. What that means in legal terms is set out further down in a section of its own, because many readers take more from such a notice than it actually says.
Money Mule and Trust Assistant: How the Job Advertisement Describes the Work
Advertisements of this construction read harmlessly. What is promised is home working, flexible hours, a manageable weekly workload and pay that looks conspicuously high for the effort involved. No specialist knowledge is required, only reliability, a German bank account and a willingness to process matters promptly. Those three requirements are the actual job description.
As the application progresses, the task shifts. «Check payment processing» becomes «confirm receipt and forward», and «forward» becomes «exchange the amount into crypto-assets at a particular trading venue and send it to a specified address». The justification sounds commercial: saving on fees, serving a foreign group company, testing a payment service. Queries are answered politely, though never with anything verifiable.
Where the money on the account comes from
BaFin words the origin of the amounts carefully and still clearly: the funds transferred to the employee's account probably come from individuals or companies who have themselves become victims of criminal acts, fraud in particular. In practice these are sums from sham investment platforms, from manipulated invoices or from shock calls. That the regulator warns regularly about precisely these platform series is something we traced in August in an analysis of BaFin warnings on crypto platform series.
What emerges is a chain that begins with an investor who has lost money and ends at a wallet address abroad. In the middle sits a person with a real name, a real address and a real account. They are the only point in that chain investigators can identify without effort.
Third-Party Payments Through Your Own Bank Account: Why the Crypto Exchange Step Is the Core of the Scheme
A bank transfer can be clawed back, at least within a window and with some prospect of success. Once the amount has been exchanged into crypto-assets and sent to an external address, that possibility ends. The exchange step is therefore no incidental part of the instruction; it is its purpose. It turns a reversible booking into a transaction that can no longer be unwound in practice.
BaFin writes one sentence on this that carries the legal classification: the transfer and exchange of funds require permission or authorisation. That holds regardless of whether someone performs the work as an employee, as a freelancer or as a favour. If you want to trade crypto-assets yourself, you will find authorised trading venues in our comparison of regulated crypto exchanges; there the provider handles the authorisation question, and nobody has to interpose a private current account.
The technical modesty of the approach is striking. It needs no exploit, no malware and no stolen seed phrase. It needs a lawful account, made available voluntarily.

The brightest link stands out first: in a payment chain the account holder is the only participant with a full name and address.
Money Laundering Under Section 261 of the German Criminal Code: Why Failing to Spot It Is Already Punishable
Section 261 of the Criminal Code (StGB) makes money laundering an offence. Subsection 1 covers, among other things, a person who exchanges, transfers or moves an object deriving from an unlawful act with the intention of frustrating its discovery, its confiscation or the investigation of its origin, and equally a person who obtains it or uses it for a third party. The sentencing range extends to five years' imprisonment or a fine. Under subsection 3, the attempt alone is punishable.
Decisive for someone who took such a position in good faith is subsection 6. Under it, a person is also punished who fails through gross negligence to recognise that the object derives from an unlawful act; here the sentencing range is up to two years' imprisonment or a fine. Intent is therefore not a requirement. Pushing aside the obvious doubts is enough.
What gross negligence means in this context
Gross negligence means an aggravated form of carelessness. Receiving conspicuously high pay for a simple forwarding step, taking in amounts from complete strangers, getting no written information about the principal, receiving instructions through a messenger app rather than a company address: doing all of that assembles precisely the circumstances a court later puts together. An employment contract offers no relief here, because it says nothing about where the money came from.
Subsection 5 comes on top: in particularly serious cases the sentencing range runs from six months to ten years. Such a case generally arises where a person acts commercially or as a member of a gang. Anyone forwarding amounts regularly over months and being paid for it moves close to that description without ever having felt like a gang member.
Voluntary Disclosure Under Section 261(8) StGB: The Way Out the Statute Sets Out Expressly
The law provides a route to impunity, and it is narrowly cut. Under Section 261(8) StGB, a person is not punished who voluntarily reports the offence to the competent authority or voluntarily causes such a report to be made. Voluntariness falls away where the offence had already been discovered in whole or in part at that point and the person knew this or had to reckon with it on a reasonable assessment of the situation. In the cases under subsections 1 and 2, the provision additionally requires that the object be secured.
In practice this means the timing decides. Anyone who waits until the bank freezes the account or a police summons lands in the letterbox has usually missed the route. This passage is why the matter is urgent as soon as the suspicion arises, and why it does not improve with a weekend's reflection.
Authorisation Requirement Under Section 9 KMAG: Who May Offer Crypto-Asset Services
The supervisory side sits in the Crypto Markets Supervision Act. Under Section 9(1) sentence 1 number 3 KMAG, BaFin can order the immediate cessation of business operations and their prompt wind-down where crypto-asset services are offered without the authorisation required by Article 59(1)(a) of Regulation (EU) 2023/1114. The order can expressly extend beyond the company to its shareholders and the members of its governing bodies.
This authorisation is the core of European crypto regulation. A provider serving customers in Germany needs it; it is publicly viewable and it can be checked. That regulation now reaches into the selection of individual tokens is shown by the European anti-money-laundering framework, which we broke down using the example of privacy coins and the AMLR requirements.
For assessing a job offer, a simple order of operations follows. First comes the question of whether the company is authorised at all. Only after that is it worth looking at pay, working hours and contract terms.
One detail of the statute is rarely mentioned and hits applicants directly. Where it is established, or facts justify the assumption, that a company provides unauthorised business or is involved in initiating, concluding or settling it, then under Section 10(1) KMAG not only the company but also the members of its governing bodies, its shareholders and its employees must, on request, provide BaFin and the Deutsche Bundesbank with information on all business matters and submit documents.
Sentence 2 of the same provision extends this duty beyond the employment relationship: an employee must provide information and submit documents on request even after leaving the company. Resigning therefore does not end the obligation to cooperate. Anyone who may have to produce documents should keep them from the outset rather than reconstruct them afterwards.
Under subsection 1 sentence 3, the regulator can also issue directions to secure customer funds, data, crypto-assets and other assets. Anyone holding their own balances with a provider under investigation is indirectly affected by such measures. That is one of the reasons why holdings not actively traded are better kept in self-custody than in an account with a provider whose authorisation is unclear.

Two minutes of checking before you accept: the regulator's company database is to job offers what a door viewer is to callers.
BaFin's Company Database: How to Check for Authorisation Before You Accept
In its notice, BaFin itself points to the tool with which the suspicion can be confirmed or dispelled in a few minutes: the regulator's company database. The directory is publicly accessible and lists the institutions and service providers authorised in Germany. The comparison works best using the full corporate name from the legal notice, not the brand from the job advertisement.
Three outcomes are possible, and each has a clear meaning. If the company appears with a matching permission, the formal hurdle is cleared. If a company of the same name appears with a permission for something entirely different, that is a warning sign of identity misuse. If nothing appears, there is no authorisation, and therefore no reason to make a bank account available.
It is also worth looking at the public register of the European Securities and Markets Authority, because a provider may hold its authorisation in another member state. Both registers are free and require no sign-up.
Our Own Survey of August 18, 2026: 24 BaFin Consumer Notices Retrieved
To gauge how often crypto now features in the regulator's warnings, we retrieved and analysed the consumer notices listed on BaFin's overview page. cryptoticker.io carried out this analysis itself on August 18, 2026.
The method in one sentence: every consumer notice linked from the «news and warnings» page was retrieved individually over HTTP, the body text was read out, and for each notice we recorded the date, the category, the legal basis cited by BaFin and the presence of crypto-assets and of features of the job scheme. Objects tested: 24 notices, twelve of them from the unauthorised business category with publication dates from August 10 to 18, 2026, and twelve from the further consumer notices category with dates from May 4 to August 13, 2026. All 24 retrievals returned HTTP 200.
What we could not check is the full year: the overview page outputs only the twelve most recent entries per category, and a browsable archive was not reachable by that route. Equally unverifiable is the outcome of the proceedings, since a consumer notice records a position and not a result. We manually rechecked the keyword-based classification; one hit on the word back office belonged to a warning about forged fixed-deposit offers and was discarded.
Six of Twelve Warnings Rest on the Crypto Markets Supervision Act
The result of the count came out more clearly than expected. Of the twelve notices in the unauthorised business category, six cite Section 10(7) KMAG as the legal basis, five cite Section 37(4) of the Banking Act, and one cites none. Across nine days, then, half of all warnings about unauthorised business concerned the crypto supervisory regime.
The comparison also shows an exact overlap: precisely those six notices resting on the KMAG mention crypto-assets in their text; none of the five Banking Act warnings does. The legal basis cited is therefore a reliable indicator of what a warning is about, even before you read it. Two of the twelve cases concerned the misuse of well-known company names for fixed-term and overnight deposit offers, and only a single case in the entire retrieval described the job scheme with account pass-through covered here: the notice of August 18, 2026.
A sober assessment follows from that. In the regulator's statistics the job advertisement scheme is one isolated case among many, while fake trading platforms account for the bulk of the notices. The harm to the individual in the job variant is of a different kind, however, because it does not consist in money lost but in criminal proceedings against you personally.
Five Features of a Fraudulent Crypto Job Advertisement
From the wording of the notice and the pattern of earlier warnings, a checklist can be derived that should be worked through before you accept.
- Your own account is part of the job description. No reputable company settles customer payments through the private account of a newly hired member of staff.
- Payments arrive from senders with no customer relationship. Changing private individuals as payers are the clearest signal.
- The instruction calls for an exchange into crypto-assets or a transfer to an external wallet address. At this point at the latest, any plausible back office role ends.
- The pay bears no relation to the task and is frequently calculated as a percentage of the amount passed through.
- The company cannot be found in BaFin's company database or is listed there with a permission that does not fit the work being offered.
If even the third point applies, the matter is settled. Deadlines and cut-off dates play no part in this question. The decision falls before you accept, and it cannot be corrected afterwards.
Checking Crypto Job Offers: What to Take Away
- Check the authorisation before you accept. Enter the corporate name from the legal notice into BaFin's company database and compare the result with the work being offered. If you would rather trade yourself, the authorised providers are set out in our crypto exchange comparison.
- Keep your bank account out of other people's payment flows. Your own holdings need no third person and no forwarding; how self-custody works in practice is set out in our hardware wallet comparison.
- Act immediately if money has already moved. Stop payments, inform the bank, take legal advice and have the disclosure under Section 261(8) StGB assessed while it is still voluntary. For regular trading afterwards, our broker comparison is worth a look.
The regulator's full warning is set out in BaFin's consumer notice of August 18, 2026, and the wording of the criminal provision in the official text of Section 261 StGB.
(As of August 18, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)