We scanned 40 web3
game companies.
39 came back red.
Here is what they missed.
Between 6 and 13 August 2026 we ran 40 web3 gaming companies through an automated MiCA compliance review, using only their public websites and documentation. The results were consistent enough to be worth publishing. This page reports what we found in aggregate. It does not name any company.
This is not an industry of bad actors.
The obvious reading of a 39-out-of-40 result is that web3 gaming is full of companies cutting corners. The data does not support that. The findings cluster almost entirely around disclosure obligations — risk warnings, whitepaper structure, environmental statements — rather than around anything resembling deliberate evasion.
What the pattern actually shows is scope confusion. Most of these studios built their games and published their documentation before MiCA applied to them, and did so in the vocabulary of game development rather than financial regulation. The regulation then arrived and reclassified a marketplace as a trading platform, a wallet as custody, and a tokenomics page as a whitepaper subject to Annex I.
The most-missed requirement in the entire dataset is a good illustration. Thirty-five of forty companies have no environmental impact disclosure. That obligation is real, it sits in Article 6(1)(j), and essentially nobody in games knows it exists.
What gets missed, and how often.
Every finding across all 40 scans, grouped by obligation. The count is the number of companies where the scan raised that finding at least once.
| Obligation missed | Companies | MiCA reference | Notes |
|---|---|---|---|
| Marketing without risk warnings | 38 / 40 | Art. 7(1) | Earnings language with no capital-at-risk disclaimer anywhere on the site. |
| No accessible MiCA whitepaper | 38 / 40 | Art. 4(1), 6 | Either absent, or published in a form that does not meet Annex I. |
| Missing mandatory risk statements | 37 / 40 | Art. 7(1) | The specific wording MiCA requires, not present in any marketing page. |
| CASP services without authorisation | 35 / 40 | Art. 59 | At least one regulated service running with no verified EU authorisation. |
| No environmental impact disclosure | 35 / 40 | Art. 6(1)(j) | The least-known requirement in the set. Almost nobody has it. |
| No management confirmation statement | 31 / 40 | Art. 6(6) | The signed statement the whitepaper is required to carry. |
| Future value assertions in marketing | 22 / 40 | Art. 6(4) | Prohibited outright, and common in token pages. |
| Whitepaper missing date or structure | 21 / 40 | Art. 6(8), 12 | Often a document that predates the version of the game now shipping. |
| Loot boxes with transferable assets | 20 / 40 | Art. 3(1)(5) | Sits at the intersection of MiCA and national gambling law. |
| Token may be a financial instrument | 17 / 40 | Art. 2(4) / MiFID II | Governance or revenue-share features that need a MiFID II analysis. |
| No KYC/AML framework disclosed | 13 / 40 | AMLR / TFR | Marketplaces operating with no stated customer due-diligence process. |
| No EU legal establishment | 11 / 40 | Art. 59(1), 61 | Removes the reverse-solicitation defence entirely. |
Four obligations are missed by almost everyone. None of them are obscure.
Which regulated services games are actually running.
MiCA does not care what a feature is called in the game. It cares what the feature does. These are the crypto-asset services the scans identified across the cohort.
| Service identified | Companies |
|---|---|
| Marketplace or trading platform | 34 / 40 |
| Custody or wallets | 19 / 40 |
| Order execution or transfers | 16 / 40 |
| Swap, AMM, or bridge | 16 / 40 |
| Fiat on/off-ramp | 15 / 40 |
| Staking or yield | 14 / 40 |
| Token placement or sale | 6 / 40 |
An in-game marketplace is the single most common exposure, found in 34 of 40. It is also the feature least likely to be recognised as regulated, because from inside a game it is a shop. Under MiCA, a venue where players trade transferable assets with each other is closer to an exchange.
The exposure a studio does not control.
This was the finding we did not expect. Of the 30 companies whose scans identified a third-party infrastructure provider — chains, wallet stacks, payment vendors — 25 depend on at least one provider with no matching entry in the ESMA register, and 23 have at least one custody arrangement that could not be resolved from public documentation.
Absence from the register is not proof that a provider is unauthorised. It is an open question, and it is one most studios have never asked. A studio can do everything correctly in its own product and still inherit exposure from the wallet provider underneath it, particularly where the custody model is co-signed or otherwise shared.
The practical version: if you cannot say in one sentence who holds your players' keys and under what authorisation, that is the first thing to establish. Ask the provider in writing.
Compliance is inherited. Most studios have not checked what they inherited.
Methodology.
Forty companies, scanned between 6 and 13 August 2026. Each company was assessed once, against all of its public properties together — a studio running several games, or issuing a token from a separate entity, counts as one company, not several.
The analysis runs against 62 MiCA rules, each verified per-article against the Official Journal text. Findings pass through a two-pass find-then-verify process, and every quoted fragment is substring-matched back to the source material before it is reported. Where a site could not be crawled deeply enough to judge fairly, the scan refuses to score rather than reporting an absence it cannot stand behind. Three further companies were excluded on that basis and are not counted anywhere on this page.
Scores run 0–100. A single critical finding forces a RED classification regardless of the numeric score, which is why the one YELLOW result sits at 67 rather than anywhere nearer the middle of the range.
Two honest limits. This is an automated review of public material, not a legal opinion, and it cannot see private agreements, corporate structure, or contractual arrangements that might change the analysis. And it is a snapshot: several of these companies may have published new documentation since the scan date.
Want to know where your game sits?
The free CASP exposure checker walks through the four main triggers in a few minutes. The MiCA Scanner runs the same analysis used for this dataset against your own site and documentation.
For what the regulation requires and what a licence costs, start with MiCA compliance for web3 games.