Two things happened to Robinhood in the space of four days. On 29 May 2025, its Lithuanian subsidiary, Robinhood Europe, UAB, received the news it had been waiting for, as the Bank of Lithuania’s MiCA licence, under the EU’s crypto rulebook, took effect. On 2 June, the US parent company, Robinhood Markets, Inc., closed its purchase of the crypto exchange Bitstamp. Bitstamp’s Luxembourg company had received its own MiCA licence that May, so by early June both businesses held an EU authorisation. If Robinhood already had the licence it needed, what exactly was it paying for?
Robinhood was a familiar name by then, the US app that offers commission-free share trading, and what it bought was a business with a long track record. Bitstamp had started in Slovenia in 2011 and was run from Luxembourg by the time Robinhood came calling. Robinhood’s announcement pointed to customers spread across the EU, UK, US and Asia and to an institutional crypto business that had taken years to build. Those were the assets on offer, and the licence was only one part of the package.
That gap is where most sales pitches for licensed crypto companies go wrong. They open with the authorisation because it is the easiest thing to put on a slide. A buyer who signs gets more than a permit, though. It gets the staff, the contracts and a record with the regulator that was written long before it arrived. In the EU, the same regulator will also decide whether the new owner is fit to hold the company at all.
One brand, several companies
Bitstamp operates through several separate legal companies inside one group. Each has its own licence and its own role, and only Bitstamp Europe S.A. in Luxembourg has the EU crypto licence that allows the company to provide custody, run a trading platform and offer exchange services. A separate group company, Bitstamp Financial Services Ltd. in Slovenia, provides investment services relating to derivatives. According to the company’s own disclosure, it does not provide crypto-asset services. Customers trading derivatives therefore contract with the Slovenian entity, and the Luxembourg company’s crypto licence does not extend to that relationship. The group also maintains operations in the UK, Singapore and the US.
The reason this matters is that a crypto licence sits with a single legal entity. The right to serve customers across the EU stays with that company and never passes to its sister companies. Anyone paying for «Bitstamp» is really paying for several companies, each with its own permissions and its own supervisor.
Robinhood’s own European business is built the same way. Its services run through Robinhood Europe, UAB, which the Bank of Lithuania authorises as a brokerage firm, a crypto-asset service provider and a payment institution. That company was already licensed before the Bitstamp deal closed, and it was the US parent, not the Lithuanian subsidiary, that bought Bitstamp. None of this makes the purchase a mistake, since customers, an institutional business and years of operating history are hard to build from scratch. It does mean that a buyer who describes the deal as «buying a licence» has named only one part of what it bought, and the deal itself ran from June 2024 to June 2025 for roughly $200 million in cash, according to published accounts.
The regulator reviews the buyer
Before a buyer can take a significant stake in a licensed crypto company in the EU, the company’s regulator has to be told, and the regulator gets time to object. The requirement comes from Article 83 of MiCA. A holding of 10% of capital or voting rights qualifies, and so does a smaller stake that gives the buyer real influence over how the company is run. Crossing 20%, 30% and 50% each means filing again, and so does a deal that makes the company a subsidiary of the buyer. A buyer who starts with 12% and wants to reach 30% later will file more than once, and, having the first stake approved tells it nothing about whether the regulator will approve the next one.
Each review can run for up to 60 working days, but the count starts when the regulator acknowledges the notification, and not when the buyer files it. The rule allows two working days for that acknowledgement, although practitioners report that it often takes longer because regulators like to confirm only once they hold a complete file. During the review the regulator can also pause the clock to ask the buyer questions, for up to 20 working days, or up to 30 if the buyer is based outside the EU.
The waiting time adds up faster than the headline figure suggests. Sixty working days is about twelve weeks. With one 20-day pause it becomes 80 working days, around sixteen weeks, and a non-EU buyer given the full 30-day pause could wait 110 working days, close to twenty-two weeks. These figures are our own arithmetic from the statutory periods, and they leave out any delay before the regulator acknowledges the filing.
If the period ends without an objection, the acquisition does count as approved. Buyers should ask the regulator for written confirmation instead of reading silence as consent and request a meeting before filing. MiCA doesn’t require one, but regulators in other financial sectors often expect it. A holding company placed in the middle of the structure changes nothing, because holdings are added together at the parent level, and voting rights are counted broadly. They include rights exercised under an agreement on a lasting common management policy, rights attached to pledged shares that the buyer controls and intends to use, and proxies the buyer can exercise at its own discretion.
What the regulator wants to know
When a deal like Robinhood’s lands on a regulator’s desk, the questions it asks are mostly about the buyer. Article 84 of MiCA lists them. Is the buyer reputable and financially sound? Do the people who will run the business have the reputation, knowledge, skills and experience to do it? Can the company keep meeting MiCA’s requirements once the deal is done? And is there any reasonable suspicion that the acquisition is tied to money laundering or terrorist financing?
The regulator can object on those grounds only, or if the file it receives is incomplete or false. It can’t cap how much a buyer is allowed to hold, and it can’t ask whether the market needs the deal at all. A buyer therefore never has to argue that its purchase makes commercial sense. What it does have to show is who will own the company and who will run it afterwards. If the plan is to replace the technology platform, the management team and the main suppliers within a few months, that belongs in the filing, because the regulator is judging the company as it will be after the sale and not as it looked when the seller applied.
The choice of regulator matters as well. Each EU country has its own regulator so it differs in how quickly they move and what expectations they have. Outside the EU the picture changes again. In the UK, for example, the Financial Conduct Authority amended its rules for crypto firms starting 30 June 2026, and the thresholds now depend on whether a beneficial owner sits somewhere in the chain of control. A buyer who compares different countries is comparing different processes, and each country’s version has its own rules at the end.
Companies that sit outside the usual rules
Bitstamp and Robinhood Europe both hold full crypto licences, but plenty of firms offering crypto in the EU don’t. Under Article 60 of MiCA, certain regulated financial companies, such as investment firms, can add crypto services by notifying their regulator, without applying for a new authorisation. The services have to match what the firm is already permitted to do, so an investment firm that can execute client orders can notify crypto order execution.
For a buyer, this changes which rulebook applies. The ownership review described earlier covers ordinary crypto licence holders, but a financial company using Article 60 stays under the ownership rules of its own sector. A buyer who built its timetable around the crypto process would be planning for the wrong one. Such a company’s crypto right also depends on the licence underneath it, and it ends if that licence is withdrawn.
Dormant companies deserve a different kind of care. A target with few customers and almost no history looks simple, and it is tempting to read the quiet as a clean slate. Article 64 suggests the opposite. If a company hasn’t used its authorisation within 12 months of getting it or has gone nine months in a row without providing any crypto services, the regulator has to withdraw it. The same article gives other reasons for withdrawal, such as, notably, an authorisation that was obtained irregularly, weak anti-money-laundering controls or serious breaches of the rules.
This means that a buyer looking at a dormant company should start with the calendar. When did the company receive its authorisation? When did it last actually serve a customer? And what has the regulator asked it since then? A register entry only proves the company is listed, but it won’t say if a ground for withdrawal possibly already exists.
Where deals go wrong
Nothing about buying a licensed crypto company is unlawful, and wanting its authorisation is perfectly legitimate. So where do these deals actually come apart? In practice it tends to be one of four places.
The first is closing too early. Imagine a buyer who signs the agreement and starts treating the company as its own before the regulator has finished reviewing the deal. A signed contract doesn’t replace the notification process, so the paperwork should keep two moments apart: the day the parties agree to the sale and the day control can lawfully pass, with completion depending on clearance. MiCA provides for administrative penalties and other measures when the rules are broken, and the details are set by national law, so the target’s home regulator is the one to ask what the consequences would be.
The second is pressing on after a refusal. What does a buyer do when the regulator says no? The regulator has to explain its objection, and a private contract can’t overrule it. A buyer who disagrees should look at the legal remedies against the decision, and rebuilding the same control through a different structure is not one of them.
The third is being less than clear about who the buyer is. Holding companies and nominees are not unlawful in themselves. But indirect holdings and group arrangements are caught by the process, and incomplete or false information is itself a reason for the regulator to object. Could a regulator work out who stands behind the purchase from the file alone?
The fourth comes after a clean closing, when the new owner tries to do more than the licence allows. An authorisation for exchange and custody doesn’t stretch to a different regulated service just because the owner has changed, since each regulated service needs its own legal basis. Permission to buy the company and permission for it to run the buyer’s wider plans are two separate questions.
Buying or building
Robinhood showed that buying and building are not mutually exclusive, because it did both in the same week. The three routes compare like this:
| Route | What it gives you | Main risk | Example |
| Buy a licensed crypto company | A working operation, staff, customers and a regulatory history | Regulator’s review of the buyer; inherited problems; licence scope that doesn’t fit the plan | Robinhood–Bitstamp: about a year from announcement to closing 1202 |
| Build your own licence | A scope and operation designed around your plan | Application time and building the business before launch | Robinhood Europe’s licence from the Bank of Lithuania 1342 |
| Buy a regulated financial company that uses Article 60 | Existing investment permissions that may support crypto services | A different ownership process, and a crypto right that depends on the underlying licence | Interaction of MiCA Articles 60 and 83/84 1329 |
None of these is the safe route. Each swaps one kind of uncertainty for another, and the right choice depends on how much of the target’s existing business the buyer will actually use.
What the price should reflect
One way to work in Europe is to acquire a company that already has a licence, wait for the regulator to clear you, and then make changes to the business accommodating your own plans. The other option is to apply for a licence of your own and build exactly what you want from the beginning. Which of the two costs less? The honest answer is harder than it looks. Putting the target’s price next to the cost of a fresh application makes the purchase look better than it is because the price leaves out the review period, the transition, the staff you have to keep and the clean-up after closing.
The answer depends on what lies under the licence. Can the target actually offer the services you need, and do they match your plan? Will the legal basis for those services still hold once control changes hands? And when the seller walks away, who is left, and what do they know that you don’t? How does the reviewing regulator handle timing and requests for information? And if you plan to change things, how does the company stay compliant while you do?
MiCA’s licensing requirements cover governance, management, internal controls, IT systems and the protection of client assets. The regulator examined all of that when it granted the licence, and a buyer takes it on along with the company. A licence describes a business as it stood on the day it was granted. Whether that business is still there after the seller leaves is something only due diligence can show.
Robinhood’s week in May 2025 makes the point. It had every reason to want a licensed EU exchange, and it still secured its own licence in Lithuania on 29 May, four days before it closed the Bitstamp deal on 2 June. The licence is the easiest part of a deal to describe, which is why sales papers lead with it. The company behind it is what changes hands, so the question for any buyer is whether the price reflects that.
Learn about MiCA in Europe
Learn about Why MiCA Applications Stall Before Regulators Say No
Sources:
Bitstamp’s Slovenian company: Bitstamp Financial Services d.o.o. legal page
MiCA text (Articles 60, 64, 83 and 84): Regulation (EU) 2023/1114 on EUR-Lex
Robinhood’s closing announcement of 2 June 2025: Robinhood Completes Acquisition of Bitstamp
Robinhood Europe’s licences, on the regulator’s own register: Bank of Lithuania entry for Robinhood Europe, UAB




