OpenPayd’s MiCA Licence: What Did Malta Check?

Openpayd MiCA License

OpenPayd's MiCA Licence: What Did Malta Check?

On 24 June 2026, OpenPayd announced that OP Digital Services Limited had obtained MiCA authorisation from the MFSA.

Eight days later, on 1 July 2026, the maximum MiCA transitional period expired.

The licence permits OP Digital to provide custody, crypto-to-fiat and crypto-to-crypto exchange, execution of orders and crypto-asset transfer services. Through the MiCA passport, those services can be offered across the European Economic Area.

The timing alone does not prove that the MFSA rushed or inadequately assessed the application. Nor do historical concerns involving another OpenPayd group company automatically disqualify OP Digital.

But by June 2026, the MFSA had substantial information requiring a serious, current and group-wide assessment.

OpenPayd’s controlling shareholder was publicly identifiable. Malta’s Financial Arbiter had repeatedly referred OpenPayd-related conduct issues to the MFSA. OpenPayd had been named in 76 formal complaints registered during 2025. Turkish authorities had taken action against other financial companies controlled by the same shareholder. SEC filings published shortly before the MiCA decision confirmed his continuing control and central role in OpenPayd’s proposed Nasdaq transaction.

The question is therefore not whether the MFSA knew who controlled OpenPayd.

The question is what it did with that knowledge.

MiCA authorisation is European gatekeeping

A MiCA licence is not merely a national Maltese permission. Once authorised by its home regulator, a crypto-asset service provider can passport its services throughout the EEA.

A weak national authorisation decision therefore exports risk across Europe.

OpenPayd describes the licence as enabling stablecoin on- and off-ramping, custody, wallet infrastructure and global stablecoin transfers. The wider group says it provides financial infrastructure to more than 1,100 businesses and processes hundreds of billions of dollars in annualised volume.

This was not a licence for an immaterial start-up. It gave an established financial-infrastructure group access to the European crypto market.

OpenPayd’s controlling owner was publicly known

OpenPayd’s group information identifies OpenPayd Holdings Limited, incorporated in the United Kingdom under company number 11565881, as the group’s ultimate holding company.

UK Companies House identifies Ozan Özerk as the only active person with significant control over that company. The filed particulars state that he holds:

  • at least 75 per cent of the shares;
  • at least 75 per cent of the voting rights; and
  • the right to appoint or remove directors.

Companies House does not independently verify filed information. These are nevertheless the ownership and control particulars formally declared by OpenPayd Holdings Limited.

Özerk is therefore not merely OpenPayd’s historical founder. According to the group’s own corporate filings, he indirectly controls the ultimate holding company of the MFSA-authorised CASP.

The MFSA was required to assess him

MiCA requires national authorities to identify and assess direct and indirect holders of qualifying participations in a CASP applicant. The MFSA’s own MiCA Rulebook confirms that its fit-and-proper assessment applies to every person holding a qualifying participation in the applicant and to every beneficial owner. The Rulebook also requires the Authority to consider additional information available to it, including information not supplied by the applicant.

Those persons must be of sufficiently good repute. The assessment is not confined to final criminal convictions. The EBA/ESMA framework also covers known facts affecting reputation, the legitimate origin of funds, ongoing proceedings, reasonable grounds for suspicion and circumstances indicating increased money-laundering or terrorist-financing risk.

This does not mean that every allegation, investigation or adverse article requires rejection of an application. It does mean that such information cannot simply be ignored.

The MFSA had to identify Özerk, assess his reputation and determine whether the ownership and wider group structure presented risks to the sound and prudent management of OP Digital.

OpenPayd had been named in 76 formal complaints

Malta’s Office of the Arbiter for Financial Services recorded 75 formal complaints under the standalone entry for OpenPayd Financial Services Malta Limited in 2025: 73 in banking and payment services and two in investments.

A separate multi-provider complaint additionally named OpenPayd together with Foris MT Limited and Foris Dax MT Limited.

OpenPayd was therefore named in 76 registered complaints during 2025, as shown on page 79 in the OFAS annual report for 2025 (compare page 79 of the Arbiter´s Final report for 2025).

This does not establish that every complaint was justified, fraud-related or upheld. It does establish that the issues could not credibly be treated as one isolated incident.

The complaints concerned OpenPayd Financial Services Malta Limited, not the MiCA applicant OP Digital. But both entities belong to the same OpenPayd Group and operate in closely connected payment, fiat, stablecoin and crypto markets under the same ultimate holding company.

For an authority assessing group governance, shared controls, intragroup dependencies and financial-crime risk, the complaints against the regulated sister company were plainly relevant.

The MFSA had already received formal OpenPayd referrals

Before the MiCA authorisation, Malta’s Financial Arbiter had issued several decisions concerning OpenPayd’s virtual-IBAN infrastructure.

In published cases, the Arbiter held that OpenPayd had credited funds to the holder of a vIBAN-linked account rather than to the beneficiary named by the remitter, without specific authority from the payer. He described the conduct as a breach and referred it to the MFSA.

In another decision, the Arbiter expressly invited the MFSA to investigate whether OpenPayd’s onboarding and KYC procedures were sufficiently effective to prevent fraud facilitation.

The compensation claims were nevertheless dismissed, with the Arbiter attributing the victims’ losses to their “greed and gross negligence”.

These decisions did not establish misconduct by OP Digital or Özerk. But they placed the MFSA on notice of possible weaknesses involving:

  • vIBAN and beneficiary transparency;
  • corporate-client onboarding;
  • KYC controls;
  • transaction monitoring; and
  • the use of OpenPayd infrastructure in fraud-related payment chains.

A serious MiCA assessment should have examined whether those risks were group-wide, whether OP Digital relied on the same governance or control environment and whether remediation had occurred.

The Turkish enforcement action was also publicly known

In late 2025, Turkish authorities took action concerning Ozan Elektronik Para A.Ş. and Aveon Global Sigorta A.Ş., two financial companies owned or majority-owned by Özerk (compare the OCCRP-reporting).

The reported allegations concerned the introduction of criminal proceeds, including proceeds from illegal betting, into the financial system. Assets were seized, executives were detained or arrested, and Ozan Elektronik was placed under state-appointed trusteeship.

Neither OpenPayd nor OP Digital was publicly identified as a subject of the Turkish investigation. Özerk himself was not publicly named as a suspect. OpenPayd stated that the Turkish companies were outside the OpenPayd Group and did not share its operations. No final judgment has established criminal conduct by Özerk.

These qualifications prevent any legitimate claim that Özerk or OpenPayd participated in the alleged conduct.

They do not make the information irrelevant to a fit-and-proper assessment of a controlling owner of regulated financial companies.

The MFSA itself reportedly stated that it considers information relevant to the fitness and properness of persons connected with licensed entities and would take appropriate action where necessary.

Seven months later, it authorised an OpenPayd company under MiCA.

Did the MFSA seek information from the Turkish authorities? Did it reassess Özerk? Did it examine possible common personnel, technology, funding, compliance functions or service providers? Did it impose enhanced conditions?

The public record does not say.

SEC filings confirmed Özerk’s continuing control

Any suggestion that Özerk had become a passive founder was contradicted by SEC filings published shortly before the MiCA decision.

Under OpenPayd’s proposed SPAC transaction with Titan Acquisition Corp., a new Cayman holding company would acquire OpenPayd Holdings Limited. Existing shareholders would roll over their equity into the listed group at an agreed equity value of approximately USD 800 million, subject to the transaction terms.

The SEC documents describe Özerk as:

  • Key Company Shareholder;
  • representative of the OpenPayd shareholders;
  • sole pre-closing shareholder of the new public holding company; and
  • director of that holding company.

The agreements also contemplated the transfer to him of 1,035,000 additional PubCo shares and 1,216,508 private warrants in connection with the termination of the existing shareholders’ agreement.

The transaction had not closed, and there is no evidence that the proposed listing influenced the MFSA.

But the filings confirmed that Özerk was not exiting OpenPayd. He remained its controlling and economically central shareholder.

They were public approximately three weeks before the MiCA licence was announced.

StablR: Earlier Questions, Now Concrete Consequences

OpenPayd is not the first case in which EFRI has questioned the MFSA’s assessment of ownership, management history and group risk. In July 2025, EFRI asked the MFSA to reassess StablR Ltd’s EMI licence, citing its management by former Payvision executives, the publicly opaque ownership behind its Dutch parent Plutus B.V. and unresolved questions over how Payvision’s AML history had been considered.

Those concerns acquired new urgency in May 2026. StablR disclosed unauthorised external access to its platform and admitted that the circulating supply of its EURR and USDR tokens was no longer fully backed at the 1:1 ratio required under MiCA. Minting and redemption were suspended, trading venues were asked to halt activity, and StablR activated its recovery plan and notified the MFSA.

The incident does not prove that StablR’s ownership, its executives’ previous roles or the MFSA’s licensing decision caused the compromise. It does, however, show why ownership, management history, outsourcing, ICT governance and operational resilience cannot be dismissed as confidential details inside a licensing file. According to StablR’s latest published update of 8 July 2026, minting and redemption remained suspended while the investigation continued.

StablR and OpenPayd therefore expose the same accountability problem from different directions: Malta grants licences with EU-wide consequences, but the public cannot determine how material ownership, governance and control risks were assessed—or what the MFSA does when those risks become operational reality.

ESMA had already criticised Malta’s MiCA gatekeeping

The most damaging context comes from ESMA itself.

In July 2025, ESMA published a peer review of the MFSA’s authorisation and early supervision of an unidentified Maltese CASP. There is no basis to suggest that the reviewed company was OP Digital.

The findings nevertheless concerned the MFSA’s licensing process.

ESMA concluded that material issues remained unresolved when the licence was granted. It found that the assessment should have been more thorough and that the MFSA had not adequately considered relevant supervisory history.

The review identified weaknesses in areas including:

  • growth and customer onboarding;
  • governance and conflicts of interest;
  • intragroup arrangements;
  • ICT infrastructure;
  • custody;
  • and AML/CFT risks and controls.

The MFSA was assessed as only partially meeting expectations in the authorisation process.

By June 2026, the Authority had had almost one year to apply ESMA’s recommendations.

The OP Digital decision is therefore a direct test of whether Malta strengthened its MiCA gatekeeping—or repeated the same weaknesses.

What did the MFSA actually conclude?

EFRI does not allege that OP Digital obtained its MiCA authorisation unlawfully. We do not allege that Özerk committed money laundering, that OpenPayd knowingly processed fraud proceeds or that the MFSA deliberately ignored information.

The documented contradiction is sufficient.

MiCA required the MFSA to identify and assess OP Digital’s indirect qualifying shareholders. Public records identified Özerk as OpenPayd’s controlling owner. OpenPayd’s Maltese payment institution had been named in 76 formal complaints and had been the subject of conduct findings and regulatory referrals. Turkish authorities had taken action against other financial companies controlled by Özerk. SEC filings confirmed his continuing role and control. ESMA had already criticised the MFSA’s treatment of supervisory history, governance, onboarding and AML risks in a previous CASP authorisation.

Eight days before the transitional period ended, the MFSA authorised another OpenPayd group company to operate across Europe.

The issue is not that Malta could not identify the owner.

Did MFSA Ignore All the Red Flags?

The European Commission, ESMA and AMLA should require the MFSA to provide a non-confidential explanation of:

  • whether Özerk was assessed as an indirect qualifying shareholder;
  • whether a fresh fit-and-proper review was conducted;
  • whether the OpenPayd complaints and referrals were considered group-wide;
  • whether the Turkish enforcement action and SEC filings were examined;
  • whether foreign authorities were consulted; and
  • whether enhanced conditions, remediation or independent reviews were imposed.

MiCA licences travel across Europe.

The scrutiny behind them must be strong enough to travel with them.

Leave a Comment