Research Report No. 07 · Law & Deadlines

Deadlines in cases of crypto and investment fraud

An overview of civil and criminal statutes of limitations — with case law references and a practical checklist. Status: July 2026.

3 years
Standard limitation period for damages claims begins upon knowledge (§§ 195, 199 BGB)
13 months
Exclusion period vis-à-vis one's own bank (§ 676b BGB)
5–10 years
Statute of limitations for prosecution in cases of fraud (§ 263 StGB)
10 years
Absolute maximum period under civil law (§ 199 para. 3 BGB)
Abstract hourglass with blue glowing particles flowing from top to bottom against a dark background, symbolizing time and data.

Whitepaper 2026

Executive Summary

  • Two watches: The practically decisive reaction windows come from the rules of the payment service providers, not from the law.
  • Civil law: 3 years from knowledge of the damage and the liable party, absolutely 10 years from the accrual of the claim.
  • Against their own bank: 13-month exclusion period from the date of debit — not subject to suspension, applies only to unauthorized payments.
  • Criminal law: 5 years for simple fraud, 10 years for organized/commercial fraud; absolutely double that.
  • Deadline start date: In complex fraud schemes, this usually only happens once the essential investigation results are known — mostly through access to the files.
  • Additional flank: Money laundering violations by the participating crypto exchange as a possible point of reference — not yet legally established.

01 Immediate measures

The most practically important windows of opportunity in cases of crypto fraud arise not from the law, but from the rules and regulations of payment service providers. These windows are significantly shorter than any statute of limitations and often determine whether the money can be recovered at all.

The most important first steps
  • Bank immediately by phone and in writing Request a SEPA recall (transfer recall) — with real-time transfers, every minute counts.
  • Do not make any further payments., not even for alleged "taxes", "unlock fees" or "recovery services".
  • Secure access: Change passwords, enable two-factor authentication, and check devices for malware.
  • Secure evidence: Chat histories, transaction hashes, wallet addresses, bank statements, screenshots of the platform.

02 Civil law deadlines

2.1 Regular limitation period — three years (§§ 195, 199 para. 1 BGB)

Claims for damages arising from tortious acts, such as those under Section 823 Paragraph 2 of the German Civil Code (BGB) in conjunction with Section 263 of the German Criminal Code (StGB) (fraud), generally become time-barred after three years. The limitation period begins at the end of the year in which the claim arose and the injured party had knowledge of the damage and the tortfeasor, or should have had such knowledge without gross negligence.

In complex fraud schemes such as multi-tiered crypto platforms, it is important to note that victims cannot be expected to file charges solely based on initial findings by the public prosecutor's office. In such cases, the statute of limitations typically only begins to run once the victim is aware of the essential findings of the investigation—usually through access to the investigation files.

2.2 Absolute maximum period — ten years (§ 199 para. 3 no. 1 BGB)

Regardless of knowledge or gross negligence in failing to know, most claims for damages become time-barred no later than ten years after they arise – to the exact day. This absolute upper limit applies even if the fraud has not been discovered by then.

2.3 Claims against your own bank

In the case of unauthorized payments, such as those resulting from account takeover or spoofing, a separate legal basis applies: According to Section 675u Sentence 2 of the German Civil Code (BGB), the bank must reimburse the amount immediately and regardless of fault; the burden of proof for valid authorization lies with the bank (Section 675w BGB). However, a significantly shorter limitation period of generally 13 months from the debit date applies to reporting an unauthorized payment transaction (Section 676b BGB) – after which the claim against the bank is usually forfeited.

In cases of authorized but fraudulently obtained transfers—the most common scenario in investment fraud, since the victim authorizes the payment themselves—bank liability is more difficult to establish. It is primarily governed by the bank's general duty to warn and investigate, as well as the regular limitation periods outlined in sections 2.1 and 2.2.

2.4 Special case: Securities service providers

For claims against authorized securities services companies, the shorter limitation period of Section 37a of the German Securities Trading Act (WpHG) (old version) may be relevant. However, the Federal Court of Justice has ruled that this short limitation period does not apply to companies operating without a BaFin license. Since fraudulent crypto platforms almost never have a BaFin license, the general limitation periods from sections 2.1 and 2.2 usually apply.

ClaimdeadlineStart of the time period
Damages arising from a tort3 yearsEnd of year, from the date of knowledge of damage and perpetrator
Absolute maximum period10 yearsOrigin of the claim (to the exact day)
Refund to own bank (unauthorized)13 monthsDebit to account (exclusion period)

Overview of civil law deadlines. The 13-month period is not a limitation period, but a preclusive period — it cannot be suspended.

03 Criminal law deadlines

3.1 Filing a criminal complaint — generally no deadline

Fraud (§ 263 of the German Criminal Code) is a crime prosecuted ex officio. A criminal complaint can generally be filed at any time until the statute of limitations expires. A formal criminal complaint is only required in exceptional cases, such as minor damages to family members; in such cases, the filing deadline is three months from the date of knowledge of the crime and the perpetrator. This is practically rarely applicable in cases of typical cryptocurrency fraud perpetrated by third parties.

3.2 Statute of limitations for criminal prosecution (§§ 78 ff. StGB)

The statute of limitations depends on the maximum penalty prescribed for the offense. For simple fraud under Section 263 Paragraph 1 of the German Criminal Code (StGB) – punishable by imprisonment of up to five years or a fine – the limitation period is five years. If the offense is considered a particularly serious case, such as gang-related or commercial fraud with a penalty of six months to ten years, the limitation period is extended to ten years. Organized crypto fraud platforms frequently meet these criteria. Attempted fraud is subject to the same limitation period as completed fraud.

3.3 Commencement of the time limit (§ 78a StGB)

The statute of limitations does not begin with the planning or the first attempt at deception, but only with the completion of the crime. According to the Federal Court of Justice, in cases of investment fraud, the crime is considered complete as soon as the misleading information has been made accessible to a larger group of people. In ongoing fraud schemes with many victims over a longer period, the last fraudulent act is generally considered the starting point—an active platform effectively postpones the start of the limitation period as long as it recruits new victims.

3.4 Absolute limitation period (§ 78c para. 3 StGB)

Investigative measures such as interrogations or searches can interrupt the statute of limitations, causing it to begin anew. However, this is not possible indefinitely: The absolute limitation period is twice the statutory period. For simple fraud, this is ten years; for aggravated fraud, it is twenty years. After this period, a conviction is definitively precluded.

3.5 Interaction with civil enforcement

Filing a criminal complaint is important for investigations and potential asset seizures under Sections 73 and 111b of the German Code of Criminal Procedure (StPO), but it does not replace the need for civil enforcement. For this, targeted legal motions are necessary in the criminal proceedings, as the police rarely act on their own initiative. Seized assets can potentially be distributed among the victims through an application for damages in criminal proceedings or a subsequent civil lawsuit.

variant of the actLimitation periodAbsolute limitation period
Simple fraud (§ 263 para. 1 StGB)5 years10 years
Organized/commercial fraud (§ 263 para. 3 of the German Criminal Code)10 years20 years
Attempted fraudlike a perfectaccordingly

Statute of limitations for criminal fraud. The absolute deadline is twice the statutory deadline and cannot be extended further by interrupting actions.

Damage event20 yearsBank recall / SEPA recallimmediately — minutes to hoursCredit card chargeback ≈ 120 days · PayPal buyer protection ≈ 180 daysup to about 6 monthsReimbursement against one's own bank (§ 676b BGB) — limitation period13 monthsCivil law limitation period — 3 years from knowledge, absolute 10 years3 years → absolutely 10 yearsStatute of limitations for prosecution of fraud — 5–10 years, absolute up to 20 years5–10 years → absolutely up to 20 years
Deadlines over time, scaled to 20 years. Thick bars represent the standard deadline, transparent continuation represents the absolute maximum deadline. The most practically effective windows (recall, chargeback) are barely visible on this scale—and that's precisely the problem.

„"The shortest deadlines are not stipulated in any law — they are found in the rules and regulations of the payment service providers."“

Immediate action vs. statute of limitations

04 Regulatory development (as of 2026)

Since October 2025, IBAN name verification has been mandatory for bank transfers across the EU. The planned PSD3/PSR reform will also introduce bank liability for authorized payments obtained through spoofing—for example, if a perpetrator impersonates a bank employee and the customer subsequently authorizes a payment. This extended liability is expected to be implemented in 2027 or 2028; it is not currently in effect.

05 Cryptocurrency exchanges in focus: Money laundering violations

Cryptocurrency exchanges and other crypto asset service providers (CASPs) have been subject to anti-money laundering regulations in Germany since January 1, 2020, as obliged entities under Section 2 Paragraph 1 No. 2 of the German Money Laundering Act (GwG). Since the expiration of the MiCAR transition period—shortened to December 31, 2025 in Germany, and no later than July 1, 2026 across the EU—crypto asset services in the European Union may only be provided by providers licensed under the MiCA Regulation. This category is relevant for victims because a breach of these obligations can result in both regulatory and criminal consequences for the exchange, as well as—in individual cases—civil law claims.

5.1 Reporting obligations and current data situation

Cryptocurrency service providers must, among other things, verify the identity of their customers (Know Your Customer), conduct a risk analysis in accordance with Sections 4 and 5 of the German Money Laundering Act (GwG), and immediately submit a suspicious activity report to the Financial Intelligence Unit (FIU) in accordance with Section 43 of the GwG if they suspect any wrongdoing. Under the conditions of Section 46 of the GwG, the transaction in question must be stopped. In 2024, the FIU registered approximately 8,700 suspicious activity reports related to cryptocurrencies—a new record high out of a total of 265,708 reports received. Bitcoin was by far the most frequently mentioned cryptocurrency, followed by Ethereum, XRP, Tether, and Litecoin. The reported cases often involved trading platforms, mixing services, or gambling.

5.2 Supervisory and criminal proceedings

  • BaFin, August 2024: Nationwide raid against operators of crypto exchange machines; 13 machines operated without the required permit under Section 32 of the German Banking Act (KWG) were seized, along with approximately 250,000 euros in cash.
  • BKA / Frankfurt Public Prosecutor's Office (ZIT), November 2025: The platform "cryptomixer.io," used as a money laundering infrastructure, was shut down as part of the international "Operation Endgame." Crypto assets worth approximately €25 million were seized, and the charges included commercial money laundering and operating a criminal trading platform. The crypto swapping service "eXch" was also taken offline in the same operation.
  • USA, November 2023: Binance reached a $4.3 billion criminal settlement with the US Department of Justice, pleading guilty to failing to maintain an effective anti-money laundering program. The Commodity Futures Trading Commission (CFTC) also fined Binance $1.35 billion and its then-founder and CEO $150 million.

5.3 Case law

The criminal law classification of crypto assets is the subject of several landmark decisions. The Berlin Court of Appeal (Kammergericht) has ruled that Bitcoin is not a unit of account within the meaning of the German Banking Act (Kreditwesengesetz)—a decision which the German Federal Financial Supervisory Authority (BaFin) nevertheless does not adhere to in its supervisory practice due to the lack of binding effect of a criminal judgment. Also crucial for the anti-money laundering assessment of crypto transactions is a decision by the Munich I Regional Court (Landgericht München I), which convicted a defendant of money laundering after he acquired Bitcoin of unknown origin via darknet marketplaces; the court considered the anonymity of the transaction and a price significantly below market value as sufficient evidence of the assets' criminal origin.

5.4 Significance for civil claims of injured parties

For victims, the anti-money laundering obligations of the cryptocurrency exchange involved can provide an additional point of leverage: If an exchange fails to report under Section 43 of the German Money Laundering Act (GwG) or block accounts under Section 46 GwG despite recognizable grounds for suspicion, legal scholars debate whether this may also constitute a breach of contractual protective obligations (Section 280 Paragraph 1 of the German Civil Code (BGB)) or a protective statute within the meaning of Section 823 Paragraph 2 BGB. According to current research, there is no established, published case law on this specific legal basis for claims against cryptocurrency exchanges; the question must be examined on a case-by-case basis and should be accompanied by specialized legal advice. Also practically significant is the right to information under data protection law pursuant to Article 15 of the GDPR, which allows victims to request transaction data and risk assessments from the platform for their own evidentiary purposes.

This aspect of civil law is to be distinguished from the time limits presented in Chapter 2: Here, too, the general limitation periods of §§ 195, 199 BGB apply, whereby the commencement of the period is regularly linked to the knowledge of the relevant breach of duty by the stock exchange.

Note regarding Chapter 5

The civil law classification of AML/G violations as a basis for claims against cryptocurrency exchanges, referenced in section 5.4, is based on legal scholarship, not on established published case law. It should be understood as a guideline, not as a definitively settled legal situation, and must be examined separately in each individual case.

Abstract data stream: blue glow lines flowing from a left source and breaking into orange particles at right, symbolizing data transfer.
Any expired deadline is final. While investigations are underway, assets are being moved via wallets, bridges and off-ramps — civil claims cannot wait for this.

06 Practical checklist: Deadlines at a glance

measureRule of thumb deadline
Bank transfer recallImmediately, count the minutes
Credit card chargebackapproximately 120 days
PayPal Buyer Protectionapproximately 180 days
Objection to authorized direct debit8 weeks
Dispute unauthorized direct debit13 months
Claim for reimbursement against one's own bank (unauthorized)13 months (exclusion period)
Criminal chargesNo deadline
Civil law limitation period (standard case)3 years, at the latest 10 years
Statute of limitations for prosecution of fraud5–10 years (10–20 in total)

Rules of thumb, not legal advice. Chargeback and buyer protection deadlines depend on the rules of the respective providers and may vary in individual cases. Regarding criminal charges: there is no fixed deadline, but the sooner the better for securing evidence.

07 Recommendation for action

  • Immediately: Stop or reverse payment methods, secure evidence, and do not make any further payments.
  • Parallel: File a criminal complaint with the police — with as complete a documentation of the transactions as possible.
  • Promptly, not just shortly before the deadline: Engage a specialist lawyer for banking and capital markets law or criminal law to initiate the suspension of the limitation period — for example by issuing a payment order or filing a lawsuit — in time before the 3-year period or the bank-specific 13-month period expires.
  • Once an investigation is underway: Requesting access to files through a lawyer can affect both the civil law claim assessment and the start of the time limit.

08 Classification by Financial Forensics

Expert commentary

Why short deadlines are more important than long ones. The limitation periods determine whether a claim is enforceable — the recall and chargeback windows determine whether there are any assets left against which a claim can be made.

Why the start of the time limit is the point of contention in practice. On multi-stage platforms, more than a year often passes between the initial payment, suspicion, and reliable knowledge of the damage and the perpetrator. Linking the start of the limitation period to the date of the first transfer regularly results in wasted time.

What needs to be secured forensically at an early stage. Transaction hashes, wallet addresses, and off-ramp references are persistent on-chain, but the association with a counterparty is not—exchange data is subject to deletion periods. Early backup and a data access request under Article 15 GDPR preserve the evidence that will later determine the validity of a claim.

What this means for those affected. Two parallel paths – a criminal complaint for investigation and asset seizure, and legal representation to prevent further action on one's own claim. One does not replace the other.

09 Legal notice

This white paper provides general information and does not constitute legal advice for any specific case. The commencement and duration of any limitation period depend heavily on the specific circumstances, particularly on when exactly knowledge of the damage and the perpetrator arose and how the act is classified under criminal law. For a binding assessment and to ensure compliance with any deadlines, a lawyer specializing in banking and capital markets law or criminal law should be consulted promptly.

List of sources and case law
Legal basisGerman Civil Code (BGB) §§ 195, 199, 203, 204, 280, 675u, 675w, 676b, 823 · German Criminal Code (StGB) §§ 73 ff., 77b, 78, 78a, 78c, 247, 248a, 261, 263, 264a · German Code of Criminal Procedure (StPO) §§ 111b, 403 ff., 406e · German Securities Trading Act (WpHG) (old version) § 37a · Money Laundering Act (GwG) §§ 2, 4, 5, 6, 43, 46, 56 · German Banking Act (KWG) §§ 1, 25h, 32 · Regulation (EU) 2023/1114 (MiCAR).
Case lawFederal Court of Justice (BGH), Judgment of March 5, 2024 – XI ZR 107/22 (BGHZ 240, 23) — Bank's obligation to reimburse unauthorized payments; burden of proof pursuant to Section 675w of the German Civil Code (BGB). Federal Court of Justice (BGH), Decision of June 27, 2024 – 6 StR 16/24 — Statute of limitations for investment fraud (Section 264a of the German Criminal Code (StGB)); completion of the offense upon public disclosure of misleading prospectuses. Federal Court of Justice (BGH), Judgment of December 19, 2006 – XI ZR 56/05 — Inapplicability of Section 37a of the German Securities Trading Act (WpHG) (old version) to investment intermediaries operating without a BaFin license. Berlin Higher Regional Court (KG Berlin), Decision of September 25, 2018 – (4) 161 Ss 28/18 (35/18) — Bitcoin not a unit of account. See Section 1 Paragraph 11 of the German Banking Act (KWG). · Munich Regional Court I, Judgment of February 8, 2024 – 7 KLs 301 Js 178368/22 — Conviction for money laundering in connection with the acquisition of Bitcoin from Darknet sources.
Supervisory and investigative authoritiesFIU Germany, Annual Report 2024, published June 10, 2025 (zoll.de) — Statistics on suspicious activity reports related to cryptocurrencies. BaFin, Press Release of August 20, 2024 — Raid against operators of crypto exchange machines. BKA, Press Release of December 1, 2025 — Shutdown of „cryptomixer.io“ as part of „Operation Endgame“. BaFin/FIU, Joint Report of July 8, 2026 — Information on money laundering risks during the transition to full MiCAR implementation. US Department of Justice / CFTC, Press Releases November 2023 — Settlement with Binance Holdings Ltd. and Changpeng Zhao.

Research overview as of July 2026. Not legal advice in individual cases; the start and duration of deadlines depend on the specific circumstances.

Professional headshot of an older man in a dark blazer and light shirt, looking at the camera.

David Lüdtke

Managing Director · OSINT Analyst & Crypto Forensic Expert · Financial Forensics GmbH

Court-admissible crypto transaction analysis, OSINT-based asset investigation, and expert reports for defense attorneys, insolvency administrators, and companies. Certified Crystal Expert (CECF, CEEI, CEUI). Financial Forensics Supports law firms, companies, investigative bodies and insolvency administrators — focus areas: Blockchain forensics, wallet analysis, court-admissible documentation, OSINT.

Contact: postfach@finanz-forensik.de +49 6057 772 994 86

Lost your crypto assets? Every day counts.

We secure evidence, create legally sound crypto forensics reports, and support law firms and victims in asset recovery — before deadlines expire.