News
Weekly Brief 19.08.2026: Goobit/BTCX Appoints New CEO
Weekly brief for the Baltic and Nordic segment: Swedish exchange Goobit (BTCX) changes leadership (Gustav Buder from 15.08.) amidst its MiCA licence rejection and appeal, with context and a watchlist.
In the last 24-48 hours, there hasn't been a clearly datable new major event in our segment, so we're summarising the most significant datable development of the week: the leadership change at Swedish exchange Goobit (BTCX) (new CEO Gustav Buder from 15th August) against the backdrop of its MiCA rejection and court appeal. With regional context and a watchlist (Coldcard, ESMA register).
Wednesday, 19th August 2026. This is a Weekly Brief format publication. In the last 24-48 hours, there hasn't been a clearly datable, new major event in our segment - crypto exchanges and CASPs, hardware wallets, crypto cards, and tax tools serving the Baltics (LV, LT, EE) and Nordics (FI, SE, NO, DK) - that could be presented as fresh daily news. Therefore, we are summarising the most significant datable development of the past week with a regional connection: the leadership change at Swedish exchange Goobit (BTCX) against the backdrop of its MiCA licence rejection. Other ongoing stories are covered in the watchlist as context, rather than being repeated as new news.
Goobit/BTCX: New CEO Amidst Swedish MiCA Rejection
Swedish group Goobit AB, which operates the BTCX exchange - one of the oldest still-operating Bitcoin exchanges in the world, founded in 2011 - announced a change in leadership on 14th August. Gustav Buder, who previously led international exchange Bybit's operations in the Nordics, became the new CEO from 15th August. The outgoing CEO, Christian Ander, who returned to the position in February 2022, will transition to the role of Chairman of the Board (pending shareholder approval). The company describes Buder's mandate as focusing on product development, "regulatory maturity", and growth in the Nordic digital asset market.
The leadership change occurs within a specific regulatory context, which is more important to the segment than the personnel change itself. On 2nd July 2026, the Swedish Financial Supervisory Authority (Finansinspektionen) rejected Goobit AB's application for a MiCA (CASP) authorisation. On 28th July, the regulator also rejected the company's request to review the decision, concluding that the case review had followed applicable regulations. Goobit announced that it is continuing its appeal of the decision in administrative court, insisting that the application should be assessed based on the company's actual operations, limited service range, and established control environment. At the same time, the company states that it has "prepared BTCX for the MiCA regime" and continues to operate regardless of the outcome of the rejection.
It's important to distinguish facts from interpretation. The regulator's rejection and the appeal are specific, datable events; the assertion that a new CEO and MiCA readiness will provide a way out of the situation is management's positioning, not an independently verified outcome. The result of the appeal and its timeline are currently unknown, and until then, Goobit's CASP status in Sweden remains unresolved.
Context: What This Means for the Regional Segment
Goobit's case illustrates that after the end of the MiCA transition period (1st July 2026), obtaining authorisation in the Nordics is not automatic, even for experienced local operators. The Swedish regulator has demonstrated a willingness to reject applications, and this changes the risk landscape for the entire regional exchange segment: MiCA compliance becomes a real barrier, not just a formality. For Baltic users, the direct impact is indirect, but the signal is clear - local presence and history do not guarantee a licence, and some regional players may find themselves in transitional uncertainty while appeals are ongoing.
Another noteworthy element is personnel flow. The fact that a Nordic head of an international exchange is moving to lead a local platform focused on a regulated institutional direction aligns with a broader trend in the segment: competition for a regulated, institution-friendly position is intensifying, and regulatory compliance is becoming a key competitive argument, not just a cost.
Watchlist (Ongoing Stories, Not Fresh News)
These points are not news from the last 24 hours; we are keeping them on our watchlist with precise previous dates.
Coldcard (Coinkite) incident: We continue to monitor the draining of funds caused by the hardware wallet seed entropy error. The bug is found in firmware version 4.0.1 (March 2021), where seed generation was diverted to a software pseudo-random number generator, making keys predictable; affected models include Mk2, Mk3, Mk4, Q, and Mk5. Attacks began on 30th July, with the corrected firmware released on 31st July. By mid-August, estimates suggest approximately 1,778 Bitcoins (around USD 112 million) were drained across more than 5,000 addresses, with additional funds under the attackers' control. The numbers are still estimates and are changing, so we consider this an ongoing, not a new, event. Coinkite CEO Rodolfo Novak publicly apologised; the conclusion for regional users remains unchanged - a firmware update alone is not sufficient; affected devices require new seed generation on the corrected version and fund migration.
ESMA MiCA Register: Following the 31st July update, the register contains 321 CASPs, but none of the recently added companies are from the Baltics or Nordics. The movement of authorisations for regional firms remains the key structural indicator to follow in the coming weeks.
Hardware Wallets: The reminder for Baltic and Nordic users remains valid - check if your device model and firmware are affected by the Coldcard incident, and if necessary, migrate to a new seed generated with secure entropy.
Summary for Market Participants
Regulatory compliance in the Nordics is no longer a formality. Goobit's MiCA rejection confirms that even an old, local operator may not receive CASP authorisation; investors and partners should monitor not only products but also each platform's licensing status and potential appeals.
Evaluate management and status announcements separately from regulator decisions. A new CEO and declared "MiCA readiness" do not change the fact that Goobit's authorisation issue in Sweden is currently in court and unresolved.
For hardware wallet users, the priority remains checking for the Coldcard incident and, if necessary, migrating to a new seed; the risk is tied to specific models and firmware versions, not regional platforms.
Monitor the next ESMA register update - the movement of CASP authorisations in the region is the most important indicator for our segment in the coming weeks.
Sources
- Finansinspektionen - Cryptoasset services (CASP authorisations)
- ESMA - Markets in Crypto-Assets Regulation (MiCA)
- MarketScreener - Swedish FSA rejects Goobit AB's MiCA application (02.07.2026)
- TradingView / Modular Finance - Goobit proceeds with its appeal following Finansinspektionen's decision (28.07.2026)
- TradingView / Modular Finance - New CEO to take over at Goobit (14.08.2026)