Summary
- The Financial Action Task Force (FATF) asserts that many decentralized finance (DeFi) platforms operate under the guise of decentralization, falling under its regulatory framework when identifiable individuals exercise control.
- The report calls for nations to identify these controllers and regulate them as virtual asset service providers, with banning non-compliant platforms as a last resort.
- Approximately 93% of jurisdictions surveyed have not yet enforced these regulations on qualifying DeFi setups, with only two having ever licensed or registered such platforms.
A significant portion of decentralized finance does not exhibit true decentralization, according to a recent report from the Financial Action Task Force (FATF), which advocates for regulation akin to that of traditional financial institutions.
In a report released on Tuesday, the FATF indicated that its regulations apply to any DeFi setup where an identifiable individual maintains "control or sufficient influence," irrespective of the project's claims to decentralization. The Paris-based organization categorizes DeFi into three types: platforms with identifiable controllers; those that are practically centralized but whose operators remain anonymous; and a truly decentralized minority that is exempt from its regulations.
Despite many DeFi initiatives marketing themselves as fully decentralized, the report highlights that centralized components "frequently persist in practice," manifested through concentrated governance tokens, administrative powers, control over updates, and financial benefits accruing to insiders.
FATF President Giles Thomson stated that the report aims to prevent criminals from exploiting new technologies to "launder dirty money" while simultaneously "supporting responsible financial innovation," emphasizing the importance of robust information sharing between public and private sectors.
Are They Truly Decentralized?
The report identifies both on-chain and off-chain indicators of control, such as upgrade keys, "kill switch" functions, the ability to set fees or risk parameters, concentrated voting power, control over public websites or applications, and corporate entities that employ core developers or manage the treasury. In instances where control is evident, FATF insists that the individuals behind it—whether they are developers, significant token holders, front-end operators, or funders—should be licensed and monitored like any other financial entity. Even operating a front-end that directs users to a protocol may qualify.
In reality, compliance is nearly non-existent. Nearly 93% of jurisdictions that responded to a recent FATF survey have not implemented the standards for any qualifying DeFi arrangements, and only 26 out of 142 have evaluated any associated risks. Although four jurisdictions have established licensing rules, only two have ever used them to register or license a platform. While FATF guidance is not legally binding, member countries are assessed on their adherence, and persistent non-compliance can lead to a country being placed on the watchdog's "grey list." This report follows a broader FATF update from days prior, which indicated that most countries still face challenges in enforcing crypto regulations comprehensively.
Last Resort: A Ban
The FATF encourages countries to bridge the regulatory gap by mandating or at least motivating DeFi projects to integrate anti-money laundering controls directly into their smart contracts or user interfaces, including sanctions screening and proof-of-KYC checks before certain functions are activated.
For genuinely leaderless projects, regulators are advised to focus on choke points surrounding them, such as stablecoin issuers capable of freezing tokens, exchanges facilitating fiat on- and off-ramps, and front-end operators. If a platform is uncooperative, the report suggests jurisdictions can ultimately ban it from operating within their territories. Banks and exchanges are also urged to conduct due diligence on any DeFi platform they engage with or cease their dealings.
North Korea's DeFi Exploits
The report emphasizes how criminals exploit the DeFi sector, specifically mentioning North Korea. State-affiliated hackers are implicated in two attacks in April that collectively siphoned off over $570 million: the $285 million exploit of the Solana-based Drift Protocol, executed in just 12 minutes, and a $292 million hack of KelpDAO.
These incidents accounted for around 76% of the year’s total crypto-hacking losses. The report also highlights ransomware groups, professional laundering networks, and investment frauds as significant users of DeFi's mixers, bridges, and swaps.
Crackdowns are already in progress elsewhere. U.S. prosecutors have secured prison sentences for the co-founders of Bitcoin mixer Samourai Wallet and a conviction against Tornado Cash developer Roman Storm. These cases align with the FATF's stance that those who create and operate the code can be classified as regulated financial entities.
As of this year, the total value locked in DeFi reached $86.6 billion, reflecting an increase of approximately 85% since 2023, with the leading dozen protocols controlling over 60% of this total, according to the report, which urges regulators to adhere to the FATF framework to avoid enabling large-scale illicit finance.