Key facts
- The Financial Action Task Force (FATF) stated that many DeFi platforms have centralized elements and should be regulated.
- FATF rules apply to DeFi arrangements where identifiable individuals maintain control or sufficient influence.
- Centralized elements include concentrated governance tokens, administrative privileges, and control over upgrades.
- Nearly 93% of surveyed jurisdictions have not applied FATF standards to qualifying DeFi arrangements.
- FATF recommends regulators focus on choke points like stablecoin issuers and exchanges for leaderless DeFi.
- Non-cooperating platforms can be banned by jurisdictions as a last resort.
The Financial Action Task Force (FATF) has stated that many decentralized finance (DeFi) platforms are not as decentralized as they appear and should be regulated like other financial businesses. In a report released Tuesday, the global anti-money-laundering body indicated that its rules apply to any DeFi arrangement where identifiable individuals retain control or significant influence, regardless of the project's claimed decentralization.
Centralized elements that persist in practice include concentrated governance tokens, administrative privileges, control over protocol upgrades, and the flow of fees and rewards to insiders, according to the report. FATF President Giles Thomson stated the goal is to prevent criminals from exploiting new technologies for illicit finance while supporting responsible innovation, emphasizing the importance of public-private information sharing.
The report outlines both on-chain and off-chain indicators of control, such as upgrade keys, 'kill switch' functions, the power to set fees or risk parameters, concentrated voting power, control over public websites or applications, and corporate entities managing core developers or treasuries. Where such control is identified, FATF asserts that the individuals responsible should be licensed and supervised as financial firms. Even operating a front-end that directs users to a protocol can qualify.
Despite these findings, the report notes that implementation is lagging, with nearly 93% of surveyed jurisdictions having not applied FATF standards to qualifying DeFi arrangements. Only two out of 142 jurisdictions have ever licensed or registered a DeFi platform. FATF guidance is not legally binding but influences member country grading, and persistent gaps can lead to a country being placed on the FATF's 'grey list.'
FATF recommends that countries encourage DeFi projects to integrate anti-money-laundering controls, such as sanctions screening and KYC checks, directly into their smart contracts or interfaces. For genuinely leaderless protocols, FATF suggests regulators focus on surrounding choke points, including stablecoin issuers, exchanges facilitating fiat on- and off-ramps, and front-end operators. The report also states that jurisdictions can ban platforms that refuse to cooperate from operating within their territory.
The report highlights the use of DeFi by criminals, citing North Korea's state-linked hackers who allegedly drained over $570 million in two April attacks. It also points to ransomware crews, laundering networks, and investor frauds as significant users of DeFi mixers, bridges, and swaps. The FATF's stance aligns with recent actions by U.S. prosecutors who have secured convictions against individuals involved in crypto mixers like Samourai Wallet and Tornado Cash, treating the builders and operators of such code as regulated money businesses.
