FATF Says Most DeFi Platforms Are Centralized, Subject to VASP Rules

3 hour ago 4 sources neutral

Key takeaways:

  • FATF designation exposes DeFi tokens to regulatory risk, potentially triggering repricing of centralized protocols.
  • The Drift Protocol and KelpDAO hacks highlight vulnerabilities, souring sentiment on Solana and restaking ecosystems.
  • Developer prosecutions could shift capital toward fully decentralized or privacy-preserving assets.

The Financial Action Task Force (FATF), the global anti-money laundering watchdog, has declared that the vast majority of decentralized finance (DeFi) platforms are not truly decentralized and should be regulated as Virtual Asset Service Providers (VASPs). In a report published on July 21, the Paris-based body asserts that centralized elements “frequently persist in practice” in DeFi projects, despite claims of full decentralization.

The FATF report categorizes DeFi arrangements into three groups: those with identifiable controllers; those that are effectively centralized but whose operators remain hidden; and a minority that are truly decentralized. Only the last category escapes the existing standards. The watchdog identifies several signs of underlying control, including concentrated governance token holdings, administrative privileges, upgrade authority, and fee structures that benefit insiders. In such cases, the people behind the protocol—developers, large token holders, or front-end operators—should be licensed and supervised like any traditional financial firm.

Despite the FATF’s stance, enforcement remains minimal. Nearly 93% of surveyed jurisdictions have not applied the rules to qualifying DeFi arrangements, and only two have ever licensed or registered a platform. The report urges governments to close this gap by requiring or encouraging DeFi projects to build anti-money-laundering and counter-terrorism financing controls into their smart contracts or interfaces. For platforms that refuse to cooperate, a ban is listed as a last resort.

The report also highlights criminal exploitation of DeFi, singling out North Korea-linked hackers behind two April attacks that drained over $570 million—a $285 million exploit of Solana perpetuals exchange Drift Protocol and a $292 million hack of KelpDAO. Together, these accounted for 76% of the year’s crypto-hacking losses. The findings add fuel to ongoing U.S. prosecutions, such as the conviction of Tornado Cash developer Roman Storm, reinforcing the idea that those who build and run DeFi code can be held accountable as regulated money services businesses.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.