Centralized Elements ‘Frequently Persist’ in DeFi and Should Be Regulated: FATF

Bitbuy
Blockonomics



In brief

  • The Financial Action Task Force said that many DeFi platforms are decentralized in name only and fall under its rules wherever identifiable people control them.
  • Its report urges countries to find those controllers and regulate them as virtual asset service providers, and, as a last resort, to ban platforms that refuse to cooperate.
  • Nearly 93% of surveyed jurisdictions have yet to apply the rules to qualifying DeFi arrangements, and just two have ever licensed or registered one.

Much of decentralized finance is not as decentralized as it looks, and the platforms behind it should be regulated like other financial businesses, the world’s main anti-money-laundering body said in a new report.

In a report published Tuesday, the Financial Action Task Force said its rules already apply to any DeFi arrangement where an identifiable person keeps “control or sufficient influence,” regardless of how decentralized a project claims to be. The Paris-based body, whose standards are used across more than 200 jurisdictions, sorts DeFi into three groups: platforms with identifiable controllers; those that are centralized in practice but whose operators stay hidden; and a genuinely leaderless minority it calls truly decentralized. Only the last escapes its standards.

Although many DeFi projects present themselves as fully decentralized, centralized elements “frequently persist in practice,” the report found, through concentrated governance tokens, administrative privileges, control over upgrades, and the fees and rewards that flow to insiders.

FATF President Giles Thomson said in a statement accompanying the report that the goal is to stop criminals exploiting new technology to “launder dirty money” while “supporting responsible financial innovation,” calling strong public-private information sharing central to the response.

okex

Decentralized in name only?

The report lays out on-chain and off-chain signs of control, including upgrade keys and “kill switch” functions, the power to set fees or risk parameters, concentrated voting power, command of the public website or app, and the corporate entities that employ core developers or hold the treasury. Where such control exists, FATF said, the people behind it, whether developers, large token holders, front-end operators or funders, should be licensed and supervised like any financial firm. Even running a front-end that funnels users to a protocol can be enough to qualify.

In practice, almost no one is doing this. Nearly 93% of the jurisdictions that responded to a recent FATF survey have not applied the standards to any qualifying DeFi arrangement, and only 26 out of 142 have assessed the risks at all. Four have licensing rules on the books, while just two have ever used them to register or license a platform. FATF guidance is not law, but members are graded on how closely they follow it, and persistent gaps can help land a country on the watchdog’s “grey list.” The report comes on the heels of a broader FATF update days earlier that found most countries still struggling to enforce crypto rules across the board.

A ban as a last resort

FATF wants countries to close the gap by requiring, or at least encouraging, DeFi projects to build anti-money-laundering controls straight into their smart contracts or interfaces, from sanctions screening to proof-of-KYC checks before certain functions run.

For projects that really are leaderless, it steers regulators toward the choke points around them: stablecoin issuers that can freeze tokens, exchanges that handle fiat on- and off-ramps, and front-end operators. And where a platform refuses to cooperate, the report says, a jurisdiction can as a last resort ban it from operating in its territory. Banks and exchanges, for their part, are told to run due diligence on any DeFi platform they touch, or stop dealing with it.

North Korea’s DeFi haul

The report leans heavily on how criminals already work the sector. It singles out North Korea, whose state-linked hackers it says were behind two April attacks that together drained more than $570 million: the $285 million exploit of Solana perpetuals exchange Drift Protocol, pulled off in just 12 minutes, and a $292 million hack of KelpDAO.

Together they made up some 76% of the year’s crypto-hacking losses. The report also points to ransomware crews, professional laundering networks, and investor frauds as heavy users of DeFi’s mixers, bridges and swaps.

That crackdown is already underway elsewhere. U.S. prosecutors this year secured prison terms for the two co-founders of Bitcoin mixer Samourai Wallet and a conviction against Tornado Cash developer Roman Storm, cases built on the same idea FATF presses here: that the people who build and run the code can be treated as regulated money businesses.

DeFi’s total value locked reached $86.6 billion this year, up about 85% since 2023, with the top dozen protocols holding more than 60% of it, per the report, which calls for regulators to implement the FATF rulebook rather than leaving a gap that could enable illicit finance at scale.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos and more.



Source link

fiverr

Be the first to comment

Leave a Reply

Your email address will not be published.


*