EU staking review threatens crypto yields and network security could pay the price

Ledger
Changelly



Some of the most consequential financial rules begin with surprisingly little text.

For example, on page 36 of the European Commission’s current MiCA review, item 66 asks whether Europe’s treatment of staking is adequate and, if it isn’t, what requirements should apply to companies providing staking services.

The question is brief, but the consequences wouldn’t be.

There isn’t a proposed staking license, a new capital requirement, or an agreed position in Brussels that any of those things should exist. The European Commission’s MiCA review consultation remains open until Sept. 30 at 23:59 CEST and could eventually feed into legislation that amends MiCA, but the Commission says explicitly that the document isn’t a final policy position.

okex

Even so, the question tells us a lot about where European crypto regulation is heading. MiCA already governs much of what a centralized staking provider does when it takes custody of customer assets, and Brussels is now asking whether staking has become large and complicated enough to be treated as a regulated service in its own right.

For users, that could eventually mean more specific rules around slashing, withdrawal delays, fees, and who carries the loss when something goes wrong. For companies, it could mean another authorization layer and a more expensive compliance burden on top of MiCA, while protocols face a harder problem because staking is both a financial service and one of the basic mechanisms through which proof-of-stake blockchains operate.

That dual identity is where the regulatory argument gets difficult.

Staking started as network infrastructure, with participants locking assets, running validator software, following the protocol rules, and receiving rewards for helping the network reach consensus. Once exchanges, custodians, banks, and staking platforms placed themselves between the holder and the validator, the same activity started to look much more familiar to financial regulators.

At that point, some form of regulation was always going to follow.

Europe already regulates custodial staking

It’s common to hear that staking falls outside MiCA, but that’s only partly right.

MiCA doesn’t contain a standalone regulated service called staking. Someone who stakes their own assets directly with a blockchain doesn’t need a MiCA authorization just because they’re participating in proof-of-stake consensus.

The European Commission has already drawn a distinction between that kind of proprietary staking and staking-as-a-service. If a company takes a customer’s crypto, or controls the keys needed to access it, and stakes those assets for the customer, the service falls under MiCA’s rules for custody and administration, according to ESMA’s guidance on staking-as-a-service.

That sounds pretty straightforward until you look at how many different businesses now sit under the word “staking.”

Someone running an Ethereum validator with their own 32 ETH and keeping control of the keys is staking directly, while a specialist validator can run the technical infrastructure for a customer who keeps the withdrawal key, which can make the relationship noncustodial. An exchange can hold the customer’s ETH, decide how it will be staked, collect the rewards, take a fee, and credit the remainder back to the customer’s account, while liquid staking adds another layer because the user gives up the underlying asset and receives a token representing the staked position that can then be traded or posted as collateral elsewhere.

An EBA and ESMA joint crypto-asset report estimated the value of liquid staking at $44 billion in October 2024, with almost 80% of that activity on Ethereum. At the time, Lido alone represented roughly $25 billion.

These models aren’t equivalent because control isn’t distributed in the same way. The provider that holds the asset or controls the key can decide where it gets delegated and how rewards are handled, while it may also determine how quickly the customer gets the asset back and what happens when a validator is penalized.

That’s why MiCA already imposes detailed obligations once custody enters the picture. A licensed custodian needs a written agreement explaining the service and the fees, while also maintaining records of client positions and procedures designed to protect those assets. Customer crypto has to be separated from the firm’s own holdings, and there must be a process for returning it under MiCA Article 75.

MiCA also requires firms holding client crypto to protect customer ownership rights, including in insolvency, and prevents them from treating those assets as their own property under Article 70’s client-asset safeguards.

ESMA has gone further on staking itself. A CASP can’t take customer crypto and stake it for its own benefit, even if the customer agrees. The provider and customer can enter a staking arrangement where rewards are divided, but the assets don’t become the firm’s proprietary staking inventory, according to ESMA’s guidance on the use of client assets for staking.

Europe therefore isn’t starting from a regulatory vacuum, because the existing framework effectively says that staking is a protocol activity until an intermediary takes custody and turns it into a service. The Commission is now asking whether that distinction still works.

A separate staking regime would regulate the layer around the validator

The consultation doesn’t tell us what a dedicated staking regime would contain, so it’s too early to say Europe is about to impose a particular capital rule or require insurance for every validator service. However, the areas regulators are looking at aren’t difficult to infer because EBA and ESMA have already spent considerable time cataloguing the risks.

Assets can become unavailable during protocol withdrawal periods, validators can be penalized or slashed, and customers may not understand how rewards are calculated or how much the provider deducts. Liquid-staking tokens can also trade away from the value of the underlying position, while using those tokens as collateral elsewhere can add another layer of leverage, according to the EBA and ESMA staking risk assessment.

A standalone framework could make providers spell out who bears those risks. If a validator is slashed, for example, the customer could be told in advance whether the loss sits with them or the provider, while a company could be required to explain how it chooses validator operators and what happens if one of them fails operationally.

Withdrawal terms could become more formal too because a user pressing “unstake” may assume the asset will be available immediately, even though the protocol itself can impose an exit period and the intermediary may add more processing time on top.

Reward advertising is another obvious area because a percentage shown next to a staking button can make a complicated combination of protocol issuance, validator performance, fees, and temporary incentives look like an ordinary savings yield, so regulators may want providers to separate those pieces more explicitly.

That could make the service easier to understand, but it would also make it more expensive to offer.

For a large exchange or bank that already has a MiCA authorization, another regulatory layer could mostly mean adding staking-specific policies to an existing compliance operation. Smaller validator businesses face a very different problem because their advantage may come from running reliable infrastructure rather than operating anything that resembles a financial institution.

If serving European customers directly begins to require more regulatory reporting, legal work, insurance, and customer-service infrastructure, the provider has to decide whether the market is still worth serving. Some will pay the cost, some will leave, and others will stop dealing with users directly and work behind a large licensed custodian instead.