FATF: Much of DeFi isn’t as decentralized as it looks — and should be regulated
A new report from the Financial Action Task Force (FATF) warns that many decentralized finance projects contain persistent centralized elements and should be treated like traditional financial businesses when those elements give identifiable people control or influence.
The Paris-based watchdog — whose standards guide more than 200 jurisdictions — splits DeFi into three buckets: platforms with identifiable controllers, platforms that are centralized in practice but whose operators are hidden, and a small minority that are truly leaderless. Only that final category escapes FATF oversight. In practice, the report says, projects that market themselves as “decentralized” frequently still concentrate power in ways that create regulatory risk.
What counts as control
FATF lists both on-chain and off-chain indicators that signal control or sufficient influence over a protocol, including:
- Upgrade keys or “kill switches” that can change or disable contracts
- The ability to set fees, risk parameters, or economic incentives
- Concentrated voting power in governance tokens
- Control of the public website or front-end interface
- Corporate entities that employ core developers or hold the treasury
Who should be regulated
Where these control points exist, FATF says the people behind them — developers, large token holders, front-end operators or funders — should be licensed and supervised like any other financial firm. Even operating a front-end that directs users to a protocol can be enough to trigger oversight. Banks and centralized exchanges are also urged to run due diligence on any DeFi platform they interact with, and to stop dealing with ones that pose unacceptable risks.
Giles Thomson, FATF president, framed the guidance as balancing two aims: stopping criminals from exploiting new technology to “launder dirty money” while “supporting responsible financial innovation,” with strong public–private information sharing at the center of the response.
Enforcement gaps and uneven adoption
Despite the guidance, actual implementation is sparse. FATF’s survey found that almost 93% of responding jurisdictions have not applied FATF standards to any qualifying DeFi arrangement. Only 26 of 142 jurisdictions have even assessed DeFi risks. Four jurisdictions have licensing rules on the books for such activity, and just two have used them to register or license a platform. While FATF guidance is not law, members are evaluated on compliance — persistent gaps can contribute to placement on FATF’s “grey list.”
How FATF wants DeFi to change
FATF recommends countries require — or at least encourage — DeFi projects to bake anti-money-laundering (AML) controls into smart contracts and interfaces. Suggested measures include sanctions screening, proof-of-KYC checks before certain functions run, and other preventative controls. For genuinely leaderless projects, regulators should target upstream and downstream choke points: stablecoin issuers that can freeze assets, exchanges handling fiat on- and off-ramps, and front-end operators. As a last resort, jurisdictions can ban platforms that refuse to cooperate.
Criminal misuse and recent incidents
The report highlights how criminals already exploit DeFi. It singles out state-linked North Korean hackers behind two April attacks that together drained more than $570 million: a $285 million exploit on Solana perpetuals exchange Drift Protocol (allegedly executed in 12 minutes) and a $292 million hack of KelpDAO. FATF says those events accounted for roughly 76% of the year’s crypto-hacking losses. The report also flags ransomware groups, professional laundering networks, and investor frauds that use mixers, bridges and swaps.
Regulatory precedents and market scale
FATF’s push aligns with recent enforcement actions that treat protocol operators as regulated actors — U.S. prosecutions this year included prison terms for the co-founders of Bitcoin mixer Samourai Wallet and a conviction of Tornado Cash developer Roman Storm. Meanwhile, DeFi’s total value locked reached $86.6 billion this year — up about 85% since 2023 — with the top dozen protocols holding more than 60% of that capital, underscoring the scale of potential illicit-finance risk if gaps remain.
Bottom line
FATF is urging jurisdictions to implement its rulebook for DeFi rather than leave enforcement gaps that could enable illicit finance at scale. For developers and projects, the message is clear: if control points exist, expect regulatory scrutiny — and plan to embed compliance capabilities or risk being cut off by banks, exchanges or regulators.
Read more AI-generated news on: undefined/news