MiCAR and DeFi: Where the Protocol Ends and the Service Begins
MiCAR does not regulate DeFi as a whole: fully decentralized services remain outside its scope, but front-ends, aggregators, advanced wallets, and lending platforms may qualify as CASPs. An operational guide to distinguish between protocol, access layer, and service.
— Studio LX20 Law Firm
Regulation (EU) 2023/1114 on markets in crypto-assets ("MiCAR") entered into force on 29 June 2023. The regime for asset-referenced tokens and e-money tokens applies from 30 June 2024; the regime for crypto-asset service providers (CASPs) and other crypto-assets from 30 December 2024. In this context, the relationship between MiCAR and decentralized finance (DeFi) is one of the most debated and least settled areas. The European legislation has adopted a cautious approach: it does not exclude DeFi as a whole, but limits the exemption to services provided in a fully decentralized manner and without any intermediary. This operational distinction, far from being merely theoretical, determines the regulatory qualification of the most innovative business models in the sector.
Two levels to be kept distinct
A terminological premise is necessary. In the debate on MiCAR and DeFi, two different levels are often conflated.
The first is the protocol level. This concerns smart contracts, liquidity pools, automated mechanisms for lending, borrowing, staking, swaps, or liquidity provision, often described as decentralized infrastructures. When the protocol is genuinely such—immutable code, distributed governance, absence of entities organizing its operation—recital 22 of MiCAR provides a clear indication that it does not fall within the scope of the Regulation.
The second is the protocol access level. This concerns front-ends, wallets, aggregators, centralized platforms, application interfaces, entities that promote the service, retain fees, select protocols, or act as de facto intermediaries. On this level, the assessment changes: the qualification as a CASP becomes a concrete possibility and must be analyzed on a case-by-case basis.
The two levels interact, but they are not interchangeable. A protocol may be decentralized, but the interface that allows the user to interact with it may not be. A transaction may be executed on a smart contract but be commercially organized by an identifiable entity.
Recital 22: Fully decentralized DeFi
The starting point is recital 22 of MiCAR. The Regulation clarifies that where crypto-asset services are provided in a *fully decentralized manner* and *without any intermediary*, they do not fall within its scope. The wording is precise and must be understood in its two cumulative elements: full decentralization and the absence of an intermediary.
The scope of this provision is significant, but it should not be applied extensively without precise limits. The recital does not create a general exemption for any project that qualifies as "DeFi"; it identifies a limited sub-category of operations where no regulatable entity can be found.
It is crucial to understand that decentralization is not a commercial label, but an operational fact. A protocol can be based on smart contracts and, at the same time, have an identifiable development team, active governance, a foundation, an entity that collects fees, or coordinates updates. In such cases, the fact that the technical transaction occurs *on-chain* is not sufficient to remove the model from MiCAR's scope.
A correct presentation of the scope avoids lumping together "DeFi," "smart contracts," "non-custodial wallets," and "absence of regulation," as these are distinct technical and legal phenomena.
When a DeFi operator can become a CASP
MiCAR regulates crypto-asset service providers. Article 3(1), points (17) to (26), of MiCAR defines crypto-asset services: custody and administration of crypto-assets on behalf of clients; operation of a trading platform; exchange of crypto-assets for funds or for other crypto-assets; execution of orders for crypto-assets on behalf of clients; placing of crypto-assets; reception and transmission of orders for crypto-assets on behalf of clients; advice, portfolio management; transfer services for crypto-assets on behalf of clients.
The point is that a DeFi front-end, an aggregator, a wallet with transactional functions, a platform that routes transactions to decentralized pools, or an entity that organizes staking or lending via smart contracts can fall under one or more of these categories. The fact that the technical transaction occurs on a decentralized protocol does not neutralize the regulatory qualification of the entity that organizes, manages, or promotes access.
Qualification requires a case-by-case analysis. It is necessary to verify who controls the interface, who selects the protocols, who determines the transaction path, who collects fees, who receives users' tokens—even if only temporarily—and who assumes contractual liability towards the end-user.
ESMA, in its interpretative documents, has clarified that the services for which a CASP seeks authorization must correspond to the operational reality of the activity performed. In other words, the regulatory qualification follows the real economic function and not the commercial representation.
Non-custodial wallets: the boundary with custody
The issue of non-custodial wallets should be kept separate from DeFi in the strict sense.
The mere development or provision of software that allows the user to independently hold their own private keys does not, in itself, constitute custody under MiCAR. The regulatory definition of custody revolves around the holding, even temporarily, of crypto-assets on behalf of third parties: if the provider never has control of the keys, the custodial element is absent.
The picture changes if the wallet integrates additional functions. In-app swaps, routing to DEXs, bridging, staking, lending, borrowing, reception and transmission of orders, selection of protocols for user interaction: each of these functions can constitute a separate category under MiCAR. A wallet that combines self-custody + automated swaps + access to lending platforms may, from a regulatory perspective, represent a point of service delivery that requires specific analysis.
Here too, the point is not the wallet in the abstract, but its operational model. A wallet can be just a technical tool for self-custody; or it can become the *access layer* through which the user engages in transactions that are, in substance, provided by an identifiable entity.
Lending, borrowing, and staking: the grey area
The joint EBA-ESMA Report of 16 January 2025, prepared pursuant to Article 142 of MiCAR in response to the Commission's request of 9 February 2024, pays specific attention to DeFi, crypto-lending, and crypto-staking, acknowledging that these are the most complex borderline areas.
The central distinction is between the direct use of a protocol and a service organized by an identifiable entity.
In the first case, the user interacts with smart contracts not managed by an intermediary, while in the second, a platform collects assets, selects protocols, builds strategies, promises returns, or actively manages the operational flow.
In the second scenario, the DeFi element does not neutralize its potential regulatory relevance. The operator might not be the protocol itself, but the entity organizing access to the protocol. This is where the risk of qualification as a CASP or, in some cases, as an issuer of financial products under other regulations lies.
The boundary with financial instruments
A further distinction that should be made is that MiCAR does not apply to crypto-assets that qualify as financial instruments under MiFID II. In that case, the issue is not MiCAR, but the law of financial services and instruments as a whole.
This is particularly relevant for hybrid tokens, governance tokens with economic rights, liquid staking instruments, tokenized claims, or structures that grant the holder rights of a substantially participatory or creditor nature. The MiFID II qualification prevails: if the token *is* a financial instrument, MiCAR gives way to the regulation of financial instruments, with radically different consequences regarding prospectuses, market abuse, intermediation, and investor protection.
A correct presentation therefore avoids treating all DeFi tokens as MiCAR crypto-assets. Some may be out of scope due to the absence of an identifiable issuer or full decentralization; others may be out of scope because they are *within* MiFID II.
The Italian framework
In the Italian market, MiCAR applies directly as an EU Regulation; the domestic legal system has implemented it with Legislative Decree No. 129 of 5 September 2024, which designates the Bank of Italy and Consob as the national competent authorities and regulates procedural, sanctioning, and supervisory aspects. The authorities' interpretative guidelines tend to be substantive: regulatory qualifications follow the actual function performed and not the commercial framework chosen by the operator.
For operators building DeFi-facing models, the issue is not just whether to obtain a CASP authorization. The issue is preparing a documented regulatory qualification: a technical description of the model, identification of who controls what, the role of the front-end, the method of collecting fees, the presence or absence of identifiable entities along the operational chain, the tax regime, and the AML profile.
The analysis will tend to be based on the function actually performed, regardless of the project's commercial qualification.
Outlook
Three themes are expected in the next twelve months.
First: the progressive emergence of borderline cases involving advanced non-custodial wallets, aggregators, and DeFi front-ends. The market will tend to shift many regulatorily sensitive functions from centralized exchanges to *DeFi-facing* interfaces: the authorities' response will be crucial for stabilizing qualifications.
Second: greater European focus on lending, borrowing, and staking. The joint EBA-ESMA Report of 16 January 2025 has already identified these activities as areas of development and risk; the EU's trajectory is towards a deepening of legislation or regulation in the next 12-24 months.
Third: convergence between MiCAR and other regulations. For DeFi-facing operators, MiCAR qualification will be only one part of the analysis: AML, the travel rule, DORA, GDPR, payment services, consumer protection, and, where applicable, MiFID II all contribute to defining the overall framework.
In summary
MiCAR does not regulate DeFi as a whole. Services provided in a fully decentralized manner, without any intermediary, should not fall within the scope of the Regulation. But this does not constitute a general exemption for everything that self-qualifies as "DeFi".
The operational criterion is substantive: protocol, access layer, and service must be kept distinct. Non-custodial wallets, front-ends, aggregators, and platforms for lending, borrowing, and staking can fall under one or more CASP categories depending on the concrete structure of the activity.
The point is not the "DeFi" label. The point is who controls what, who does what for the client, and what economic and regulatory function is being performed.