Key Highlights
- The European Banking Authority has asked the European Commission to examine new MiCA rules for crypto firms that connect customers to DeFi lending protocols, recommending a cost-benefit analysis of potential duties for intermediated borrowing and lending.
- The EBA identified two possible regulatory changes: adding intermediated crypto borrowing and lending to MiCA’s list of CASP services, and setting requirements for CASPs facilitating access to DeFi lending through interfaces or products.
- The Commission’s targeted consultation closes on September 30, 2024, and may accompany its report with a legislative proposal if warranted, though no new rules are currently enacted.
EBA Urges Commission Review of MiCA Rules for DeFi Access Points
The European Banking Authority (EBA) has formally requested that the European Commission examine potential new rules under the Markets in Crypto-Assets (MiCA) regulation targeting crypto-asset service providers (CASPs) that connect customers to decentralized finance (DeFi) lending protocols. In its September 24 response to the Commission’s consultation, the regulator called for a cost-benefit analysis of possible duties for intermediated borrowing and lending, specifically focusing on CASPs that give clients access to DeFi lending through interfaces or product offerings. The EBA emphasized that consumer risks—including incomplete information about fees, yields, collateral changes, leverage amplifying losses, and risks from commingling, outages, hacks, and poor recordkeeping—prompted its call to assess the issue.
Mapping CASP Roles in DeFi Lending
The EBA’s review maps potential CASP roles in DeFi lending while noting that direct smart-contract use remains unresolved. The authority identified two distinct regulatory pathways for the Commission’s consideration. The first would add intermediating crypto borrowing and lending to MiCA’s existing list of CASP services. The second would establish specific requirements for CASPs that facilitate access to DeFi lending protocols, whether through a user interface or a product providing exposure to DeFi yields. The Commission would need to weigh the scale of these activities, the extent of retail participation, and the materiality of risks before deciding whether to pursue legislation.
Proposed Safeguards and Access Restrictions
Among the six DeFi lending safeguards proposed for Commission analysis, the EBA suggested suitability tests to assess whether a customer should participate, leverage caps, and fuller disclosures to address borrowing risks. For DeFi access specifically, the regulator floated extra warnings that activity through a truly decentralized protocol may lack regulatory safeguards, as well as certification of lending protocols for resilience to cyberattacks. A separate option concerns tokens whose issuers lack required MiCA authorization: the EBA said CASPs could be prohibited from intermediating or facilitating borrowing and lending involving assets that meet MiCA’s definition of an asset-referenced or e-money token but have no authorized issuer.
Why This Matters
The EBA’s recommendations signal a potential regulatory boundary forming around the “front-end” access points to DeFi—wallets, apps, and structured products that bridge retail users to on-chain lending protocols like Aave. While the underlying protocols continue to execute loans autonomously via smart contracts, the firms controlling the user-facing layer could face new suitability checks, disclosure requirements, and leverage restrictions. The distinction between an interface providing protocol access, a service intermediating a loan, and a product offering DeFi exposure will be critical: any future measure must translate these categories into clear obligations for firms and customers. The Commission’s consultation closes on September 30, 2024, at 11:59 p.m. Central European Summer Time, and its subsequent report—potentially accompanied by a legislative proposal—will determine whether these proposals advance into binding law. Until then, the current MiCA framework remains unchanged for DeFi lending access.
Frequently Asked Questions
Does the EBA’s response create any new rules for DeFi lending today?
No. The EBA’s response is a recommendation to the European Commission to examine potential legislation. It does not enact any new lending rules or change current MiCA requirements. The Commission must still conduct its analysis, weigh the scale and risks of intermediated DeFi access, and decide whether to pursue a legislative proposal.
How would the proposed rules affect direct smart-contract interaction with DeFi protocols?
The EBA’s review explicitly notes that direct smart-contract use remains unresolved. The proposals target CASPs that facilitate access through interfaces or products—not users interacting directly with protocol smart contracts. Future lawmakers would still need to define the scope of “facilitating access” and decide how to treat direct on-chain interaction.
What specific consumer risks did the EBA cite to justify its recommendations?
The EBA highlighted incomplete information about fees, yields, and collateral requirement changes; leverage amplifying losses; risks from commingling, outages, hacks, and poor recordkeeping; absence of creditworthiness checks; and possible over-indebtedness as the key consumer harms driving its call for regulatory examination.

