Centralized Elements 'Frequently Persist' in DeFi and Should Be Regulated: FATF

Summary

The FATF says much of DeFi is effectively centralized and should be regulated like other financial businesses whenever any identifiable person has control or sufficient influence. It divides DeFi into three categories: platforms with known controllers, those centralized in practice but with hidden operators, and a small truly decentralized group that escapes its standards. Signs of control include governance token concentration, admin and upgrade keys, fee-setting power, kill switches, website/app control, and corporate entities tied to developers or treasuries. When such control exists, developers, major token holders, front-end operators, and funders may need licensing and supervision. Compliance is weak: most responding jurisdictions have not applied the rules to qualifying DeFi, and very few have assessed risks or licensed platforms. FATF urges built-in AML controls, stronger checks at stablecoin issuers, exchanges, and front ends, and bans if necessary. It cites major criminal abuse of DeFi, including North Korea-linked hacks and laundering through mixers, bridges, and swaps.