Every website or wallet that offers access to unregistered securities is in breach of securities regulations — including platforms like aave.com and compound.finance, which provide access to pooled lending products that qualify as unregistered securities under the Howey Test.

Publishing open-source code is protected by free speech. However, if that code results in the operation of a securities product accessible to retail users, financial regulations apply regardless of how the code was published.

The DAO defense does not hold

Some projects have declared themselves DAOs and argued that regulations do not apply. The FATF (Financial Action Task Force) Travel Rule and VASP framework address this directly:

  • If a company controls the private keys, that company must register as a VASP (Virtual Asset Service Provider).
  • If a DAO controls the private keys of the smart contracts, all token holders of that DAO become VASPs.
  • If there is no DAO and no company, the developer who deployed the contracts becomes a VASP.

There is no structural arrangement — company, DAO, or anonymous deployment — that places a DeFi product outside the scope of VASP obligations once it is accessible to users.

Where regulation stands now

VASP regulation is no longer forthcoming — it is being implemented. The EU's MiCA regulation entered into force in 2024. The UK, Singapore, UAE, and a growing list of jurisdictions have either enacted or are actively enforcing VASP registration requirements, including KYC, AML, transaction monitoring, and regulatory reporting.

This regulatory infrastructure creates transparency into which users from which jurisdictions are using which products. DeFi platforms that pool client assets are required to apply for a securities licence — not for their governance token, but for the product itself.

Further info