

Decentralised Finance (DeFi) was built on the ambitious promise of an open, permissionless, and leaderless financial ecosystem. However, a landmark report from the global anti-money laundering watchdog, the Financial Action Task Force (FATF), has delivered a sharp reality check to the Web3 industry: much of the DeFi landscape is decentralised in name only.
According to the Paris-based international body, centralised elements frequently persist behind the scenes of popular DeFi protocols. Consequently, FATF is urging global regulators to hold identifiable creators, operators, and governance token holders to the same strict standards applied to traditional financial institutions — warning that platforms refusing to comply could face outright territory-wide bans.
While Web3 advocates often market DeFi as a collection of autonomous smart contracts operating entirely free from human interference, FATF’s investigation reveals a starkly different operational picture. In practice, the vast majority of protocols retain significant centralised levers of control.
FATF categorises the current DeFi landscape into three distinct tiers:
Crucially, FATF standards apply to any project falling within the first two categories. Only the tiny minority of truly leaderless protocols escapes direct Virtual Asset Service Provider (VASP) compliance obligations.
How does a regulator determine whether a supposedly decentralised protocol is actually controlled by a few key actors? FATF highlights both on-chain and off-chain markers that reveal where true operational authority lies.
Key indicators of centralised control include:
FATF stresses that even maintaining a front-end website that funnels retail users toward a smart contract protocol can be sufficient to trigger regulatory supervision and licencing requirements.
Despite FATF’s firm stance, national governments have been extraordinarily slow to enforce these rules. A survey conducted by FATF across member jurisdictions highlights a dramatic gap between regulatory intentions and real-world enforcement:
While FATF guidance does not automatically constitute domestic law, member states are evaluated on how closely they align with these standards. Nations that persistently ignore these gaps risk landing on FATF’s high-risk "grey list", a status that brings severe international banking and economic penalties.
FATF’s aggressive push for supervision stems directly from the explosive growth of DeFi and its increasing exploitation by illicit actors. Total Value Locked (TVL) across DeFi protocols reached $86.6 billion, representing an 85% surge since 2023, with over 60% of total liquidity concentrated in just twelve major protocols.
This massive concentration of capital has attracted sophisticated cybercriminals. The report specifically highlights state-sponsored hacking networks, particularly those associated with North Korea, which executed major exploits draining over $570 million in a single month. Key incidents cited include a $285 million attack on Solana perpetuals platform Drift Protocol and a $292 million breach of KelpDAO — accounting for roughly 76% of all crypto hacking losses recorded during that timeframe.
Beyond state-backed cyber attacks, DeFi tools such as cross-chain bridges, decentralised exchanges (DEXs), and privacy mixers continue to be heavily utilised by ransomware syndicates, professional money laundering networks, and financial fraudsters.
To close these vulnerabilities, FATF advocates a dual strategy combining technological compliance mechanisms with assertive legal enforcement.
Regulators are encouraged to require DeFi projects to build compliance mechanisms directly into their smart contracts or front-end interfaces. This includes real-time sanctions screening and cryptographic proof-of-KYC (Know Your Customer) verifications before users can execute core functions.
Where protocols are genuinely leaderless, regulators are instructed to target secondary "choke points." These include centralized fiat on-and-off ramps, web hosting providers, front-end operators, and stablecoin issuers capable of freezing illicit tokens on-chain.
Furthermore, law enforcement agencies are already establishing formidable legal precedents. US prosecutors recently secured convictions against Samourai Wallet co-founders and Tornado Cash developer Roman Storm on charges of operating an unlicensed money transmitter. These judicial outcomes align directly with FATF's central thesis: individuals who build, deploy, and maintain software can be held legally accountable if they retain influence over systems that facilitate illicit financial movement.
The era of regulatory ambiguity for "decentralised in name only" platforms is rapidly coming to an end. As FATF tightens its supervisory expectations globally, Web3 projects face a stark choice: achieve absolute, uncompromising decentralisation with no admin controls or insider privileges, or integrate formal compliance and licencing into their operational models. For platforms seeking to navigate a middle ground, the risks of regulatory sanctions, criminal prosecution, and outright territorial bans have never been higher.
For more details on this topic, read the full original report coverage on Decrypt:
👉 Centralized Elements 'Frequently Persist' in DeFi and Should Be Regulated: FATF
Disclaimer: This article is provided for informational purposes only, mistakes may be made, and it's not offered or intended to be used as legal, tax, investment, financial, or any other advice.
