The European Banking Authority (EBA) has urged the European Commission to consider expanding Markets in Crypto-Assets (MiCA) rules to cover decentralized finance (DeFi) borrowing and lending intermediaries ahead of a key September 30 consultation deadline. Published on September 24, the regulatory response calls for a formal cost-benefit analysis into crypto-asset service providers (CASPs) that connect retail users to protocol loans.
Key Takeaways
- EBA Recommendation: Proposes adding crypto borrowing and lending intermediation to the official MiCA service list for CASPs.
- DeFi Gateway Focus: Target rules would apply to applications like MetaMask that facilitate access to protocols such as Aave.
- Proposed Controls: Calls for suitability tests, leverage caps, cybersecurity certifications for lending protocols, and restrictions on unauthorized tokens.
- Upcoming Clock: The European Commission consultation window closes at 11:59 p.m. Central European Summer Time (CEST) on Sept. 30.
Proposed Safeguards for Intermediated Lending
Under the EBA proposal, European officials outlined two primary options for legislative consideration. The first would explicitly add intermediating crypto borrowing and lending to MiCA's regulated list of CASP services. The second option would establish target compliance requirements for CASPs providing consumer access to DeFi lending protocols through mobile apps, front-end interfaces, or structured investment products.
The EBA cited several consumer risks driving its proposal, including undisclosed fees, volatile collateral requirement changes, operational outages, and a lack of borrower creditworthiness assessments. Proposed remedies include mandatory suitability tests for retail users, strict leverage limits, and clear risk warnings when users interact with unverified decentralized smart contracts. Additionally, the EBA suggested prohibiting CASPs from facilitating loans that involve unauthorized asset-referenced tokens or e-money tokens. While international regulators address market structure through separate frameworks—such as when the Federal Reserve proposed rules under the GENIUS Act—EU officials are focusing heavily on access portals.
Smart Contracts vs. Gateway Interfaces
The regulator's document highlights the distinction between autonomous protocols and user-facing software. For instance, MetaMask provides user guides detailing in-app stablecoin deposits into Aave liquidity pools, while Aave documentation outlines multiple entry points including its web interface, third-party apps, or direct smart contract interactions.
By targeting the entities managing front-end applications, European regulators aim to establish clear legal boundaries without directly regulating autonomous code. As financial institutions expand into on-chain finance—much like how Ondo Finance launched BlackRock-backed on-chain portfolios—defining where user interface responsibility begins remains a pivotal regulatory issue.
Why It Matters
The EBA recommendations signal that European authorities view software interfaces and wallet providers as the primary choke point for enforcing consumer protections in DeFi. By holding user-facing CASPs accountable rather than attempting to enforce rules on immutable smart contracts, the EU is establishing a pragmatic compliance parameter. If the European Commission moves forward with legislative proposals after the September 30 deadline at 11:59 p.m. CEST, wallet operators and interface providers will need to institute robust compliance procedures to serve European citizens.
