MiCA is coming for DeFi vaults, but regulation will be difficult

cointelegraphPublished on 2026-08-22Last updated on 2026-08-22

Abstract

The European Commission is exploring whether to extend the Markets in Crypto-Assets (MiCA) regulation to cover decentralized finance (DeFi) lending and borrowing, including lending vaults. These vaults, which channel billions into on-chain credit markets, present significant regulatory challenges because their decentralized structure doesn't map neatly onto existing financial frameworks. Their legal status is currently based on non-binding interpretations that they fall outside MiCA and EU fund rules. The article uses Morpho's decentralized lending protocol as an example, illustrating how responsibilities are divided among various participants (owner, curator, allocator, sentinel), making it difficult to identify a single "provider" to regulate. Experts warn that broadly categorizing "DeFi lending" could inadvertently capture vastly different structures. They argue that any regulatory approach should focus on the specific structure and control mechanisms of a vault, rather than using decentralization as a simple dividing line, and that DeFi lending may require a dedicated, carefully crafted framework distinct from traditional finance. The Commission's consultation closes on September 30, 2026. The core challenge for regulators is not just whether to regulate DeFi lending, but how to design rules that distinguish between different forms of on-chain lending and the entities that control them.

MiCA left crypto lending outside its original rulebook — but now Brussels is considering whether to bring it in.

On May 20, 2026, the European Commission asked stakeholders to weigh in on areas left outside the original Markets in Crypto Assets (MiCA) framework. These include issues around decentralized finance (DeFi) and crypto lending and borrowing.

One area of contention involves lending vaults, which can channel billions of dollars into onchain credit markets without looking like conventional lending. Their legal status currently depends on non binding interpretations that they fall outside of MiCA and EU fund rules.

Yuriy Brisov, an EU digital assets lawyer and partner at Digital & Analogue Partners, tells Magazine the law pertaining to vaults at present is unclear:

“EU law has no category called a ‘vault.’ A lawyer therefore defines it the way a regulator would qualify it: by function, not by label.”

That’s just one of myriad regulatory problems, since vaults can perform the economic functions of lending while spreading other functions over smart contracts and multiple participants rather than a single company.

If Brussels decides lending should come inside the regulatory perimeter, what does that mean for DeFi, and where does it leave the people and protocols behind these vaults?

Morpho puts the problem into practice

Decentralized lending protocol Morpho’s lending infrastructure gives some clues as to why this question will be so hard to answer. The way its vaults are set up and managed does not neatly map on to any existing regulatory model.

Targeted consultation on the review of Regulation on the Markets in Crypto Assets (MiCA). Source: European Comission

Its Vault V2 architecture divides responsibilities between an owner, curator, allocator and sentinel. The curator configures strategy and risk parameters, while the allocator executes allocations and the sentinel has powers intended to reduce risk.

While none of this establishes any of these participants as providing a regulated lending service under MiCA, it does show why identifying the relevant “provider” is less straightforward than with a conventional lender.

Related: Bitwise to launch onchain vaults via Morpho

Jonathan Galea, a partner at Cahill Gordon & Reindel, explored the issue in a recent client update on lending vaults and their position under EU financial regulation. His analysis looks at how vault structures can sit across MiCA, stablecoin rules and European fund law.

Galea says policymakers should be careful about treating lending vaults as a single category, telling Magazine, “lending vaults solve more practical problems than they create.”

He says lending vaults help direct fragmented liquidity into lending markets, while other vaults may buy and sell crypto assets and should be treated differently:

“Bring ‘DeFi lending’ into the perimeter as a single label, and structures that deserve opposite answers risk ending up captured together.”

That would be important if Brussels decides to regulate lending, since a broad category covering “DeFi lending” could capture structures with very different economic functions—and people exercising control over them.

Who should actually be regulated?

MiCA currently excludes crypto asset services that are provided in a “fully decentralized manner,” although it can apply where only part of an activity is performed in a decentralized way.

Morpho’s Vault V2 architecture. Source: Morpho

One possible solution would be to make decentralization the dividing line, but Galea argues that could disadvantage newer protocols. He says:

“Decentralization is a spectrum and a function of time: a test built on it would penalize newer, more novel protocols while entrenching mature incumbents that have had years to distribute control.”

Brisov says the focus should instead be on the structure of the vault and the control people have over it:

“The safer ground is structural: there is no undertaking, no appointed manager, the holder has a direct coded claim on the pool, and the user can exit before any parameter change takes effect.”

He says if Brussels decides that lending and borrowing warrant regulation, they should be explicitly added to the list of regulated crypto asset services rather than broadening the definition of a crypto asset service provider itself.

Related: ‘DeFi doesn’t exist anymore,’ just onchain finance: Andre Cronje

Curve Finance founder Michael Egorov argues that the rules also need to account for the differences between decentralized lending and conventional finance. He says:

“If DeFi lending is ever brought into the scope of regulation, it should be treated completely differently. DeFi doesn’t need some of the safeguards which traditional lending requires, and yet, at the same time, it may need others.”

Egorov says regulation should be approached “really carefully,” and that a dedicated framework could improve safety and open DeFi lending to new users, while avoiding rules that some protocols cannot comply with because of how they’re built.

The Commission’s consultation closes Sept. 30, and what follows could determine whether lending vaults remain outside MiCA or become subject to a new regulatory framework.

For Brussels, the challenge is not simply whether to regulate DeFi lending; it’s how to write rules that distinguish between very different forms of onchain lending and the people (if any) that actually exercise control over them.

Magazine: 200,000 fake AI ‘victims’ deployed to scam bait online fraudsters

Related Questions

QWhat is the main regulatory challenge for DeFi lending vaults under MiCA, according to the article?

AThe main challenge is determining how to apply regulations to lending vaults, as they perform the economic functions of lending but spread responsibilities across smart contracts and multiple participants, making it difficult to identify a single, clear 'provider' to regulate under the existing MiCA framework.

QAccording to lawyer Yuriy Brisov, how should a 'vault' be defined under EU law?

AYuriy Brisov states that EU law has no category called a 'vault,' so it must be defined by its function rather than its label. A lawyer would define it the way a regulator would qualify it—based on what it does.

QWhy does Jonathan Galea warn against treating all 'lending vaults' as a single regulatory category?

AJonathan Galea warns that treating all lending vaults as a single category could capture structures with very different economic functions and control mechanisms under the same rules. He argues that vaults solving different practical problems, like directing liquidity versus buying/selling assets, deserve different regulatory treatment to avoid inappropriate regulation.

QWhat is a potential problem with using 'decentralization' as the dividing line for regulation, as discussed in the article?

AUsing decentralization as a dividing line could disadvantage newer protocols, as decentralization is a spectrum and a function of time. Such a test would penalize novel protocols while entrenching mature incumbents that have had more time to distribute control.

QWhat alternative regulatory approach does Michael Egorov, Curve Finance founder, suggest for DeFi lending?

AMichael Egorov argues that if DeFi lending is regulated, it should be treated completely differently from traditional finance. He suggests a dedicated framework that accounts for DeFi's unique needs, providing necessary safeguards it may lack while avoiding rules incompatible with its decentralized structure, ultimately improving safety and accessibility.

Related Reads

Grayscale Report: Financial Privacy in the AI Era, Why Zcash Should Not Be Overlooked?

Title: Grayscale Report: Financial Privacy in the AI Era – Why Zcash Should Not Be Overlooked The article argues that privacy is a fundamental, not niche, attribute of functional money. It highlights that technological shifts, like the rise of AI and stablecoins, are driving a new wave of public focus on financial privacy. Zcash, a decentralized digital currency similar to Bitcoin but with built-in privacy via zero-knowledge proofs, is positioned to address this need. Unlike transparent blockchains, Zcash offers users the option to conduct "shielded" transactions that hide sender, receiver, and amount while remaining verifiable. The report details Zcash's evolution, noting key upgrades that improved usability and security. It points to rising on-chain usage of privacy features as evidence of real demand. Currently, ZEC holds a minimal share (~0.4%) of the total crypto market cap. Grayscale suggests this reflects a market assumption that privacy is a marginal concern. The investment thesis hinges on a potential market re-evaluation: if privacy is recognized as a core monetary feature in an era of enhanced surveillance, Zcash's current valuation represents significant upside potential. Key risks discussed include regulatory challenges, historical trusted setup concerns for older pools (mitigated by newer protocols), quantum computing threats, and execution risks associated with future technical upgrades. The conclusion is that while the future scale of private digital currency is uncertain, the market currently prices in little chance of its value increasing substantially, presenting a potential opportunity for investors.

marsbit2h ago

Grayscale Report: Financial Privacy in the AI Era, Why Zcash Should Not Be Overlooked?

marsbit2h ago

Vitalik Moves to Local Mixing as Obfuscation Series Reaches Third Stage

Ethereum co-founder Vitalik Buterin published the third part of his series on cryptographic obfuscation, focusing on a method called "local mixing." This method abandons lattices and elliptic curves in favor of ideas borrowed from hash function design. Buterin described local mixing as a "completely different way of cryptography," free from elliptic curves, prime factorization, and lattices, making it more akin to symmetric cryptography used in everyday encryption. The process begins with a circuit of logic gates like XOR, AND, and NOT. It undergoes a pipeline that ensures a correct output while obscuring any trace of the internal logic. Key steps include adding reversibility, strengthening, mechanization, mixing, and finally obfuscation. The mixing step scatters extra logic gates and shuffles their arrangement. Reversibility is foundational, allowing gates to be rewritten as other reversible gates with similar behavior. Buterin acknowledged local mixing is a "wild and risky undertaking," lying on the "graveyard of failed attempts at white-box cryptography." However, its proponents argue it needs more research effort and a willingness to accept higher overhead costs. Buterin suggested AI could accelerate its development. He called obfuscation the "final boss of cryptography," with the most complex constructions having runtimes exceeding the universe's age. The article concludes by explaining obfuscation's utility: it can encrypt a program so it still functions with normal inputs and outputs while hiding the code. Combined with blockchain, this moves toward a "trusted third party that requires no trust," enabling applications like private, collusion-resistant voting without relying on a trusted committee.

cryptonews.ru3h ago

Vitalik Moves to Local Mixing as Obfuscation Series Reaches Third Stage

cryptonews.ru3h ago

Trading

Spot
活动图片