The Financial Action Task Force (FATF), an intergovernmental body based in Paris that sets global anti-money-laundering standards, has called for stricter oversight of decentralized finance (
The Financial Action Task Force (FATF), an intergovernmental body based in Paris that sets global anti-money-laundering standards, has called for stricter oversight of decentralized finance (DeFi) platforms. In its latest report, FATF stated that many DeFi platforms operate as “decentralized in name only,” and often remain under the control or significant influence of identifiable individuals or groups. Where such control exists, the FATF asserts that the responsible parties must be subject to the same regulations as other financial institutions.
Regulatory gaps in DeFi oversight
FATF’s report highlighted that nearly 93% of surveyed jurisdictions have not yet enforced its anti-money-laundering standards on DeFi arrangements that meet the criteria for regulation. Out of the 142 jurisdictions that responded, only 26 have begun risk assessments, just four have put licensing rules in place, and only two have licensed or registered a DeFi platform to date.
The organization sorts DeFi projects into three categories: those with identifiable controllers, platforms that are centralized in practice but have hidden operators, and a limited group that are truly decentralized. Only the last are exempt from FATF’s recommendations. Despite the claims of decentralization, the report found that elements such as concentrated governance tokens, administrator privileges, upgrade controls, and insider rewards mean that many projects are centralized in practice.
Mini dictionary: Financial Action Task Force (FATF), an international body that develops standards and promotes effective implementation of legal and operational measures for combating money laundering, terrorist financing, and related threats to the international financial system.
The FATF guidance covers a range of visible and hidden signs of control, including the ability to update code, manage fees, adjust risk parameters, operate public interfaces, or influence a project treasury. When such influence is present, parties behind the platform—whether developers, core token holders, interface operators, or funders—should be licensed and subject to supervision. Running a platform front-end that directs users to underlying protocols can also qualify as sufficient control.
Calls for stronger compliance and enforcement
FATF President Giles Thomson stated that the aim is to prevent criminals from exploiting DeFi technology to launder illicit funds, while still allowing responsible innovation. He identified strong public-private information sharing as a critical part of the enforcement strategy. The FATF report urges governments to identify responsible parties behind DeFi projects and to regulate them as virtual asset service providers.
Centralized elements often exist within so-called decentralized projects, resulting in governance centralization, administrative rights, or fee structures that benefit insiders, according to the FATF report.
If project organizers refuse to cooperate, FATF recommends that, as a last resort, jurisdictions consider banning such platforms from operating locally. The guidance also encourages DeFi projects to integrate anti-money-laundering measures, such as sanctions screening or KYC proof, directly into smart contracts or user interfaces.
Where projects are truly decentralized, regulators are encouraged to focus on related “choke points” such as stablecoin issuers that can freeze assets, centralized exchanges handling fiat conversions, or operators controlling user-facing websites. Banks and exchanges are advised to perform due diligence on any DeFi services they interact with or cease engagement with non-compliant platforms.
The FATF report emphasizes the role of DeFi in recent major hacks and criminal activity, specifically noting North Korea-linked attacks in April that resulted in combined losses of over $570 million. The report details a $285 million exploit of Solana-based Drift Protocol, which occurred in 12 minutes, and a $292 million attack on KelpDAO. Combined, these incidents accounted for about 76% of all crypto-related hacking losses this year.
Mini dictionary: Drift Protocol is a decentralized perpetual exchange on the Solana blockchain, while KelpDAO is a DeFi protocol offering liquid staking services and yield strategies.
Recent enforcement actions, including US convictions against Samourai Wallet co-founders and Tornado Cash developer Roman Storm, underscore the view that developers and operators behind DeFi platforms can be prosecuted and regulated as money service businesses.
The report also highlights the use of DeFi mixers, bridges, and swaps by ransomware operators, organized laundering rings, and groups conducting fraudulent investment schemes.
DeFi growth and the regulatory response
According to FATF, DeFi’s total value locked (TVL) stands at $86.6 billion this year, an increase of about 85% since 2023, with the top 12 protocols controlling over 60% of this value. FATF urges regulators to close existing loopholes and implement its standards to combat large-scale illicit finance risks while supporting responsible growth of the sector.
Jurisdiction SurveyedApplied FATF Rules to DeFiRisk Assessments ConductedLicensed a DeFi PlatformTotal (142)~7%262
The post FATF urges global DeFi crackdown, cites $570 million North Korea-linked hacks appeared first on COINTURK NEWS.