Loading market data...

EBA Asks Brussels to Study MiCA Rules for DeFi Lending Access

EBA Asks Brussels to Study MiCA Rules for DeFi Lending Access

The European Banking Authority has asked the European Commission to examine whether MiCA needs new rules for crypto firms that connect customers to DeFi lending. In a September 24 response, the EBA called for a cost-benefit analysis covering both intermediated crypto borrowing and lending and crypto-asset service providers that give clients access to DeFi lending through interfaces or products. The recommendation is a request to assess legislation — it changes no lending rule on its own.

Two possible routes for Brussels

The EBA floated two changes for the Commission to study. One would add intermediating crypto borrowing and lending to MiCA's list of CASP services. The other would set requirements for CASPs that facilitate access to DeFi lending protocols, whether through an interface or a product offering DeFi exposure.

Before deciding whether to pursue legislation, the Commission would need to weigh how large these activities actually are, how many retail users are involved, and how serious the risks are. Those are open questions, not settled ones.

Suitability tests, leverage caps, cyber certification

The EBA suggested a menu of possible safeguards for the Commission to analyse. They include suitability tests, leverage caps, fuller disclosures, and extra warnings that truly decentralized protocols may lack regulatory safeguards. It also raised certification of lending protocols for resilience to cyberattacks.

A separate option targets tokens whose issuers lack required MiCA authorization. Under that idea, CASPs could be prohibited from intermediating or facilitating borrowing and lending involving assets that meet MiCA's definition of an asset-referenced or e-money token but have no authorized issuer.

The harms the EBA is worried about

The regulator tied its proposals to consumer risks. It listed incomplete information about fees, yields, or changes to collateral requirements; leverage that can amplify losses; risks from commingling, outages, hacks, and poor recordkeeping; the absence of creditworthiness checks; and possible over-indebtedness.

Those concerns are broad, and the EBA did not single out any one platform. It proposed six DeFi lending safeguards for the Commission to examine. None of them is an enacted rule today.

MetaMask and Aave in the frame

The proposals land in territory that popular interfaces already occupy. MetaMask's lending guide describes in-app access to Aave stablecoin pools, with mobile steps for depositing tokens. Aave's own access guide says users can reach the protocol through its interface, other applications, or direct smart contract interaction.

Neither guide establishes whether MetaMask's feature is available to EU customers, or how any named operator would be classified under a future CASP rule. That gap matters: the EBA's second option turns on what counts as facilitating access, and the facts so far don't settle it.

What happens next

The Commission's targeted consultation closes on September 30 at 11:59 p.m. Central European Summer Time. Feedback will feed into the Commission's report on MiCA's application and crypto-market developments. The Commission says it may accompany that report with a legislative proposal if warranted.

For now, the EBA's proposals signal a possible access and compliance boundary. The reach and the specific requirements remain undecided.