
The European Banking Authority has requested the European Commission to conduct a cost-benefit analysis of potential regulatory duties for crypto-asset service providers that facilitate customer access to decentralized finance lending protocols, citing consumer risks such as inadequate disclosures, leverage dangers, and lack of creditworthiness checks, with the Commission’s consultation closing on September 30.
AI-generated summary
The European Banking Authority has asked the European Commission to examine new MiCA rules for crypto firms that connect customers to DeFi loans, following concerns about consumer risks in intermediated crypto borrowing and lending activities.
The European Banking Authority has asked the European Commission to examine new MiCA rules for crypto firms that connect customers to DeFi loans.
Its September 24 response calls for a cost-benefit analysis of possible duties for intermediated borrowing and lending, and for crypto-asset service providers (CASPs) that give clients access to DeFi lending through interfaces or products.
A loan can run on an on-chain protocol while a company supplies the app that brings a customer to it. The EBA’s recommendation puts that company-controlled route within the Commission’s review, and it is a request to assess legislation, so the EBA’s response itself changes no lending rule.
The regulator said consumer risks prompted its call to examine the issue.
The EBA identified two possible changes. The first would add intermediating crypto borrowing and lending to MiCA’s list of CASP services, while the second would set requirements for CASPs facilitating access to DeFi lending protocols, whether through an interface or a product offering exposure to DeFi.
The Commission would need to weigh the scale of these activities, retail participation and the seriousness of the risks before deciding whether to pursue legislation.
Suitability tests could assess whether a customer should take part, while leverage caps and fuller disclosures could address borrowing risks.
For DeFi access, the EBA suggested extra warnings that activity through a truly decentralized protocol may lack regulatory safeguards. It also floated certification of lending protocols for resilience to cyberattacks.
A separate option concerns tokens whose issuers lack required MiCA authorization. The EBA said CASPs could be prohibited from intermediating or facilitating borrowing and lending involving assets that meet MiCA’s definition of an asset-referenced or e-money token but have no authorized issuer. The proposed restriction limits CASPs' access to those lending activities.
The response describes potential consumer harms behind the proposals, such as incomplete information about fees, yields, or changes to collateral requirements, leverage that can amplify losses, and risks from commingling, outages, hacks, and poor recordkeeping.
It also flags the absence of creditworthiness checks and possible over-indebtedness.
An app can connect a user to DeFi loans
MetaMask’s lending guide describes in-app access to Aave stablecoin pools, with mobile steps for depositing tokens. Aave’s access guide says users can reach the protocol through its interface, other applications, or direct smart contract interaction.
The documents show how users can access lending infrastructure through different routes.
Neither guide establishes whether MetaMask’s feature is available to EU customers or how any named operator would be classified under a future CASP rule. The EBA’s proposal specifically discusses CASPs that facilitate access.
Future lawmakers would still have to define that activity and decide how to treat direct smart contract use. Depending on those choices, an app could face checks or warnings at its entry point while a protocol continues executing loans on-chain.
The Commission’s targeted consultation closes on Sept. 30 at 11:59 p.m. Central European Summer Time. Feedback will inform its report on MiCA’s application and crypto-market developments.
The Commission says it may accompany that report with a legislative proposal if warranted. Until then, the EBA’s proposals signal a possible access and compliance boundary, with its reach and requirements still to be decided.
The EBA's document also points to why an access rule could differ across products. It asks the Commission to consider the nature and scale of an activity, the extent of retail participation, and the materiality of its risks.
The response mentions an interface giving protocol access, a service that intermediates a loan, and a product providing DeFi exposure. Any future measure would have to translate those distinctions into clear obligations for firms and customers, including the checks and disclosures attached to each route.
AI outlook — possibilities, not facts
The European Commission will launch a formal assessment of whether to amend MiCA to include intermediated crypto borrowing and lending as a CASP service
Likely · Within months
Regulatory guidance will emerge requiring CASPs to provide clearer warnings about the lack of safeguards in truly decentralized DeFi lending protocols
Possible · Within months

Bitget reported that approximately $387.5 million in assets were transferred to attacker-controlled addresses during a wallet breach on Sept. 24, with withdrawals suspended through Sept. 25 while deposits and trading continued. The exchange cited its User Protection Fund as covering the loss and noted collaboration with Mandiant and SlowMist. Syngnum announced an alternative custody solution for institutional clients on the same day, allowing trading using collateral held at the Swiss bank, though details on client uptake and whether any protected assets were affected remain undisclosed.

The US Department of Justice is pursuing civil forfeiture of $84.2 million that flowed through accounts used by Montana-based payments firm Capstone Ltd. to process Tether transactions. The complaint alleges Capstone operated as an unlicensed money transmitter in multiple states, misrepresented itself to banks as an IT services company, and had ties to EQIBank, a Dominica-licensed digital bank. Tether confirmed EQIBank handled its USDT transfers but denied knowledge of Capstone's alleged misconduct, noting its exposure is under 0.034% of group assets.

Strategy announced a proposal to pay daily dividends on four preferred share series used in its Bitcoin financing strategy, aiming to accelerate cash flow to investors without altering dividend rates or securities' economics, with effectiveness dependent on investor valuation of timing and pending approvals.

Strategy is seeking shareholder approval to switch four preferred stocks, including STRC, to daily dividend payments without changing dividend rates or total payout. The proposal follows Strive's earlier move to daily dividends and aims to address leverage-driven price volatility in STRC, which fell below $100 earlier this year due to unexpected market leverage.

MicroStrategy aims to transition four preferred share classes to daily dividend payments to lower volatility and increase liquidity. Shareholders are scheduled to vote on the proposal on October 28, with potential implementation beginning in November.

Morgan Stanley will serve as a strategic partner at the upcoming NEXTPredict summit in New York, marking the first public institutional bank engagement with the prediction market sector as firms evaluate the industry's potential for hedging and forecasting.