← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Malta Tests Decentralization Scoring for DeFi Under MiCA

Zephyra|June 18, 2026|BPF
EXECUTIVE SUMMARY

The Malta Financial Services Authority (MFSA) on June 17 published a discussion paper proposing that decentralization be measured on a spectrum rather than as a binary pass/fail test — a framework that, if adopted, would pull dozens of nominally decentralized protocols into the regulatory perimet...

"Clearer standards are needed for DeFi governance, accountability and what constitutes 'full decentralization.'" — Malta Financial Services Authority, Discussion Paper on Decentralised Finance, June 17, 2026

Executive Summary

The Malta Financial Services Authority (MFSA) on June 17 published a discussion paper proposing that decentralization be measured on a spectrum rather than as a binary pass/fail test — a framework that, if adopted, would pull dozens of nominally decentralized protocols into the regulatory perimeter of the EU's Markets in Crypto-Assets Regulation (MiCA). The consultation, open until July 10, arrives two weeks before the July 1 deadline when MiCA's transitional grandfathering period closes across all 27 EU member states and the broader EEA. Any crypto-asset service provider operating without authorization after that date will be in breach of EU law.

The timing is not coincidental. The European Commission on May 20 launched its own parallel targeted consultation on whether MiCA should be expanded to cover DeFi, staking, lending, NFTs, prediction markets, and perpetual futures — with responses due August 31, 2026, and a formal report to the European Parliament due by June 30, 2027. Malta's paper is a national-level pilot that could shape the EU-wide approach. The MFSA is the first individual member-state regulator to publish a structured framework for assessing DeFi decentralization under MiCA.

Table of Contents

  1. The Regulatory Gap: MiCA's Decentralization Exemption
  2. Malta's Proposal: Decentralization as a Spectrum
  3. The Data Problem: How Concentrated Is DeFi Governance?
  4. Five Mechanisms the MFSA Wants to Examine
  5. The EU-Wide Regulatory Timeline
  6. Implications for Protocols and Capital Flows
  7. Key Takeaways
  8. Conclusion

The Regulatory Gap: MiCA's Decentralization Exemption

MiCA Recital 22 states that crypto-asset services "provided in a fully decentralised manner without any intermediary" fall outside the regulation's scope. The text provides no test, no criteria, and no measurable threshold for what "fully decentralised" means. That ambiguity has functioned as a de facto exemption for the entire DeFi sector.

As of June 2026, approximately 204 crypto-asset service providers (CASPs) hold full MiCA authorization across EU member states, according to the ESMA register. Germany leads with 53 licensed CASPs, followed by the Netherlands (25), France (13), Norway (13), and Malta (12). None of these licenses cover DeFi protocol operations. The roughly $130–140 billion in global DeFi total value locked — of which European users account for an estimated 25–30%, or approximately $33–42 billion — sits entirely outside the regulated perimeter.

The gap is structural. MiCA was drafted between 2020 and 2022, when DeFi TVL was a fraction of current levels. The regulation addressed centralized exchanges and token issuers. DeFi was treated as a future problem. That future has arrived, and regulators are now working backward to close the gap.

Malta's Proposal: Decentralization as a Spectrum

The MFSA's discussion paper, published June 17, rejects the binary framing embedded in MiCA. Rather than asking whether a protocol is or is not decentralized, the paper proposes assessing decentralization across multiple dimensions simultaneously:

  • Governance concentration: Who holds voting power? How many addresses control a majority of governance tokens?
  • Administrator keys: Does a single entity or small multisig control contract upgrades, parameter changes, or emergency pause functions?
  • Protocol upgrade rights: Can the codebase be altered after deployment? By whom?
  • Front-end control: Who operates the user-facing interface? Can it censor transactions or restrict access?
  • Treasury management: Who controls protocol-owned funds?

The MFSA explicitly notes that "many DeFi platforms continue to use features that give certain individuals or groups control over key operations" while claiming decentralized status. The implication: a protocol that scores poorly on multiple dimensions would fall within MiCA's scope regardless of its marketing.

This spectrum approach mirrors language in the European Commission's May 20 consultation, which asks whether "certification schemes for DeFi protocols and smart contracts" should be developed. Malta appears to be prototyping at the national level what Brussels may eventually mandate EU-wide.

The Data Problem: How Concentrated Is DeFi Governance?

The MFSA's concern is not theoretical. A March 2026 ECB Working Paper (No. 3208), authored by economists Alexandra Born, Zakaria Gati, Claudia Lambert, Mahvish Naeem, and Antonella Pellicani, analyzed governance concentration across four major protocols — Aave, MakerDAO, Ampleforth, and Uniswap — using on-chain data.

The findings were stark:

  • Top 100 holders control more than 80% of governance token supply in each of the four protocols examined
  • Approximately half or more of total holdings are linked to the protocols themselves or to exchanges — not independent token holders
  • Top voters are mostly delegates who, in many cases, "could not be identified nor linked to token holders"

Separate academic research on voting power confirms the pattern at a more granular level. In Compound, 10 voters hold 57.86% of total voting power. In Uniswap, 10 voters hold 44.72%. At Aave, the top three voters control over 58% of total voting weight, with the single largest holder commanding 27.06%.

These numbers directly undermine any claim of "full decentralization" as contemplated by MiCA Recital 22. If a handful of addresses can unilaterally alter protocol parameters, the system has identifiable controlling actors — exactly the condition that triggers regulatory jurisdiction.

The ECB paper's conclusion is pointed: "Effective supervision will require smarter identification of responsible parties rather than accepting surface-level claims of disintermediation."

Five Mechanisms the MFSA Wants to Examine

The discussion paper goes beyond diagnosis. It outlines five specific mechanisms the MFSA is evaluating for potential regulatory application:

1. Smart Contract Audits as a Regulatory Requirement The MFSA is seeking views on whether MiCA-licensed CASPs should be required to conduct smart contract audits, governance reviews, and risk assessments before connecting their platforms or clients with DeFi protocols. This would create a compliance bottleneck: regulated entities would need to vet unregulated protocols before interacting with them.

2. Legal Entity Structures for DeFi The paper examines possible legal frameworks for DeFi projects, including DAOs and segregated cell companies (SCCs). SCCs, already used in Maltese insurance and fund structures, allow a single legal entity to ring-fence assets and liabilities into separate "cells." The MFSA is exploring whether this structure could give DeFi protocols a legal identity without requiring full corporate incorporation.

3. Guardian Agents The MFSA introduces the concept of "guardian agents" — automated monitoring systems that "monitor, evaluate, and constrain the behaviour of other autonomous systems to ensure compliance with predefined objectives and risk tolerances." In practice, these would function as on-chain compliance bots that could flag or block transactions that violate regulatory parameters.

4. Decentralization Scoring Framework The paper asks whether a standardized framework should be developed to score a protocol's decentralization across the dimensions listed above, creating a measurable threshold below which MiCA obligations would apply.

5. Due Diligence Requirements for CASP-DeFi Interaction Regulated CASPs that route client activity through DeFi protocols could face specific due diligence obligations, including ongoing monitoring of protocol governance changes, smart contract upgrades, and treasury movements.

The EU-Wide Regulatory Timeline

Malta's paper exists within a broader regulatory convergence:

| Date | Event | |------|-------| | May 20, 2026 | European Commission launches targeted MiCA review consultation | | June 17, 2026 | MFSA publishes DeFi discussion paper | | July 1, 2026 | MiCA transitional grandfathering period closes across EU/EEA | | July 10, 2026 | MFSA consultation deadline | | August 31, 2026 | European Commission consultation deadline | | H2 2026 (expected) | ESMA Level 3 guidance on "fully decentralised" definition | | June 30, 2027 | Commission report to European Parliament and Council |

The convergence of these timelines suggests that by mid-2027, the EU will have a formal position on whether and how DeFi falls within MiCA's scope. Malta is positioning itself to influence that outcome. Given the country's track record — it was among the first EU jurisdictions to establish a comprehensive crypto regulatory framework under its 2018 Virtual Financial Assets Act — its proposals carry weight in Brussels.

Implications for Protocols and Capital Flows

If the spectrum approach is adopted, the consequences for the DeFi sector are material:

Protocols with concentrated governance will face a binary choice: decentralize meaningfully — distributing governance tokens more broadly, removing admin keys, deploying immutable contracts — or register as regulated entities under MiCA. The compliance cost of MiCA authorization is estimated at €500,000 to €2 million for mid-tier CASPs, according to industry estimates cited in the Commission's May consultation. For DeFi protocols operating without corporate structures or revenue models that support compliance teams, this cost may be prohibitive.

Capital may migrate to protocols that can demonstrate genuine decentralization. Protocols that score well on the MFSA's proposed dimensions — minimal governance concentration, no admin keys, immutable contracts, decentralized front-ends — could become preferred venues for European institutional capital seeking regulatory clarity.

The CASP-DeFi interaction rules could create a choke point. If regulated exchanges and custodians are required to audit DeFi protocols before interacting with them, the roughly 204 licensed CASPs become de facto gatekeepers. Protocols that fail audits would be cut off from the regulated on-ramp, fragmenting liquidity between compliant and non-compliant venues.

The combined market capitalization of governance tokens stands at approximately $30 billion as of April 2026, according to CoinGecko data. Major asset managers — including Apollo, BlackRock, and Citadel — have begun acquiring governance tokens to gain influence over on-chain credit infrastructure. Any regulatory framework that ties governance concentration to compliance obligations would directly affect the economics of these positions.

Key Takeaways

  • Malta's MFSA published a discussion paper on June 17 proposing that DeFi decentralization be assessed as a spectrum, not a binary exemption. The consultation closes July 10.
  • ECB Working Paper No. 3208 found that top 100 governance token holders control over 80% of supply across Aave, MakerDAO, Ampleforth, and Uniswap — data that supports the MFSA's premise.
  • The European Commission's parallel MiCA review consultation (open until August 31) explicitly asks whether certification schemes for DeFi protocols should be developed, suggesting Malta's approach may scale EU-wide.
  • MiCA's transitional period closes July 1, 2026. After that date, any CASP operating without authorization in the EU is in breach. DeFi protocols that retain centralized features may be next.
  • Five specific regulatory mechanisms — mandatory smart contract audits, legal entity structures, guardian agents, decentralization scoring, and CASP due diligence — are on the table.
  • An estimated $33–42 billion in DeFi TVL attributable to European users currently sits outside any regulatory framework. That may not last.

Conclusion

Malta's discussion paper is a technical document, not a legislative proposal. It asks questions rather than imposing rules. But the questions themselves are consequential. By framing decentralization as a measurable spectrum rather than an abstract binary, the MFSA has articulated a framework that, if adopted, would collapse the regulatory buffer zone that most DeFi protocols rely on to operate without authorization in Europe.

The timing — two weeks before MiCA's grandfathering period expires, three months before the Commission's consultation closes, and concurrent with ESMA's expected Level 3 guidance — indicates coordinated momentum. The question for the DeFi sector is no longer whether European regulation will reach protocols that retain centralized control points. It is how soon, and at what threshold.

Sources & References

  1. MFSA Discussion Paper on Decentralised Finance (DeFi) — Official MFSA press release, June 17, 2026
  2. MFSA Discussion Paper PDF — Full discussion paper
  3. Malta's financial regulator explores bringing parts of DeFi under MiCA's orbit — CoinDesk, June 18, 2026
  4. Malta Pushes to Define What Actually Counts as 'Decentralized' Under MiCA — CryptoTimes, June 18, 2026
  5. Malta Weighs Applying MiCA Rules to DeFi — BloomingBit/CoinDesk, June 18, 2026
  6. ECB Working Paper No. 3208: Who to Regulate? Identifying Actors Within DeFi's Governance — European Central Bank, March 2026
  7. ECB paper finds DeFi governance concentrated — The Block, March 2026
  8. European Commission Launches Targeted Consultation on the Review of MiCA — Maples Group, May 2026
  9. MiCA CASP Licences in Europe: March and April 2026 Update — LegAsset, April 2026
  10. DeFi: Mirage or reality? Unveiling wealth centralization risk in Decentralized Finance — ScienceDirect, 2025