Curve founder says FATF pressure could make DeFi safer and more decentralized
Curve Finance (CRV) founder Michael Egorov said regulatory pressure from the Financial Action Task Force could push decentralized finance protocols toward greater decentralization and stronger security, even as he criticized the way AML rules are being applied to the sector.
"The more a protocol minimizes privileged access, removes upgrade risks, and eliminates the ability for any party to interfere with user funds, the stronger case it can make in terms of security," Egorov said in an interview with The Block.
His comments followed the FATF's July 21 report on how its anti-money laundering and counter-terrorist financing standards (AML/CFT) should apply to DeFi.
The report centered on whether a person or entity has "control or sufficient influence" over a DeFi arrangement, rather than whether a protocol describes itself as decentralized or uses automated smart contracts.
FATF said blockchain infrastructure, open-source software, and smart contracts do not by themselves determine whether AML/CFT requirements apply. Regulators should instead examine governance, operational, and economic structures to identify whether an individual or entity exercises control or sufficient influence.
The report also lists factors including the ability to change protocol parameters, upgrade smart contracts, exercise administrative privileges, control governance voting blocs, and manage access to permissioned functions. Influence over development teams, front-end applications, and key service providers can also be considered.
Egorov said regulators should first establish what a protocol can technically do before determining who controls it.
"If governance cannot touch user funds, then why even go in-depth to figure out how decentralized that governance is?" he said.
User-fund control
Egorov said the ability to redirect customer funds should carry greater weight in regulatory assessments than the identity of a protocol's developers or front-end operators.
"Front ends, development teams, and governance can all change over time, but the smart contract architecture determines what is actually possible," he said, calling it "the most objective measure" of a protocol.
He said a protocol is less decentralized when user funds can be redirected through a multisig or externally owned account. Smart-contract upgradeability is another key consideration because governance could potentially introduce changes that allow funds to be redirected.
Where upgradeability is controlled by an onchain decentralized autonomous organization, regulators would then need to examine the distribution of voting power, Egorov said.
FATF similarly identified concentrated governance ownership, proposal rights, and veto powers among the indicators authorities may consider. It said the factors are not exhaustive and should not be applied as a rigid checklist.
FATF divides DeFi arrangements into three categories. Arrangements with identifiable controllers fall within its standards, as do arrangements where controllers exercise control but cannot readily be identified. Truly decentralized arrangements, where no person maintains control or sufficient influence, fall outside the direct scope of the standards but can still present financial crime risks.
Egorov said the presence of a development team alone should not establish control.
"Writing code and maintaining software does not automatically translate to having direct control over the protocol," he said.
A development team's role becomes relevant, he said, when it has governance influence or the ability to upgrade smart contracts through emergency or other privileged mechanisms.
Regulatory pressure and security
Egorov said he does not believe AML/CFT rules are currently efficient for DeFi or should be applied to the sector in their current form.
But he said regulatory pressure could have a different effect on how protocols are designed.
"I think that this kind of pressure from regulators can, ironically, force DeFi to be safer than it is," he said.
He said protocols could respond by reducing privileged access, removing upgrade risks, and eliminating the ability of any party to interfere with user funds.
Egorov also distinguished between decentralized protocols and "CeDeFi," which he described as retaining centralized points of control. He said such structures could face greater regulatory scrutiny.
Meanwhile, the FATF report said financial institutions and VASPs interacting with DeFi arrangements should assess governance structures and AML/CFT safeguards, with enhanced due diligence for higher-risk exposures such as bridges, mixers, and cross-chain services.
Implementation gap
The report identifies a substantial gap between FATF's standards and their implementation by national authorities. Almost 93% of reporting jurisdictions, or 132 of 143, had not implemented Recommendation 15 for DeFi arrangements falling within the regulatory perimeter.
Only two of 142 jurisdictions reported having licensed or registered a DeFi arrangement in practice. FATF attributed the implementation difficulties to DeFi's global reach, the absence of clear jurisdictional anchors, limited technical expertise among supervisors, and the difficulty of distinguishing decentralized technology from centralized governance.
Egorov said the outcome will depend on whether regulators account for DeFi's technical differences when designing the rules.
"If rules from traditional finance simply get copied to DeFi, the outcome would be largely negative," he said. "In DeFi, mechanisms and risks all work very differently."
FATF's approach also follows earlier work on stablecoins and unhosted wallets. In a March report, the watchdog said jurisdictions should consider requiring stablecoin issuers to implement technical measures that can freeze, burn, or deny-list assets in the secondary market.
FATF said peer-to-peer stablecoin transfers through unhosted wallets create vulnerabilities because they occur without a regulated virtual asset service provider or financial institution subject to standard AML/CFT obligations.
For DeFi, however, Egorov said regulators should first establish what a protocol can actually do, then determine who has the authority to exercise those capabilities.
"Right now, regulators are still too focused on identifying people, when they ought to establish first who actually has control," he said.
The FATF report is non-binding and does not impose a single global licensing model. It is expected to influence national legislation, supervisory decisions, and FATF's mutual evaluation process, which assesses member countries' compliance with its standards.
Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
The Japanese Yen gives back half a record intervention
Can Compound crypto’s $52M DeFi push send COMP toward $20?

British Pound Sterling's three-month high was made in America
