Europe Gives Itself Until September 30 to Decide if Your DeFi Wallet Is a Broker
The European Banking Authority asked Brussels on September 24 to study whether crypto apps that connect users to DeFi loans should face MiCA-style duties. No rule changed yet, but the Commission's consultation shuts on September 30, and the answer could turn every lending tab into a regulated service.
The European Banking Authority isn't proposing a rule. It's asking a question. That question, sent to Brussels on September 24, could decide whether the lending tab inside your crypto wallet counts as a regulated financial service.
Here's what the filing actually says: before MiCA gets updated, the Commission should run a cost-benefit analysis on whether companies connecting customers to DeFi loans deserve their own set of obligations.
Nothing changes today. The EBA's document is a response to a consultation, not an enforcement action, and it carries no legal weight on its own. But it draws a boundary line that Brussels now has to either accept or erase.
The September 30 Clock
The Commission's targeted consultation on the MiCA review closes September 30 at 11:59 p.m. Central European Summer Time. After that, the Commission writes up what it heard, and it says it may attach a legislative proposal to that report if the case is strong enough.
So the industry has days, not months, to shape the record.
The EBA floated two possible changes. The first would add intermediating crypto borrowing and lending to MiCA's list of CASP services, which is the menu of activities a licensed firm is allowed to perform. The second would write specific requirements for CASPs that give clients access to DeFi lending protocols, whether through an interface or through a product that offers exposure to DeFi.
Then there's the third piece, and this one is sharper. The EBA said CASPs could be barred from intermediating or connecting customers to borrowing and lending involving assets that meet MiCA's definition of an asset-referenced or e-money token but have no authorized issuer. That's a restriction aimed at unauthorized stablecoin issuers, routed through the firms that touch them.
Reading between the lines, that's the option with teeth.
The consumer-harm list behind all of this is long. The EBA points to incomplete disclosure of fees, yields, and collateral changes. It flags borrowing that can amplify losses, commingling of assets, outages, hacks, and weak recordkeeping. And it notes the absence of any creditworthiness check, which means over-indebtedness is a live worry in a market with no underwriting.
Six possible safeguards went into the document for Commission analysis. Suitability tests to screen whether a customer should borrow at all. Caps on borrowed positions. Fuller disclosures. Extra warnings that a truly decentralized protocol may offer no regulatory protection. Certification of lending protocols for resilience to cyberattacks. None of these are enacted rules. They're menu items.
Why DeFi lending and not something else? Because the plumbing already exists. MetaMask's own lending guide walks users through depositing stablecoins into Aave pools from mobile. Aave's access guide lists three routes into the protocol: its own interface, other applications, and direct smart contract interaction.
An app can bring the customer. The protocol executes the loan on-chain. The EBA is asking who owns the first half of that sentence.
Who Wins and Who Loses
From a compliance standpoint, the answer is uncomfortable for anyone running a wallet with a yield feature.
Here's the thing. Regulators can't easily reach a smart contract deployed on Ethereum. There's no registered entity to serve, no board to subpoena, no jurisdiction that clearly applies. So they're going after the last identifiable company in the chain. That's pragmatic. It's also a workaround, and everyone involved knows it.
MetaMask is the obvious test case. Its lending feature sits inside a product that millions of people already use, and if the Commission adopts the first option, that feature starts looking like a regulated service that requires suitability checks, disclosures, and probably identity data the wallet doesn't currently collect.
That's the real cost here. Not a ban. A compliance bill.
Winners? Licensed CASPs that already run suitability and disclosure machinery. They get a moat, because a small wallet team in Lisbon can't build the same back office. Losers? Non-custodial apps that built distribution on the promise of no gatekeeping. And arguably the users themselves, who lose a frictionless path to on-chain yield and gain a questionnaire.
The stablecoin piece deserves its own callout. By threatening to restrict CASPs' access to lending involving unauthorized asset-referenced and e-money tokens, the EBA is creating a pressure point that doesn't require naming any issuer. Cut off the distributors, and the issuers lose the market. The precedent here's important, because it's the same playbook the EU has used on other fronts.
What regulators are really signaling: consumer protection language is the wrapper, but market access is the mechanism.
And it's worth asking a blunt question. If a user bypasses the app entirely and calls the Aave contract directly, does any of this reach them? The EBA's response doesn't resolve that, and it can't. The Commission would have to define the activity first, and direct smart contract use remains the open wound in every DeFi rulemaking on earth.
So we'd end up with a two-tier system. A regulated front door with warnings, checks, and paperwork. An unregulated side door that requires you to know what a contract address is. That doesn't protect the retail users the EBA says it's worried about. It just protects the ones who never learned to skip the app.
The Takeaway
The interesting detail isn't the list of safeguards. It's the framing. The EBA chose to define the regulatory surface as the interface, not the protocol, and that choice will outlast this particular consultation.
If the Commission follows through, every crypto app in Europe that offers a lending button becomes a compliance project. If it doesn't, the EBA has still planted the argument for the next review cycle, and the next one after that.
Either way, watch September 30. That's the deadline for comments, and it's the last moment the industry gets to shape the record before Brussels decides whether your wallet is a broker.