Regulation
New EEA Handbook to Address Regulatory Ambiguity in DeFi Laws
The Enterprise Ethereum Alliance (EEA) has launched a comprehensive DeFi Risk Assessment Guidelines handbook, aimed at unravelling the complexities and regulatory uncertainties surrounding decentralized finance (DeFi).
Although the EEA initiative is primarily aimed at fostering innovation in the DeFi sector and addressing concerns about potentially restrictive legislation from global regulators.
The new released guidelines delve into the complexities of DeFi operations, offering detailed insights into how to assess, manage and mitigate various risks. This resource comes at a critical time, with the EEA highlighting a significant gap in consistent accounting standards and regulatory guidance, particularly evident in frameworks such as the EU Regulation of cryptocurrency markets.
“There is still a lot of regulatory uncertainty around the ‘boring’ accounting issues, securities regulation and so on because regulators are still learning about [DeFi] “space,” Charles Nevile, director of technical programs at the EEA, told crypto.news.
These guidelines aim to equip DeFi protocols to proactively engage with compliance requirements and establish industry-backed best practices for risk assessment. They are also designed to help DeFi developers demonstrate due diligence in a landscape where detailed regulatory mandates are scarce. Amid growing pressure from regulators and policymakers threatening with anti-crypto legislation and countermeasures, the EEA guidelines cover a very broad field.
Topics range from governance and tokenomics to software issues, liquidity, and compliance with regulatory and external market factors. They also address specific challenges in software components such as oracles, smart contracts, and bridges, focusing on security and interoperability. For practical application, the guidelines outline best practices for risk management such as user education, bug bounty programs, stress testing, security updates, and data encryption. An extensive glossary of DeFi-related terms is included to help newcomers navigate the complex industry jargon.
In addition to helping developers, the guidelines serve as a framework for regulators and licensing authorities, already influencing licensing requirements at the Abu Dhabi Global Market (ADGM) and being included in use cases in the EU Sandbox programme.
Nevile also emphasized the importance of regulatory involvement in DeFi development. “The best way to do this is for regulators to participate alongside industry members in a multi-stakeholder development approach,” he said.
The guidelines have received support from a diverse group of EEA board members, including crypto industry leaders from Consensys and the Ethereum Foundation, as well as major corporate entities such as JP Morgan, Santander and Microsoft.
The EEA stated that its guidelines will be applicable to both non-crypto companies and regulators. Furthermore, these guidelines are essential for financial institutions assessing investment risks. Dyma Budorin, co-chair of the EEA’s DRAMA working group and CEO of Hacken, emphasized the usefulness of the guidelines for traditional financial institutions wary of entering the DeFi space.
“They don’t know what the risks are in DeFi, and that’s why they don’t get into it,” Dyma Budorin, co-chair of the EEA’s DRAMA working group and CEO of blockchain security firm Hacken, noted in a statement to crypto.news. “DeFi protocols that want to collaborate with old money can use the DeFi risk assessment guidelines as best practice references,” Budorin added.
As mainstream traditional financial firms increasingly embrace DeFi, the relevance of the EEA guidelines is highlighted. In particular, Black rock launched its inaugural tokenized fund on Ethereum this year, marking a significant step into the DeFi space by one of the world’s leading asset managers.
Similarly, financial giants such as JP Morgan, Goldman Sachs, and HSBC are actively exploring DeFi via tokenization, further integrating blockchain technologies into their operations. To keep pace with these advances, the EEA intends to continue its oversight through the Working Group, ensuring that the guidelines evolve in response to new developments and user feedback. This iterative process aims to refine and improve the guidelines to better serve the industry.
A recent security incident occurred on July 16 involving the Arcadia Finance protocol highlights the critical need for robust DeFi risk assessment and implementation of preventative measures. In this breach, hackers targeted a specific contract address, mining over $455,000 in various cryptocurrencies, which were later laundered via Ethereum-based mixing service Tornado Cash. The incident highlighted persistent security vulnerabilities in DeFi protocols, reinforcing the importance of comprehensive risk management strategies as advocated by EEA guidelines.