Ccryptonary

UK rules · DeFi

“Decentralised” is not a regulatory answer.

Last updated

The UK approach looks at the real activity and the people carrying it on. A DeFi label alone does not decide whether a service is inside or outside the perimeter.

01

Who controls it?

Look for an operator, front-end owner, governance body, fee recipient or person able to change contracts.

02

What activity occurs?

Trading, arranging, custody, lending and other services can have different regulatory treatment.

03

Where is it carried on?

A protocol can be global while an interface, operator or promotion targets UK consumers.

04

What protection exists?

Smart-contract audits, an insurance fund or a DAO vote are not the same as statutory consumer protection.

The regulatory position

Case by case, with more guidance to come.

An identifiable intermediary carrying on a regulated activity may be caught even when smart contracts are involved. A genuinely decentralised protocol presents harder perimeter questions. The FCA has indicated further guidance will follow.

The practical position

Assume less recourse, not less risk.

Code risk, oracle failure, governance capture, bridge exploits, liquidation and stablecoin depegs can stack together. An attractive yield is compensation for risk—not evidence that risk has disappeared.

Regulation and tax are separate

A service being outside a regulatory perimeter does not remove UK tax obligations. Swaps, liquidity-pool transactions, rewards and lending arrangements can create disposals or income depending on the facts.

Read the DeFi tax guide →

Before connecting a wallet

  • • Verify the official domain and contract addresses.
  • • Read admin-key, upgrade and emergency-pause controls.
  • • Check liquidity, oracle and bridge dependencies.
  • • Use a separate wallet and test with a small amount.