The Malta Financial Services Authority’s recent consultation on Decentralised Finance comes at a time when the digital assets market is becoming more serious, more regulated and more connected to traditional finance. Crypto is no longer only a space for early adopters. It is now part of a wider discussion around the Markets in Crypto-Assets Regulation, stablecoins, tokenisation, custody, market integrity and institutional participation.
For Malta, this is an important moment. Malta was one of the first European jurisdictions to build a legal framework for virtual financial assets. With the Markets in Crypto-Assets Regulation (“MiCA”), now shaping the crypto market across the European Union, the focus has moved from whether digital assets should be regulated to how regulation can support innovation while protecting users and the wider market.
Understanding DeFi
Decentralised finance, or DeFi, can be understood as a digital version of many services already found in traditional finance. In the traditional market, people use banks, brokers, exchanges or fund managers to lend, borrow, trade, earn yield or hold assets. In DeFi, similar activities can take place through blockchain-based programs called smart contracts, often without a traditional intermediary standing in the middle.
The function is familiar, but the structure is different. A lending protocol may look similar to a bank loan, a decentralised exchange may look similar to a trading platform, and a liquidity pool may perform a role similar to market-making. The difference is that DeFi relies on code, digital wallets and blockchain networks instead of branches, brokers, clearing systems and centralised institutions.
That is what makes DeFi attractive. It can make financial activity faster, more open and more transparent. But it also creates a real legal problem.
The Regulatory Challenge
Most financial regulation is built around identifiable people and institutions. A bank has a licence. An investment firm has directors. A fund manager has duties. A payment institution has compliance obligations. There is usually a company, a registered office and someone a regulator can contact.
DeFi does not always work like that. A protocol may be governed by token holders. Developers may be based in different countries. Liquidity may come from anonymous digital wallets. A website may be operated by one group, while the smart contracts are controlled or upgraded by another.
This creates a simple but difficult question. If something goes wrong, who is responsible?
The collapse of TerraUSD and Luna in 2022 helps explain the issue. TerraUSD was not a pure DeFi protocol by itself. It was an algorithmic stablecoin, meaning a crypto-asset designed to keep a stable value through code and market incentives rather than traditional reserves. However, it became closely connected to DeFi through Anchor Protocol, where users placed TerraUSD for high advertised yields. When confidence in TerraUSD failed, the impact spread across the wider crypto market.
The lesson is that stablecoins, lending products and yield platforms can become deeply connected. If users rely on a token as stable, and that token is then used across DeFi products, a failure can move quickly through the ecosystem.
Market Conduct and Data Risk
Mango Markets shows the issue from another angle. Mango was a decentralised trading platform, but United States authorities still treated conduct on the platform as market manipulation and fraud. The case involved alleged manipulation of token prices and the extraction of more than 100 million dollars from the protocol.
This matters because DeFi does not remove familiar financial risks. Market manipulation can still happen. Artificial pricing can still harm users. A smart contract may operate exactly as coded, but the result can still be unfair or damaging.
It also shows why data matters in DeFi. Many protocols rely on external information, such as asset prices or collateral values. If that information is wrong or manipulated, the whole system can be affected. In traditional finance, market data and trading infrastructure are closely monitored because errors can have serious consequences. DeFi faces the same issue, only in a different technical form.
MiCA and the Question of Responsibility
This is where MiCA becomes important. MiCA is not a rejection of crypto. It is an attempt to bring clearer rules to a market that has already shown risks around stablecoins, disclosures, custody, governance, market abuse, anti-money laundering controls and operational resilience.
At the same time, MiCA does not answer every DeFi question. Fully decentralised services without an intermediary may fall outside its scope. That leaves a practical issue for businesses and regulators. When is a project genuinely decentralised, and when are there still people controlling, promoting or benefiting from it?
The answer should depend on substance, not labels. A project should not be able to avoid regulation simply by calling itself decentralised. The real analysis should look at who controls the protocol, who can change the code, who earns revenue, who operates the user interface and whether users are relying on identifiable persons.
Institutional Interest in DeFi Infrastructure
DeFi should not be viewed only through failures. The technology behind it is increasingly being tested by serious financial institutions.
Singapore’s Project Guardian is a useful example. Institutions such as DBS Bank, J.P. Morgan and SBI Digital Asset Holdings tested tokenised assets and DeFi-style infrastructure for foreign exchange and government bond transactions. The point is not that these institutions entered open, unregulated DeFi. They did not. The point is that they are studying whether parts of DeFi, such as tokenisation, automated settlement and smart contract execution, can improve traditional financial markets.
This shows where the market may be heading. Banks and asset managers are not simply adopting open DeFi as it exists today. They are testing the useful parts of blockchain finance within more controlled and regulated environments.
That makes the legal questions more important, not less. If DeFi-style infrastructure begins to connect with banks, funds, custodians and payment systems, then questions around responsibility, custody, data accuracy, anti-money laundering compliance, governance and operational resilience become central.
Malta’s Opportunity
For Malta, this creates an opportunity. Malta already has experience in the virtual financial assets sector. MiCA now gives the European Union a more harmonised framework. Together, they can help Malta support digital asset businesses that want to innovate within a credible and properly regulated environment.
The answer is not to stop innovation. The answer is to make it safer, clearer and more accountable.
At Zerafa, we see this as part of the natural evolution of financial services. Decentralised finance, tokenisation, stablecoins and digital asset infrastructure will continue to develop. The role of legal advisers is to help businesses understand where innovation meets regulation, where risk becomes responsibility and how projects can be structured in a way that is credible, transparent and legally sound.
The future of crypto in Malta and the European Union will not be defined by decentralisation alone. It will be defined by whether decentralised systems can become trustworthy, resilient and ready for a mature financial market.
