Unchained
Unchained

2 Lawyers on How the U.S. Can Finally Regulate DeFi - Ep. 604

Listen to the episode on Apple Podcasts, Spotify, Fountain, Overcast, Podcast Addict, Pocket Casts, Pandora, Google Podcasts, Amazon Music, or on your favorite podcast platform. Trying to regulate DeFi is a huge challenge because in a truly decentralized system, there should be no centralized actors

Featured Speakers

Michael Mosier GuestRebecca Reddick Guest

Topics Discussed

Episode Summary

Executive Summary: Rebecca Reddick and Michael Mosier outline a new DeFi regulation framework that preserves base-layer neutrality while targeting real control points. They argue the BSA should apply only to systems with true independent control, genuine DeFi should be treated as critical infrastructure, and RPC nodes-as-a-service (critical communications transmitters) offer a practical choke point to combat illicit finance without turning software or validators into banks.

Main Topics: Why DeFi needs a different regulatory approach (Priority: 5/5): The guests explain that traditional AML/BSA rules were built for intermediaries with custody and siloed records, while DeFi is transparent, peer-to-peer, and often intermediaryless. That makes old compliance models a poor fit. Independent control as the threshold for regulation (Priority: 5/5): They propose a legal test focused on whether a person or entity has total, unilateral, and immediate control over another party’s value in the system. Mere influence, security overrides, or limited multisig authority should not automatically make someone a financial institution. Genuine DeFi as critical infrastructure (Priority: 5/5): Autonomous protocols with no true controller—such as the protocol layer of Uniswap or Tornado Cash—should be treated like critical infrastructure rather than financial institutions, with an emphasis on resilience, cyber defense, and information sharing. Three DeFi illicit-finance risk vectors (Priority: 4/5): They distinguish cyber risk, system-management risk, and usage risk. This framing shifts attention from TradFi-style customer data collection to vulnerabilities in code, admin control, and downstream misuse of blockchain rails. CCTs: regulating RPC nodes as a service (Priority: 5/5): The paper proposes 'critical communications transmitters' for RPC nodes-as-a-service, since most blockchain communications flow through them. These providers transmit communications, not value, and could be used as an effective anti-illicit-finance gateway. Crypto ISAC model and information sharing (Priority: 4/5): Borrowing from CISA and FS-ISAC, the authors advocate a voluntary, collaborative ecosystem where threats, typologies, and alerts are shared rapidly among developers, infrastructure providers, and government agencies. Tornado Cash and sanctions collateral damage (Priority: 4/5): They argue Tornado Cash’s protocol is genuine DeFi, but systems around it may still be regulated if they show independent control. They caution against heavy sanctions tools where innocent users are heavily impacted.

Key Arguments: The BSA was designed for intermediaries and record-silo problems; DeFi’s public ledgers and lack of custodial chokepoints mean the same framework cannot be mapped one-to-one. The right regulatory test is not 'who controls software' but who has total, unilateral, immediate control over a third party’s value. Multisig signers, DAO token holders, and governance participants can influence systems without qualifying as banks or financial institutions because they usually lack immediate, direct value control. Genuine DeFi should be treated like critical infrastructure: the priority should be resilience, cyber standards, audits, and threat sharing rather than KYC-heavy obligations. RPC nodes-as-a-service are a realistic enforcement lever because a large share of blockchain communication passes through them, letting regulators and providers stop high-risk activity before finality. Regulation should avoid capturing software, front ends, validators, or the base layer; the goal is to preserve neutrality and permissionlessness while addressing practical illicit-finance risks. A crypto ISAC could mirror the FS-ISAC/CISA model, enabling voluntary, rapid intelligence-sharing instead of coercive reporting or registration regimes. Tornado Cash’s autonomous protocol should not be treated as if it were a financial intermediary, though surrounding services or control layers may still create regulatory exposure. Sanctions are a blunt tool with significant collateral damage; AML/illicit-finance policy should aim for narrower, more proportionate interventions.

Data Points: DeFi developer ecosystem: over 2,000 developers - Used in the sponsor read describing Polkadot, not the speakers' analysis Transaction routing through RPC nodes: 80% - Used to argue RPC nodes-as-a-service are a meaningful gateway for financial integrity controls CISA critical infrastructure sectors: 16 - Used to explain the critical infrastructure framework the authors want to analogize for DeFi FS-ISAC membership: 4,600 members - Used as an example of a private-sector information-sharing network supporting financial resilience Tornado Cash user activity without illicit links: at least 70% - Cited to argue sanctions had major collateral impact on innocent users HSBC cartel flow example: $880 million - Referenced as an example of large-scale illicit money movement and the need for proportionate response GameFi transaction example: 43 million transactions - Used in sponsor read about Mythical Games on Polkadot Mythical Games player base: 650,000 players - Used in sponsor read about Polkadot ecosystem adoption Episode date: February 6, 2024 - Podcast metadata in the intro

Pivotal Quotes: "the base layer needs to remain critically neutral and permissionless" — Rebecca Reddick / Michael Mosier: Core design principle underpinning their proposed regulatory framework "you need total independent control in the sense that you can sort of deny that transaction indefinitely from happening" — Michael Mosier: Defines the threshold for when control should trigger BSA-style treatment "there's nobody here to do anything" — Rebecca Reddick: Describes the common regulatory problem when authorities look for a responsible party in genuinely decentralized systems

Implications: The proposal could redirect crypto policy away from blanket KYC on software and toward infrastructure-based, risk-based controls. If adopted, it would likely shape future DeFi bills, agency guidance, and industry standards around neutrality, cyber resilience, and targeted enforcement.

🔓 Sign Up for Unlimited Episode Search

About Unchained

View all episodes from Unchained