DeFi protocol frontend in Hungary
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Hungary with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASP registration with Magyar Nemzeti Bank (MNB) required under Act CXXXVI of 2013 (Pmtv.) if the frontend involves any degree of custody or intermediation (hu.aml.vasp-registration-under-the-transposition)
- Customer due diligence (KYC) obligations apply under Pmtv. for any VASP-licensed activity (hu.aml.purpose-of-registration-this-registration)
- Transaction monitoring and suspicious activity reporting (SAR) obligations under Pmtv. (hu.aml.purpose-of-registration-this-registration)
- Under MiCA (effective 2025+), if the frontend provides 'custody and administration of crypto-assets on behalf of third parties' or other CASP services, full CASP authorization from MNB is required — covering operational, organizational, and prudential requirements beyond AML registration (hu.aml.authorization-as-a-casp-under, hu.aml.scope-this-authorization-is-comprehensive)
- MiCA Article 67 requires: keep client crypto-assets and funds separate from own assets; maintain records for immediate segregation; return client assets without undue delay (hu.aml.keep-client-crypto-assets-and-funds, hu.aml.maintain-records-and-accounts-that, hu.aml.return-client-crypto-assets-and-funds)
Key Restrictions
- If the frontend is purely non-custodial (no control over user assets, no private keys held, no fee-taking that triggers intermediary status), there is ambiguity — Hungarian law defines VASPs primarily around custodial wallet providers, so a purely frontend/interface may fall outside VASP registration, but this is uncertain (hu.aml.vasp-registration-under-the-transposition)
- If the frontend takes fees (e.g., swap fees, frontend fees), it may be classified as providing a crypto-asset service requiring CASP authorization under MiCA (hu.aml.authorization-as-a-casp-under)
- MNB has issued warnings against unlicensed foreign entities offering crypto services to Hungarian residents and can prohibit services targeting Hungary (hu.enforcement.issuing-warnings-against-unlicensed-service, hu.enforcement.mnb-warnings-the-mnb-often)
- Local entity likely required for MNB VASP registration or MiCA CASP authorization (no passport for non-EU entities without local establishment)
Key Risks
- Regulatory ambiguity: Hungarian law currently defines VASPs around custodial wallet providers — a purely non-custodial, non-fee-taking frontend may not be a regulated VASP, but MNB has broad discretion to interpret the law broadly (hu.aml.vasp-registration-under-the-transposition)
- MiCA transition risk: from 2025, any frontend that intermediates access to DeFi protocols may be captured under CASP definitions, requiring full authorization (hu.aml.authorization-as-a-casp-under)
- Enforcement risk: MNB has prohibited foreign crypto service providers from targeting Hungarian residents and filed criminal complaints — the Xifra Lifestyle case shows active enforcement against unlicensed operators (hu.enforcement.entity-targeted-xifra-lifestyle-also, hu.enforcement.outcome-the-mnb-prohibited-xifra)
- Tax risk: NAV (tax authority) actively enforces tax rules on crypto transactions, and a frontend operator may face tax reporting obligations (hu.enforcement.tax-authority-nav-the-national)
- No safe harbor for fully decentralized protocols — MNB treats the operator/legal entity behind the frontend as responsible
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
VASP Registration: Under the transposition of the EU's 5th and 6th Anti-Money Laundering Directives (AMLD5/AMLD6), custodial wallet providers are classified as Virtual Asset Service Providers (VASPs).
Obligation: VASPs, including those offering custodial services, are required to register with, or be licensed by, the Hungarian Financial Supervisory Authority (primarily the Magyar Nemzeti Bank - MNB, the Central Bank of Hungary, which oversees financial market supervision) for AML/CTF purposes.
Purpose of Registration: This registration primarily obliges the entity to comply with AML/CTF requirements, such as customer due diligence (KYC), transaction monitoring, and suspicious activity reporting, rather than specific operational custody rules.
Act CXXXVI of 2013 on the prevention and combating of money laundering and terrorist financing (Pmtv.) – This is Hungary's primary AML law, amended to include virtual asset service providers.
Authorization as a CASP: Under MiCA, any entity providing "custody and administration of crypto-assets on behalf of third parties" will be classified as a Crypto-Asset Service Provider (CASP) and will require prior authorization by a national competent authority (in Hungary, this will be the MNB).
Scope: This authorization is comprehensive and covers specific operational, organizational, and prudential requirements, going far beyond mere AML registration.
Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (MiCA).
Keep client crypto-assets and funds separate from their own crypto-assets and funds.
Maintain records and accounts that allow for the immediate segregation of client crypto-assets and funds from own assets and from those of other clients.
Return client crypto-assets and funds without undue delay upon their request.
Issuing warnings against unlicensed service providers (often foreign entities).
Providing guidance and requiring registration for Virtual Asset Service Providers (VASPs) under AML rules.
Entity Targeted: Xifra Lifestyle (also known as Xifra Global, Xifra LLC). Violation Type: Unlicensed financial service provision (offering investment services related to cryptocurrency trading without the necessary MNB authorization) and operating a scheme with characteristics of a pyramid scheme. Penalty Amount: The MNB issued a public warning and a cease-and-desist order. While no specific administrative fine amount was publicly disclosed by the MNB in its initial announcement, the action effectively prohibited the entity from operating in Hungary and referred the case to law enforcement for potential criminal proceedings.
Outcome: The MNB prohibited Xifra Lifestyle from offering its services to Hungarian residents. The MNB also filed a criminal complaint against the unknown perpetrators. The platform subsequently largely ceased operations in Hungary.
MNB Warnings: The MNB often issues general warnings to consumers about the risks of crypto, or specific warnings about unlicensed foreign entities, without a formal "fine" or "penalty amount" attached, but these are crucial in protecting consumers and maintaining market integrity.
Tax Authority (NAV): The National Tax and Customs Administration (NAV) enforces tax laws on crypto income and transactions, but these are typically individual or corporate audits and assessments rather than publicly announced "enforcement actions" against specific crypto platforms with a universal "penalty."
Regulator Name: Magyar Nemzeti Bank (MNB - Hungarian National Bank)
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — A DeFi frontend operating in/into Hungary with any custody or fee-taking activity is likely a regulated VASP/CASP requiring MNB registration or authorization; a purely non-custodial interface without fees occupies a legal grey area but faces enforcement risk from the MNB.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?