← Regulations / Hungary / Operating Models / DeFi frontend

DeFi protocol frontend in Hungary

Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.

Conditional AI-Generated · Unreviewed

DeFi frontend is conditionally permitted in Hungary with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • VASP registration with Magyar Nemzeti Bank (MNB) required under Act CXXXVI of 2013 (Pmtv.) if the frontend involves any degree of custody or intermediation (hu.aml.vasp-registration-under-the-transposition)
  • Customer due diligence (KYC) obligations apply under Pmtv. for any VASP-licensed activity (hu.aml.purpose-of-registration-this-registration)
  • Transaction monitoring and suspicious activity reporting (SAR) obligations under Pmtv. (hu.aml.purpose-of-registration-this-registration)
  • Under MiCA (effective 2025+), if the frontend provides 'custody and administration of crypto-assets on behalf of third parties' or other CASP services, full CASP authorization from MNB is required — covering operational, organizational, and prudential requirements beyond AML registration (hu.aml.authorization-as-a-casp-under, hu.aml.scope-this-authorization-is-comprehensive)
  • MiCA Article 67 requires: keep client crypto-assets and funds separate from own assets; maintain records for immediate segregation; return client assets without undue delay (hu.aml.keep-client-crypto-assets-and-funds, hu.aml.maintain-records-and-accounts-that, hu.aml.return-client-crypto-assets-and-funds)

Key Restrictions

  • If the frontend is purely non-custodial (no control over user assets, no private keys held, no fee-taking that triggers intermediary status), there is ambiguity — Hungarian law defines VASPs primarily around custodial wallet providers, so a purely frontend/interface may fall outside VASP registration, but this is uncertain (hu.aml.vasp-registration-under-the-transposition)
  • If the frontend takes fees (e.g., swap fees, frontend fees), it may be classified as providing a crypto-asset service requiring CASP authorization under MiCA (hu.aml.authorization-as-a-casp-under)
  • MNB has issued warnings against unlicensed foreign entities offering crypto services to Hungarian residents and can prohibit services targeting Hungary (hu.enforcement.issuing-warnings-against-unlicensed-service, hu.enforcement.mnb-warnings-the-mnb-often)
  • Local entity likely required for MNB VASP registration or MiCA CASP authorization (no passport for non-EU entities without local establishment)

Key Risks

  • Regulatory ambiguity: Hungarian law currently defines VASPs around custodial wallet providers — a purely non-custodial, non-fee-taking frontend may not be a regulated VASP, but MNB has broad discretion to interpret the law broadly (hu.aml.vasp-registration-under-the-transposition)
  • MiCA transition risk: from 2025, any frontend that intermediates access to DeFi protocols may be captured under CASP definitions, requiring full authorization (hu.aml.authorization-as-a-casp-under)
  • Enforcement risk: MNB has prohibited foreign crypto service providers from targeting Hungarian residents and filed criminal complaints — the Xifra Lifestyle case shows active enforcement against unlicensed operators (hu.enforcement.entity-targeted-xifra-lifestyle-also, hu.enforcement.outcome-the-mnb-prohibited-xifra)
  • Tax risk: NAV (tax authority) actively enforces tax rules on crypto transactions, and a frontend operator may face tax reporting obligations (hu.enforcement.tax-authority-nav-the-national)
  • No safe harbor for fully decentralized protocols — MNB treats the operator/legal entity behind the frontend as responsible

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

aml 60% confidence

VASP Registration: Under the transposition of the EU's 5th and 6th Anti-Money Laundering Directives (AMLD5/AMLD6), custodial wallet providers are classified as Virtual Asset Service Providers (VASPs).

aml 60% confidence

Obligation: VASPs, including those offering custodial services, are required to register with, or be licensed by, the Hungarian Financial Supervisory Authority (primarily the Magyar Nemzeti Bank - MNB, the Central Bank of Hungary, which oversees financial market supervision) for AML/CTF purposes.

aml 60% confidence

Purpose of Registration: This registration primarily obliges the entity to comply with AML/CTF requirements, such as customer due diligence (KYC), transaction monitoring, and suspicious activity reporting, rather than specific operational custody rules.

aml 60% confidence

Act CXXXVI of 2013 on the prevention and combating of money laundering and terrorist financing (Pmtv.) – This is Hungary's primary AML law, amended to include virtual asset service providers.

aml 60% confidence

Authorization as a CASP: Under MiCA, any entity providing "custody and administration of crypto-assets on behalf of third parties" will be classified as a Crypto-Asset Service Provider (CASP) and will require prior authorization by a national competent authority (in Hungary, this will be the MNB).

aml 60% confidence

Scope: This authorization is comprehensive and covers specific operational, organizational, and prudential requirements, going far beyond mere AML registration.

aml 60% confidence

Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets, and amending Regulations (EU) No 1093/2010 and (EU) No 1095/2010 and Directives 2013/36/EU and (EU) 2019/1937 (MiCA).

aml 60% confidence

Keep client crypto-assets and funds separate from their own crypto-assets and funds.

aml 60% confidence

Maintain records and accounts that allow for the immediate segregation of client crypto-assets and funds from own assets and from those of other clients.

aml 60% confidence

Return client crypto-assets and funds without undue delay upon their request.

enforcement 60% confidence

Entity Targeted: Xifra Lifestyle (also known as Xifra Global, Xifra LLC). Violation Type: Unlicensed financial service provision (offering investment services related to cryptocurrency trading without the necessary MNB authorization) and operating a scheme with characteristics of a pyramid scheme. Penalty Amount: The MNB issued a public warning and a cease-and-desist order. While no specific administrative fine amount was publicly disclosed by the MNB in its initial announcement, the action effectively prohibited the entity from operating in Hungary and referred the case to law enforcement for potential criminal proceedings.

enforcement 60% confidence

Outcome: The MNB prohibited Xifra Lifestyle from offering its services to Hungarian residents. The MNB also filed a criminal complaint against the unknown perpetrators. The platform subsequently largely ceased operations in Hungary.

enforcement 60% confidence

MNB Warnings: The MNB often issues general warnings to consumers about the risks of crypto, or specific warnings about unlicensed foreign entities, without a formal "fine" or "penalty amount" attached, but these are crucial in protecting consumers and maintaining market integrity.

enforcement 60% confidence

Tax Authority (NAV): The National Tax and Customs Administration (NAV) enforces tax laws on crypto income and transactions, but these are typically individual or corporate audits and assessments rather than publicly announced "enforcement actions" against specific crypto platforms with a universal "penalty."

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — A DeFi frontend operating in/into Hungary with any custody or fee-taking activity is likely a regulated VASP/CASP requiring MNB registration or authorization; a purely non-custodial interface without fees occupies a legal grey area but faces enforcement risk from the MNB.

Questions this verdict aims to answer

  • Is operating the frontend a regulated activity even if the protocol is decentralized?
  • What geofencing or KYC obligations apply?
  • Does fee-taking change classification?