DeFi protocol frontend in Liechtenstein
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Liechtenstein with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- Customer identification and verification (official ID documents, name, DOB, nationality, address) for natural persons under the Due Diligence Act (SPG/SPV)
- For legal entities: obtain entity name, legal form, registered address, registration number, articles of association, and identify/verify Ultimate Beneficial Owners (UBOs)
- Proof of address (e.g. utility bill, bank statement) required
- Screening of customers and UBOs against UN, EU, and OFAC sanction lists and PEP lists
- Understanding the purpose and intended nature of the business relationship (transaction volume, type, source of funds/wealth)
- Continuous monitoring of business relationships and transactions for consistency with customer risk profile
- Source of Funds (SoF) and Source of Wealth (SoW) assessment for higher-risk relationships or significant transactions
- If the frontend takes custody, holds private keys, or facilitates transfers on behalf of users, additional obligations under TVTG (Token and TT Service Provider Act) apply, including AML/CFT compliance as a regulated TT Service Provider
- Supervision by the Financial Market Authority (FMA) Liechtenstein
Key Restrictions
- If the frontend takes fees and/or provides active intermediation (e.g., order routing, swap execution on behalf of users), it likely qualifies as a regulated VT Service Provider under TVTG and requires FMA registration
- If the frontend holds or accesses user private keys or custody of tokens, it qualifies as a TT Custodian / Key Depository under TVTG requiring FMA authorization and minimum capital of CHF 100,000
- If the frontend merely provides a non-custodial informational interface to permissionless smart contracts without taking fees or exercising control over user transactions, regulatory treatment is ambiguous — the FMA has not issued specific guidance on pure frontend interfaces
- Geofencing/KYC: obligations are risk-based; if classified as a regulated VT Service Provider, KYC/AML on all customers is mandatory — unrestricted access (no screening) would be non-compliant
- Fee-taking (e.g., swap fees, routing fees) likely triggers classification as a VT Exchange Service Provider or VT Transfer Service Provider under TVTG
Key Risks
- Regulatory ambiguity: the FMA has not issued explicit guidance on whether a non-custodial, fee-taking DeFi frontend that never holds keys or custody is a regulated VT Service Provider — leading to classification risk
- Enforcement risk: FMA actively issues public warnings against unauthorized operators and has tools to issue cease-and-desist orders and impose supervisory measures (li.licensing.issuing-public-warnings-against-unauthorized, li.licensing.imposing-supervisory-measures-leading-to, li.licensing.issuing-cease-and-desist-orders)
- MiCA alignment: Liechtenstein must align with MiCA from December 30, 2024, which may expand/redefine the scope of regulated crypto-asset services, potentially capturing more frontend activities
- If operating without a license when the FMA determines an activity is regulated, exposure to orders demanding cessation of operations in Liechtenstein (li.enforcement.outcome-public-notification-of-unauthorized)
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Definition under TVTG: A "VT Exchange Service Provider" is a person who facilitates the exchange of VT Tokens against fiat currencies or other VT Tokens. This covers traditional cryptocurrency exchanges.
Requirement: Registration with the FMA as a VT Exchange Service Provider is mandatory.
VT Key Depository: A person who holds private keys for clients or is responsible for their storage.
VT Protector: A person who holds VT Tokens in its own name for the account of a third party (client).
VT Payment Service Provider: The TVTG explicitly defines a "VT Payment Service Provider" as a person who provides payment services involving VT tokens or virtual currencies.
VT Transfer Service Provider: A person who facilitates the transfer of VT Tokens on behalf of a third party. This can also encompass aspects of payment processing.
Due Diligence Act (DDA) (Sorgfaltspflichtgesetz):
Law on Professional Due Diligence for the Prevention of Money Laundering, Organised Crime and Terrorist Financing (Due Diligence Act, Sorgfaltspflichtgesetz - SPG): This is the overarching AML/CFT law that sets out the due diligence obligations for all financial intermediaries, including VASPs.
Identification and Verification of the Customer and UBO:
Screening: Customers and their UBOs must be screened against national and international sanction lists (e.g., UN, EU, OFAC) and politically exposed persons (PEP) lists.
Understanding the Purpose and Intended Nature of the Business Relationship:
Source of Funds (SoF) / Source of Wealth (SoW):
VASPs must continuously monitor the business relationship, including transactions, to ensure that the activities are consistent with their knowledge of the customer, their business, and risk profile.
Exchanges: Provide services for the exchange of virtual assets against fiat currency or other virtual assets.
Transfer Service Providers: Perform virtual asset transfers.
Definition of TT Custodian: According to Art. 4 para. 1 lit. e TVTG, a TT Custodian is "a service provider who holds tokens in custody for third parties and provides services for the safeguarding of private keys or other means of access to tokens."
Licensing Process: Any entity wishing to act as a TT Custodian must obtain prior authorization from the FMA. The requirements for obtaining a license as a TT Service Provider are outlined in Articles 12-17 of the TVTG and include:
Minimum Capital Requirements: As per Art. 17 TVTG, TT Service Providers, including TT Custodians, must have a minimum capital of CHF 100,000. The FMA may require higher capital based on the scope and risk of the services provided.
Entity Targeted: Various companies identified for unauthorized operation, often involving crypto/token offerings. (Specific company names are usually listed on the FMA's warning page, which is regularly updated). Violation Type: Operating financial services or token services without the necessary license under the TVTG or other relevant financial market laws, often coupled with allegations of scams or misleading information. Penalty Amount: Not a direct monetary fine imposed by the FMA in this context, but rather a public warning and expectation of cessation of activity. Failure to comply can lead to further legal action. Outcome: Public notification of unauthorized activity, demand for cessation of operations in Liechtenstein, consumer protection.
Outcome: Public notification of unauthorized activity, demand for cessation of operations in Liechtenstein, consumer protection.
Issuing public warnings against unauthorized entities.
Issuing cease-and-desist orders.
MiCA Implementation: MiCA is a comprehensive EU regulation for crypto-assets that will become fully applicable in phases, with most provisions for crypto-asset service providers (CASPs) applying from December 30, 2024.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi frontend serving Liechtenstein users is likely regulated as a VT Service Provider under the TVTG if it takes fees or exercises active intermediation, requiring FMA registration, KYC/AML compliance, and potentially CHF 100,000 minimum capital if it touches custody/keys; pure informational interfaces without fee-taking face classification ambiguity as the FMA has not issued specific guidance on non-custodial frontends.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?