DeFi protocol frontend in Vietnam
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Vietnam with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000 — verifying customer identities
- Must retain data on Vietnam servers for 10 years, including transaction history, wallet addresses, IP/device logs, and account info
- Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection
- Must achieve Level 4 cybersecurity (highest standard) including encryption, intrusion detection, and continuous monitoring to support CDD
- VASPs must apply AML/CTF obligations as part of licensing, including internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance
- Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT
- No explicit STR filing mechanism detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations
Key Restrictions
- Operating a DeFi frontend that screens users or intermediates transactions likely qualifies as a VASP under the 2025 framework and requires a license
- Foreign investors require a single VND account at a licensed local bank; all transactions use VND
- Pilot program (five-year duration) began in 2025 — prior to 2026, VASPs were not explicitly regulated; now full VASP licensing applies
- Systems must achieve Level 4 cybersecurity (highest standard) — likely cost-prohibitive for small frontend operators
- Proactive adoption of FATF VASP standards is recommended for compliance transition
Key Risks
- Regulatory ambiguity around whether a non-custodial, fee-taking DeFi frontend constitutes a VASP under the framework — unclear if purely non-custodial interfaces are captured
- Enforcement precedent: ONUS platform prosecuted for fraud and money laundering (2026), signaling aggressive enforcement posture toward crypto intermediaries
- High licensing burden (Level 4 cybersecurity, 10-year data retention in Vietnam, qualified personnel) may be prohibitive for smaller/foreign DeFi frontend operators
- No explicit STR filing mechanism detailed yet — operational uncertainty on reporting pathways
- Foreign operators face mandatory local bank account and VND-only transaction requirements, complicating cross-border DeFi operations
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Ministry of Finance (MOF) — Lead authority
State Securities Commission (SSC) — Licensing review and compliance monitoring
State Bank of Vietnam (SBV) — Financial oversight
Ministry of Public Security (MPS) — Cybersecurity and financial integrity
The framework mandates VASPs to apply AML/CTF obligations as part of licensing, treating crypto exchanges as market infrastructure akin to securities exchanges. This includes internal policies for AML/CFT, counter-proliferation financing, risk management, and market surveillance.
Oversight involves MOF (lead), SSC (receiving applications), SBV (financial integrity), and MPS (AML, cybersecurity).
VASPs must conduct updated KYC for transactions equivalent to at least USD 1,000, verifying customer identities to mitigate fraud, money laundering, and terrorist financing.
Licensing demands detailed internal procedures for KYC, integrated into IT systems with audit trails, alongside personnel qualified in finance and IT.
Foreign investors require a single VND account at a licensed local bank; all transactions use VND.
Systems must achieve Level 4 cybersecurity (highest standard), including encryption, intrusion detection, and continuous monitoring to support CDD.
Proactive adoption of FATF VASP standards is recommended for compliance transition.
VASPs must retain data on Vietnam servers for 10 years, including transaction history, originator/beneficiary details (e.g., wallet addresses), IP/device logs, and account info.
Platforms require programmed AML/KYC processes with anti-tampering logs, secure key management, and transaction monitoring for STR detection.
No explicit STR filing mechanism is detailed in pilot docs, but AML/CTF policies imply reporting via MPS/SBV coordination during licensing appraisals and operations.
Custody and client protection rules reinforce STR through risk controls and complaint handling.
Prior to 2026, VASPs were not explicitly regulated under AML laws, but the pilot program (five-year duration) now enforces compliance to prevent illicit flows.
Key reference: Resolution No. 05/2025/NQ-CP (September 9, 2025) establishes the licensing regime with AML/CTF as a core objective; Decision No. 96/QD-BTC details procedures, including AML appraisals.
Regulator: Ministry of Public Security (MoPS).
Entity Targeted: ONUS cryptocurrency platform (including tokens VNDC, ONUS, and HNG), operated by Vương Lê Vĩnh Nhân (Eric Lê/Vuong Le Vinh Nhan) and associates. Violation Type: Fraud via token price manipulation, deceptive marketing, misleading promotions, artificial trading to control supply/demand, property appropriation, and money laundering using platform infrastructure. Penalty Amount: Not yet finalized; investigation targets billions of dollars in mobilized funds and investor losses (preliminary estimates in billions of USD).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- low
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend that intermediates transactions or collects fees likely qualifies as a VASP under Vietnam's 2025 licensing pilot, requiring a high-burden license with full KYC/AML, Level-4 cybersecurity, 10-year local data retention, and a local entity, though ambiguity remains about whether purely non-custodial interfaces without fee-taking fall within scope.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?