Compliance is not a betrayal of original intentions, but an inevitable path for Web3 projects to enter the mainstream.

Introduction

"As long as the code is sufficiently decentralized, there is no legal entity, and regulators have no basis for enforcement." This was once considered a safe haven by many founders of on-chain lending protocols. They attempted to establish an "algorithmic bank" with no CEO and no headquarters.

However, with the imposition of penalties in the U.S. Ooki DAO case, this cloak of "de-entityization" is being pierced layer by layer by regulators. Under stricter "look-through regulation" logic, how far can on-chain lending truly go?

 

On-Chain Lending: The Autonomous Bank of Web3

On-chain lending can be understood as an automatically operated lending machine with no human operators, featuring the following main functions:

  • Automated Liquidity Pools: Lenders deposit funds into a public pool managed by code and immediately begin earning interest.
  • Over-Collateralization: Borrowers must collateralize assets exceeding the loan amount to manage risk.
  • Algorithmic Interest Rates: Interest rates are automatically adjusted by algorithms based on supply and demand dynamics, ensuring full market orientation.

This model eliminates the intermediary role of traditional banks, enabling a 24/7 global automated lending market. It requires no manual review, as all processes are automatically executed by code, significantly improving capital efficiency, unlocking asset liquidity, and providing a native source of leverage for the crypto asset market.

 

An Ambitious Ideal: Why Founders Pursue "De-Entityization"

In traditional finance, banks and lending platforms have clear corporate entities, making it evident whom to hold accountable when issues arise. In contrast, on-chain lending is designed to erase the question of "who." It pursues not mere anonymity, but a specific system architecture, primarily reflected in two aspects:

1. The Counterparty Is Code, Not a Person

You no longer enter into contracts with any company or individual; instead, you interact directly with a public, self-executing smart contract. All lending rules, such as interest rates and collateralization ratios, are hard-coded. Your counterparty is this program.

2. Decisions Are Made by the Community, Not by Management

The protocol has no board of directors or CEO. Major upgrades or parameter adjustments are determined by governance token holders distributed globally through voting. Power is decentralized, thereby rendering the attribution of responsibility ambiguous.

For entrepreneurs,opting for “de-entityization” is not only driven by ideology but also constitutes a pragmatic survival strategy, with the core objective being defensive:

  • Regulatory Defense:Traditional lending requires costly financial licenses and strict compliance. By positioning themselves as “technology developers” rather than “financial institutions,” projects aim to circumvent these barriers.
  • Liability Defense:When events such as hacker attacks cause user losses, the team may assert that “the code is open-source and the protocol is non-custodial,” seeking to avoid bearing liability for compensation as traditional platforms would.
  • Jurisdictional Defense:The absence of a physical entity and the global distribution of servers make it difficult for any single country to shut it down easily. This "unclosable" characteristic serves as its ultimate defense against geopolitical risks.

 

The reality is stark: Why does the notion that "code is innocent" fail to hold up?

I. Regulatory Risks:

Regulators' vigilance toward on-chain lending stems from three core risks that cannot be overlooked:

1. Shadow Banking:

On-chain lending essentially creates credit while operating entirely outside the central bank and financial regulatory frameworks, constituting typical shadow banking activities. In the event of a large-scale price decline triggering cascading liquidations, it could give rise to systemic risks and impact the entire financial system.

2. Unregistered Securities:

When users deposit assets into liquidity pools to earn interest, regulators such as the U.S. Securities and Exchange Commission (SEC) view this conduct as akin to issuing unregistered "securities" to the public. As long as returns are promised and provided, securities laws may be violated regardless of how decentralized the technology is.

3. Money Laundering Risks:

Liquidity pool models are easily exploited by hackers: they deposit stolen illicit funds as collateral and borrow out clean stablecoins, thereby breaking the traceability of the fund flow and facilitating money laundering with ease, which poses a direct threat to financial security.

Regulatory Principle: Substance Over Form

  • Functional Regulation: Regulators are not concerned with whether you are a company or code; they focus solely on whether you are substantively engaging in banking activities such as taking deposits and making loans. As long as you are conducting financial business, you are subject to financial regulation.
  • Piercing enforcement: Where no clear legal entity can be held accountable, regulators will directly trace liability to the underlying developers and core governance token holders. The Ooki DAO case serves as precedent, in which members who participated in governance voting were also held liable.

In simple terms, "de-entityization" merely makes a system appear to be "driverless." However, if it poses risks to financial stability or harms investors, the regulatory "traffic police" will inevitably issue penalties and seek to identify the "vehicle owners" hidden behind the scenes.

II. Common Misconceptions:

Many entrepreneurs attempt to evade regulation through the following methods, but these defenses have proven to be highly fragile. The following four points represent common misconceptions:

  • Misconception 1: DAO governance provides immunity from liability because decisions are made by community vote, and the law cannot punish the multitude.

In the Ooki DAO case, token holders who participated in voting were likewise deemed managers and subject to penalties. If a DAO is not registered, it may be treated as a "general partnership," with each member bearing unlimited joint and several liability.

  • Misconception 2: Writing code without operating: I only developed open-source smart contracts, and the front end was deployed by others.

Although EtherDelta was a decentralized trading protocol, the U.S. Securities and Exchange Commission (SEC) determined that its founder, Zachary Coburn, wrote and deployed the smart contracts and profited therefrom, thereby bearing liability for operating an unregistered exchange.

  • Misconception 3: Anonymous deployment prevents identification: The team’s identities are concealed, server IP addresses are hidden, and tracking is impossible.

Absolute anonymity is largely a myth. Identities may be exposed through cashing out funds on centralized exchanges, commit records in code repositories, and social media information.

  • Misconception 4: Offshore structures are beyond regulatory reach: The company is incorporated in Seychelles, servers are cloud-based, and the U.S. SEC lacks jurisdiction.

The United States exercises robust long-arm jurisdiction. As long as even one U.S. user accesses the service, or transactions involve U.S. dollar stablecoins, U.S. regulators may assert jurisdiction. BitMEX was heavily penalized for such reasons, and its founders received criminal sentences.

 

Entrepreneurs’ Dilemma: Practical Challenges of Complete “De-entityization”

When entrepreneurs opt for complete “de-entityization” to evade regulatory oversight, they encounter numerous obstacles:

1. Inability to Execute Contracts, Hindering Collaboration

Code cannot serve as a legal person to execute contracts. When it is necessary to lease servers, engage audit firms, or collaborate with market makers, no one is authorized to sign on behalf of the protocol. If an individual developer signs, that individual assumes liability; if no one signs, it becomes impossible to establish collaborations with reputable large-scale institutions.

2. Inability to Enforce Rights, Leading to Arbitrary Code Replication

Web3 advocates open-source principles, but this means competitors can lawfully replicate your code, user interface, and even brand in their entirety, making only minor modifications (i.e., “forking”). In the absence of a legal entity, it is difficult to protect intellectual property rights through litigation or other legal remedies.

3. Lack of Bank Accounts, Impeding Fundraising and Payroll

A DAO lacks bank accounts, which prevents it from directly receiving fiat currency investments or paying salaries and social insurance contributions for employees. This not only severely restricts talent acquisition but also hinders the inflow of capital from traditional large-scale institutional investors.

4. Slow Decision-Making, Missing Critical Windows for Crisis Response

Ceding decision-making authority entirely to the DAO community means that any significant decision must undergo protracted processes of proposal, discussion, and voting. In the event of a hacking incident or severe market volatility, such “democratic procedures” may cause the project to miss the optimal window for response, rendering it unable to compete with centralized counterparts in terms of efficiency.

 

Compliance Pathway: How Entrepreneurs Can “Re-establish an Entity”

In light of practical realities, top-tier projects no longer pursue absolute de-entityization. Instead, they are shifting toward a pragmatic “Code + Law” model, the core of which is to establish a compliant “shell” for the protocol.

Three prevailing compliance architectures currently in use:

1. Two-tier architecture with separation of development and governance:

  • Operating company:Incorporate an ordinary software company in Singapore or Hong Kong to handle front-end development, recruitment, and marketing. It positions itself as a “technology service provider” and does not directly engage in financial activities.
  • Foundation:Establish a non-profit foundation in the Cayman Islands or Switzerland to manage the token treasury and community voting. It serves as the legal embodiment of the protocol and assumes ultimate responsibility.

2. DAO limited liability company:

Directly leverage the laws of Wyoming (United States) or the Marshall Islands to register the DAO itself as a novel form of limited liability company. In this way, members’ liability is limited to their capital contributions, thereby avoiding the risk of unlimited liability.

3. Compliant front-end and permissioned DeFi:

Although the underlying protocol cannot prevent anyone from using it, the official website operated by the project team can screen users:

  • Geographic blocking:Prohibit IP addresses from sanctioned or high-risk jurisdictions from accessing the platform.
  • Address Screening:Use professional tools to block known hacker and money laundering addresses.
  • Establish KYC Liquidity Pools:Collaborate with institutions to create lending pools specifically serving professional users who have completed identity verification.

 

Conclusion: From "Code Utopia" to "Compliance Infrastructure"

The next major growth area for on-chain lending is undoubtedly real-world assets (RWA), which involve bringing real-world assets (such as government bonds and real estate) on-chain. To accommodate trillions in traditional capital, clear legal entities and compliance structures are the entry ticket.

Compliance is not a betrayal of original principles, but the inevitable path for Web3 projects to enter the mainstream. The future of on-chain lending is not a choice between "decentralization or compliance," but a dual-track integration of "code autonomy + legal entities."