en

EU staking review threatens crypto yields and network security could pay the price

image
rubric logo Legal
moon 1

Some of the most consequential financial rules begin with surprisingly little text.

For example, on page 36 of the European Commission's current MiCA review, item 66 asks whether Europe's treatment of staking is adequate and, if it isn't, what requirements should apply to companies providing staking services.

The question is brief, but the consequences wouldn't be.

There isn't a proposed staking license, a new capital requirement, or an agreed position in Brussels that any of those things should exist. The European Commission's MiCA review consultation remains open until Sept. 30 at 23:59 CEST and could eventually feed into legislation that amends MiCA, but the Commission says explicitly that the document isn't a final policy position.

Even so, the question tells us a lot about where European crypto regulation is heading. MiCA already governs much of what a centralized staking provider does when it takes custody of customer assets, and Brussels is now asking whether staking has become large and complicated enough to be treated as a regulated service in its own right.

For users, that could eventually mean more specific rules around slashing, withdrawal delays, fees, and who carries the loss when something goes wrong. For companies, it could mean another authorization layer and a more expensive compliance burden on top of MiCA, while protocols face a harder problem because staking is both a financial service and one of the basic mechanisms through which proof-of-stake blockchains operate.

That dual identity is where the regulatory argument gets difficult.

Staking started as network infrastructure, with participants locking assets, running validator software, following the protocol rules, and receiving rewards for helping the network reach consensus. Once exchanges, custodians, banks, and staking platforms placed themselves between the holder and the validator, the same activity started to look much more familiar to financial regulators.

At that point, some form of regulation was always going to follow.

Europe already regulates custodial staking

It's common to hear that staking falls outside MiCA, but that's only partly right.

MiCA doesn't contain a standalone regulated service called staking. Someone who stakes their own assets directly with a blockchain doesn't need a MiCA authorization just because they're participating in proof-of-stake consensus.

The European Commission has already drawn a distinction between that kind of proprietary staking and staking-as-a-service. If a company takes a customer's crypto, or controls the keys needed to access it, and stakes those assets for the customer, the service falls under MiCA's rules for custody and administration, according to ESMA's guidance on staking-as-a-service.

That sounds pretty straightforward until you look at how many different businesses now sit under the word “staking.”

Someone running an Ethereum validator with their own 32 $ETH and keeping control of the keys is staking directly, while a specialist validator can run the technical infrastructure for a customer who keeps the withdrawal key, which can make the relationship noncustodial. An exchange can hold the customer's $ETH, decide how it will be staked, collect the rewards, take a fee, and credit the remainder back to the customer's account, while liquid staking adds another layer because the user gives up the underlying asset and receives a token representing the staked position that can then be traded or posted as collateral elsewhere.

An EBA and ESMA joint crypto-asset report estimated the value of liquid staking at $44 billion in October 2024, with almost 80% of that activity on Ethereum. At the time, Lido alone represented roughly $25 billion.

These models aren't equivalent because control isn't distributed in the same way. The provider that holds the asset or controls the key can decide where it gets delegated and how rewards are handled, while it may also determine how quickly the customer gets the asset back and what happens when a validator is penalized.

That's why MiCA already imposes detailed obligations once custody enters the picture. A licensed custodian needs a written agreement explaining the service and the fees, while also maintaining records of client positions and procedures designed to protect those assets. Customer crypto has to be separated from the firm's own holdings, and there must be a process for returning it under MiCA Article 75.

MiCA also requires firms holding client crypto to protect customer ownership rights, including in insolvency, and prevents them from treating those assets as their own property under Article 70's client-asset safeguards.

ESMA has gone further on staking itself. A CASP can't take customer crypto and stake it for its own benefit, even if the customer agrees. The provider and customer can enter a staking arrangement where rewards are divided, but the assets don't become the firm's proprietary staking inventory, according to ESMA's guidance on the use of client assets for staking.

Europe therefore isn't starting from a regulatory vacuum, because the existing framework effectively says that staking is a protocol activity until an intermediary takes custody and turns it into a service. The Commission is now asking whether that distinction still works.

A separate staking regime would regulate the layer around the validator

The consultation doesn't tell us what a dedicated staking regime would contain, so it's too early to say Europe is about to impose a particular capital rule or require insurance for every validator service. However, the areas regulators are looking at aren't difficult to infer because EBA and ESMA have already spent considerable time cataloguing the risks.

Assets can become unavailable during protocol withdrawal periods, validators can be penalized or slashed, and customers may not understand how rewards are calculated or how much the provider deducts. Liquid-staking tokens can also trade away from the value of the underlying position, while using those tokens as collateral elsewhere can add another layer of leverage, according to the EBA and ESMA staking risk assessment.

A standalone framework could make providers spell out who bears those risks. If a validator is slashed, for example, the customer could be told in advance whether the loss sits with them or the provider, while a company could be required to explain how it chooses validator operators and what happens if one of them fails operationally.

Withdrawal terms could become more formal too because a user pressing “unstake” may assume the asset will be available immediately, even though the protocol itself can impose an exit period and the intermediary may add more processing time on top.

Reward advertising is another obvious area because a percentage shown next to a staking button can make a complicated combination of protocol issuance, validator performance, fees, and temporary incentives look like an ordinary savings yield, so regulators may want providers to separate those pieces more explicitly.

That could make the service easier to understand, but it would also make it more expensive to offer.

For a large exchange or bank that already has a MiCA authorization, another regulatory layer could mostly mean adding staking-specific policies to an existing compliance operation. Smaller validator businesses face a very different problem because their advantage may come from running reliable infrastructure rather than operating anything that resembles a financial institution.

If serving European customers directly begins to require more regulatory reporting, legal work, insurance, and customer-service infrastructure, the provider has to decide whether the market is still worth serving. Some will pay the cost, some will leave, and others will stop dealing with users directly and work behind a large licensed custodian instead.

That last outcome could reshape staking more than any disclosure rule because a bank or major exchange could become the regulated front door through which customers reach a large number of independent validator operators. The customer gets one regulated counterparty rather than having to assess each validator, but the regulated firm gains more influence over where customer stake is delegated.

For a proof-of-stake network, that isn't just a business question because validator distribution is part of network security. A framework designed to protect customers could therefore make access safer while concentrating more decision-making inside the firms that can afford the regulatory perimeter.

Users get more protection and less freedom

Users would feel that trade most directly because a dedicated staking framework could force providers to explain, before the customer deposits anything, what can delay a withdrawal and how much of the protocol reward the company keeps. It could also make them spell out whether an outside validator is involved and what happens to the customer's assets if that operator makes a costly mistake.

For a retail user who doesn't want to understand the validator architecture underneath the product, that's probably an improvement.

Institutional investors may benefit even more because large funds and banks don't usually avoid staking because the mechanics of proof of stake are too complicated to understand. They hesitate when legal title, liability, custody, exit rights, and counterparty obligations can't be fitted comfortably into their existing risk frameworks.

A more formal European regime could make those issues easier to resolve internally, but the cost would show up somewhere else. If compliance becomes more expensive, providers will either absorb it or charge customers more, which can lower net staking rewards, while smaller proof-of-stake networks may simply disappear from the product menu if they aren't worth the compliance work.

Validator due diligence could also favor large operators that already know how to pass institutional onboarding. A smaller operator may be technically excellent but still lose business because it can't produce the documentation a regulated custodian wants.

There's also the problem of writing one financial rule around blockchains that don't all work the same way. Ethereum's slashing and validator mechanics aren't Solana's, and neither looks exactly like the delegation models used elsewhere, so a rule written with the largest network in mind can become awkward when applied to systems with different technical assumptions.

Users who don't like the regulated version would still have another route because they can move assets into self-custody and interact directly with validators or decentralized protocols.

MiCA itself recognizes that services provided in a fully decentralized way without an intermediary can fall outside its scope. The current MiCA review document separately examines where that boundary should sit, including cases where admin keys, governance concentration, or identifiable operators make a protocol less decentralized than its branding implies.

That could leave Europe with two very different staking markets. One would run through exchanges, banks, custodians, and approved validator networks, with identity checks and regulator-supervised processes around the customer relationship, while the other would continue directly onchain for users willing to keep custody and accept the technical responsibility themselves.

The uncomfortable part is what happens in between because protocols with foundations, front ends, governance groups, or upgrade keys may discover that being decentralized in software doesn't automatically mean regulators treat the service as fully decentralized.

That problem extends well beyond staking, but staking may be one of the first places where Europe has to draw the line in a way that affects everyday users.

Finance has gone through this before

Crypto often frames regulation as a fight between a new technology and an old state, while financial history tends to be less dramatic and much more repetitive.

New products start with very little specialized regulation because lawmakers haven't decided how to classify them. The market expands, large institutions get involved, and eventually enough money is exposed that regulators stop treating it as an experiment, after which the rules begin accumulating, and the economics of providing the product start changing with them.

The product usually doesn't disappear, but the businesses that can absorb the new regulatory cost gain ground, while smaller providers consolidate, specialize, or leave.

OTC derivatives went through something similar after the 2008 financial crisis. Before the crisis, enormous volumes of swaps were traded bilaterally between counterparties, and when major institutions began failing, regulators discovered how difficult it was to see the network of exposures and how much depended on a relatively small group of firms.

The reforms that followed pushed standardized derivatives toward central clearing and reporting, while uncleared trades faced heavier margin and capital requirements. By 2017, the central clearing rate for interest-rate derivatives had climbed from around 20% in 2010 to at least 60%, according to a BIS analysis of post-crisis derivatives clearing.

The market survived, but providing the infrastructure became more concentrated around large clearing houses and banks.

Money-market funds offer an even closer example of how regulation can alter the version of a product investors choose. The SEC tightened the rules several times after 2008, and its 2014 reforms forced institutional prime funds away from the stable $1 net asset value while also changing liquidity requirements.

By the 2016 implementation deadline, roughly $1 trillion had left prime money-market funds, with most of the money moving into government funds instead, according to the Federal Reserve's account of the migration.

Investors didn't stop using money-market funds; they moved toward the form of the product that worked better under the new rules, and staking could follow a similar path.

If Europe makes custodial staking more expensive and more prescriptive, users don't necessarily stop staking. Some may migrate toward the large providers that can absorb the cost, while others may decide self-custody makes more sense, and providers will redesign the product around whichever regulatory boundary Brussels eventually draws.

That's where the debate becomes more difficult than simply deciding whether regulation is good or bad.

Custodial staking does create relationships that need rules somewhere. If an exchange takes a customer's $ETH, decides where to stake it, loses some through an operational error, and then delays the withdrawal, saying that staking is merely blockchain consensus isn't much of an answer to the customer.

At the same time, staking isn't just a yield product invented by an intermediary because it's how many blockchains decide who gets to produce blocks and verify transactions. Treat it too much like a conventional investment service, and regulators risk turning part of network security into another branch of regulated asset management.

That was always going to become harder to avoid as the market got larger. When staking was something technically sophisticated users did from their own machines, there wasn't much political urgency around creating a dedicated rulebook. Once major exchanges began offering one-click staking to millions of customers and institutional custodians began packaging validator rewards as a financial service, the regulatory vacuum became much harder to maintain.

Europe hasn't decided what comes next, and for now item 66 just asks whether staking should have its own rules.

If Brussels eventually decides that it should, the deeper meaning will be hard to miss because staking will have completed the same journey many financial products made before it, from an unfamiliar technical mechanism to a commercial product and then into an industry where regulators decide who can provide it and under what conditions.

That may make staking safer for the customer who never wanted to understand validators in the first place, but it could also make it more expensive, more concentrated, and much further from the permissionless system it came from.