DeFi Security AllianceRequest an audit
Menu

DeFi regulation & security

DeFi regulation in Hungary

Hungary’s separate exchange-validation regime was repealed in 2026. MNB authorization and the EU rules still need their own assessment.

Sources checked
Published
Prepared by
DeFi Security Alliance

Scope: Hungarian CASP authorization and the documented repeal of exchange-validation rules. Historical transactions, criminal liability and individual tax cases are outside this guide.

Update the regulatory baseline

The SZTFH's current notice reports that Act XXXVIII of 2026, published on 30 July, removed the statutory exchange-validation licensing and registration provisions and related criminal rules. It also describes termination of the relevant proceedings and the loss of effect of earlier validation permits.

The amending Act provides for commencement on the eighth day after publication. By the review date of this guide, the change has taken effect. Do not carry a 2025 validator requirement into a current operating checklist. The repeal does not itself grant a MiCA permission or decide the treatment of a historical transaction.

Use the MNB authorization procedure

The MNB CASP authorization guide directs the relevant electronic applications through ERA, using the prescribed licensing forms and supporting electronic documents. It also identifies the good-business-reputation questionnaire and electronic-signature process. Keep proof of submission and monitor the official delivery channel for requests.

First distinguish an Article 63 CASP authorization from Article 60 eligibility for an existing financial institution. The latter depends on institution type and service equivalence. MNB supervision is separate from the former SZTFH validation permission.

For a DeFi-related service, identify the customer-facing entity, controlled interfaces and signing powers. MiCA Recital 22 does not create an exemption merely because the product uses a permissionless smart contract. Record which person performs or controls each proposed service before selecting a regulatory route.

Keep permissions and technical controls separate

This DeFiSec worksheet helps remove outdated requirements while retaining evidence for the obligations that still apply.

Hungary: permission and control-change worksheet
RecordEvidence to retainDecision supported
Former validation stepDated repeal source and the affected internal procedureWhich legacy step can be retired after a scoped review?
MNB procedureERA submission receipt, signed forms and response logWhat was filed, by whom and for which entity?
Service permissionAuthorized services or Article 60 eligibility assessmentWhich customer functions may be activated?
Transfer controlsCounterparty checks, missing-data workflow and decision logsCan the provider handle a transfer under the applicable TFR rules?
Product changesWallet permissions and deployment historyHas a technical change altered the service classification?

Travel Rule information and customer due diligence require their own controls. Pharos Production's MiCA KYC engineering guide can help connect identity checks to onboarding and transfer handling. Use the EU Travel Rule guide for the legal transfer scenarios, including self-hosted addresses.

Review changes without erasing the audit trail

Keep a record of the old procedure, the source establishing the change and the approved replacement. Removing a validator integration should not remove unrelated transaction records or customer-protection controls. Set retention rules from the applicable obligations and the actual data purpose.

For a CASP within DORA's scope, operational resilience, supplier oversight and incident handling remain continuing responsibilities. A repeal in one national regime is not evidence that an ICT dependency or custody risk disappeared. Validate the revised workflow before exposing it to customers.

Continue your research

Sources and further reading

Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.

  1. MiCA — Regulation (EU) 2023/1114European Union ·
  2. DORA — Regulation (EU) 2022/2554European Union ·
  3. Transfer of Funds Regulation (EU) 2023/1113European Union ·
  4. MiCA KYC requirements: onboarding and Travel Rule integrationPharos Production ·
  5. Change in crypto exchange validation rulesSZTFH ·
  6. Act XXXVIII of 2026: repeal of exchange-validation provisionsHungarian National Legislation Database ·
  7. CASP authorization guideMagyar Nemzeti Bank ·

Publication record

First publication of this guide and its source-backed evidence map.

Report an outdated source