DeFi regulation & security
DeFi regulation in Hungary
Hungary’s separate exchange-validation regime was repealed in 2026. MNB authorization and the EU rules still need their own assessment.
- Sources checked
- Published
- Prepared by
- DeFi Security Alliance
Scope: Hungarian CASP authorization and the documented repeal of exchange-validation rules. Historical transactions, criminal liability and individual tax cases are outside this guide.
Update the regulatory baseline
The SZTFH's current notice reports that Act XXXVIII of 2026, published on 30 July, removed the statutory exchange-validation licensing and registration provisions and related criminal rules. It also describes termination of the relevant proceedings and the loss of effect of earlier validation permits.
The amending Act provides for commencement on the eighth day after publication. By the review date of this guide, the change has taken effect. Do not carry a 2025 validator requirement into a current operating checklist. The repeal does not itself grant a MiCA permission or decide the treatment of a historical transaction.
Use the MNB authorization procedure
The MNB CASP authorization guide directs the relevant electronic applications through ERA, using the prescribed licensing forms and supporting electronic documents. It also identifies the good-business-reputation questionnaire and electronic-signature process. Keep proof of submission and monitor the official delivery channel for requests.
First distinguish an Article 63 CASP authorization from Article 60 eligibility for an existing financial institution. The latter depends on institution type and service equivalence. MNB supervision is separate from the former SZTFH validation permission.
For a DeFi-related service, identify the customer-facing entity, controlled interfaces and signing powers. MiCA Recital 22 does not create an exemption merely because the product uses a permissionless smart contract. Record which person performs or controls each proposed service before selecting a regulatory route.
Keep permissions and technical controls separate
This DeFiSec worksheet helps remove outdated requirements while retaining evidence for the obligations that still apply.
| Record | Evidence to retain | Decision supported |
|---|---|---|
| Former validation step | Dated repeal source and the affected internal procedure | Which legacy step can be retired after a scoped review? |
| MNB procedure | ERA submission receipt, signed forms and response log | What was filed, by whom and for which entity? |
| Service permission | Authorized services or Article 60 eligibility assessment | Which customer functions may be activated? |
| Transfer controls | Counterparty checks, missing-data workflow and decision logs | Can the provider handle a transfer under the applicable TFR rules? |
| Product changes | Wallet permissions and deployment history | Has a technical change altered the service classification? |
Travel Rule information and customer due diligence require their own controls. Pharos Production's MiCA KYC engineering guide can help connect identity checks to onboarding and transfer handling. Use the EU Travel Rule guide for the legal transfer scenarios, including self-hosted addresses.
Review changes without erasing the audit trail
Keep a record of the old procedure, the source establishing the change and the approved replacement. Removing a validator integration should not remove unrelated transaction records or customer-protection controls. Set retention rules from the applicable obligations and the actual data purpose.
For a CASP within DORA's scope, operational resilience, supplier oversight and incident handling remain continuing responsibilities. A repeal in one national regime is not evidence that an ICT dependency or custody risk disappeared. Validate the revised workflow before exposing it to customers.
Continue your research
Sources and further reading
Legislation and regulator publications establish the legal basis. Technical resources explain implementation. Source checks cover the passages cited in this guide.
- MiCA — Regulation (EU) 2023/1114European Union ·
- DORA — Regulation (EU) 2022/2554European Union ·
- Transfer of Funds Regulation (EU) 2023/1113European Union ·
- MiCA KYC requirements: onboarding and Travel Rule integrationPharos Production ·
- Change in crypto exchange validation rulesSZTFH ·
- Act XXXVIII of 2026: repeal of exchange-validation provisionsHungarian National Legislation Database ·
- CASP authorization guideMagyar Nemzeti Bank ·