Home / History / DeFi Dawn / Compliance vs composability
2019–2020

Compliance vs composability

FATF travel rule and OFAC anxieties meet unstoppable contracts.

DeFi Dawn

Story beats & cast

KYC/AML overlaysCompliance tooling
Events
  • Travel rule guidance
  • Mixer scrutiny rises
Actors
  • Regulators worldwide — Policy makers

Compliance vs composability

Rules vs. permissionless rails

Travel rule meets smart contracts

In 2019–2020, FATF’s “travel rule” required VASPs (exchanges/custodians) to share sender/receiver info. Meanwhile, DeFi let anyone swap or lend without KYC. Regulators saw a leak in the perimeter; builders saw censorship creeping toward open rails. The clash defined the next few years of design choices.

CeFi venues began geo-blocking certain tokens and regions; frontends added disclaimers. On-chain contracts, however, kept executing—showing that enforcement would focus on access points and operators, not the code alone.

Sanctions and mixers in the crosshairs

Sanctions lists expanded to include mixers (e.g., Tornado Cash, later). OFAC sanctions led some frontends to block addresses; RPC providers and infra firms followed. Smart contracts themselves stayed live, but risk shifted to users and developers interacting with them. The community debated whether neutrality could survive regulatory heat. The OFAC press release ↗ shows how explicit the clampdown became.

CeFi/DeFi blending and censorship questions

KYC’d pools and allowlists

Protocols like Aave Arc launched permissioned markets for institutions; some stablecoin issuers and bridges enforced allowlists. This appeased compliance teams but fractured liquidity and composability. Users asked: which legos can still snap together if half the pieces require KYC? Aave Arc’s launch notes ↗ framed it as “bringing institutions on-chain.”

Oracle- or governance-enforced blocks

Projects considered blocking sanctioned addresses via governance oracles. Critics warned this created kill switches and governance capture risks. Supporters argued it kept protocols accessible in regulated jurisdictions. The experiment highlighted how “unstoppable” contracts often had admin or governance hooks. Maker’s blocklist poll ↗ shows how contentious these levers are.

Frontends vs. contracts

Most enforcement hit frontends: web apps geofenced, hid pools, or added warnings. Power users switched RPCs or used alternative interfaces. This split underscored a design principle: minimize trust in any single frontend, or accept that UX can be censored even if the contract can’t.

How the tension reshaped design

Protocols pre-empt regulation

Some teams added compliance modes, emergency pause powers, or chainalysis integrations. Others doubled down on minimization: no admin keys, fully on-chain UIs, and decentralized RPC relays. The split created two DeFis: one courting institutions, one chasing trust-minimized purity.

Composability under strain

When pools or bridges enforce allowlists, downstream protocols can inherit restrictions (or break if they don’t). This forced clearer documentation of assumptions: which tokens can be frozen, who can upgrade, and what events trigger censorship.

Legacy

The compliance vs. composability era taught builders to assume scrutiny and design for resilience. It normalized multiple UX layers (regulated frontends + unstoppable contracts) and pushed infra toward decentralization (RPC diversity, open-source frontends). It also left open questions about where the line between safety and censorship should sit.