18 June 2026
ESMA ¦ Q&A 2883 on Crypto-Asset Lending Services under MiCA
ESMA sets the conditions for crypto-asset lending by CASPs under MiCA
The Markets in Crypto-Assets Regulation (MiCA) does not regulate crypto-asset lending, yet crypto-asset service providers (CASPs) that offer it remain bound by MiCA’s conduct rules. In its Q&A 2883 of 18 June 2026, the European Securities and Markets Authority (ESMA) confirms that CASPs may offer lending services and spells out the conditions. The general MiCA duties continue to apply, the risks must be disclosed plainly, clients’ crypto-assets may only be lent with their prior express and specific consent, and lending revenues belong to the client after a fair fee.
An unregulated service inside a regulated firm
Recital 94 of MiCA leaves the lending and borrowing of crypto-assets outside the list of regulated crypto-asset services. ESMA therefore treats lending as an unregulated service and refers CASPs to its earlier Statement on avoiding misperceptions, its guidance for firms that offer unregulated services alongside regulated ones. The Q&A covers crypto-asset lending only. Securities lending is expressly excluded and may require a separate authorisation.
The difficulty is that the regulated and the unregulated sit inside the same client relationship. A client who opens an account with an authorised CASP for custody or exchange will reasonably assume that a lending or “earn” product in the same app comes with the same protections. It does not, and ESMA expects the CASP to make that clear.
General conduct duties still apply
Lending may be missing from MiCA’s service catalogue, but the CASP’s general obligations still cover it. Under Article 66(1) of MiCA, a CASP must act honestly, fairly and professionally in the best interests of its clients. Under Article 66(2), all information addressed to clients, marketing communications included, must be fair, clear and not misleading.
ESMA draws one specific consequence: CASPs should avoid confusing clients when they offer lending next to regulated services. In practice this concerns product presentation. Interface design, product names, onboarding flows and promotional material should give no impression that a lending programme shares the authorisation status or the safeguards of the firm’s regulated activities.
Risks that must be disclosed
ESMA names counterparty risk, collateral shortfall risk and the risk of losing access to lent crypto-assets if the CASP fails. It adds a point many retail clients will not expect: MiCA’s safeguarding arrangements do not apply to assets used in lending programmes. Once a client’s crypto-assets leave custody and enter a lending pool, the segregation the client may have counted on no longer protects them.
These risks have to be disclosed in a fair, clear and non-misleading way. ESMA also expects CASPs to ensure adequate collateral and to assess the robustness of the lending arrangements or protocols they use, decentralised ones included. A CASP that routes client assets into decentralised finance protocols therefore needs to understand the smart contract, the collateral mechanics, the liquidation logic and who ultimately borrows the assets.
Client assets are not the firm’s to use
The core of the answer concerns client assets. Under Article 70(1) of MiCA, a CASP that holds clients’ crypto-assets or the means of access to them must safeguard the clients’ ownership rights and must not use those assets for its own account.
ESMA reads this strictly. Lending clients’ crypto-assets requires the client’s prior express and specific consent, limited to clearly defined terms. A consent clause buried in general terms and conditions, without prominence, does not meet that standard. A generic clause accepted at onboarding will therefore not support a lending programme built on client assets.
For financial crime teams this point carries particular weight. The collapse of several centralised crypto lenders in 2022 showed how quickly client assets can be commingled, re-used and lost when consent is vague and internal controls are weak. Misuse of client assets can amount to misappropriation or breach of trust, and the proceeds of such conduct are a familiar source of funds that later need laundering. A documented, specific consent marks the boundary between a legitimate lending programme and the use of other people’s property without their authority.
Revenues follow the risk
ESMA also decides who keeps the economic benefit. Clients bear the risks of lending, so the revenues should accrue to them. A CASP may charge a fair and proportionate fee that reflects its operational costs. Keeping additional revenues would not be consistent with acting in the client’s best interests.
That rules out a model in which the platform pays clients a fixed, modest yield and keeps the spread it earns on their assets. Supervisors can now use the fee structure as a test of compliance with Article 66(1), and CASPs will need to document how they price the service, allocate revenue and calculate client returns.
When lending becomes a fund
The Q&A is without prejudice to case-by-case classification. Depending on their features and contractual terms, some lending arrangements may fall within other EU or national frameworks. ESMA gives the Alternative Investment Fund Managers Directive (AIFMD) as an example: certain arrangements could meet the definition of an alternative investment fund.
Pooled lending products are the obvious candidates. Where client assets are collected, pooled and deployed under a defined strategy for the benefit of investors, the product starts to resemble a collective investment undertaking more than a service. If it qualifies as an AIF, the fund framework follows, with manager authorisation, depositary requirements and investor disclosures. In Luxembourg, with a large fund industry and a growing crypto sector, that boundary needs legal analysis before a product goes to market.
Financial crime controls around lending programmes
The Q&A does not deal with money laundering directly, but its logic leads there. Lent assets leave the CASP’s direct control and go to borrowers or protocols whose identity, source of funds and purpose may be opaque. Collateral posted by borrowers can itself come from illicit activity, and decentralised protocols may pool liquidity from addresses linked to fraud or sanctions evasion.
An assessment of the robustness of a lending arrangement, as ESMA requires it, should therefore include counterparty due diligence, blockchain analytics on collateral and borrower addresses, sanctions screening and monitoring of flows into and out of the lending pool. Where the CASP itself selects the borrowers, its customer due diligence obligations extend to those relationships.
What CASPs should review now
Supervisors now have a reference point for assessing the lending and “earn” products of authorised CASPs. Firms should replace general consent clauses with a separate, prominent and specific consent for each lending arrangement, and check their marketing and app design for anything suggesting that lending is regulated or protected under MiCA. Risk disclosures on counterparty, collateral and insolvency risk deserve a fresh look, as does the question whether the fee model passes revenues to clients beyond a cost-based fee.
Firms should also document their assessment of every lending counterparty and protocol, decentralised ones included, and obtain a legal view on whether a pooled lending product could qualify as an AIF. A CASP that cannot produce this record will struggle to defend its lending programme before its national competent authority.
Dive deeper
- European Securities and Markets Authority (ESMA) ¦ ESMA_QA_2883 Crypto-Asset lending services under MiCA ¦ Link