Skip to content

Infrastructure for MiCA CASPs, Crypto Exchanges, and Brokers

In short

Infrastructure for CASPs, crypto exchanges, and brokers is the engineering on top of the authorisation: product rails built on balances the venue already custodies (earn as vault lending structured around the MiCA Article 50 prohibition, staking with per-customer reward records, Lombard-style credit, cards, e-money token distribution) plus a compliance chain (onboarding, screening, Travel Rule, records, continuity) wired so evidence accumulates as the obligations run.

250+
projects shipped since 2016
50+
trading pairs on the first BaFin-licensed DEX
$2B+
in assets secured through Safe across 120+ networks
0
vulnerabilities across delivered projects
Trusted by teams building on-chain

MiCA has redrawn the market for crypto-asset service providers: hundreds of CASPs are now authorised across the EEA, and the transitional regime for nationally registered VASPs (virtual asset service providers) ended on 1 July 2026, with ESMA requiring unauthorised providers to stop onboarding EU clients and implement wind-down plans. For an authorised CASP, crypto exchange, or broker, competition has moved to what runs on the authorisation, and that is engineering in two directions.

The first is product rails that turn custodied balances into regulated revenue: earn structured as vault lending, staking with per-customer reward records, credit against pledged crypto, cards, and euro stablecoin balances. The second is a compliance stack wired so onboarding, screening, Travel Rule, record-keeping, and continuity each produce their own evidence as they run. Protofire builds both. We are an engineering firm with 250+ projects since 2016, and we helped build the world's first BaFin-licensed DEX.

The stack behind a regulated crypto venue

The client channel and authorisation on top; audited on-chain rails underneath; the product and evidence layers in between are what get engineered.

01

Client channel & brand

The exchange, broker app, or white-label front clients already use; new products appear inside it.
02

Venue & execution

Matching, routing, and liquidity engineering, with per-order records kept for best-execution review.
03

Custody & key governance

Segregated client custody under Safe policies and MPC vendors, with own-account use of client assets prohibited.
04

Product rails

Earn structured as curated vault lending, staking with reward records, credit against pledged crypto, card spend, EMT balances.
05

Compliance evidence chain

Onboarding, screening, Travel Rule, record-keeping, and continuity, each step logging the record examiners will ask for.
06

Attestation & reserves

Proof-of-Reserve attesting reserve balances against client liabilities, continuously.
07

Monitoring & response

On-chain threat monitoring with pre-authorised automated response, bounded by limits the venue sets.
01

Who this is for

Four venue profiles bring us this work. An authorised CASP or crypto exchange that holds client balances earning nothing and wants regulated products on them: earn, staking, credit, cards. A broker or neobank with crypto custody adding a second and third product on balances it already holds.

A firm coming off a lapsed VASP registration that intends to keep serving EU clients by migrating clients, balances, and Travel Rule wiring onto an authorised provider's rail while keeping its brand and front end. And a licensed institution adding crypto-asset services to an existing permission, which needs the day-one compliance stack built as one evidenced operating chain.

Credit institutions taking the MiCA Article 60 notification route are covered on the banks and credit institutions page. In every case the venue keeps the client relationship and the authorisation; we build the engineering underneath.

02

Products on balances you already custody

Each product has a regulatory shape it must be built in, and each is already live in the market. Earn: MiCA Article 50 bars paying any holding-linked benefit on e-money token balances, but lending sits outside MiCA scope, so the live structure is a curated vault the client lends into, receiving a vault position and earning what borrowers pay; a MiCA-licensed neobank runs it client-side today, and a systemically important bank group runs the same structure on its own stablecoins. Staking: ESMA Q&A 2067 treats staking-as-a-service as ancillary to custody; the validator operation is rented, and the build is the per-customer reward record a statement and a tax return are made from. Credit: a Lombard loan against pledged crypto, outside MiCA scope under Recital 94, with ESMA confirming a CASP may offer it; collateral is marked continuously and margined at disclosed thresholds, with a margin call before partial liquidation. Cards: spend authorised in real time against the customer's own smart account, with the program never taking custody. Euro balances: a third-party e-money token distributed from a licensed issuer; custody and transfers of EMTs also count as payment services under PSD2, so since the EBA's no-action window closed on 1 March 2026 a non-bank CASP needs a PSP authorisation or partnership for that leg. We build each rail into the venue's existing custody, ledger, and consent flows.

03

Compliance that produces its own evidence

An authorised CASP inherits an operating chain along with the licence: client onboarding and screening, Travel Rule data on every transfer under the recast Transfer of Funds Regulation (applying since 30 December 2024, with no de-minimis threshold on the information duty), record-keeping under Delegated Regulation 2025/1140, continuity arrangements under Delegated Regulation 2025/299, and DORA for ICT resilience. Self-hosted addresses carry their own tests: a EUR 1,000 threshold for assessing control, and EBA guidelines that prescribe five verification methods, with a bare self-declaration not among them.

The difference between a stack that passes examination comfortably and one that consumes the compliance team is architectural: each obligation should produce its own evidence as it runs, so an examination is served from records that already exist. That is a data-engineering problem as much as a legal one, and it is the problem we build for, including for venues absorbing a migrating client book at a multiple of normal onboarding volume after the July 2026 cliff.

04

What we build for exchanges and brokers

We build the venue, the rails, and the evidence chain. For the venue itself, DEX development covers matching, routing, and liquidity engineering, including permissioned, KYC-gated venues. For custody, Safe multisig deployment and Fireblocks integration put client assets under key governance a regulator can trace; we are an official Safe Guardian with $2B+ secured across 120+ networks.

For the compliance chain, compliance integration wires KYC, screening, and Travel Rule flows into the venue's stack. For products, white-label lending powers credit and vault-lending earn, validator infrastructure powers staking, and account abstraction powers card spend from smart accounts. Proof of Reserve attests client balances continuously, smart-contract audit hardens everything that touches client assets, and managed on-chain operations runs the monitoring and on-call after launch.

06

A partner that has shipped a regulated venue

Protofire is an engineering-led blockchain firm with 250+ projects shipped since 2016, across 60+ networks and 95+ protocols, with zero vulnerabilities across delivered projects. We helped build the world's first BaFin-licensed DEX for tokenized real-world assets, with KYC and multi-tier permissioning, 50+ trading pairs, and compliant large-trade execution, so we have shipped a regulated exchange under a German licence.

We are an official Safe Guardian securing $2B+ across 120+ networks, the custody governance underneath client assets. We are a core contributor to Chainlink and operate enterprise-scale Proof-of-Reserve attesting billions in reserves, the layer that answers "are client assets actually there" continuously.

And we maintain Solhint, the Solidity linter used by over a million developers, and harden every contract we ship before an external auditor sees it.

The venue already holds the expensive parts: the authorisation, the custody, the fiat ramps, and years of client due diligence. What turns those into new revenue is the connection to audited on-chain rails, built in the shape the regulation permits.

Regulated venue engineering, in production
50+trading pairs on the first BaFin-licensed DEX

We helped build the world's first BaFin-licensed DEX for tokenized real-world assets, with KYC and multi-tier permissioning, plus dOTC, Swarm's decentralized OTC venue, for compliant large-trade execution.

Swarm MarketsView project →
Billionsin reserves attested on-chain

We built and operate real-time proof-of-reserve infrastructure at enterprise scale, covering billions in reserves, the continuous answer to whether client assets are actually there.

Enterprise-scale PoRView project →
$2B+secured across 120+ EVM networks

As an official Safe Guardian, we deploy audited Safe contracts as institutional-grade custody, with client-asset segregation and separated signing roles so no single key can move funds.

Safe Multisig WalletView project →
7,000+stakers, institutional on-chain staking

We rebuilt KyberDAO's delegation with trustless reward contracts, cutting operational costs 50% and onboarding institutional staking like StakeDAO's $50M+ TVL in 90 days.

FAQ

What does a MiCA-authorised CASP have to run from day one?
A MiCA-authorised CASP runs one evidenced operating chain from day one: client onboarding and screening, Travel Rule data on every crypto-asset transfer under the recast Transfer of Funds Regulation (no de-minimis threshold on the information duty), record-keeping under Delegated Regulation 2025/1140, continuity arrangements under Delegated Regulation 2025/299, and DORA for ICT resilience. Self-hosted addresses add a EUR 1,000 threshold for assessing control, and the EBA's Travel Rule guidelines prescribe five verification methods, a bare self-declaration not among them. The architectural goal is evidence produced in the flow of operations, so an examination is answered from records that already exist.
Can a CASP pay interest on client stablecoin balances?
A CASP cannot pay interest on client stablecoin balances: MiCA Article 50 prohibits granting any remuneration or benefit tied to how long an e-money token is held, including benefits sourced from third parties. What remains open is lending: the client's tokens leave the balance and enter a curated, audited lending vault, the client receives a vault position in exchange, and earns what borrowers pay, less disclosed vault fees, on an asset they lent. Crypto lending itself sits outside MiCA and defers to national law, and the product is presented to clients as an unregulated service, per ESMA's guidance. The structure is live at regulated institutions today, and licence scope decides whether it is available to a given CASP, so counsel review comes before the build.
Our VASP registration lapsed under MiCA. Can we keep serving EU clients?
The transitional period ended 1 July 2026, and ESMA's statement of 23 June 2026 required unauthorised providers to stop onboarding EU clients and have wind-down plans implemented. The migration pattern is to move clients onto an authorised provider's rail: clients are re-onboarded by the authorised CASP, balances migrate into segregated sub-accounts, Travel Rule wiring is re-pointed, and the firm keeps its brand and front end. Whether the front-end role stays outside the scope of regulated service provision depends on the facts and needs a counsel opinion; the engineering side (re-onboarding, balance migration, transfer-information wiring) is what we build.
How does an exchange add staking on custody it already runs?
For an exchange or broker, staking turns custodied balances that sit idle into a second product on infrastructure it already runs. ESMA Q&A 2067 (20 June 2024) treats staking-as-a-service as ancillary to custody of crypto-assets, explicit client consent is required, and Article 75(8) keeps the institution liable for client losses attributable to it. ESMA Q&A 2607 (9 July 2025) adds that staking client assets for the CASP's own account breaches Article 70(1) even with consent. The validator operation is rented from an operator; the build is the reward ledger behind client statements and tax reporting. We operate validator infrastructure and build that record into the venue's ledger.
Does MiCA regulate crypto-backed lending by a CASP?
The lending itself is not regulated by MiCA: Recital 94 states MiCA does not address lending and borrowing of crypto-assets, and ESMA Q&A 2883 (18 June 2026) confirms a CASP may offer the service while it stays unregulated under MiCA. The custody and transfer legs remain fully regulated (safeguarding under Article 70(1), conduct under Article 66, custody under Article 75), ESMA holds that safeguarding does not extend to assets placed into a lending programme, and client assets may be lent only with prior, express, and specific consent. Authorisation to grant credit stays national, country by country. That is the position as the rules stand in 2026: the Commission's MiCA review consultation, extended to 30 September 2026, is weighing whether lending comes into scope. We build the collateral marking, margining, and liquidation machinery, and the per-customer records around it.
How is proof of reserves engineered for an exchange?
Proof of reserves for an exchange is engineered as continuous on-chain attestation rather than a periodic report: reserve addresses and custody balances are read by oracle infrastructure and published continuously, so the reserve side of client-asset backing is verifiable at any time against the venue's stated client liabilities. We are a core Chainlink contributor and built enterprise-scale Proof-of-Reserve infrastructure attesting billions in reserves, and we wire attestation into the venue's own custody and ledger so the published number and the books are reconciled continuously from the same sources.

Reviewed by Luis Medeiros, Field CTO at Protofire. Last reviewed: August 2026.

Book a call with Alejandro Losa

Schedule a call with our Web3 Solution Architect to receive practical recommendations and a prompt proposal for upgrading your solution.

Protofire 2026. All rights reserved

Message us on Telegram