Infrastructure for MiCA CASPs, Crypto Exchanges, and Brokers
Infrastructure for CASPs, crypto exchanges, and brokers is the engineering on top of the authorisation: product rails built on balances the venue already custodies (earn as vault lending structured around the MiCA Article 50 prohibition, staking with per-customer reward records, Lombard-style credit, cards, e-money token distribution) plus a compliance chain (onboarding, screening, Travel Rule, records, continuity) wired so evidence accumulates as the obligations run.
MiCA has redrawn the market for crypto-asset service providers: hundreds of CASPs are now authorised across the EEA, and the transitional regime for nationally registered VASPs (virtual asset service providers) ended on 1 July 2026, with ESMA requiring unauthorised providers to stop onboarding EU clients and implement wind-down plans. For an authorised CASP, crypto exchange, or broker, competition has moved to what runs on the authorisation, and that is engineering in two directions.
The first is product rails that turn custodied balances into regulated revenue: earn structured as vault lending, staking with per-customer reward records, credit against pledged crypto, cards, and euro stablecoin balances. The second is a compliance stack wired so onboarding, screening, Travel Rule, record-keeping, and continuity each produce their own evidence as they run. Protofire builds both. We are an engineering firm with 250+ projects since 2016, and we helped build the world's first BaFin-licensed DEX.
The stack behind a regulated crypto venue
The client channel and authorisation on top; audited on-chain rails underneath; the product and evidence layers in between are what get engineered.
Client channel & brand
Venue & execution
Custody & key governance
Product rails
Compliance evidence chain
Attestation & reserves
Monitoring & response
Who this is for
Four venue profiles bring us this work. An authorised CASP or crypto exchange that holds client balances earning nothing and wants regulated products on them: earn, staking, credit, cards. A broker or neobank with crypto custody adding a second and third product on balances it already holds.
A firm coming off a lapsed VASP registration that intends to keep serving EU clients by migrating clients, balances, and Travel Rule wiring onto an authorised provider's rail while keeping its brand and front end. And a licensed institution adding crypto-asset services to an existing permission, which needs the day-one compliance stack built as one evidenced operating chain.
Credit institutions taking the MiCA Article 60 notification route are covered on the banks and credit institutions page. In every case the venue keeps the client relationship and the authorisation; we build the engineering underneath.
Products on balances you already custody
Each product has a regulatory shape it must be built in, and each is already live in the market. Earn: MiCA Article 50 bars paying any holding-linked benefit on e-money token balances, but lending sits outside MiCA scope, so the live structure is a curated vault the client lends into, receiving a vault position and earning what borrowers pay; a MiCA-licensed neobank runs it client-side today, and a systemically important bank group runs the same structure on its own stablecoins. Staking: ESMA Q&A 2067 treats staking-as-a-service as ancillary to custody; the validator operation is rented, and the build is the per-customer reward record a statement and a tax return are made from. Credit: a Lombard loan against pledged crypto, outside MiCA scope under Recital 94, with ESMA confirming a CASP may offer it; collateral is marked continuously and margined at disclosed thresholds, with a margin call before partial liquidation. Cards: spend authorised in real time against the customer's own smart account, with the program never taking custody. Euro balances: a third-party e-money token distributed from a licensed issuer; custody and transfers of EMTs also count as payment services under PSD2, so since the EBA's no-action window closed on 1 March 2026 a non-bank CASP needs a PSP authorisation or partnership for that leg. We build each rail into the venue's existing custody, ledger, and consent flows.
Compliance that produces its own evidence
An authorised CASP inherits an operating chain along with the licence: client onboarding and screening, Travel Rule data on every transfer under the recast Transfer of Funds Regulation (applying since 30 December 2024, with no de-minimis threshold on the information duty), record-keeping under Delegated Regulation 2025/1140, continuity arrangements under Delegated Regulation 2025/299, and DORA for ICT resilience. Self-hosted addresses carry their own tests: a EUR 1,000 threshold for assessing control, and EBA guidelines that prescribe five verification methods, with a bare self-declaration not among them.
The difference between a stack that passes examination comfortably and one that consumes the compliance team is architectural: each obligation should produce its own evidence as it runs, so an examination is served from records that already exist. That is a data-engineering problem as much as a legal one, and it is the problem we build for, including for venues absorbing a migrating client book at a multiple of normal onboarding volume after the July 2026 cliff.
What we build for exchanges and brokers
We build the venue, the rails, and the evidence chain. For the venue itself, DEX development covers matching, routing, and liquidity engineering, including permissioned, KYC-gated venues. For custody, Safe multisig deployment and Fireblocks integration put client assets under key governance a regulator can trace; we are an official Safe Guardian with $2B+ secured across 120+ networks.
For the compliance chain, compliance integration wires KYC, screening, and Travel Rule flows into the venue's stack. For products, white-label lending powers credit and vault-lending earn, validator infrastructure powers staking, and account abstraction powers card spend from smart accounts. Proof of Reserve attests client balances continuously, smart-contract audit hardens everything that touches client assets, and managed on-chain operations runs the monitoring and on-call after launch.
Start from a proven blueprint
Each blueprint in our library is an architecture running at a regulated institution today, documented down to the regime that permits it, who operates it, and which layers you own, rent, or have us build. Eight are drawn for CASPs, exchanges, and brokers:
The MiCA compliance stack
→Onboarding, screening, Travel Rule, records, and continuity, wired so each obligation produces its own evidence.
Migration off a lapsed VASP registration
→Move clients, balances, and Travel Rule wiring onto an authorised rail, and keep your brand.
Stablecoin earn on vault positions
→Let clients lend idle stablecoin balances into a curated vault and earn what borrowers pay.
Client staking on custodied assets
→Add staking on the custody you already run, with a per-customer reward record built in.
Credit against a client's crypto
→Lend fiat or stablecoins against pledged crypto, marked and margined continuously.
Crypto-backed cards
→Let customers spend on-chain balances with a card, while the program never takes custody.
Euro e-money token distribution
→Put a euro stablecoin in the product by contracting a licensed issuer.
On-chain threat monitoring
→Answer defined on-chain threats in seconds from a pre-agreed matrix, bounded by limits you set.
A partner that has shipped a regulated venue
Protofire is an engineering-led blockchain firm with 250+ projects shipped since 2016, across 60+ networks and 95+ protocols, with zero vulnerabilities across delivered projects. We helped build the world's first BaFin-licensed DEX for tokenized real-world assets, with KYC and multi-tier permissioning, 50+ trading pairs, and compliant large-trade execution, so we have shipped a regulated exchange under a German licence.
We are an official Safe Guardian securing $2B+ across 120+ networks, the custody governance underneath client assets. We are a core contributor to Chainlink and operate enterprise-scale Proof-of-Reserve attesting billions in reserves, the layer that answers "are client assets actually there" continuously.
And we maintain Solhint, the Solidity linter used by over a million developers, and harden every contract we ship before an external auditor sees it.
“The venue already holds the expensive parts: the authorisation, the custody, the fiat ramps, and years of client due diligence. What turns those into new revenue is the connection to audited on-chain rails, built in the shape the regulation permits.”
We helped build the world's first BaFin-licensed DEX for tokenized real-world assets, with KYC and multi-tier permissioning, plus dOTC, Swarm's decentralized OTC venue, for compliant large-trade execution.
We built and operate real-time proof-of-reserve infrastructure at enterprise scale, covering billions in reserves, the continuous answer to whether client assets are actually there.
As an official Safe Guardian, we deploy audited Safe contracts as institutional-grade custody, with client-asset segregation and separated signing roles so no single key can move funds.
We rebuilt KyberDAO's delegation with trustless reward contracts, cutting operational costs 50% and onboarding institutional staking like StakeDAO's $50M+ TVL in 90 days.
FAQ
What does a MiCA-authorised CASP have to run from day one?
Can a CASP pay interest on client stablecoin balances?
Our VASP registration lapsed under MiCA. Can we keep serving EU clients?
How does an exchange add staking on custody it already runs?
Does MiCA regulate crypto-backed lending by a CASP?
How is proof of reserves engineered for an exchange?
Reviewed by Luis Medeiros, Field CTO at Protofire. Last reviewed: August 2026.


