Ooki DAO set the precedent that token holders can be personally liable. Here's what FATF, the CFTC and MiCA require from DAO governance, treasury and grants.
Table of contents
- In June 2023, a US court granted the CFTC a default judgment against the Ooki DAO, a $643,542 penalty plus a shutdown order, holding the DAO liable as an unincorporated association whose token-holders generally do not enjoy limited liability.
- That precedent reframes KYC for DAOs from a protocol nicety into a question of personal and organisational exposure for the people who govern, sign, and fund.
- Under FATF's 2021 owner/operator test, a DAO can be a virtual asset service provider where creators, owners, or operators maintain control or sufficient influence, even if the arrangement looks decentralised.
- Every DAO touches three compliance surfaces: token-voting governance, multisig signer screening, and treasury KYB on counterparties and grantees.
- Sanctions exposure is real: the 2022 Tornado Cash designation showed sanction-by-association risk in DeFi, though courts later narrowed it and it was delisted in 2025, so the risk is serious but legally contested.
- Credential-gated governance, verifying a voter or signer is eligible without exposing their full identity on-chain, is how a DAO can add KYC without doxxing its community.
KYC for DAOs is the practice of applying identity, sanctions, and counterparty checks to a DAO's governance, signers, and treasury, so the people who control it can show they are not facilitating prohibited activity. After CFTC v. Ooki DAO held a DAO liable as an unincorporated association, this is about personal and organisational exposure, not protocol design.
TL;DR
KYC for DAOs stopped being theoretical in June 2023, when a US court granted the CFTC a default judgment against the Ooki DAO: a $643,542 penalty, a trading and registration ban, and an order to shut the protocol's website down. The court held the Ooki DAO was a "person" under the Commodity Exchange Act and an unincorporated association, a structure that generally does not shield its members from liability. Token-based governance, the court reasoned, looked like membership.
That changes the question for DAO operators, multisig signers, and treasury managers from "can a protocol be regulated" to "what is my personal exposure." Under FATF's owner/operator test, a DAO can be a virtual asset service provider where identifiable people maintain control or influence. This guide covers what Ooki held, when FATF treats a DAO as a VASP, the three compliance surfaces every DAO touches, the sanctions risk, and how credential-gated governance adds KYC without doxxing the community.
10 min read. Last updated 21 August 2026.
What did CFTC v. Ooki DAO actually hold?
In June 2023, Judge William Orrick of the US District Court for the Northern District of California granted the CFTC a default judgment against the Ooki DAO, imposing a civil penalty of $643,542, permanent trading and registration bans, and an order that the DAO and any party providing web hosting or domain services shut down its website. The decision is widely described as the first time a court found a DAO to be a legal person capable of being held liable as an entity.
Two findings matter most for KYC for DAOs. First, the court held the Ooki DAO was a "person" under the Commodity Exchange Act, so it could be charged. Second, it found the DAO was an unincorporated association under state and federal law, a structure that generally does not provide limited liability to its members, and it treated participation in token-based governance as membership. What Ooki did not do is declare every DAO automatically liable; the court was clear that outcomes depend on the facts and the nature of a DAO's operations. But the direction is unmistakable, and it is why KYC for DAOs now matters: governance participation can carry personal exposure.
When does a DAO become a VASP under FATF?
FATF's October 2021 updated guidance set out an owner/operator test for decentralised arrangements. The software itself is not a virtual asset service provider, FATF was explicit that its standards do not apply to underlying code, but creators, owners, and operators who maintain control or sufficient influence over a DeFi arrangement, even one that appears decentralised, may be VASPs where they provide or actively facilitate VASP services.
The factors FATF flags include whether a party profits from the service, whether it can set or change parameters, and whether there is an ongoing business relationship with users, even one exercised through smart contracts or voting. A genuinely and fully decentralised arrangement with no such party is unlikely to be a VASP; a DAO with identifiable people steering it may well be. For DAOs, the practical takeaway is that "decentralised" is not a compliance status, it is a spectrum, and the more identifiable control exists, the closer the VASP obligations, including KYC and the Travel Rule covered in our FATF Travel Rule guide.
What compliance surfaces does every DAO touch?
Even a lean DAO touches three surfaces where KYC for DAOs becomes concrete.
Governance and voting is the first: if token-based voting can constitute membership and liability, a DAO has reason to know that participants in consequential votes are not sanctioned parties. Multisig signer screening is the second: the people holding the keys to the treasury are the clearest "operators," and screening them against sanctions and PEP lists is a basic control given their exposure. Treasury KYB on counterparties is the third: when a DAO pays a vendor, funds a grant, or interacts with a protocol, it should know who is on the other side, the same business-verification logic as any other organisation moving money, which connects to KYC for crypto and the broader crypto compliance software stack.
None of these requires the DAO to abandon decentralisation wholesale. They require applying identity and sanctions checks at the points where real-world legal exposure attaches.
How does sanction-by-association affect DAO grants and treasury?
Sanctions are the sharpest edge of KYC for DAOs. The 2022 OFAC designation of Tornado Cash showed that interacting with a sanctioned protocol or address can create exposure by association, a serious risk for a DAO disbursing grants or moving treasury funds to addresses it has not screened. A grant to a sanctioned recipient, or treasury exposure to a sanctioned mixer, is not excused by decentralisation.
The nuance, which an honest guide should state, is that the Tornado Cash sanction was legally contested: courts later found OFAC had overstepped in sanctioning immutable smart contracts, and Tornado Cash was removed from the sanctions list in 2025. So the lesson is not that all on-chain interaction is forbidden, it is that DAOs must screen counterparties and grantees against current sanctions lists and document the check, because the exposure is real even as its legal boundaries are still being drawn. Screening treasury counterparties against OFAC, EU, UK, and UN lists, and recording the result, is the defensible posture.
Can DAO voting be KYC'd without doxxing voters?
This is the objection every DAO raises, and the answer is yes, through credential-gated governance. Instead of publishing identities on-chain, a DAO can require that a voter or signer holds a verifiable credential proving they are eligible, verified, and not sanctioned, while revealing only that fact, not the underlying identity, to the protocol. Techniques such as selective disclosure and zero-knowledge attestation let someone prove "I am a KYC-verified, non-sanctioned eligible participant" without exposing their name to the public chain, and account-abstraction approaches can gate actions on holding such a credential.
This is exactly where a privacy-first, decentralised KYC model fits. Zyphe verifies a participant and issues a reusable credential while the underlying identity data stays sharded across decentralised storage under a customer-held key, so a DAO can gate governance and signing on verified, non-sanctioned status without building a doxxing database or handing identities to a central store. Credential-gated access, not public identification, is how KYC for DAOs respects both compliance and pseudonymity, building on decentralised KYC and decentralised PII storage.
Does MiCA regulate DAOs?
Mostly not directly, and it is worth being precise because this is often overstated. The EU's Markets in Crypto-Assets regulation governs crypto-asset service providers, entities that provide defined services, and it largely does not capture fully decentralised arrangements that have no identifiable issuer or service provider. MiCA even mandated further work on decentralised finance rather than regulating it outright, leaving a recognised DeFi and DAO gap.
The practical reading: a DAO with an identifiable operator providing crypto-asset services in the EU may fall within MiCA's CASP scope and its obligations, while a genuinely decentralised DAO may sit outside the current CASP regime, in the same grey zone FATF's owner/operator test describes. Do not assume MiCA either fully covers or fully exempts your DAO; assess whether identifiable persons are providing in-scope services, and expect the DeFi perimeter to keep evolving. The connected obligations, where they apply, are the same KYC, sanctions, and Travel Rule duties any VASP faces.
What would a regulator subpoena from a DAO?
If a regulator came to a DAO tomorrow, the records it would seek are knowable, and they define KYC for DAOs in practice; most DAOs cannot produce them. Expect demands for the identities and screening of multisig signers and core contributors, governance records showing who controlled consequential decisions, treasury flows with counterparty and grantee identification, sanctions-screening logs for disbursements, and any KYC performed on participants who provided or facilitated services.
The defensible posture is to keep that evidence as a by-product of operations: screen signers and document it, KYB treasury counterparties before paying them, log sanctions checks on grants, and gate governance on verifiable credentials so eligibility is provable. A DAO that can produce who controlled what, who received funds, and what was screened is in a far stronger position than one whose answer is that no one was responsible, the exact posture Ooki punished.
When is a DAO genuinely outside scope?
Honesty matters: not every DAO is a VASP, and over-applying KYC where it is not required can itself be a mistake. A genuinely and fully decentralised arrangement, with no identifiable owner or operator profiting from or controlling the service, no ability for any party to change parameters, and no ongoing business relationship with users, may fall outside FATF's VASP definition and outside MiCA's CASP scope. In that case forcing identity collection can create privacy and data-liability problems without a regulatory basis.
The catch is that very few DAOs are actually that decentralised. Most have a core team, a multisig, a treasury, and people who profit or steer, which is precisely the identifiable control FATF and the Ooki court looked for. So the honest test is not "do we call ourselves decentralised" but "is there any identifiable person controlling or facilitating a service." If yes, the compliance surfaces apply. If genuinely no, document why, because that assessment is itself the evidence. If you need help running it, book a DAO compliance posture review.
The bottom line
Ooki ended the comfortable assumption that a DAO is beyond reach. A $643,542 penalty and a finding that token-based governance is membership in an unincorporated association mean KYC for DAOs is now about personal and organisational exposure, not protocol aesthetics. FATF's owner/operator test points the same way: identifiable control brings VASP obligations.
The workable response is targeted, not total: screen multisig signers, KYB treasury counterparties and grantees against current sanctions lists, and gate governance with credential-based verification that proves eligibility without doxxing the community. That posture, decentralised where it can be and verified where it must be, is how a DAO stays compliant without abandoning what makes it a DAO.
Get a DAO compliance posture review, or see how it works.
Related resources
- KYC for crypto
- KYC for crypto exchanges
- FATF Travel Rule compliance for VASPs in 2026
- Crypto compliance software: a 2026 comparison
- Decentralised KYC
- Decentralised PII storage
- How it works
Cited sources
- CFTC, statement on the Ooki DAO litigation victory (June 2023): https://www.cftc.gov/PressRoom/PressReleases/8715-23
- FATF, Updated Guidance for a Risk-Based Approach to Virtual Assets and VASPs (October 2021): https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Guidance-rba-virtual-assets-2021.html
- US Treasury OFAC, sanctions programs (Tornado Cash designation and subsequent changes): https://ofac.treasury.gov/
- ESMA, Markets in Crypto-Assets (MiCA): https://www.esma.europa.eu/
- FATF Recommendations: https://www.fatf-gafi.org/en/topics/fatf-recommendations.html
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.