On-chain Credit Starts Adding KYC: Will Permissionless Lending Disappear?

 / 
1

Do you find it strange? On-chain credit scores used to be available without submitting any personal information. Why are more people talking about KYC recently? The truth is that on-chain lending is splitting into two parts. One part stays open: anyone can enter, and no one asks who you are. The other part now asks you to prove who you are first. These two parts will not swallow each other in the short term, but the rules will change.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

Why permissionless lending still survives — because collateral calls the shots

Right now, real "credit score" use cases in DeFi are mostly low-collateral or no-collateral loans. The review logic is simple: you must not default, because the protocol cannot chase you personally. The only way is to make defaulting unprofitable — either through over-collateralization so you repay voluntarily, or by tying a credit score to a wallet address you do not want to abandon.

But if you stay over-collateralized (150% or more), permissionless lending does not need to disappear. The collateral itself is enough to cover risk, so the protocol does not need to know who you are. This means: no matter how much KYC expands, over-collateralized lending can stay permissionless. This is exactly the main part of DeFi lending today — in protocols like Aave and Compound, users deposit ETH to borrow stablecoins. The core risk control is the collateral ratio, not identity.

Why KYC is being added — because institutions want to borrow, and they want to borrow big

The real driver behind KYC entering on-chain credit is not regulators pointing a gun at Aave. It is institutional money wanting to enter, but not being able to get in.

Protocols like Maple Finance, Goldfinch, and Clearpool are basically building a traditional credit desk on-chain. Their borrowers are institutions, not anonymous wallets. Institutional borrowers can get under-collateralized loans, but the cost is passing KYC and off-chain legal agreements first. Aave Arc's Licensed Pools follow the same logic: institutions like Fireblocks must be whitelisted before entering the pool.

These compliant pools and the permissionless Aave main market exist side by side. Compliant pools have more limited liquidity and smaller spreads. The main market has larger spreads and higher yields. Regulation is not cutting off permissionless lending with one stroke. It is letting the market split into two layers — money with different risk appetites goes to different pools.

The ultimate problem: an on-chain native credit bureau is hard to build

Blockbooster's analysis clearly breaks down why on-chain credit's end game is stuck. Three things are needed: persistent identity, cross-protocol default transmission, and standardized scoring. Each of these is extremely hard to build on-chain.

  • Persistent Sybil-resistant identity is a deadlock. Strong identity binding (KYC, biometrics) sacrifices permissionlessness. Lightweight solutions cannot stop someone from switching to a new address and starting over.

  • Credit bureaus are a public goods coordination problem. Traditional credit bureaus took decades of regulation and mergers to form. Expecting a widely adopted credit bureau to grow on-chain within a few years is almost impossible.

Under these structural constraints, products that work today are not building those missing locks on-chain. Instead, they borrow the missing parts from off-chain: legal recourse, biometric identity, and KYC compliance frameworks.

What may disappear is not permissionless lending, but credit-score-based no-collateral loans

That may sound tricky, but the key difference is here:

  • Over-collateralized permissionless lending will not disappear, because collateral itself is the risk control.

  • Low-collateral or no-collateral on-chain lending must either rely on KYC plus legal agreements (the permissioned route), or on a flywheel that rewards borrowers who keep their promises. Protocols like Divine use a "repay to earn credit" logic, letting borrowers turn a clean history into something more valuable.

On the Aave governance forum, someone proposed a ZK compliance layer. Users complete verification with a third-party KYC provider, then generate a ZK proof on-chain. The protocol only verifies the compliance status, without storing any personal information. This could satisfy MiCAR regulatory requirements without turning Aave into a data controller. If this kind of solution works, compliance and privacy do not have to be an either-or choice.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

How to check where you stand

If you care about where on-chain credit is heading, you can do two things:

  1. Check whether the protocol you are using has a KYC entry. If the protocol has Licensed Pools or a KYC whitelist, but you have not completed identity verification, confirm whether your pool is a permissionless market. In protocols like Aave, compliant pools and permissionless pools are isolated. If you have been using the permissionless version, you do not need to worry for now.

  2. Watch the borrower structure of low-collateral protocols. If you deposit in protocols like Maple or Clearpool, check the borrower list. If most borrowers are institutions that passed KYC, then KYC itself is not a bad thing; it may lower default risk. The real risk is borrowers who have neither KYC nor collateral.