Last updated: 30 August 2026
Four statements frequently appear in crypto business plans:
“We are decentralised.”
“We never hold the private keys.”
“We trade only our own money.”
“We only operate mining equipment.”
Each statement may be relevant. None should be treated as a complete licensing opinion.
Pakistan’s PVARA framework regulates functions rather than product labels. The decisive questions are what service is provided, whether it is provided to another person, who controls the customer journey, who can move assets, and who benefits commercially from the arrangement.
A genuinely autonomous protocol, self-custody software, own-account trader or proprietary miner may fall outside a particular licence category. Add a controlled frontend, administrative keys, transaction routing, customer funds, managed strategies or third-party mining services, and the result can change.
PVARA perimeter
- DeFi: No blanket exemption; classify each function
- Non-custodial wallet: Mere software with exclusive user key control is excluded from Custody
- Proprietary trading: Sole own-account trading is separated from Broker-Dealer Services where no customer orders or assets are involved
- Proprietary mining: Expressly outside Mining Services
- Third-party mining: Hosted mining, pools and client reward administration may require a licence
- Key test: Substance, control and service to others—not the technology label
The PVARA functional test
The Virtual Assets Act, 2026 and PVARA licensing framework cover eleven categories, including Advisory, Broker-Dealer, Custody, Exchange, Lending and Borrowing, Derivatives, Management and Investment, Transfer and Settlement, token issuance and Mining-Related Services.
General Activity-Specific Regulation 2 prevents a business from relying on one category to perform another. Where a product combines several regulated functions, each substantive category must be obtained.
For an emerging model, ask:
- Is a service being provided as a business to another person?
- Who contracts with, markets to and supports the user?
- Who controls the website, application or API through which the service is accessed?
- Who can deploy, upgrade, pause or redirect the smart contracts?
- Who determines fees, listings, collateral, liquidations or governance parameters?
- Who holds or can access customer keys, assets or transaction permissions?
- Does the operator route, execute, settle or intermediate transactions?
- Are returns earned solely from the operator’s own assets or from customer participation?
The answers should be supported by code permissions, corporate documents, multisignature arrangements, frontend terms, fee flows and operational evidence.
DeFi platforms: Decentralised technology is not automatic decentralisation
PVARA does not create a standalone “DeFi licence.” A DeFi product must be decomposed into its functions.
A protocol might provide:
- token swaps resembling Exchange or Broker-Dealer Services;
- liquidity pools or borrowing markets resembling Lending and Borrowing;
- automated vaults resembling Management and Investment;
- bridges or routers resembling Transfer and Settlement;
- derivatives, perpetuals or leveraged exposure;
- stablecoin issuance; or
- custody where a person controls assets or access credentials.
The relevant categories apply according to the service actually delivered.
The control test
A project is unlikely to become unregulated merely because transactions settle through immutable code. PVARA can examine whether an identifiable person or group:
- developed and continues to operate the commercial service;
- controls the principal frontend or branded application;
- retains administrative or emergency keys;
- selects or removes pools and assets;
- sets fees or receives protocol revenue;
- controls an oracle, sequencer, bridge or matching mechanism;
- determines collateral ratios or liquidation parameters;
- operates a treasury or market-making function;
- markets the service to Pakistani users; or
- provides customer support and dispute resolution.
DAO terminology does not eliminate control where founders, a foundation, a company or a small multisignature committee can determine material outcomes.
When a protocol may be genuinely decentralised
The licensing analysis is more difficult where:
- smart contracts are immutable;
- no person can pause or upgrade them;
- users interact directly without an operated frontend;
- no identifiable business admits customers or intermediates transactions;
- governance is genuinely dispersed; and
- developers no longer provide the regulated service.
That does not automatically prove exemption. The Act’s territorial reach, the original issuance, continuing fee entitlements, marketing and other legal regimes still require review.
Where no existing category neatly fits a novel model, PVARA’s Regulatory Sandbox may allow controlled testing. The sandbox is not permission to operate an otherwise licensable DeFi business publicly without approval.
Common DeFi licence combinations
| DeFi model | Likely PVARA analysis |
| Operated token-swap interface with controlled liquidity routing | Exchange and/or Broker-Dealer; Transfer analysis |
| Lending pool administered through upgradeable contracts | Lending and Borrowing; possible Custody and Transfer |
| Automated yield vault selecting strategies | Management and Investment; possible Lending, Custody and Broker-Dealer |
| Perpetual DEX with operator-controlled frontend and parameters | Derivatives plus Exchange or Broker-Dealer; possible Custody |
| Branded bridge routing customer transfers | Transfer and Settlement; Custody if assets or keys are controlled |
| Protocol-issued stablecoin | FRT or ART Issuance plus connected categories |
Non-custodial wallets: The private-key test
Regulation 3(2) of the Custody Services Regulations excludes the mere provision of software, hardware or infrastructure that enables the customer to retain exclusive control over private keys.
A basic self-custody wallet may therefore fall outside Custody where:
- keys are generated and remain on the user’s device;
- the provider never receives the seed phrase;
- the user alone can sign and authorize transfers;
- the provider cannot freeze or redirect assets;
- recovery does not give the provider unilateral or joint control; and
- no employee or service provider can access signing credentials.
The exclusion concerns Custody. It does not exempt other services embedded in the wallet.
When “non-custodial” may still involve control
Custody analysis should be revisited where the provider:
- holds one key in a multisignature arrangement;
- can reconstruct or recover the user’s key;
- operates account-abstraction permissions capable of signing transactions;
- controls withdrawal allowlists or approval policies;
- can block, reroute or reverse transfers;
- holds keys during onboarding or migration; or
- uses a third party that can access customer signing credentials.
Control can be joint or indirect. A marketing statement that “we cannot access funds” should be tested against the actual wallet architecture.
Embedded wallet services
A self-custody interface may still require other categories if it:
- routes swaps or receives transaction-based execution revenue;
- recommends assets to individual users;
- initiates or processes transfers as a service;
- aggregates and selects trading venues;
- provides managed yield strategies;
- facilitates lending or staking; or
- sells leveraged or derivative products.
The wallet may remain non-custodial while the surrounding business is a regulated Broker-Dealer, adviser, transfer provider or another VASP.
Proprietary traders: When own-account activity is outside Broker-Dealer Services
Schedule I separates a person dealing solely on its own account from Broker-Dealer Services where the person does not execute customer orders and does not hold or control customer assets.
A genuine proprietary trader ordinarily:
- uses only its own corporate capital;
- trades for its own benefit and risk;
- has no customers;
- accepts no deposits or investment contributions;
- gives no third party a claim to the trading portfolio;
- does not execute or route orders for others; and
- does not market brokerage, management or investment services.
Such a business may fall outside the PVARA Broker-Dealer licensing perimeter. It may still need ordinary corporate registration, tax treatment, lawful banking arrangements and compliance with sanctions, fraud and market-conduct laws.
When proprietary trading becomes a regulated service
The exclusion can fail where the business:
- takes investor or customer funds into trading accounts;
- shares returns through managed accounts or pooled arrangements;
- sells funded-trader accounts or executes participant strategies;
- manages assets for affiliates or beneficial owners;
- offers copy trading or signals tailored to customers;
- makes markets or quotes prices to customers;
- internalises customer orders;
- trades customer collateral; or
- presents itself as a licensed broker or investment manager.
Legal ownership of the trading account is not conclusive. Money labelled a “loan” may economically create a managed-investment or customer arrangement if repayment or return depends on trading performance.
Proprietary activity inside a licensed VASP
Regulation 56 of the Services Regulations applies where a licensed VASP trades as principal or on its own account in connection with customer services. The VASP must maintain governance, limits, transaction records, conflict controls and disclosures.
It must not use customer order information, front-run customers or materially disadvantage them. An Exchange or Broker-Dealer cannot place proprietary activity outside its controls merely by assigning it to an affiliate or treasury desk.
Crypto mining: Proprietary mining versus services for clients
The Mining-Related Services Regulations draw an express line between proprietary mining and third-party service provision.
Regulation 2(3) states that Mining Services cover licensed mining-related activities involving services to third parties and do not include purely proprietary mining outside the licensing perimeter.
Proprietary mining
A company that owns its equipment, pays its own energy costs, mines or validates solely for itself and retains its own rewards ordinarily does not need a Mining-Related Services licence merely for that activity.
Other laws still apply, including those concerning:
- electricity procurement and tariffs;
- grid connection and load approval;
- land use, construction and environmental matters;
- importation and certification of equipment;
- tax and customs;
- cybersecurity and data infrastructure; and
- provincial or sector-specific approvals.
PVARA exclusion does not mean mining can ignore energy or infrastructure regulation.
Regulated Mining Services
A Mining-Related Services licence may apply where a business:
- hosts, manages, maintains or operates mining equipment for clients;
- administers a mining or validation pool;
- pools or routes clients’ computational or validator resources;
- receives client money or virtual assets for mining;
- controls client wallets or mining credentials;
- calculates and allocates mining rewards; or
- distributes rewards to participants.
The minimum paid-up capital for Mining-Related Virtual Asset Services is PKR 500 million, subject to risk-based additions and the continuing liquidity requirement.
Mining controls
A licensed mining provider must address:
- ownership and segregation of client equipment and assets;
- energy sources, capacity and service continuity;
- pool selection and concentration risk;
- hashrate or validator-performance reporting;
- reward calculation, fees and distribution;
- wallet and key management;
- downtime, slashing, forks and protocol changes;
- cybersecurity and physical security;
- conflicts between proprietary and client mining; and
- termination, equipment return and wind-down.
Where the provider holds client rewards or keys, Custody may also apply. Distributing rewards may engage Transfer and Settlement. Staking or validator arrangements may trigger Management, Lending or other analysis depending on asset use and decision-making authority.
A practical decision matrix
| Activity | Licence likely? | Main caution |
| Publishing immutable open-source code with no continuing service | Possibly outside, fact-sensitive | Frontend, fees, control and marketing may change the result |
| Operating an upgradeable DeFi frontend for Pakistani users | Likely category analysis required | Classify swaps, lending, management, derivatives and transfers separately |
| Self-custody wallet with exclusive user keys | Custody generally not required for mere software | Embedded routing or financial services may be licensed |
| Wallet provider holding a recovery or co-signing key | Custody likely relevant | Joint and indirect control count |
| Company trading only its own capital | Generally outside Broker-Dealer perimeter | No customer orders, assets or performance-linked external money |
| Licensed exchange trading its own book | Within licensed-VASP controls | Conflicts, market integrity and information barriers |
| Mining own equipment solely for own rewards | Mining licence generally not required | Energy, tax and infrastructure laws remain |
| Hosted mining or client mining pool | Mining-Related Services likely | Custody and Transfer may also apply |
Evidence for a perimeter assessment
A written opinion should examine more than the website description. Collect:
- smart-contract architecture and audit reports;
- administrative, pause and upgrade-key maps;
- multisignature signers and governance powers;
- frontend and API ownership;
- fee recipients and treasury flows;
- wallet recovery and transaction-signing design;
- customer agreements and risk disclosures;
- source and legal ownership of trading capital;
- investor, loan and profit-sharing agreements;
- mining equipment ownership and hosting contracts; and
- reward calculation, custody and distribution flows.
If the evidence conflicts with the marketing description, PVARA will assess the operational reality.
Common mistakes
Ignoring connected categories. Custody, Transfer, Lending, Management or Derivatives may also apply.
Treating DeFi as an exemption. It is a delivery model, not a licence category.
Equating open-source code with no operator. Frontend, governance and revenue can identify a service provider.
Using a DAO label to disguise concentrated control. Voting distribution and admin keys matter.
Calling a wallet non-custodial without testing recovery. Co-signing or reconstruction may create control.
Ignoring embedded swaps and yield products. Non-custodial technology can deliver licensed services.
Mixing investor money with proprietary capital. External participation changes the own-account analysis.
Using customer information for the proprietary book. Licensed VASPs require strict conflicts controls.
Assuming all mining is exempt. Only purely proprietary mining is outside the Mining Services perimeter.
Calling hosted mining equipment rental. Operating assets and allocating client rewards may be regulated.
Final word
PVARA’s perimeter follows responsibility.
If nobody provides a service, nobody controls the assets and nobody operates the commercial arrangement, the licensing case may be weaker. But most real products have a team controlling the interface, contracts, treasury, fees, keys or customer relationship.
Likewise, using only company capital or mining only company-owned equipment can keep activity proprietary. The moment other people’s money, assets, orders, equipment or rewards enter the model, the analysis changes.
Do not begin with the label “DeFi,” “self-custody,” “prop trading” or “mining.” Begin with control, customers, asset flows and decision-making authority. That is where the PVARA answer is found.
Legal disclaimer: This article provides general information as at 30 August 2026 and does not constitute legal, regulatory, tax, financial, energy or investment advice. Classification depends on the actual software architecture, control rights, customer relationships, funding, asset flows, mining arrangements and territorial connection. PVARA and other authorities may issue additional rules, conditions or interpretations. Businesses should obtain professional advice and confirm current requirements directly with PVARA and all other relevant authorities.
FAQs
1. Does PVARA regulate DeFi?
Potentially. There is no single DeFi licence, but the protocol, frontend or operator may perform one or more regulated services. The analysis turns on functions, control and the service provided to users.
2. Is an immutable smart contract automatically exempt?
No automatic exemption should be assumed. Immutability is relevant, but frontend control, fee rights, governance, marketing, token issuance and territorial connection must also be assessed.
3. Does a self-custody wallet need a Custody licence?
Mere software or hardware allowing the customer exclusive control of private keys is excluded from Custody. Recovery, co-signing or transaction-control features can change the result.
4. Does a company trading only its own crypto need a Broker-Dealer licence?
Generally not where it deals solely on its own account, executes no customer orders and holds no customer assets. The exemption must reflect the funding and operations in practice.
5. Does a Bitcoin miner need a PVARA licence?
Not merely for purely proprietary mining. Providing hosted mining, pooling resources or administering client assets and rewards may require Mining-Related Services authorisation.
6. Can an uncertain DeFi model use the Regulatory Sandbox?
Potentially. PVARA’s sandbox materials contemplate innovative products including DeFi protocols and smart contracts. Admission and testing conditions must be obtained before regulated live activity.