DeFi is pseudonymous, not anonymous, and the gap matters. Where identity checks apply, why protocols stay permissionless while front ends do not, and what on-chain analysis can work out about you.

The common belief is that DeFi is anonymous and regulators have not caught up. Both halves are wrong, and the second one is expensively wrong for anyone building a business.
A wallet address is a pseudonym. It carries no name, but it carries a complete, permanent, public transaction history.
That history is far more revealing than most people assume. Chain analysis links addresses through shared funding, timing patterns and interaction graphs. One connection to an identified account — an exchange withdrawal, a purchase, a public donation address — and the pseudonym attaches to a person. Retroactively, across the entire history.
This is the practical difference: anonymity would mean nobody can tell. Pseudonymity means nobody can tell yet.
The dividing line is not technical. It is whether a business sits between you and the protocol.
Where it applies: exchanges, fiat on and off ramps, custodial wallets, and increasingly the hosted front ends operated by a company. These are regulated financial services in most jurisdictions, whatever they are built on.
Where it does not: the smart contracts themselves. A lending market cannot verify identity, has no discretion to refuse, and has no operator to serve an obligation on. Interacting directly with a contract from your own wallet involves no counterparty to check you.
This is why the regulatory picture looks contradictory from outside. The protocols really are permissionless. The businesses around them really are regulated. Both statements are true at once.
Europe's framework put this on a formal footing. Crypto-asset service providers need authorisation, and with it come customer due diligence, transaction monitoring and reporting obligations.
The result is a mature vendor category rather than a compliance scramble. Identity verification, business verification for corporate customers, sanctions and PEP screening, and ongoing monitoring are now standard components. We cover the tooling in crypto KYC providers and KYC and KYB software for exchanges.
The Travel Rule adds a second layer: originator and beneficiary information has to travel with transfers between regulated providers, which is why withdrawals to unhosted wallets increasingly prompt extra questions.
For an ordinary user, the workflow is now fairly predictable. You verify identity once at the on-ramp. On-chain activity from your own wallet is not separately gated. When you return to a regulated venue, the funds you bring may be screened for where they have been.
That last part surprises people. Receiving funds that previously passed through a sanctioned or mixed source can flag your account even if you did nothing wrong — which is an argument for caring about provenance, not just custody.
There is a real tension here and it is worth stating without spin.
Financial privacy is a legitimate interest. Publishing your entire transaction history to anyone who asks is not a normal condition of using money, and pseudonymity is a thin substitute for it.
At the same time, the same transparency is what lets anyone verify a protocol's solvency without trusting an auditor. You cannot have verifiable reserves and opaque ledgers simultaneously. The transparency that erodes your privacy is the same property that makes the system checkable.
Zero-knowledge approaches — proving you are eligible without revealing who you are — are the plausible resolution, and they are still early.