The Vault Vacuum: The Registration Status of DeFi Vault Protocols Under U.S. Federal Securities and Commodities Laws
A Regulatory Analysis for DeFi Vault Operators, Protocol Developers, and Yield Platform Participants in the wake of Commissioner Hester Peirce’s Warning to Market Participants
August 10, 2026
On July 22, 2026, Commissioner Hester Peirce put the DeFi industry on notice. In a statement addressing DeFi vaults and lending strategies, she warned that market participants who “do headstands, backflips, and other gymnastics to read the law so that it does not apply to crypto assets and activities that are well within the scope of the federal securities laws… will have a painful fall.”[1] The message was unambiguous: the novel technological architecture underlying these protocols is not, on its own, enough of a basis to avoid registration. It may also indicate that this period of unfettered growth is coming to an end.
I. Introduction
The digital asset industry has produced no shortage of novel financial architectures, but few present as thorny a set of registration questions as the decentralized finance (“DeFi”) vault protocol. The basic pitch is disarmingly simple: deposit your crypto here, and we will make it grow. Of course, this is also, roughly speaking, the basic pitch of every pooled investment vehicle regulated under U.S. law since 1940. These smart-contract-based systems, which aggregate depositor funds and deploy them across yield-generating strategies, occupy a unique position in the U.S. regulatory landscape. They closely resemble the pooled investment vehicles and financial intermediaries that Congress brought within the ambit of federal securities and commodities regulation nearly a century ago[2]. However, they operate openly without SEC registration.
Is this multi-billion dollar market segment simply a group of daring mavericks temporarily operating with impunity until a future administration reins them in with a wave of enforcement actions? Or have these entrepreneurs genuinely invented new, distinct functions that properly operate outside of the traditional registration regime? Or is it something in between?
And, if these vaults and their curators really are something new and distinct, what risks do they pose by operating in a way so functionally similar to a traditionally registered entity, but outside the system of protections offered by the SEC?
In the medium and long term, the classification of DeFi vault protocols and the entities and individuals operating them remains uncertain. The consequences for the protocols and their operators of getting this analysis wrong are potentially severe: civil enforcement actions, disgorgement and penalties, criminal referrals, and the existential risk of being ordered to cease operations entirely. The risk of permitting a shadow market of legitimate quasi-investment advisers operating outside of the SEC’s or CFTC’s investor protection regimes is open to debate.
In this article, we provide a structured analysis of the registration frameworks most likely to apply to DeFi vault protocol operators under current U.S. law. We examine the Investment Company Act of 1940, the Investment Advisers Act of 1940, the Securities Act of 1933, the Commodity Exchange Act, and the Bank Secrecy Act, identifying the functional characteristics of vault protocols that may trigger registration requirements under each regime. We explore the protections offered by, and burdens imposed by, registration, the structural similarities between vaults and curators and traditionally registered entities, and possible rationales for operating outside of the regulatory regime.
II. What Are DeFi Vault Protocols?
DeFi vault protocols are smart-contract-based systems that aggregate depositor funds and deploy them across one or more yield-generating strategies. They act like programmable, non-custodial managed accounts on chain. Upon deposit, the vault’s controller (the architectural component that runs the strategy logic) runs predefined logic to route deposits into strategies such as lending, liquidity provision, staking, and arbitrage or delta-neutral trading. There are multiple types of vault protocols, including (1) yield-generating vaults, in which stablecoins or liquid assets are deposited to earn yield through automated allocation to lending platforms or liquidity pools; (2) real world asset (“RWA”) backed vaults, in which off-chain assets such as T-bills or private credit are tokenized and held, streaming predictable yield while maintaining on-chain visibility; (3) delta-neutral vaults, which utilize long and short hedging to generate income without taking direct market exposure; (4) leveraged loopers, in which stablecoins are borrowed against collateral and re-deployed into the same strategy to further boost yield; and (5) multi-strategy vaults, which blend stablecoins, RWAs, or staking across different strategies to provide multifaceted exposure.
A. How DeFi Vaults Operate
Typically, a depositor sends digital assets to a vault smart contract. In return, the depositor receives a vault token, LP share, or receipt token representing a proportional claim on the vault’s pooled assets and accumulated yield. The vault’s smart contracts, operating according to a predefined or dynamically adjusted strategy, then deploy the pooled deposits across one or more DeFi protocols to generate returns. The depositor is then able to redeem their vault token for the underlying asset at any time to receive their principal and accrued interest.
B. Governance and Control Structures
DeFi vault protocols exhibit a spectrum of governance and control arrangements, each with distinct implications for regulatory classification. At one end are vaults governed by a centralized development team that retains full control over strategy selection. At the other end are vaults governed by decentralized autonomous organizations (DAOs), in which governance token holders vote on strategy proposals, fee structures, and protocol upgrades. In between sits the curator model, in which a protocol developer delegates the asset management function to independent third-party curators who exercise discretion within the constraints of the smart contract architecture.
C. Fee Structures and Revenue Models
DeFi vault operators typically generate revenue through management fees (a percentage of assets under management), performance fees (a percentage of yield generated), or both. As discussed below, these fee arrangements are relevant to the registration analysis: the receipt of compensation for deploying or managing pooled assets is a threshold element of several federal registration regimes, including investment adviser and commodity pool operator registration.
III. Commissioner Peirce Steps into the Void: Recent Statement on Crypto Vaults
On July 22, 2026, Commissioner Hester M. Peirce issued a statement titled “Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies,” providing the first direct analysis from SEC personnel on DeFi vaults. The statement’s core message was that moving traditional financial activities onchain does not exempt them from federal securities laws. Peirce warned that market participants who “do headstands, backflips, and other gymnastics to read the law” to evade securities regulation “will have a painful fall.”
Commissioner Peirce acknowledged that vaults occupy a spectrum of governance structures, ranging from fully automated systems governed by immutable smart contracts to arrangements involving significant human discretion over asset allocation. She noted that parties involved in selecting yield-generating activities, reallocating assets, or choosing decision-makers “may want to analyze whether their activities implicate the federal securities laws.”
The statement identified several potential regulatory issues. A vault could constitute an investment contract, vaults holding or allocating assets to securities could trigger Investment Company Act requirements, and onchain lending notes could qualify as securities under the Reves test. Additionally, Commissioner Peirce noted that involvement in managing vaults and lending strategies “may implicate investment adviser issues.”
Notably, Commissioner Peirce struck a collaborative tone, inviting market participants to engage with the SEC. “We welcome inquiries from market participants involved in designing and operating vaults or facilitating onchain lending,” she stated, adding that the SEC is open to discussing “how to serve your customers in compliance with the federal securities laws.” She also acknowledged that existing regulations may need modification to accommodate innovation, inviting industry input on potential rule changes that would protect investors while facilitating capital formation.
IV. The Uncanny Valley: Vaults and their Curators Share Many Attributes of Regulated Entities
Arguably, the defining feature of DeFi vault protocols, from a regulatory perspective, is that they pool user assets and deploy them in a manner that closely resembles the operations of traditional pooled investment vehicles, managed accounts, or commodity pools. In many cases, the vault operator exercises discretion over how deposited assets are allocated, rebalanced, and harvested.
At the same time, DeFi vaults are built on permissionless, open-source smart contract infrastructure that was not designed with federal registration frameworks in mind. They operate globally, around the clock, and without traditional intermediary relationships.
Let us begin with the straightforward reading of existing law — the reading that, if you squint, makes DeFi vault operators look a lot like old school regulated intermediaries.
A. Vault Token Purchases as Investments
The threshold question for any DeFi vault is whether the product constitutes a “security” within the meaning of the federal securities laws. If it does, the registration, disclosure, and antifraud requirements under the Securities Act of 1933 and the Securities Exchange Act of 1934 apply. The well-established frameworks of the Howey test and the Reves test provide the analytical tools for making this determination.
Under the Howey test, a transaction constitutes an investment contract if it involves (1) an investment of money, (2) in a common enterprise, (3) with the expectation of profits, (4) derived from the essential managerial efforts of others.[3] Generally, with DeFi vaults, the first two prongs are relatively straightforward: a depositor commits crypto assets, which courts have recognized as satisfying the “investment of money” requirement,[4] into a pooled vehicle that aggregates capital from multiple participants, creating a common enterprise. The third prong is similarly met where the vault markets itself as offering yield or returns. The fourth prong, however, is where the analysis becomes more nuanced. In a fully automated vault governed entirely by immutable smart contracts, one could argue that no “essential managerial efforts of others” exist and that the protocol simply executes pre-programmed logic. However, where a vault’s strategy is actively managed, periodically rebalanced, or subject to governance decisions by a core team or DAO, the case for satisfying the fourth prong strengthens considerably.[5] The more discretion human actors exercise over the deployment and management of deposited assets, the more likely it is that a vault will be characterized as an investment contract.
Commissioner Peirce’s statement on DeFi vaults acknowledges that vault operators occupy a spectrum of involvement in which operators may engage in ranging from little to no human involvement via programmatic allocations determined by smart contracts, to allocations at the sole discretion of a person or group of persons. She noted that active involvement in vault strategy management may implicate the federal securities laws. Most notably, she warned that a vault could constitute “a common enterprise in which users invest money with a reasonable expectation of profits to be derived from the vault deployer’s and curator’s entrepreneurial or managerial efforts,” and that a vault holding securities or allocating assets to securities investments “could fall into investment company territory.”[6]
Under the securities laws, “notes” are also considered de facto securities. Under the Reves test, a note is presumed to be a security unless it bears a “resemblance” to an enumerated category of instruments already determined not to be securities.[7] If you call your product a “bond” and it pays a fixed return, the Reves analysis is not going to be suspenseful.
There are few clues as to how the SEC views vault investments. One important indication is the 2023 settled enforcement action against BarnBridge DAO.[8] BarnBridge operated SMART Yield pools that collected stablecoin deposits from investors and deployed them into third-party crypto lending platforms to earn interest. BarnBridge advertised these products as fixed income notes. Between March 2021 and March 2023, more than $509 million worth of crypto assets were invested into SMART Yield Pools by investors using 1,235 unique addresses. The SEC applied the Reves test, finding that SMART Yield bonds were “fixed income debt securities in the form of a callable note” since BarnBridge explicitly characterized its SMART Yield pools as “fixed income” instruments that offered “senior” and “junior” tranches with predictable yield profiles. Because BarnBridge did not file a registration statement or qualify for an exemption, the SEC found that BarnBridge violated Sections 5(a) and 5(c) of the Securities Act (15 U.S.C. §§ 77e(a), (c)) by engaging in an unregistered offering.
The BarnBridge enforcement action carries significant implications for contemporary vault protocols. The SEC’s analysis focused heavily on the marketing of the product. Modern vault protocols that market their products using language suggestive of fixed returns, debt obligations, or income-generating notes or describes itself as offering “yield” or “returns” on deposits may be increasing the similarity to a registered Investment Adviser. As discussed below, this risk exists irrespective of whether the assets within the vault are securities or not. The BarnBridge settlement confirmed that the SEC is willing to look through to identify the source of human control. The Commission described BarnBridge as a “purportedly decentralized autonomous organization” and held its two co-founders personally liable as “control persons” who were responsible for the unregistered offering.[9] For vault curators who operate under a DAO umbrella or claim that governance is sufficiently “decentralized” to avoid securities law liability, BarnBridge offers a sobering precedent: the SEC could identify the individuals who designed, launched, and controlled the protocol’s investment strategy, and it will hold them accountable regardless of the governance labels attached to the organization.
B. Vaults as Investment Companies
The Investment Company Act of 1940 regulates pooled investment vehicles, i.e., entities that collect investor capital and invest it in securities. Under Section 3(a)(1)(C) of the Act (15 U.S.C. § 80a-3(a)(1)(C)), any issuer that is engaged or proposes to engage in the business of investing, reinvesting, owning, holding, or trading in securities, and that owns or proposes to acquire investment securities having a value exceeding 40 percent of the value of its total assets (exclusive of government securities and cash items), qualifies as an investment company and must register with the SEC.
Like BarnBridge’s SMART Yield Pools, modern vaults aggregate depositor capital, deploy it to third-party lending or liquidity protocols, and distribute yield back to depositors on a pro rata basis. The economic substance is nearly identical: a depositor provides capital, a protocol (or curator) decides where to deploy it, and the depositor receives yield generated by those deployment decisions.
In BarnBridge, the SEC found that the SMART Yield pools constituted unregistered investment companies under Section 3(a)(1)(C), because the pools were engaged in the business of investing in assets that qualified as investment securities, and those securities exceeded 40 percent of each pool’s total assets. Importantly, the Investment Company Act analysis turns on the character of the assets within the vault. Vaults that hold and invest in securities may trigger registration requirements. By contrast, a vault that deploys exclusively into overcollateralized lending markets, where the underlying loans are fairly characterized as non-securities, would not meet the 40% threshold and would not be required to register as an investment company.
C. Curators as Investment Advisers
For vault curators that deploy strategies that hold and invest in securities, the Investment Advisers Act of 1940 may present a natural fit. The statute regulates any person who, for compensation, engages in the business of advising others as to the value of securities or as to the advisability of investing in, purchasing, or selling securities. Whether a particular curator meets this definition requires an analysis of each of the definition’s three elements: (1) whether the curator provides advice regarding securities; (2) whether the curator is engaged in the business of providing such advice; and (3) whether the curator receives compensation for such advice. For vaults that hold and invest in securities, a vault curator who makes discretionary decisions about where to deploy pooled user assets, i.e., selecting lending venues, setting allocation weights, rebalancing across strategies, and who charges a fee for doing so, is performing almost exactly the function of an investment adviser. The second prong – whether the person is “engaged in the business” of providing investment advice – is where the SEC’s interpretive guidance becomes particularly relevant. The SEC has advised that providing investment advice does not have to be a person’s sole or even primary business activity. As the SEC explained in Release IA-1092, the inquiry is whether the advisory activity is conducted “on such basis that it constitutes a business activity occurring with some regularity.” For vault curators, the compensation element is typically satisfied given that most charge management fees, performance fees, or both. As to the third factor, regularity of advice, curators who actively manage vault allocations, rebalance positions in response to market conditions, or update strategies on an ongoing basis are providing investment advice with more than occasional frequency.
D. Potential CEA Registration
DeFi vaults that deploy depositor assets into strategies involving derivatives, or involving leveraged and margined retail commodity transactions may be engaging in activities that only CFTC registrants may lawfully conduct.[10] Vaults that trade in these products could be characterized as unregistered Commodity Pools, and curators/operators may be required to register as a Commodity Trading Advisors or Commodity Pool Operators. The CFTC’s enforcement actions against bZeroX, LLC (“bZeroX”), its founders Tom Bean and Kyle Kistner, and bZeroX’s successor, Ooki DAO—which[11] resulted in the first federal court order to shut down and classify a DAO as a “Person” for registration purposes—demonstrate that the Commission does not regard decentralized architecture alone as a defense against registration of both the platform and the controlling persons.
E. The FinCEN Question
Another classification question that arises is whether such curators may be considered money transmitters. Money transmitters are businesses that accept currency or funds from one person and send them to others by any means. This classification is broad and at first glance, very well may capture some vault curators, to the extent they can be said to maintain custody or control over funds. If classified as a money transmitter, a vault curator would be considered a Money Services Business and, on the federal level, be required to register with the Financial Crimes Enforcement Network (“FINCEN”). Each state may also require registration with the respective state regulator. As such, compliance with federal and state regulators can result in a large and complex undertaking with noncompliance resulting in fines and even prison time.[12] However, under FinCEN’s 2019 framework,[13] a person who deploys immutable, non-upgradeable smart contract infrastructure and exercises no ongoing custody or transmission function has a strong argument that they are merely providing infrastructure services—not acting as a money transmitter. But curators who exercise ongoing discretion over how pooled assets are deployed across markets, even if they lack the technical ability to withdraw funds directly, occupy a gray zone that FinCEN has not definitively addressed. The distinction between “control over strategy” and “control over assets” has not been resolved, and vault operators should not assume that the absence of withdrawal authority is dispositive.
IV. The Case for the Defense: Why Vaults Escape the Grasp of Registration
And yet, here we are in mid-2026, and the vault ecosystem is not operating in the shadows. It operates in broad daylight, with total deposits reaching $131 billion as of April 2026 (up from $24 billion in April 2023), institutional backing from Coinbase, Apollo, Wintermute, and Bitwise, and no apparent expectation from anyone that the deployers of vault software or vault curators need to register with the SEC as investment advisers or that vaults themselves need to register as investment companies.
This is not how unregistered markets typically behave. Participants in genuinely illegal markets do not publish their strategies on public dashboards, submit comment letters to the CFTC, or partner with NASDAQ-listed companies. Something else is going on. Below we will explore some of the best arguments for why these entities do not require registration with the SEC or CFTC.
A. Vault Interests Are Not Securities
The threshold argument is definitional: the securities law analysis turns on (1) whether the assets within the vault are securities, (2) whether the relationship between the vault curator and depositors constitutes an investment contract under Howey, and (3) whether the receipt tokens themselves are securities. If none of these elements involve securities, then neither the Securities Act nor the Investment Company Act applies, and the entire SEC registration framework is inapposite. Accordingly, the most obvious answer to the question, Why don’t Vault providers and curators need to register with the SEC? is: there aren’t any securities involved.
The clearest application of this argument relates to the Investment Company Act. If the assets within a vault are not securities but, for example, stablecoins or non-security digital commodities, then the vault need not register under that Act.
There is a strong argument that vault receipt tokens themselves are not securities. A vault receipt token represents a pro rata claim on a pool of lending positions. The argument is that this is economically closer to a bank deposit or a participation in a loan syndication than to a share in an investment company. The depositor is not buying a “security”; rather, the depositor is lending stablecoins and receiving a receipt. The March 2026 SEC-CFTC Joint Interpretive Release supports this view. See SEC & CFTC, Joint Interpretive Release on Digital Asset Activities (Mar. 2026). According to that Release, certain DeFi activities, including staking, wrapping, and administrative or ministerial functions, are expressly excluded from the securities framework. If vault deposit tokens are characterized as receipts evidencing a lending position rather than investment contracts, they may fall outside the Howey analysis entirely.
Of course, the SEC did not apply Howey to the BarnBridge SMART Yield product, and it did not focus on receipt tokens. There, the SEC applied the Reves “notes” test and found them to be securities precisely because they promised returns based on pool performance. The argument that vault interests are not securities may work best for vaults that (1) do not involve active discretionary management by a curator, and (2) operate according to a fixed, published strategy that executes automatically via smart contracts.
The BarnBridge precedent provides one roadmap for distinguishing vault products from securities. Several factors merit consideration: (1) whether the vault markets itself using fixed-income terminology (as BarnBridge did) or merely as a mechanism for participating in DeFi lending markets; (2) whether depositors receive a token that promises a specific return or rate, or a receipt representing a proportional claim; (3) whether the vault operator exercises discretionary control over strategy, or whether the deployment is governed entirely by immutable, transparent smart contract logic; and (4) whether the vault primarily deploys into overcollateralized lending markets (which may be characterized as “loans” under Reves) or into more complex instruments that more closely resemble securities. Vault operators who can clearly distinguish their products from BarnBridge along multiple dimensions have a stronger argument that their tokens fall outside the securities framework.
B. Lending Markets vs. Investment Vehicles
A related argument focuses on the underlying activity. Vaults do not “invest” in the traditional sense. Instead, they allocate deposits to overcollateralized lending markets where borrowers post collateral and pay interest. Nothing is “purchased or sold” in the way that a mutual fund purchases equities or bonds on a secondary market. The vault simply makes loans (or, more precisely, supplies liquidity to smart contracts that make loans) and earns interest on those loans.
The argument is that lending is not “investing in securities” for purposes of the Investment Company Act. A bank that makes loans is not an investment company. A loan syndication participant is not buying securities.[14] If what the vault does is make overcollateralized loans (or allocate to markets that make such loans), then even if 100% of the vault’s assets are deployed, they are deployed in loans, not investment securities — and the 40% test under Section 3(a)(1)(C) is not triggered.
This argument has roots in traditional finance lending analyses as well. The Commission has long distinguished between notes that are “securities” and ordinary commercial lending. In Reves, the Supreme Court identified several categories of notes that are not securities, including notes delivered in consumer financing, notes secured by a home mortgage, short-term notes secured by a lien on a small business, notes evidencing character loans to bank customers, and notes formalizing open-account debts incurred in the ordinary course of business. The common thread is that these instruments arise from a commercial or consumer lending context rather than an investment context.
If vaults participate in lending in functionally the same way as banks do, the same regulatory framework should apply. When a depositor places funds with a bank, the bank lends those funds to borrowers and pays the depositor interest. There would be no suggestion that the depositor has purchased a security. If DeFi vaults are functionally equivalent to decentralized banks in that they accept deposits and make overcollateralized loans, then perhaps they should be regulated (if at all) under a banking-like framework rather than a securities framework. However, this argument crumbles if the underlying instrument into which the vault deploys capital is itself a security.
C. When A Curator Is Not “Managing” a Methodology
One of the most interesting arguments goes to the Investment Advisers Act. The claim is that a curator does not provide personalized “advice” in the statutory sense because the vault’s strategy, parameters, allocation methodology, and risk framework are all published transparently on-chain and in public documentation. Every depositor receives the same treatment. No one is being “advised” in the way that a wealth manager advises a client. The curator is simply publishing a model portfolio and anyone who wants to can participate in it (or leave it).
This argument tracks the publisher’s exclusion under Section 202(a)(11)(D) of the Advisers Act (15 U.S.C. § 80b-2(a)(11)(D)), which exempts publishers of bona fide publications providing impersonal investment advice. A fully transparent, on-chain strategy that anyone can inspect, that treats all depositors identically, and from which anyone can exit at any time without permission, is arguably more like publishing a newsletter than running a managed account. The curator’s methodology is the publication. The vault is the distribution mechanism.
We don’t find this argument persuasive. The publisher’s exclusion has historically been interpreted narrowly. It applies to genuinely impersonal advice and has not historically been applied to discretionary management of pooled assets. A curator who dynamically rebalances allocations in response to market conditions, who is compensated through performance fees (not subscription fees), and who exercises ongoing judgment is arguably doing something qualitatively different from publishing a static model portfolio. The SEC’s view, expressed in multiple no-action letters and enforcement contexts, is that the exclusion does not cover persons who exercise ongoing discretionary authority over client assets.[15]
D. The Non-Custodial Architecture Eliminates the Core Harms
Another structural, policy-focused argument is that the non-custodial design of vaults eliminates the specific harms that registration was designed to prevent. In most vaults, curators cannot withdraw user funds; they can only reallocate them between approved markets. Users retain full withdrawal rights at all times without intermediary approval.[16]
The traditional harms that registration is designed to prevent, e.g. misappropriation, self-dealing, and commingling, are structurally mitigated (though not eliminated) by the architecture itself. A curator who cannot touch depositor funds presents a different risk profile than a fund manager who holds assets in an omnibus account. The vault’s smart contract enforces the separation that, in traditional finance, must be policed by regulation and audit. If the purpose of registration is investor protection, and the architecture already provides many of those protections through code, then perhaps the regulatory overlay is unnecessary — or at least requires a different, lighter-touch framework.
This architectural argument has intuitive appeal, but it requires careful qualification. The non-custodial design does mitigate certain risks, the curator cannot abscond with depositor funds, cannot commingle assets with their own, and cannot preferentially redeem favored investors ahead of others. These are real protections that code enforces more reliably than auditors or regulators could.
However, the non-custodial architecture does not eliminate all investor protection concerns and creates a different set of risk factors. Smart contract risk remains significant: bugs, exploits, or oracle manipulation can result in total loss of deposited funds, and unlike regulated entities, vault protocols typically disclaim all liability and offer no recourse. Governance risk persists where DAOs or multisig holders can modify vault parameters, whitelist new strategies, or change fee structures. Economic risk — the risk that the curator’s strategy simply underperforms or that market conditions cause losses — is not addressed by custody arrangements at all.
The more sophisticated version of this argument focuses on substitutability: non-custodial architecture can substitute code-based protections for regulation-based protections. Where the Investment Company Act requires independent boards and leverage limits, smart contracts can enforce allocation constraints and borrowing caps. Where the Advisers Act requires conflict disclosure, on-chain transparency allows anyone to inspect exactly where assets are deployed. Some vault protocols have introduced additional governance safeguards, including “guardians” or “sentinels” who act as a check on curators’ ability to change a vault’s strategy or key risk parameters, and “time-locks” that impose waiting periods (typically around three days) before exposure changes take effect, giving depositors the opportunity to exit before new risk profiles are implemented. The question is whether these code-based protections are adequate substitutes — or whether they address different risks than the ones registration was designed to prevent.
Regulators have historically been skeptical of “the technology makes regulation unnecessary” arguments. The SEC’s consistent position has been that it regulates activities, not technologies, and that functionally equivalent activities warrant equivalent regulation regardless of the delivery mechanism.[17] A vault that performs the economic function of a managed investment product may be subject to managed investment product regulation even if its technological architecture differs from traditional funds.
Commissioner Peirce’s July 2026 statement is consisted with this longstanding regulatory philosophy. Although she acknowledges that vaults “fall along a spectrum” of governance structures, she was clear that “[m]oving activities that fall within the scope of the federal securities laws onchain, as a general matter, does not take those activities outside the scope of the laws the Commission administers.” At the same time, her statement came with an invitation to collaborate with market participants.[18] This invitation to dialogue, rather than an enforcement-first posture, represents a meaningful shift in the SEC’s approach to emerging DeFi structures. Despite this collaborative tone, the burden still lies on the industry to demonstrate that the architectural differences are not merely formal but genuinely eliminate the harms that registration is designed to prevent, and to address the additional harms that may arise from the technological infrastructure itself.
E. “Engaged in the Business”
Generally, the SEC staff considers a person to be “engaged in the business” of providing investment advice if they hold themselves out as an adviser.[19] Traditionally, indicia of “holding out” include advertising as an “investment adviser” or “investment manager,” including using letterhead indicating the same.
Certainly, vault curators do not hold themselves out as investment advisers, in that they do not identify as such. Can this really be enough? Can you avoid registration simply by artfully avoiding describing yourself as an “investment adviser” or similar title?
The short answer is probably not. The SEC has made clear that the “engaged in the business” inquiry is fact specific. The 2019 Commission Interpretation Regarding Standard of Conduct for Investment Advisers[20] emphasized that the determination depends on whether a person “holds himself or herself out as an investment adviser or as providing investment advice,” but also that the determination relies on the totality of the circumstances, including (1) whether the person receives compensation, (2) whether they provide advice with some regularity, and (3) whether they provide advice to others as part of a business.
Further, the determination that a curator is “holding out” as an adviser is similarly fact intensive. An analogy can be drawn to robo-advisors, which provide automated investment services. The Commission determined that, although robo-advisors were not marketed in the context of investment advisory services, the services constituted substantially the same function — namely, providing recommendations regarding securities.[21]
The dispositive consideration is that if a curator wishes to avoid adviser categorization, it must structure the protocol as genuinely ministerial by publishing a fixed, rules-based methodology that executes automatically without ongoing human judgment. A curator who exercises any discretion after the initial publication will potentially subject itself to registration requirements.
F. Don’t Forget about the Commodity Exchange Act.
The CEA defines a “Commodity Pool” as any “ investment trust, syndicate, or similar form of enterprise operated for the purpose of trading in commodity interests,” where “commodity interests” means futures, options, swaps, or “Retail Commodity Transaction” (broadly, commodities traded on leverage). Commodity Pool Operators are persons who are “engaged in a business that is of the nature of a commodity pool” and “solicits, accepts, or receives from others” funds to trade in such pools.
Vaults that deploy exclusively into overcollateralized lending markets almost certainly are not engaging in activities regulated by the CFTC, as the underlying assets would not be “commodity interests.” But some vaults generate yield by trading in perps, leveraged products, or other on-chain products that could be so considered. Are vaults that trade in commodity interests Commodity Pools, and are vault curators unregistered commodity pool operators?
In the CFTC’s successful enforcement actions against bZeroX and Ooki DAO, the CFTC looked through the decentralized nature of the DAO offering Retail Commodity Transactions, and focused liability both on the structure as a whole and on the individuals most responsible for running it. We think that vaults that engage in significant activities involving derivatives, and do not take sufficient steps to exclude U.S. persons from depositing into the vaults, are at real risk of a CFTC enforcement case (assuming the CFTC decides to wade back into the enforcement business).
Despite these arguments, even if the CFTC’s jurisdiction is extended to vault protocols, it may not be exclusive. Vaults that deploy into both lending markets and derivative-like strategies could face overlapping SEC and CFTC jurisdiction. The March 2026 Joint Interpretive Release (the “Interpretive Release”) attempted to clarify jurisdictional boundaries, but significant gray areas remain.[22] According to the Interpretive Release, a vault operator who tries registers as a CTA or a CPO may still face SEC enforcement if the vault tokens themselves are deemed securities.
V. The Stakes: What Is Gained and Lost When Quasi-Advisers Operate Outside the Traditional System?
The preceding sections have analyzed whether DeFi vault protocols and their curators are required to register under existing law. But there is a distinct and equally important question: even if they can avoid registration, should they? What are the costs to investors and to markets of permitting a $131 billion industry of quasi-investment advisers to operate without the protections that registration provides?
The Investment Company Act and the Investment Advisers Act were enacted in the aftermath of the 1929 crash and the ensuing market failures to address specific, well-documented harms: conflicts of interest between managers and investors, self-dealing, lack of transparency in pooled vehicles, and the tendency of unsophisticated investors to be harmed by undisclosed risks in managed products.
The Investment Advisers Act imposes fiduciary duties on registered advisers: the duty of loyalty, requiring advisers to act in clients’ best interests and not place the adviser’s interests ahead of clients’; and the duty of care, requiring advisers to provide advice that is suitable and based on reasonable investigation.[23] These duties are enforceable by the SEC and, in many cases, by private litigants. Unregistered curators owe no such duties. A curator who allocates vault assets to a protocol in which the curator holds a governance stake, or who receives undisclosed compensation from a lending platform for directing deposits, faces no legal consequence under the Advisers Act if the curator is deemed outside the statutory categorization.
The Investment Company Act imposes structural protections on registered funds. These protections aim to prevent specific, well-documented risks of self-dealing and conflicts of interest. DeFi vaults that aggregate user capital and deploy it at the discretion of a curator are not immune to these risks. The non-custodial architecture mitigates some concerns but does not address conflicts that arise in protocol development, fee structure determinations, or preferential treatment of affiliated protocols.
Without the requirement of regulation, disclosure and reporting are at the discretion of vault operators and curators. Registered advisers, on the other hand, are required to file Form ADV, which addresses a wide range of items including fees, conflicts, disciplinary history, and investment strategies. Registered investment companies must provide prospectuses and shareholder reports that thoroughly address risk factors. Unregistered vaults decide what to disclose and when to disclose it, with many choosing to provide only the smart contract address. As a result, the vault market’s standards for disclosures vary widely and are generally not comprehensive, with platforms typically emphasizing headline yield metrics while offering limited detail on the risk to depositor funds. Unsophisticated depositors are left vulnerable to the risks associated with depositing funds, and potentially nefarious vault providers may take advantage of consumers.
The question is not whether the protections are important — they are. The question is whether DeFi vault protocols, which arguably perform economically similar functions using different technological infrastructure, can credibly claim that the protections are unnecessary because the infrastructure is “decentralized” or “non-custodial” or “permissionless.” The SEC, for its part, has indicated in the BarnBridge action that it does not find that this defense is persuasive.
What we are left with is not a clean answer but a deeply uncomfortable uncertainty — and a market that has exploded with innovation, growth, and capital inflows that have outpaced the regulatory response.
The DeFi vault category has consolidated around the curator model with remarkable speed. By April 2026, total vault deposits reached $131 billion, while the curator market has become increasingly concentrated, with the number of curators holding at least 5% market share declining from five to three over the preceding 12 months. Annualized interest of $227 million was paid to lenders on a single platform in 2025, a 400% increase over 2024, while annualized curator fees grew from just below $2 million to $13 million — a 600% increase.[24] This is a multi-billion-dollar industry in which professional risk managers charge fees for discretionary asset allocation—an activity that, in any other context, would unambiguously trigger federal registration requirements.
At the systemic level, the growth of this unregulated shadow asset management industry raises concerns that echo the pre-2008 shadow banking system. When regulated and unregulated entities compete for the same capital, the unregulated entities enjoy a cost advantage and also may take risks that regulated entities cannot. If the unregulated sector grows large enough, its failures can have spillover effects on the broader market.
One particularly concerning risk is looping, a widely used capital efficiency strategy in vaults. Looping involves the recursive use of borrowed funds as collateral to generate amplified exposure: a depositor borrows against vault shares, uses the proceeds to acquire more of the same or correlated assets, posts those assets as collateral, and repeats the process. This activity may occur at the depositor level, resembling traditional margin investing, or at the vault level, where a curator embeds leverage directly into the vault’s investment strategy, thereby increasing both expected yield and downside exposure for all depositors.
This is the kind of risk for which regulation may be prudent. In the registered funds and investment advisory contexts, leverage, borrowing, derivatives exposure, conflicts of interest, liquidity risks, valuation practices, and investment strategies are subject to disclosure, governance, and compliance obligations. Investment companies must disclose material risks and investment practices to investors, operate within regulatory limits on leverage and senior securities, maintain compliance programs, and provide periodic reporting. Investment advisers likewise have fiduciary obligations and must disclose material risks, conflicts, methods of analysis, and investment strategies, including circumstances in which those strategies may expose clients to heightened losses. These requirements are designed to ensure that investors understand not only the potential return profile of a strategy, but also the mechanisms by which losses may be magnified.
Looping across multiple asset classes creates such heightened interconnected risk surfaces that are difficult for investors to evaluate absent standardized disclosure. Each additional asset class that can be looped expands the potential for correlated liquidations and cross-protocol contagion. When asset values decline, the leverage created through looping can force rapid deleveraging, causing liquidations in one protocol to depress collateral values elsewhere and triggering further liquidations. These procyclical feedback effects can accelerate market stress and impose losses on investors who could not have understood the extent of embedded leverage within the vault strategy absent disclosures. Registration and disclosure requirements would therefore help ensure that vault operators and curators clearly identify looping strategies, disclose liquidation triggers and counterparty dependencies. It is prudent that investors be provided with the information necessary to assess whether the promised yield justifies such substantial risks.
On the other hand, the traditional registration frameworks are, as outlined, not well suited to DeFi’s technological infrastructure. Requiring vault protocols to register as investment companies and curators to register as investment advisors would impose structures and requirements on the protocols that may conflict with the framework and governance structures.
***
Despite the striking industry adoption, resemblance to traditionally registered investment vehicles, until Commissioner Peirce’s recent statements, the regulators have been silent. The CFTC has not sued major vault providers. The SEC has not sent major vault curators Wells notices. Coinbase’s legal team apparently concluded that routing customer deposits through these vaults is consistent with its regulatory obligations.
Several explanations for this state of affairs merit consideration, and they are not mutually exclusive:
- Non-custodial architecture may genuinely distinguish these arrangements from traditional managed products, and regulators may have implicitly accepted this distinction—at least for now.
- The current administration’s pro-crypto posture has created an enforcement hiatus that may not survive a change in political leadership. The SEC dismissed its enforcement actions against Coinbase, Binance, and Kraken in 2025[25], but administrations change, and the statute of limitations for registration violations is five years.[26] Notably, Commissioner Peirce’s July 2026 vault statement demonstrates that the absence of enforcement actions does not signal regulatory disinterest; the SEC is actively analyzing vault structures even as it refrains from bringing new cases.
- Regulators may simply be behind. The vault ecosystem grew from near-zero to more than $10 billion in approximately 18 months; enforcement agencies may have not yet focused on this particular market structure.
- The CLARITY Act and the Senate’s bipartisan market structure draft may provide resolution before enforcement becomes necessary. Congress could create a bespoke framework that neither requires full investment adviser registration nor leaves the market entirely unregulated.
None of these explanations provide legal certainty. They offer context for why the market operates as it does and why the risk calculus may shift rapidly and without warning.
The enforcement precedents remain on the books. The BarnBridge order and the Ooki DAO default judgment speak for themselves. The CFTC’s Division of Enforcement Director Ian McGinley was not speaking hypothetically when he characterized the Ooki DAO decision as “a wake-up call to anyone who believes they can circumvent the law by adopting a DAO structure intending to insulate themselves from law enforcement and ultimately putting the public at risk.”[27] Relics of an enforcement-focused administration remain intact, but do they still stand in this innovation-focused administration? Will regulators’ attitude swing back in the opposite direction as soon as a new administration is in office? Again, even the precedents do not provide legal certainty.
VI. Navigating the Regulatory Landscape: How Our Firm Can Help
The registration analysis for DeFi vault protocol operators is not a question that can be answered in the abstract. It requires a granular, fact-specific assessment of each protocol’s architecture, governance structure, fee model, asset deployment strategy, and user-facing representations.
CFDB brings a distinctive combination of capabilities to this analysis. With deep experience across regulatory counseling, enforcement defense, and government investigations, we advise clients at every stage of the regulatory lifecycle.
Our core capabilities in this area include the following:
Registration and Exemption Analysis. We conduct detailed assessments of whether our crypto clients’ operations and structures trigger registration requirements under the Investment Company Act, the Investment Advisers Act, the Securities Act, the Exchange Act, the Commodity Exchange Act, and the Bank Secrecy Act. We identify applicable exemptions and advise on structural choices that minimize unnecessary registration obligations while maintaining compliance.
SEC and CFTC Engagement. We represent clients in interactions with the SEC, the CFTC, and other regulatory agencies, including by preparing and filing registration applications, exemptive relief requests, and no-action letter requests.
Enforcement Defense and Government Investigations. We represent individuals and entities in SEC, CFTC, and other enforcement actions and investigations involving allegations of unregistered securities offerings, unregistered operations, unlicensed money transmission, and violations of other state and federal laws. Our government investigations and enforcement defense practice is experienced in managing civil proceedings and in negotiating resolutions that protect our clients and their businesses.
VII. Conclusion
We do not offer a definitive answer to the registration question because, in our assessment, no definitive answer currently exists. The statutory text arguably points in one direction. Market behavior definitively points in another. Commissioner Peirce’s July 2026 statement, the first direct SEC guidance on crypto vaults, provides the clearest indication yet of how the Commission may analyze these structures, but it falls short of formal rulemaking or binding interpretation.
For vault operators, curators, and their investors, the practical imperative is not to resolve the legal question in the abstract; it is to understand their specific risk profile and to make informed decisions. That analysis requires experienced counsel with deep knowledge of both the regulatory frameworks and the underlying technology.
Authored by: Ariella Guardi and Bakhtawar Mirjat
If you have any questions, please reach out to a member of the Cryptocurrency, Digital Assets & Web3 practice group including Michael Frisch, Ariella Guardi, David Lopez-Kurtz and Bakhtawar Mirjat.
References:
[1] See Commissioner Hester M. Peirce, Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies (July 22, 2026)
[2]Securities Act of 1933, 15 U.S.C. § 77a et seq.; Investment Company Act of 1940, 15 U.S.C. § 80a-1 et seq.
[3]SEC v. W.J. Howey Co., 328 U.S. 293 (1946).
[4]See, e.g., Balestra v. ATBCOIN LLC, No. 17-cv-10001 (S.D.N.Y. 2018) (holding that investors who commit cryptocurrency to a venture satisfy the investment of money prong under Howey).
[5]See, e.g., SEC v. SG Ltd., 265 F.3d 42 (1st Cir. 2001); SEC v. Life Partners, 87 F.3d 536 (D.C. Cir. 1996) (discussing the managerial efforts prong).
[6] See Commissioner Hester M. Peirce, Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies (July 22, 2026)
[7] Reves v. Ernst & Young, 494 U.S. 56 (1990).
[8] See In re BarnBridge DAO, SEC Administrative Proceeding File No. 3-21831 (Dec. 22, 2023).
[9]See Section 20(a) of the Exchange Act, 15 U.S.C. § 78t(a), and Section 15 of the Securities Act, 15 U.S.C. § 77o.
[10] 7 U.S.C. § 7 (designated contract market registration); 7 U.S.C. § 2(e) (retail commodity transactions).
[11]See CFTC v. Ooki DAO, No. 3:22-cv-05416 (N.D. Cal. June 8, 2023); In re bZeroX, LLC, CFTC Docket No. 22-31 (Sept. 22, 2022).
[12] 18 U.S.C. § 1960 (penalties can include up to 5 years of prison time and fines).
[13]See FinCEN, Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies, FIN-2019-G001 (May 9, 2019).
[14]See Reves v. Ernst & Young, 494 U.S. 56 (1990) (identifying categories of notes excluded from the securities definition, including those arising in commercial lending contexts).
[15]See Lowe v. SEC, 472 U.S. 181 (1985) (discussing scope of the publisher’s exclusion); SEC Interpretive Release No. IA-1092, 52 Fed. Reg. 38,400 (Oct. 16, 1987) (explaining that the publisher’s exclusion does not extend to persons exercising ongoing discretionary authority over client assets).
[16]See SEC, Framework for “Investment Contract” Analysis of Digital Assets (Apr. 2019) (discussing custody and control as factors in the securities analysis).
[17]See, e.g., Report of Investigation Pursuant to Section 21(a) of the Exchange Act: The DAO, Exchange Act Release No. 81207 (July 25, 2017) (applying securities laws to decentralized autonomous organization regardless of technological form).
[18] See Commissioner Hester M. Peirce, Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies (July 22, 2026).
[19]SEC Interpretive Release No. IA-1092, 52 Fed. Reg. 38,400 (Oct. 16, 1987) (discussing the “holding out” and “engaged in the business” standards).
[20]Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Investment Advisers Act Release No. 5248 (June 5, 2019).
[21]See SEC, IM Guidance Update No. 2017-02, Robo-Advisers (Feb. 2017); see also SEC Staff Bulletin: Standards of Conduct for Broker-Dealers and Investment Advisers (2019) (discussing automated advisory services).
[22] See SEC & CFTC, Joint Interpretive Release on Digital Asset Activities (Mar. 2026).
[23][23]See SEC v. Capital Gains Research Bureau, Inc., 375 U.S. 180 (1963) (establishing the fiduciary duty of investment advisers); Commission Interpretation Regarding Standard of Conduct for Investment Advisers, Release No. IA-5248 (June 5, 2019).
[24]Morpho, “The Morpho Effect: 2025” (Dec. 29, 2025)
[25]SEC v. Coinbase, Inc., No. 1:23-cv-04738 (S.D.N.Y.); SEC v. Binance Holdings Ltd., No. 1:23-cv-01599 (D.D.C.); SEC v. Payward, Inc. (Kraken), No. 3:23-cv-06003 (N.D. Cal.)
[26]28 U.S.C. § 2462 (five-year statute of limitations for civil penalties)
[27]See Statement of CFTC Division of Enforcement Director Ian McGinley on the Ooki DAO Litigation Victory, CFTC Release No. 8715-23 (June 9, 2023)