Legal Alerts Banner 2600x660 1

Vaults Do Not Yield Protection From Regulation — But the Enforcement Record Could: Commissioner Peirce’s Crypto Vaults Statement and the SEC’s Dismissals

SERCling Up banner
Key Takeaways — by Constituency
  • Vault deployers and curators: The more you select investments or allocations, re-allocate assets, or hand-pick decision-makers, the stronger every one of the four frameworks becomes. Map your discretion honestly before you market.
  • On-chain lending / protocol operators: Rate-setting, asset selection, LTV, and liquidation-threshold discretion are the Reves pressure points. Distribution and marketing (retail vs. sophisticated, yield emphasis) drive factors (ii) and (iii).
  • Tokenization platforms: As securities move on-chain, vaults holding or allocating to those securities raise live Investment Company Act questions — the fixed-portfolio/UIT vs. active-management distinction is worth designing around.
  • Advisers and funds using these tools: Discretionary management of client crypto through vaults can raise Advisers Act status and custody questions independent of the token analysis.
Practical Considerations
  • Treat discretion as the design variable. Structures should be built and documented with a clear-eyed view of where they sit on the programmatic-to-discretionary spectrum because that placement drives every framework.
  • Preserve the fair-notice record. For existing conduct, document the state of the law and the enforcement posture at the time. The dismissal record is an asset, not a footnote.
  • Watch for the notice cure. A Commission-level framework, interpretive release or rulemaking would shift the analysis prospectively. The statement’s open invitation to engage is a channel worth using deliberately, on the client’s timeline.
  • Consider proactive engagement selectively. The statement welcomes inquiries and a “compliant path.” Engagement can de-risk but consider how a negative response could impact development plans.

On July 22, 2026, SEC Commissioner Hester Peirce issued a statement, Headstands and Summervaults, cautioning that crypto “vaults” and on-chain lending strategies can fall within the federal securities laws — and that contorting the statutes to argue otherwise invites “a painful fall.”[1] The statement is only one commissioner’s view, not a new rule or the Commission’s official position, and Commissioner Peirce’s statement repeatedly frames the analysis as fact specific. However, its animating principle is unmistakable: discretion. When a person or group exercises discretion over how investors generate returns from crypto assets deployed on-chain, securities laws may attach.

Commissioner Peirce’s statement could also be read as a notice-rebuilding exercise. It arrives against an SEC enforcement record that points the other way with a wave of case dismissals, several with prejudice, that had alleged the same yield- and lending-adjacent theories that her statement now flags. That gap between doctrine and enforcement is where the practical risk (and potential opportunity) lives, and it is why any future assertion of jurisdiction over discretionary vaults or lending will have to reckon with fair-notice principles.

What the Statement Says

Building on Commissioner Peirce’s July 2025 tokenization statement (“tokenized securities are still securities”), her new statement extends the same principle to asset-deployment tools: Moving an activity on-chain does not, by itself, move it outside the securities perimeter. It describes vaults as customizable smart-contract arrangements that allocate user assets across yield-generating activities, such as staking and lending, and situates them on a spectrum from purely programmatic allocation by immutable code on one pole, to allocation at the sole discretion of a person or group at the other. It describes lending strategies in parallel terms: Participants deposit assets into on-chain systems that lend them to borrowers for a fee. A single-strategy staking contract that always delegates to the same validator set is a straightforward example near the programmatic end. A “yield aggregator” that a team actively steers among multiple protocols in search of the best return sits much closer to the discretionary end — and the statement’s analysis is aimed squarely at structures in that second category.

The through-line is who decides. The statement enumerates the discretionary acts that may pull an operator into the securities laws:

THE DISCRETION SPECTRUM — CONDUCT CONTROLLED BY PEOPLE

Vaults: selecting the yield-generating activities; re-allocating assets among them; or selecting the parties who make those decisions.

Lending: setting interest rates; deciding which assets to accept; setting loan-to-value limits; and establishing liquidation thresholds.

Programmatic / immutable end of the spectrum → weaker securities hook. Sole-discretion end → stronger hook. The more human managerial judgment, the more the securities laws are implicated.

Four Frameworks — All Keyed to Discretion

1. Investment contract / common enterprise

A vault can be a common enterprise in which users contribute assets into a common pool while expecting profits from the entrepreneurial or managerial efforts of the deployer or curator — the classic Howey/Forman formulation the statement invokes.[2] Discretion is precisely what supplies the “efforts of others” prong: A curator who chooses and rebalances strategies is furnishing the managerial effort on which the profit expectation rests. In practice, a vault in which the curator actively picks which pools to enter, exits positions opportunistically or swaps strategies in response to market conditions looks like the classic case; a vault that mechanically executes a published, unchangeable rule set (e.g., always stake 100% of deposits with a named validator) looks much less like one because there is no reliance on ongoing managerial efforts, even if it still generates a return.

2. Investment Company Act status

A vault that holds securities, or allocates assets into investments in securities, can land in investment-company territory.[3] The statement draws three analogies that track the discretion gradient: A vault with a fixed portfolio and little active management may resemble a unit investment trust; one with active reallocation may resemble a management investment company; and one offering individualized treatment could resemble a separately managed account. The classification, along with the attendant registration and custody consequences, turns on how much discretion the organizers retain. A threshold question sits underneath all three analogies: The Investment Company Act only bites if the vault’s underlying holdings are themselves securities.

3. Notes as securities — Reves

On-chain loans, “depending on the parties’ motivations, the plan of distribution, and other relevant factors,” can bear the hallmarks of notes that are securities under Reves v. Ernst & Young.[4] Notably, the statement’s own phrasing — motivations and plan of distribution — tracks the first two Reves family-resemblance factors, discussed below. This is the framework most directly in tension with the enforcement record. Courts applying Reves outside crypto have recognized only a handful of nonsecurity note categories, including consumer financing, notes secured by a home mortgage, short-term notes secured by a lien on a small business’s assets, and similar arrangements in which financing is ancillary to an underlying transaction, and on-chain yield-bearing loans rarely map cleanly onto any of these categories.

4. Investment adviser status

Managing a vault or lending strategy may also implicate the Advisers Act.[5] A curator who exercises discretion over the deployment of others’ assets for compensation looks a great deal like a person providing advice about, or managing, securities. And again, discretion is the operative fact. While the SEC and CFTC discussed harmonization, they have not yet provided specific guidance about how to think about assets under management registration thresholds in the context of vaults that are likely to contain nonsecurity assets. Curators charging performance-based fees may separately consider the Advisers Act’s restrictions on performance compensation, which apply differently depending on whether depositors qualify as “qualified clients” — a facts-and-circumstances determination that on-chain, pseudonymous participation can make difficult to verify.

The Reves Problem: Doctrine Points One Way, the Record Points the Other

Reves presumes every note is a security, rebuttable by resemblance to a judicially recognized non-security category, and applies a four-factor test: (i) the motivations of buyer and seller; (ii) the plan of distribution; (iii) the reasonable expectations of the investing public; and (iv) the presence of a risk-reducing feature such as another regulatory regime or collateral.[6] On paper, a broadly marketed, discretion-managed on-chain lending program, offered to retail for a yield, with no alternative regulatory scheme reducing risk, sits close to the security end of that test. Courts have reached inconsistent results applying these four factors even outside crypto, particularly on the third factor (the public’s reasonable expectations), which turns heavily on how a program is marketed rather than on its legal structure — a reminder that marketing materials, FAQs and social media messaging are as relevant to this analysis as the underlying smart contract.

However, the Commission has never litigated a crypto yield or lending program to a merits judgment establishing registration liability. And its enforcement record now cuts hard against the theory the statement floats:

  • Gemini Earn — the closest vehicle. The Commission sued Gemini and Genesis in January 2023, alleging the Earn lending program (users lent crypto to Genesis for yield; Gemini allegedly acted as agent/promoter for a fee) was an unregistered securities offering. The theory survived a motion to dismiss in March 2024, with the court finding the SEC had “plausibly alleged” violations. Yet on Jan. 23, 2026, the Commission dismissed with prejudice — expressly “in the exercise of its discretion” and citing 100% in-kind investor recovery, not the merits.[7]
  • BlockFi — the one registration outcome on a lending product (BlockFi Interest Accounts) came by settlement in 2022, not litigation, and thus produced no contested precedent.[8]
  • Coinbase and Consensys — allegedly discretionary staking programs (including MetaMask liquid staking) were charged by the SEC for failing to register offerings. Coinbase filed a motion to dismiss in the Southern District of New York that the Court denied, and Consensys answered complaint the SEC filed against it. The SEC then dismissed both actions with prejudice in March 2025.[9]

The pattern: more than a dozen crypto enforcement actions have been dismissed or closed since early 2025, several with prejudice, some after the Commission had survived motions to dismiss or secured favorable preliminary rulings. The dismissal papers recited prosecutorial discretion and a regulatory “course correction,” and the Commission has acknowledged prior “flaws” and a “misreading” of the securities laws in this area.[10]

The result is a doctrinal vacuum. Reves and Howey remain good law and may reach discretionary on-chain yield structures when applied cleanly. However, the Commission’s recent course of conduct indicates that it does not plan to enforce registration requirements on these types of crypto assets absent allegations of fraud. A single commissioner’s statement, however pointed, does not fill that vacuum.

The Fair-Notice Vulnerability

If the Commission later reverses course and asserts registration jurisdiction over discretionary vaults or lending, targets will have a serious fair-notice / due-process argument. Under FCC v. Fox, Christopher v. SmithKline, and the “ascertainable certainty” line (including Upton v. SEC, in which the U.S. Court of Appeals for the Second Circuit vacated a sanction because the Commission’s interpretation was not ascertainably certain), an agency may not penalize conduct it never gave regulated parties fair warning was covered.[11] Notably, this line of cases developed mostly outside the securities context — broadcast indecency in Fox, a healthcare overtime exemption in Christopher and environmental permitting in General Electric — so a court asked to apply it to crypto vaults would be extending the doctrine to a new factual setting rather than following directly on-point securities precedent. Many defendants raised fair-notice arguments in the context of SEC claims against crypto-asset defendants, and those arguments were not successful at the motion to dismiss phase, based on the specific facts the courts considered about the SEC’s approach to enforcement at the time, which has since changed. But the rejections did not indicate the defense is not available in the context of securities litigation.

Three features of the current record strengthen that defense:

  • Dismissals with prejudice, especially of a claim that had already survived a motion to dismiss, affirmatively signal that the conduct was not being pursued — the opposite of notice.
  • Affirmative disavowals. Public acknowledgments of prior “flaws” and a “misreading” of the law, plus dismissal recitals disclaiming any merits position, undercut the notice a regulated party otherwise had.
  • Absence of any rule or Commission-level position. The statement is expressly an individual commissioner’s view, hedged with “may want to analyze,” and is not a rulemaking, interpretive release, or Commission statement.

Two limits keep this from being a silver bullet, and market participants should understand both. First, fair notice is principally a defense to penalties and retroactive liability; it is weaker against purely prospective relief — a declaratory judgment that a structure is covered, or injunctive relief going forward. Second, this very statement may be the beginning of the notice cure. Read alongside the 2025 tokenization statement, it is plausibly the Commission’s messengers telegraphing that the discretionary end of the spectrum is in-scope. The fair notice protection is therefore greatest for past conduct and the current interim period, and it will erode if the Commission articulates a clear prospective position through rulemaking or a Commission-level framework.

A fair notice defense is rarely successful and should not be the foundation of legal strategy. But its potential viability highlights the regulatory uncertainty that remains across a wide range of crypto asset issues, even amidst a favorable regulatory environment.

To discuss how these principles apply to a specific vault, lending program or tokenization structure, or to assess fair-notice exposure on existing conduct please contact the author or your McGuireWoods relationship attorney.


[1] Commissioner Hester M. Peirce, Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies (July 22, 2026). The statement is an individual Commissioner statement and does not constitute a rule, regulation, or statement of the Commission.

[2] SEC v. W.J. Howey Co., 328 U.S. 293 (1946); United Housing Found., Inc. v. Forman, 421 U.S. 837, 852 (1975) (cited by the statement for the common-enterprise/expectation-of-profits framing).

[3] Investment Company Act of 1940 § 3(a)(1); see also §§ 4(2)–(3) (unit investment trusts and management companies).

[4] Reves v. Ernst & Young, 494 U.S. 56 (1990) (family-resemblance test for when a “note” is a security).

[5] Investment Advisers Act of 1940 § 202(a)(11).

[6] Reves v. Ernst & Young, 494 U.S. 56 (1990).

[7] SEC v. Genesis Global Capital, LLC & Gemini Trust Co., LLC, No. 1:23-cv-00287 (S.D.N.Y.). Complaint filed Jan. 12, 2023; motion to dismiss denied March 13, 2024; joint stipulation of dismissal with prejudice filed Jan. 23, 2026. Genesis separately settled with the SEC (approx. $21 million).

[8] In re BlockFi Lending LLC, Securities Act Release No. 11029 (Feb. 14, 2022) ($100 million combined with 32 state regulators; BlockFi Interest Accounts treated as unregistered securities under Howey and as requiring Investment Company Act registration).

[9] SEC v. Coinbase, Inc., No. 1:23-cv-04738 (S.D.N.Y.); SEC v. Consensys Software Inc., No. 1:24-cv-04578 (E.D.N.Y.). Each dismissed with prejudice pursuant to joint stipulations in Mar. 2025.

[10] The dismissal stipulations recited that the Commission acted in the exercise of its discretion to facilitate its regulatory reform efforts and that dismissal did not necessarily reflect the Commission’s position on any other case. The Commission has separately characterized fiscal year 2025 as a “necessary course correction” in its crypto enforcement approach.

[11] FCC v. Fox Television Stations, Inc., 567 U.S. 239 (2012); Christopher v. SmithKline Beecham Corp., 567 U.S. 142 (2012); Gen. Elec. Co. v. EPA, 53 F.3d 1324 (D.C. Cir. 1995) (“ascertainable certainty”); Upton v. SEC, 75 F.3d 92 (2d Cir. 1996) (vacating sanction for lack of fair notice of the Commission’s interpretation).

Subscribe