A statement from SEC Commissioner Hester Peirce has pushed a core DeFi question into the open: regulators may care less about code itself than about the people who control how capital is allocated.

In a new report, Tiger Research argued that if this legal reasoning is applied broadly, the fallout would reach far beyond on-chain vaults and risk curators. It could extend to any DeFi product that makes investment decisions on behalf of users. By the firm’s count, the total value locked potentially exposed under that framework is about $25.9 billion.
The SEC framework centers on discretion, not software
On July 22, 2026, Peirce published a statement titled Headstands and Summervaults, arguing that the Howey test can be applied to on-chain vaults and lending strategies under existing securities law.
Tiger Research said the Howey test, established by the U.S. Supreme Court in 1946, looks at the economic reality of how money is raised and managed. It does not require new legislation or fresh rulemaking to be used. In the report’s reading, that makes it durable across new financial formats, including blockchain-based products. An on-chain vault or decentralized lending strategy can still fall within the definition of an investment contract if it meets the test’s three core elements. If all three are met, the product would be treated as a security.
The statement itself does not carry direct enforcement power because it reflects the view of a single commissioner. Even so, Tiger Research described it as the first time the SEC crypto task force’s emerging framework has been mapped onto a specific product category. That alone was enough to rattle the market. MORPHO, the token of vault infrastructure protocol Morpho, fell about 5% immediately after the statement was released.
If the reasoning is ever enforced in practice, the report said the target is unlikely to be the smart contracts running the vaults. It is far more likely to be the risk curators and other DeFi operators who exercise real control over where assets go. In that framing, Morpho provides infrastructure for asset management, not the decision-making layer itself. Code without a controlling party is not the natural object of sanctions.
Why curators stand at the center
Curators decide how much capital goes where and what level of risk depositors are exposed to. That gives them genuine control over user assets, while the vault is only the mechanism through which those decisions are carried out.
Tiger Research noted that most vaults are deployed as smart contracts without admin keys or upgrade rights. Even the original deployer may be unable to stop them or alter their logic. Financial regulation, by contrast, usually assumes there is an identifiable legal entity that can receive subpoenas, have assets frozen, or comply with an injunction. Immutable code with no controller does not fit that structure.
That is why enforcement attention shifts from software to discretion. The report pointed to earlier cases involving Tornado Cash and Uniswap Labs as examples of that pattern, though those cases focused on different legal questions. Tornado Cash raised the issue of whether immutable code could be sanctioned as property. Uniswap Labs centered on whether a company operating a non-custodial interface was effectively acting as an unregistered broker or exchange. Neither one made investment discretion itself the basis for securities liability.
This time, Tiger Research said, the decisive question is not who built the protocol. It is who chooses which assets depositor capital is exposed to, how much gets allocated to each market, and how interest-rate settings or collateral parameters are adjusted to shape returns.
The report used a curator example to explain the point. If a curator selects certain lending markets from a wider field, pulls capital when risk rises, and shifts weight toward markets offering higher returns, depositors are relying on that judgment rather than on the contract code below it. Gains and losses flow directly from the curator’s choices. That pattern, the report said, closely matches the Howey concept of an expectation of profits derived from the efforts of others.
Among participants in the on-chain vault ecosystem, curators are the clearest actors exercising that kind of authority. That is why they sit at the center of the regulatory analysis.
The reach could go beyond vaults
Tiger Research said the same reasoning would not stop with vault curators if it is applied across DeFi. The SEC’s real lens, in the report’s view, is whether someone is making investment decisions for users.
That would bring adjacent categories into view. Liquid restaking operators decide which validators or actively validated services receive delegated assets. Yield aggregators compare risks and returns across lending and liquidity venues, then move capital in response. On-chain asset allocation services rebalance positions and weights over time. Where a team or operator repeatedly chooses assets and reallocates funds, Tiger Research said the function becomes materially similar to a curator’s role.
For that reason, the potential scope is wider than the vault product category alone. Whether a service falls into the frame depends on who selects assets, changes allocations, and controls loss exposure. Using that standard across categories, the report put the combined total value locked at roughly $25.9 billion.
Still, Tiger Research does not expect the legal standard to land with equal force across all participants. The intensity of scrutiny would vary with the structure of discretion.
- The highest-risk structures are those where decision-making happens in ways depositors cannot verify on-chain in real time, such as off-chain mandates and undercollateralized lending.
- Mid-risk structures include standard vault curators and liquid restaking models, where allocation choices are still made but capital flows remain visible on-chain and are constrained by governance tools such as timelocks and guardian roles.
- Lower-risk structures are immutable deployments with no controlling party and financial products already registered under securities law.
The report added that operators themselves are usually best positioned to assess their own legal exposure. That helps explain why curators and neighboring market players had already started building custom responses before Peirce’s statement was published, including investor eligibility restrictions, third-party compliance arrangements, and formal private-placement exemptions.
Four design approaches now used to reduce exposure
Tiger Research grouped the main market responses into four broad categories. None of them, it said, solves the underlying legal issue. They are mainly aimed at reducing the odds of regulatory intervention or limiting liability at the operating entity level.

The report used two questions to sort these structures: whether they rely on a recognized legal exemption, and whether the underlying allocation authority actually changes. On that basis, the market’s current responses fall into four groups:
- Direct investor accreditation and screening before capital is accepted
- Distribution through regulated entities or exchanges that already perform user KYC
- Collateral-level whitelists coordinated with asset issuers
- Structural separation between permissioned lending and permissionless yield tokens
Investor screening: Grove and GLDY
The most direct way to cut risk is to control investor eligibility before any capital enters.
Steakhouse Financial launched Grove in June 2025 as an institutional-only on-chain capital allocation channel. Access is limited to institutional RWA investors that pass advance qualification checks.
In May 2026, Orca partnered with Streamex Corp, listed on Nasdaq under STEX, to open the GLDY pool only to accredited investors. GLDY is a yield-bearing tokenized security backed by physical gold reserves and explicitly issued under Rule 506(c) of Regulation D, a private-placement exemption under U.S. securities law. Investor accounts begin with on-chain transfers frozen and are unlocked only after KYC and accredited investor verification through Streamex.
Tiger Research said both approaches create a logic for relying on private-placement exemptions rather than full public registration. But they do not remove the possibility that the product is still an investment contract under Howey. Accreditation status mainly affects the distribution path, not the deeper question of whether a security exists in the first place. In that sense, the report described this as practical risk management rather than a change in legal character.
The underlying limitation remains. The curator still chooses assets and sets allocation weights inside the vault, and those controls are untouched by access restrictions.
Using existing KYC and compliance rails: Sentora
A second model does not build a new qualification framework from scratch. Instead, it plugs into existing KYC-based distribution channels and regulated issuance infrastructure.
Tiger Research cited Kraken’s DeFi Earn product as a clear example. Veda provides vault infrastructure. Chaos Labs manages the Balanced and Boosted vaults. Sentora serves as the risk manager for the Advanced vaults, overseeing capital allocation across on-chain protocols and handling risk and liquidity management.
That setup was later used more broadly. Coinbase paired Morpho with Steakhouse Financial to offer USDC lending through Prime and High Yield vaults. Binance connected its users to Morpho vaults managed by Steakhouse and Gauntlet.
Exchange-level KYC confirms user identity, while issuer-side compliance frameworks support reserve and redemption structures. But neither one answers the central question of who decides which assets and markets receive capital. Tiger Research’s point was blunt: external compliance rails can lower risk at the asset and distribution layers, but they do not absorb the regulatory exposure or legal responsibility of the risk managers actually making allocation decisions.
Collateral whitelists: Aave Horizon
A third model appears in Aave Horizon, launched by Aave in August 2025 as an institutional RWA lending market. The product is structurally separate from the core protocol and was built around institutional asset-management requirements.
Its distinctive design choice is not to restrict user access at the distribution layer. Instead, control is shared with asset issuers over which forms of collateral are allowed into the system. Whitelists for tokenized collateral are managed by the issuers themselves, including Circle, Ripple, Superstate, and Centrifuge, with products from Janus Henderson included through that setup. The protocol remains permissionless for any wallet holding approved collateral.
In other words, the main control point is not who can enter the market but which assets qualify. Risk parameters follow guidance from LlamaRisk, and collateral valuation is backed by real-time NAV data verified by Chainlink. Tiger Research stressed that Aave Horizon is built on Aave’s existing lending infrastructure rather than on a new chain or separate protocol stack.
Even so, sharing verification duties with asset issuers does not remove Aave Horizon’s own legal and operational responsibility for setting risk parameters.
Separating permissioned lending from permissionless yield: Maple Finance
The fourth model is illustrated by Maple Finance. In April 2024, Maple shifted its full platform to a whitelist structure and made all loans fully overcollateralized. Maple Direct, its internal credit team, handles borrower due diligence, ongoing monitoring, and margin calls directly. Access is limited to approved institutional borrowers and lenders.
The more notable part of Maple’s design is the split between permissioned lending operations and permissionless yield access. In 2024, Maple launched the Syrup protocol, allowing retail users to deposit USDC without KYC in return for SyrupUSDC. Those deposits are routed into the same institutional lending pools managed by Maple Direct and tied to approved borrowers. Lending itself stays inside a tightly controlled institutional framework. The claim on those lending returns is then wrapped into a token available to any user.
Tiger Research said this does not erase regulatory risk. It relocates it. Maple Direct still exercises discretion over borrower selection, collateral terms, and margin management. At the same time, the transfer of institutional lending returns to SyrupUSDC holders creates a separate question: whether the token itself may qualify as an investment contract under Howey, along with fresh issues around distribution liability.

For that reason, the report described the split between permissioned lending and permissionless yield as a deliberate repositioning of where scrutiny may land, not a change in the legal responsibility of the entity managing capital or in the product’s basic nature.
Tiger Research said these examples touch different regulatory points but share the same limit. They are operational defenses, meant to manage exposure by separating investors, assets, and distribution channels. They are not final answers to the legal problem.
By the report’s own framework, only the Orca/GLDY structure rests on a clearly recognized exemption, through Regulation D Rule 506(c). The others, including Grove, Sentora, Aave Horizon, and Maple Finance, mainly manage and narrow risk through institutional eligibility limits, third-party compliance infrastructure, and collateral whitelists.
As long as curators or protocols still exercise discretionary asset selection and allocation, Tiger Research argued, restricting distribution and screening investors does not resolve the underlying liability.
History points to registration or a defined exemption
In Tiger Research’s view, the future of on-chain asset management will not be decided by how code looks on the surface. It will be shaped by the institutional frameworks built around discretion, disclosure, and legal responsibility.
The measures above can lower immediate exposure and create room to rely on existing private-placement exemptions. But they do not answer the two foundational questions: what standard governs a curator’s allocation decisions, and who is responsible when losses occur.
The historical record, the report said, is clear on one point. Access restrictions alone have not produced durable institutionalization.
It cited three examples. In the 1920s and 1930s, blind-pool structures in closed-end funds were widely abused because managers did not disclose investment objectives. The Investment Company Act of 1940 addressed that by institutionalizing the asset management function itself rather than by only limiting access. In 2008, after the SEC determined LendingClub’s peer-to-peer loan notes were securities, the company halted new registrations and restructured as an issuer of SEC-registered notes tied to its loans, eventually going public in 2014. In 2012, demand from the crowdfunding industry for lighter fundraising limits led to the JOBS Act and the creation of crowdfunding regulation.
What those cases have in common is not investor exclusion. It is the formal recognition of the product’s legal nature, the duties of the operator, the scope of required disclosure, and the allocation of losses. Sustainable growth in a new financial product, Tiger Research wrote, depends on whether participants can predict their rights and liabilities in advance.
That leaves several possible paths for on-chain vaults and the wider DeFi market:
- Full registration under existing securities law
- Private-placement exemptions for accredited investors
- Immutable protocol design that removes discretion entirely
- New regulatory exemptions for on-chain finance, such as proposals submitted to the SEC by Ava Labs and the Solana Policy Institute
Whichever route is taken, the report said the task is the same: identify who makes the investment decision, what disclosures are required, and where responsibility falls when outcomes turn negative.
Compliance costs may become the new barrier to entry
Tiger Research ended with a market-structure argument. The factor likely to decide competitive standing in on-chain asset management is not just performance. It is the ability to absorb compliance costs structurally and demonstrate legal accountability.
Because regulators cannot directly control code, the legal framework that assigns responsibility to human actors for the discretion they exercise is only likely to become clearer. No matter how effectively a firm positions itself during the transition period, a formal registration path or a clearly defined exemption will eventually require each operator to show the legal basis of its management structure and the boundaries of its responsibility.
At that point, compliance items such as KYC infrastructure, legal review, on-chain asset valuation, customized institutional contracts, and loss-absorption structures stop being ordinary overhead. They become separate cost centers that require ongoing capital investment.
Tiger Research said the internalization of those costs is likely to reorder the curator market. Large curators with capital, operating scale, and established institutional relationships will be able to spread compliance costs more effectively and strengthen their position. Smaller curators without the resources to build independent infrastructure will face a different choice: absorb disproportionately high costs or be folded into larger regulated protocols or distribution channels.
That is why the report treats the transition period as valuable only if firms use it to build something concrete. Operators that spend this time designing a formal registration path, identifying workable exemptions, and setting up clear accountability structures may find that regulation turns into an advantage. Those that delay may see rising compliance costs chip away at margins until market participation is no longer viable.

