On July 22, 2026, SEC Commissioner Hester Peirce issued a statement titled "Headstands and Summervaults," identifying on-chain vaults and lending strategies as potential subjects of existing securities law. This report examines the parties likely to be affected and how the industry is responding.
Key Takeaways
Applied broadly, the legal reasoning could extend beyond vaults and curators to discretionary products generally, a segment representing approximately $25.9 billion in TVL.
The SEC is not targeting code that operates outside its reach. It is targeting the human actors who exercise discretion over that code.
Teams building compliance-oriented DeFi protocols, including Steakhouse Financial and Maple Finance, have been anticipating and preparing for exactly this kind of regulatory attention.
Historical precedent suggests that only two outcomes have proven durable: full registration under existing securities law, or the creation of new statutory exemptions through legislation.
The responses currently available to market participants are, at best, interim measures. Only curators with sufficient capital to build post-action compliance infrastructure will retain their market position. Smaller curators without those resources will be displaced.
1. The SEC Is Targeting Discretion, Not Code
On July 22, 2026, SEC Commissioner Hester Peirce issued a statement titled “Headstands and Summervaults,” arguing that the Howey Test, the legal standard established by a 1946 Supreme Court decision, could be applied to on-chain vaults and lending strategies under existing securities law.
The Howey Test evaluates the economic substance of how capital is raised and managed. It does not require new legislation or regulatory rulemaking to be applied. It is a fact-based standard that has been consistently applied to new financial instruments regardless of their technical form. An on-chain vault or decentralized lending strategy, however sophisticated its blockchain architecture, could qualify as an investment contract under securities law if its structure satisfies the test’s three core criteria. When all three are met, the product is classified as a security.
The statement carries no immediate enforcement authority, as it reflects the view of a single commissioner. It is, however, the first instance in which the SEC Crypto Task Force’s developing framework has been mapped onto specific products, and it has prompted concern among relevant market participants. MORPHO, the token of the vault infrastructure protocol Morpho, fell roughly 5% immediately after the announcement.
If this legal reasoning were to be applied in practice, the regulatory target would almost certainly not be the smart contracts that power the vaults. It would be the risk curators and the DeFi actors who exercise real discretion over how assets are deployed. The vault infrastructure that Morpho has built is a technical instrument for asset management. Code with no controlling party is not a natural subject of direct regulatory sanction.
The statement carries no immediate enforcement authority, as it reflects the view of a single commissioner. It is, however, the first instance in which the SEC Crypto Task Force’s developing framework has been mapped onto specific products, and it has prompted concern among relevant market participants.
MORPHO, the token of the vault infrastructure protocol Morpho, fell roughly 5% immediately after the announcement.
If this legal reasoning were to be applied in practice, the regulatory target would almost certainly not be the smart contracts that power the vaults. It would be the risk curators and the DeFi actors who exercise real discretion over how assets are deployed. The vault infrastructure that Morpho has built is a technical instrument for asset management. Code with no controlling party is not a natural subject of direct regulatory sanction.
2. Why Curators Are the Target
Curators determine how much capital is allocated across a vault and what level of risk that capital is exposed to. In that sense, they exercise genuine discretion over depositors’ assets. The vault itself is simply a tool through which curators manage those assets. Most vaults are built as smart contracts deployed without admin keys or upgrade permissions, meaning even the original deployer cannot halt their operation or alter their logic.
Financial regulation, as it has historically operated, presupposes the existence of an identifiable legal entity capable of receiving a subpoena, having assets frozen, or complying with a cease-and-desist order. Immutable code with no controlling party has no such administrator.
The regulatory consequence is that enforcement attention has moved from code to discretion. Earlier cases involving Tornado Cash and Uniswap Labs illustrate the pattern.
The Tornado Cash case turned on whether immutable code could constitute sanctionable property. The Uniswap Labs case asked whether the company operating a non-custodial interface had effectively functioned as an unregistered broker or exchange. Both cases focused on the legal status of code and the act of running a service. Neither reached the question of investment discretion as a basis for securities liability.
This case is different. The operative question is no longer who built the protocol but who selects which assets a depositor’s capital is exposed to, how much is allocated to each market, and how interest rate conditions and collateral parameters are adjusted to influence returns. Consider a curator that selects specific lending markets from a broader set, withdraws capital when risk rises, and shifts weight toward higher-yielding markets. Depositors place their capital with that curator because they trust its judgment, not because they trust the underlying smart contract. Returns and losses flow directly from the curator’s decisions. That pattern of professional discretion exercised on behalf of depositors is precisely what gives rise to the “expectation of profits from the efforts of others” that the Howey Test identifies as a defining feature of an investment contract.
The curator is the most clearly identifiable party exercising that discretion within the on-chain vault ecosystem. That is why it sits at the center of the regulatory frame.
3. Which Categories Fall Within Scope
If this legal reasoning is applied broadly, its reach does not stop at risk curators. The SEC’s analytical focus is on who is making investment decisions on behalf of users.
Liquid restaking operators decide which validators or actively validated services (AVSs) receive asset allocations. Yield aggregators compare returns and risk across lending and liquidity markets and move capital accordingly. On-chain asset allocation services adjust holdings and weights over time. Where a specific team or operator is making ongoing decisions about asset selection and reallocation, the function is materially similar to that of a curator.
The relevant scope is therefore wider than the vault product category alone. Whether any specific service falls within it depends on who, within that service, is selecting assets, changing allocations, and controlling exposure to loss. Aggregating potential exposure across categories defined by that criterion produces a total TVL of approximately $25.9 billion.
The legal standard is unlikely to be applied uniformly across all of these participants. Its intensity will vary with the structure of the discretion involved.
At higher risk, where regulatory scrutiny would be most intense, are structures in which discretion is exercised opaquely in ways depositors cannot verify on-chain in real time, such as off-chain delegation and undercollateralized lending.
At medium risk are standard vault curators and liquid restaking structures that exercise allocation discretion, with capital flows recorded transparently on-chain and constrained by governance mechanisms such as timelocks and guardian roles.
At lower risk, and closest to compliance, are immutable protocol deployments with no controlling party, and financial products already registered under securities law.
The parties most accurately positioned to assess their own legal exposure are the operators themselves. This is why curators and adjacent market participants began developing tailored responses, including investor qualification restrictions, third-party compliance arrangements, and formal private placement exemptions, before the commissioner’s statement was issued.
4. Four Design Approaches to Reducing Regulatory Exposure
The responses developed to date do not resolve the underlying legal question. They are focused primarily on reducing the probability of regulatory application and limiting the legal liability of the operating entity.
Two analytical axes separate the approaches: whether a recognized legal exemption has been obtained, and whether actual asset allocation authority has changed. Measured against those criteria, the market’s current responses fall into four types.
Direct investor qualification: advance verification and sales restricted to accredited or qualified investors.
Established regulated distribution channels: routing through exchanges or regulated entities that have completed KYC on their users.
Collateral-level whitelisting: controlling permitted collateral assets through coordination with asset issuers.
Structural separation of permissioned lending and permissionless yield tokens: bifurcating institutional lending execution from retail-accessible yield exposure.
4.1 Investor Qualification: Grove and GLDY
The most direct way to reduce regulatory exposure is to control investor eligibility before any capital is accepted.
Steakhouse Financial launched Grove in June 2025 as an institutional-only on-chain capital allocation channel. Access is restricted to institutional RWA investors who have passed advance qualification screening.
Orca, in May 2026, partnered with Streamex Corp (Nasdaq: STEX) to open the GLDY pool for accredited investors only. GLDY is a yield-bearing tokenized security backed by physical gold reserves, issued explicitly under Regulation D, Rule 506(c), the private placement exemption under U.S. securities law. Investor accounts begin with on-chain transfers frozen and are unlocked only after passing Streamex’s KYC and accredited investor verification.
Both approaches target institutional and accredited investors, establishing a logical basis for using the private placement exemption without full public registration.
Investor qualification, however, does not neutralize a product’s characterization as an investment contract under the Howey Test. Accredited investor status is more directly relevant to the distribution path than to the question of whether a security exists in the first place. This is a practical risk-management approach within the current legal framework, not a fundamental change in legal character.
The curator’s core function of selecting assets and setting allocation weights within the vault remains unchanged, which is the structural limitation these access controls cannot address.
4.2. Existing KYC and Compliance Infrastructure: Sentora
Rather than building its own qualification framework, Sentora combines existing KYC-based distribution channels with regulated asset issuance infrastructure.
Kraken’s DeFi Earn product is the clearest example. Veda provides the vault infrastructure; Chaos Labs manages the Balanced and Boosted vaults; Sentora serves as risk manager for the Advanced vault, overseeing capital allocation across on-chain protocols and managing risk and liquidity.
This arrangement has since been adopted more broadly. Coinbase has combined Morpho and Steakhouse Financial to launch USDC lending through Prime and High Yield vaults. Binance has connected its users to Morpho vaults managed by Steakhouse and Gauntlet.
Exchange-level KYC confirms user identity, and issuer compliance frameworks support reserve and redemption structures. Neither addresses who is deciding which assets and markets receive how much capital. External compliance infrastructure reduces risk at the asset and distribution level but does not absorb the regulatory exposure or legal liability of the risk manager making allocation decisions.
4.3 Asset-Level Whitelisting: Aave Horizon
Aave launched Aave Horizon in August 2025 as an institutional RWA lending market. The product is structurally separated from the core protocol and designed to the specifications required for institutional asset management.
Aave Horizon’s distinctive design choice is to share control over permitted collateral with asset issuers rather than restricting user access directly at the distribution stage. Whitelists for tokenized collateral assets are managed by the issuers themselves: Circle, Ripple, Superstate, and Centrifuge (which includes Janus Henderson products). The protocol itself remains permissionless for any wallet holding whitelisted assets.
The governing control is not who accesses the market but which assets are eligible. Risk parameters follow recommendations from LlamaRisk, and collateral valuations are supported by NAV data verified by Chainlink in real time. Aave Horizon builds on existing Aave lending infrastructure rather than constructing a new chain or independent protocol.
Sharing verification responsibility with asset issuers does not extinguish Aave Horizon’s own legal and operational liability for its risk parameter decisions.
4.4 Structural Separation of Permissioned Lending and Permissionless Yield: Maple Finance
In April 2024, Maple Finance converted its entire platform to a whitelist structure. All loans are now fully overcollateralized, and Maple Direct, its in-house credit team, conducts borrower underwriting, ongoing monitoring, and margin calls directly. Access is limited to approved institutional borrowers and lenders.
The most notable aspect of Maple’s design is the separation between the permissioned lending operation and permissionless yield access. In 2024, Maple launched the Syrup protocol, through which retail users can deposit USDC without KYC and receive SyrupUSDC in return. Those deposits flow into the same institutional lending pool that Maple Direct already manages with its accredited borrowers. The lending itself operates under rigorous institutional compliance. The right to receive the yield that lending generates is packaged into a permissionless token and made available to any user.
This structure relocates regulatory exposure rather than eliminating it. Maple Direct’s underwriting and management discretion, including borrower selection, collateral terms, and margin calls, remains intact. The arrangement by which institutional lending returns are passed to SyrupUSDC holders generates its own question of whether that token constitutes an investment contract under the Howey Test, together with separate distribution liability.
The structural separation of permissioned lending and permissionless yield is a deliberate repositioning of where regulatory scrutiny lands. It does not change the legal liability of the entities managing the capital or the fundamental nature of the product.
The cases above address different regulatory contact points but share a common limitation. They are operational defensive structures designed to manage regulatory exposure by separating investors, assets, and distribution channels. They are not final solutions that extinguish legal risk.
Mapped against the two analytical axes introduced earlier:
One approach has obtained an explicit legal exemption: the Orca/GLDY structure, which applies Regulation D, Rule 506(c) directly.
The remaining approaches manage and constrain regulatory exposure: Grove, Sentora, Aave Horizon, and Maple Finance, through a combination of institutional qualification restrictions, third-party compliance infrastructure, and collateral whitelisting.
Restricting distribution and filtering eligibility does not resolve the underlying legal liability that attaches to a curator or protocol’s discretionary asset selection and allocation decisions.
5. What History Shows Works
The future of the on-chain asset management market will be determined not by the surface appearance of the code but by the institutional frameworks established to govern the scope of discretion, the transparency of disclosure, and the allocation of legal liability.
The measures examined above reduce immediate regulatory exposure and provide room to use existing private placement exemptions. They do not answer the foundational questions of what criteria govern a curator’s allocation decisions and who bears responsibility when losses occur.
The historical record is consistent on one point: access restrictions alone have not produced durable institutionalization.
Closed-end funds in the 1920s and 1930s saw widespread abuse of “blind pool” structures in which managers did not disclose their investment targets. The Investment Company Act of 1940 resolved this not by restricting access but by institutionalizing the asset management function itself.
In 2008, when the SEC determined that LendingClub’s peer-to-peer loan notes were securities, the company suspended new registrations and restructured as an issuer of SEC-registered notes tied to its loans, eventually listing publicly in 2014.
In 2012, the crowdfunding industry’s demand for reduced fundraising restrictions led to the JOBS Act and the creation of Regulation Crowdfunding.
What the three cases share is that they did not stop at restricting investor access. They established the legal character of the product, the obligations of the operating entity, the scope of required disclosure, and the allocation of loss. Sustainable growth for new financial instruments requires that market participants be able to predict, in advance, both their rights and their legal responsibilities.
On-chain vaults and DeFi markets face the same institutionalization challenge. The available paths are:
Full registration under existing securities law.
Private placement exemptions targeting qualified investors.
Immutable protocol design that eliminates discretion entirely.
New regulatory exemptions specific to on-chain finance, such as those proposed to the SEC by Ava Labs and the Solana Policy Institute.
Whichever path is taken, the central task is the same: establishing who makes investment decisions, what disclosures are required, and where liability falls when outcomes are adverse.
6. Compliance Costs as a New Barrier to Entry
The factor that will ultimately determine competitive position in the on-chain asset management market is the capacity to absorb compliance costs structurally and to demonstrate legal accountability.
Because regulators cannot directly control code, the framework that holds human actors legally accountable for the discretion they exercise over it will only become more clearly defined. Regardless of how effectively a firm has positioned itself in the interim, formal registration or explicit exemption frameworks will eventually require every operator to demonstrate the legal basis for its management structure and the boundaries of its liability. At that point, compliance obligations, encompassing KYC infrastructure, legal review, on-chain asset valuation, bespoke institutional contracts, and loss-absorption structures, will cease to be administrative overhead. They will become an independent cost item requiring sustained capital investment.
The internalization of these compliance costs will drive a meaningful reordering of the curator market. Large curators with capital, operating scale, and established institutional relationships will be able to distribute compliance costs efficiently and consolidate their market position. Smaller curators, without the capital to fund independent infrastructure, will face a choice between bearing disproportionate costs and accepting consolidation into larger regulated protocols or distribution channels.
The real value of the grace period that interim strategies have secured will be determined by what is built during it. Those who use this time to design formal registration pathways, identify viable exemptions, and establish clear liability structures in advance will find that regulatory requirements become a source of competitive advantage rather than a barrier. For those who defer, mounting compliance costs will erode profitability and, ultimately, foreclose market participation.
🐯 More from Tiger Research
Read more reports related to this research.DeFi Lending Is Modularizing: The Risk Management War Among Morpho, Euler, and Aave
Still 1990: Crypto Cards: $1.5 Billion a Month, but Not Yet Infrastructure
Disclaimer
This report has been prepared based on materials believed to be reliable. However, we do not expressly or impliedly warrant the accuracy, completeness, and suitability of the information. We disclaim any liability for any losses arising from the use of this report or its contents. The conclusions and recommendations in this report are based on information available at the time of preparation and are subject to change without notice. All projects, estimates, forecasts, objectives, opinions, and views expressed in this report are subject to change without notice and may differ from or be contrary to the opinions of others or other organizations.
This document is for informational purposes only and should not be considered legal, business, investment, or tax advice. Any references to securities or digital assets are for illustrative purposes only and do not constitute an investment recommendation or an offer to provide investment advisory services. This material is not directed at investors or potential investors.
Terms of Usage
Tiger Research allows the fair use of its reports. ‘Fair use’ is a principle that broadly permits the use of specific content for public interest purposes, as long as it doesn’t harm the commercial value of the material. If the use aligns with the purpose of fair use, the reports can be utilized without prior permission. However, when citing Tiger Research’s reports, it is mandatory to 1) clearly state ‘Tiger Research’ as the source, 2) include the Tiger Research logo. If the material is to be restructured and published, separate negotiations are required. Unauthorized use of the reports may result in legal action.




















