Tiger Research: SEC Targets $25.9 Billion DeFi Market, Regulatory Focus is Not on Code
- Core Viewpoint: SEC Commissioner Hester Peirce's statement argues that on-chain vaults and lending strategies can be subject to the Howey Test under securities law. The regulatory focus will shift from code to "risk curators" who hold actual decision-making power over asset allocation, affecting approximately $25.9 billion worth of discretionary DeFi products.
- Key Elements:
- The core of SEC regulation is the "decision-making power" that makes investment decisions on behalf of users, not the smart contract code itself. This is based on the "expectation of profits from the efforts of others" criterion in the Howey Test.
- The affected scope is not limited to vault curators but also includes liquidity restaking operators, yield aggregators, and on-chain asset allocation services—any DeFi product that makes investment decisions for users. The total value locked is approximately $25.9 billion.
- Current market countermeasures (such as investor qualification screening, KYC infrastructure, asset whitelists, and structural separation) are only transitional solutions. They cannot fundamentally eliminate legal risks but can only reduce the likelihood of regulatory application.
- Historical experience shows that there are only two sustainable solutions: completing full registration under current securities laws, or creating new exemption clauses for on-chain finance through legislation.
- Compliance costs will become a new barrier to entry. Large, well-capitalized curators can absorb these costs to solidify their position, while smaller curators with fewer resources will be eliminated.
This article is written by Tiger Research. A statement by SEC Commissioner Hester Peirce has brought on-chain treasuries and curators under the regulatory spotlight. If the legal logic is fully applied, the impact would not be limited to treasuries but would extend to all DeFi products that make investment decisions on behalf of users—a market with a total value locked of $25.9 billion. Regulation will not target code, but it will precisely target the people making decisions behind the code.
Key Takeaways
- If the legal reasoning is broadly applied, the impact will extend beyond treasuries and curators to all discretionary products, a market with a total value locked of approximately $25.9 billion.
- The SEC will not target code that falls outside its jurisdiction. It targets the specific operators who exercise decision-making power over the code.
- Compliance-oriented DeFi teams, including Steakhouse Financial and Maple Finance, have long been preparing for such regulatory attention.
- Historical precedent shows that only two outcomes withstand the test of time: full registration under existing securities laws, or the creation of new exemption provisions through legislation.
- The measures market participants can currently take are, at best, interim solutions. Only curators with sufficient capital to build post-hoc compliance infrastructure will be able to maintain their market position. Smaller curators with fewer resources will be eliminated.
The SEC Targets Decision-Making Authority, Not Code
On July 22, 2026, SEC Commissioner Hester Peirce issued a statement, "Headstands and Summervaults," arguing that the Howey Test (a legal standard established by the Supreme Court in 1946) could be applied to on-chain treasuries and lending strategies under existing securities laws.
The Howey Test assesses the economic substance of how funds are raised and managed. It does not require new legislation or regulatory rulemaking to apply. It is a fact-based standard that can be consistently applied to new financial instruments, regardless of their technological form. On-chain treasuries or decentralized lending strategies, no matter how complex the blockchain architecture, may be deemed investment contracts under securities laws if their structure meets the three core criteria of the test. When all three are satisfied, the product is classified as a security.
This statement does not have direct enforcement power, as it represents the view of a single commissioner. However, it marks the first time the regulatory framework being developed by the SEC's Crypto Task Force has been mapped onto specific products, causing concern among relevant market participants. The token MORPHO of the treasury infrastructure protocol Morpho fell approximately 5% immediately after the statement was released.
If this legal reasoning is put into practice, the regulatory target will almost certainly not be the smart contracts that drive the treasuries. Instead, it will be risk curators and those DeFi participants who have actual decision-making power over how assets are allocated. The treasury infrastructure built by Morpho is a technological tool for asset management. Code without a controlling party is not a natural target for regulatory sanctions.
Why Curators Have Become the Target
Curators decide how much of a treasury's capital is allocated where, and what level of risk that capital is exposed to. In this sense, they hold genuine decision-making power over depositors' assets. The treasury itself is merely a tool for the curator to manage these assets. Most treasuries are deployed as smart contracts with no admin keys or upgrade permissions, meaning even the original deployer cannot stop their operation or change their logic.
Financial regulation has historically been premised on the existence of an identifiable legal entity capable of receiving subpoenas, having assets frozen, or complying with injunctions. Immutable code without a controlling party has no such administrator.
The regulatory consequence is that enforcement attention shifts from code to decision-making authority. Earlier cases involving Tornado Cash and Uniswap Labs illustrate this pattern.
The core issue in the Tornado Cash case was whether immutable code constitutes sanctionable property. The Uniswap Labs case asked whether a company operating a non-custodial interface was effectively acting as an unregistered broker or exchange. Both cases focused on the legal status of code and the act of running a service. Neither touched on the issue of investment decision-making power as a basis for securities liability.
This time is different. The key question is no longer who built the protocol, but who decides which assets depositors' capital is exposed to, how much is allocated to each market, and how interest rate conditions and collateral parameters are adjusted to influence returns. Suppose a curator selects specific lending markets from the broader market, pulls capital out when risks rise, and shifts weight toward higher-yield markets. Depositors entrust their capital to that curator based on trust in their judgment, not trust in the underlying smart contract. Returns and losses flow directly from the curator's decisions. This pattern of professional decision-making exercised on behalf of depositors is precisely the defining characteristic of an investment contract identified by the Howey Test—"an expectation of profits from the efforts of others."
Curators are the party that most clearly exercises this type of decision-making power within the on-chain treasury ecosystem. That is why they are at the center of the regulatory framework.
Which Categories Would Be Covered
If this legal reasoning is broadly applied, the impact will not stop at risk curators. The SEC's analysis focuses on who is making investment decisions on behalf of users.
Liquid restaking operators decide which validators or actively validated services (AVS) receive asset allocations. Yield aggregators compare yields and risks across lending and liquidity markets and shift capital accordingly. On-chain asset allocation services adjust positions and weights over time. When a specific team or operator consistently makes decisions regarding asset selection and reallocation, their function is materially similar to that of a curator.
Therefore, the relevant scope is broader than the treasury product category itself. Whether any specific service falls within this scope depends on who selects assets, changes allocations, and controls loss exposure within that service. Aggregating potential exposure across categories by this standard results in a total value locked of approximately $25.9 billion.
The legal standard is unlikely to be applied uniformly across all these participants. Its intensity will vary based on the structure of the decision-making power involved.
The highest risk, attracting the strictest regulatory scrutiny, applies to structures where decision-making power is exercised in an opaque manner that depositors cannot verify in real-time on-chain, such as off-chain delegation and under-collateralized lending.
Medium risk applies to standard treasury curators and liquid restaking structures, which exercise allocation decision-making power, but capital flows are transparently recorded on-chain and subject to governance mechanisms like timelocks and guardian roles.
Lower risk, closest to compliance, applies to immutable protocol deployments without a controlling party, and financial products already registered under securities laws.
Those best positioned to accurately assess their own legal risk are the operators themselves. This is why curators and adjacent market participants, even before the commissioner's statement, had already begun developing tailored responses, including investor eligibility restrictions, third-party compliance arrangements, and formal private placement exemptions.
Four Design Approaches to Mitigate Regulatory Risk
The response measures developed so far do not solve the underlying legal issue. They primarily focus on reducing the probability of regulatory application and limiting the legal liability of the operating entity.
Two analytical dimensions distinguish these approaches: whether a recognized legal exemption has been obtained, and whether actual asset allocation authority has changed. Measured against these criteria, the market's current responses fall into four categories.
Direct Investor Eligibility Screening: Pre-verify and restrict sales to qualified investors only.
Establishing Regulated Distribution Channels: Distribute through exchanges or regulated entities that have completed user KYC.
Collateral-Level Whitelisting: Control allowed collateral assets through coordination with the asset issuer.
Structural Separation of Permissioned Lending and Permissionless Yield Tokens: Split institutional lending execution from retail-accessible yield exposure.
4.1 Investor Eligibility Screening: Grove and GLDY
The most direct way to mitigate regulatory risk is to control investor eligibility before accepting any capital.
Steakhouse Financial launched Grove in June 2025 as an institutional-only on-chain capital allocation channel. Access is limited to institutional RWA investors who pass advance eligibility screening.
Orca partnered with Streamex Corp (Nasdaq: STEX) in May 2026 to open the GLDY pool only to qualified investors. GLDY is a yield-bearing tokenized security backed by physical gold reserves, explicitly issued under Rule 506(c) of Regulation D (private placement exemption) under US securities laws. Investor accounts initially have on-chain transfers frozen, only being unlocked after passing Streamex's KYC and qualified investor verification.
Both approaches target institutional and qualified investors, establishing a logical basis for using private placement exemptions rather than full public registration.
However, investor eligibility screening does not eliminate the product's characterization as an investment contract under the Howey Test. Qualified investor status relates more directly to the distribution path than to the fundamental question of whether a security exists. This is a practical risk management method under the current legal framework, not a fundamental change in legal nature.
The curator's core function of selecting assets within the treasury and setting allocation weights remains unchanged, a structural limitation that these access controls cannot address.
4.2 Existing KYC and Compliance Infrastructure: Sentora
Rather than building its own eligibility framework, Sentora combines existing KYC-based distribution channels with regulated asset issuance infrastructure.
Kraken's DeFi Earn product is the clearest example. Veda provides the treasury infrastructure; Chaos Labs manages the Balanced and Boosted treasuries; Sentora acts as the risk manager for Advanced treasuries, overseeing capital allocation across on-chain protocols and managing risk and liquidity.
This arrangement was later adopted more broadly. Coinbase, in collaboration with Morpho and Steakhouse Financial, launched USDC lending through Prime and High Yield treasuries. Binance connected its users to Morpho treasuries managed by Steakhouse and Gauntlet.
KYC at the exchange level confirms user identity, while the issuer compliance framework supports reserve and redemption structures. Neither addresses who decides which assets and markets receive how much capital. External compliance infrastructure reduces risk at the asset and distribution levels, but it cannot absorb the regulatory risk or legal liability of the risk manager making allocation decisions.

Figure: Sentora's structure leveraging existing KYC and compliance infrastructure—users enter via CeFi exchanges (Coinbase/Kraken/Binance), are managed by risk curators like Steakhouse/Sentora/Gauntlet, and are ultimately deployed into lending pools like Morpho. Source: Tiger Research
4.3 Asset-Level Whitelisting: Aave Horizon
Aave launched Aave Horizon in August 2025, an institutional RWA lending market. The product is structurally separated from the core protocol and designed to meet the specifications required for institutional asset management.
Aave Horizon's unique design choice is to share control over allowed collateral with asset issuers, rather than directly restricting user access at the distribution stage. The whitelist of tokenized collateral assets is managed by the issuers themselves: Circle, Ripple, Superstate, and Centrifuge (including Janus Henderson products). The protocol itself remains permissionless for any wallet holding whitelisted assets.
The core control is not who accesses the market, but which assets are eligible. Risk parameters follow LlamaRisk's recommendations, with collateral valuations supported by Chainlink's real-time verified NAV data. Aave Horizon is built on top of existing Aave lending infrastructure, not a new chain or standalone protocol.
Sharing verification responsibility with asset issuers does not eliminate Aave Horizon's legal and operational liability for its risk parameter decisions.

Figure: Aave Horizon Pool operational structure—RWAs like tokenized treasuries, equities, and private credit enter a shared stablecoin pool as collateral, with issuers managing whitelists, LlamaRisk handling risk parameters, and Chainlink NAV providing price data. Source: Tiger Research
4.4 Structural Separation of Permissioned Lending and Permissionless Yields: Maple Finance
In April 2024, Maple Finance converted its entire platform to a whitelisted structure. All loans are now fully overcollateralized, with Maple Direct (its internal credit team) conducting borrower due diligence, ongoing monitoring, and margin calls. Access is restricted to approved institutional borrowers and lenders.
The most notable aspect of Maple's design is the separation between the permissioned lending operation and the permissionless yield access. In 2024, Maple launched the Syrup protocol, allowing retail users to deposit USDC and receive SyrupUSDC without KYC. These deposits flow into the same institutional lending pools managed by Maple Direct with its qualified borrowers. The lending itself operates under strict institutional compliance. The yield rights generated from lending are packaged into permissionless tokens, open to any user.
This structure repositions regulatory risk rather than eliminating it. Maple Direct's due diligence and management discretion (including borrower selection, collateral terms, and margin calls) remain unchanged. The arrangement where institutional lending returns are passed to SyrupUSDC holders raises new questions about whether the token constitutes an investment contract under the Howey Test, and separate distribution liabilities.
The structural separation of permissioned lending and permissionless yields is a deliberate repositioning of the focal point of regulatory scrutiny. It does not change the legal liability of the entity managing the capital or the fundamental nature of the product.

Figure: Maple's structural separation of permissioned lending and permissionless yield tokens—retail users deposit USDC via Syrup to receive SyrupUSDC, while Maple Direct performs due diligence, monitoring, and margin calls on institutional borrowers. Source: Tiger Research
The above cases involve different regulatory touchpoints, but share a common limitation. They are operational defense structures designed to manage regulatory risk by separating investors, assets, and distribution channels. They are not final solutions that eliminate legal risk.
Measured against the two analytical dimensions introduced earlier:
One approach secured an explicit legal exemption: the Orca/GLDY structure, directly applying Regulation D Rule 506(c).
The remaining approaches manage and limit regulatory risk: Grove, Sentora, Aave Horizon, and Maple Finance, through a combination of institutional eligibility restrictions, third-party compliance infrastructure, and collateral whitelisting.
Restricting distribution and screening eligibility does not solve the underlying legal liability attached to the curator's or protocol's discretionary asset selection and allocation decisions.
5. History Shows What Works
The future of the on-chain asset management market will be determined not by the surface appearance of code, but by the institutional frameworks established to manage the scope of discretion, disclosure transparency, and allocation of legal liability.
The measures examined above reduce immediate regulatory risk and provide space for using existing private placement exemptions. They do not address the fundamental questions of what standards govern curator allocation decisions and who bears responsibility when losses occur.
History is consistent on one point: access restrictions alone have not produced lasting institutionalization.
In the closed-end funds of the 1920s and 1930s, "blind pool" structures were widely abused, with managers not disclosing their investment objectives. The Investment Company Act of 1940 addressed this not by restricting access, but by institutionalizing the asset management function itself.
In 2008, when the SEC determined that LendingClub's peer-to-peer loan notes were securities, the company suspended new registrations and restructured into an SEC-registered


