Tiger Research: SEC Targets $25.9 Billion DeFi Market, Regulatory Focus Not on Code
- Core View: A statement from SEC Commissioner Hester Peirce argues that on-chain treasury and lending strategies can be subject to the Howey Test under securities law. The regulatory focus will shift from code to "risk curators" who hold actual decision-making power over asset allocation. This will impact an estimated $25.9 billion worth of discretionary DeFi products.
- Key Elements:
- The core of SEC regulation is the "decision-making power" that represents users in making investment choices, not the smart contract code itself. This is based on the Howey Test's criterion of "an expectation of profits from the efforts of others."
- The scope of impact is not limited to treasury curators but also includes liquidity restaking operators, yield aggregators, on-chain asset allocation services, and other DeFi products that make investment decisions on behalf of users. The total value locked is approximately $25.9 billion.
- Current market countermeasures (such as investor qualification screening, KYC infrastructure, asset whitelists, and structural separation) are only transitional solutions. They cannot fundamentally eliminate legal risks but can only reduce the likelihood of regulatory application.
- Historical experience suggests there are only two sustainable solutions: complete registration under current securities laws, or the creation of new exemptions for on-chain finance through legislation.
- Compliance costs will become a new barrier to entry. Large, well-capitalized curators can absorb these costs to consolidate their positions, while smaller curators with insufficient resources will be eliminated.
This article was written by Tiger Research. A statement by SEC Commissioner Hester Peirce has put on-chain treasuries and curators under the regulatory spotlight. If the legal logic is fully applied, the impact will not be limited to treasuries but will extend to all DeFi products that make investment decisions on behalf of users – a market with a Total Value Locked (TVL) of $25.9 billion. Regulation will not target the code, but will precisely target the people making decisions behind the code.
Key Takeaways
- If the legal reasoning is widely applied, the scope of impact will extend beyond treasuries and curators to all discretionary products, representing a total market TVL of approximately $25.9 billion.
- The SEC will not target code that falls outside its jurisdiction. It targets the specific operators who exercise decision-making power over the code.
- Compliance-oriented DeFi teams, including Steakhouse Financial and Maple Finance, have long been preparing for this type of regulatory scrutiny.
- Historical precedent suggests that only two outcomes withstand the test of time: full registration under existing securities laws, or the creation of new exemption provisions through legislation.
- The measures market participants can currently take are, at best, transitional solutions. Only curators with sufficient capital to build post-hoc compliance infrastructure will secure their market position. Smaller curators lacking resources will be eliminated.
The SEC Targets Decision-Making Power, Not Code
On July 22, 2026, SEC Commissioner Hester Peirce released a statement titled "Headstands and Summervaults," arguing that the Howey Test (the legal standard established by the Supreme Court in 1946) could be applied to on-chain treasuries and lending strategies under existing securities laws.
The Howey Test assesses the economic substance of how funds are raised and managed. It does not require new legislation or regulatory rulemaking to apply. It is a fact-based standard that can be continuously applied to novel financial instruments regardless of their technological form. On-chain treasuries or decentralized lending strategies, regardless of the complexity of their blockchain architecture, may be considered investment contracts under securities laws if their structure meets the three core criteria of the test. When all three are met, the product is classified as a security.
This statement does not have direct enforcement power, as it represents only the views of a single commissioner. However, it marks the first time the emerging regulatory framework of the SEC's Crypto Task Force has been mapped onto a specific product, raising concerns among relevant market participants. The token MORPHO of the treasury infrastructure protocol Morpho fell approximately 5% immediately after the statement's release.
If this legal reasoning is put into practice, the regulatory target will almost certainly not be the smart contracts that drive the treasuries. Instead, it will be risk curators and DeFi participants who have actual decision-making power over how assets are allocated. The treasury infrastructure built by Morpho is a technological tool for asset management. Code without a controlling party is not a natural target for regulatory sanctions.
Why Curators Have Become Targets
Curators decide how much capital in a treasury is allocated where, and what level of risk that capital is exposed to. In this sense, they hold genuine decision-making power over depositors' assets. The treasury itself is merely the tool through which the curator manages these assets. Most treasuries are deployed as immutable smart contracts without admin keys or upgrade permissions, meaning even the original deployer cannot stop their operation or change their logic.
Financial regulation has historically been predicated on the existence of an identifiable legal entity that can be served with a subpoena, have its assets frozen, or comply with an injunction. Immutable code without a controlling party has no such manager.
The regulatory consequence is that enforcement attention shifts from the code to the decision-making power. Earlier cases involving Tornado Cash and Uniswap Labs illustrate this pattern.
The core issue in the Tornado Cash case was whether immutable code constitutes sanctionable property. The Uniswap Labs case asked whether a company operating a non-custodial interface was effectively acting as an unregistered broker or exchange. Both cases focused on the legal status of the code and the act of running a service. Neither touched on investment decision-making power as a basis for securities liability.
This time is different. The key question is no longer who built the protocol, but who chooses which assets depositors' capital is exposed to, how much is allocated to each market, and how interest rate conditions and collateral parameters are adjusted to influence yields. Imagine a curator selecting specific lending markets from the broader market, pulling capital when risks rise, and shifting weights towards higher-yield markets. Depositors entrust capital to that curator based on trust in its judgment, not trust in the underlying smart contract. Gains and losses stem directly from the curator's decisions. This pattern of professional decision-making exercised on behalf of depositors is precisely the defining characteristic of an investment contract identified by the Howey Test – "the expectation of profits from the efforts of others."
Curators are the party that most explicitly exercises this type of decision-making power in the on-chain treasury ecosystem. That is why they are at the center of the regulatory framework.
Which Categories Will Be Included
If this legal reasoning is widely applied, the impact will not stop at risk curators. The SEC's analysis focuses on who is making investment decisions on behalf of users.
Liquid restaking operators decide which validators or Actively Validated Services (AVS) receive asset allocations. Yield aggregators compare yield and risk across lending and liquidity markets and transfer capital accordingly. On-chain asset allocation services adjust positions and weightings over time. When a specific team or operator consistently makes decisions regarding asset selection and reallocation, their function is substantially similar to that of a curator.
Therefore, the relevant scope is broader than the treasury product category itself. Whether any specific service falls within this scope depends on who is selecting assets, changing allocations, and controlling loss exposure within that service. Aggregating potential exposure across categories by this standard, the total TVL is approximately $25.9 billion.
The legal standard is unlikely to be applied uniformly across all these participants. Its intensity will vary based on the structure of the decision-making power involved.
The highest risk, facing the strictest regulatory scrutiny, involves structures where decision-making power is exercised in an opaque manner that depositors cannot verify on-chain in real time, such as off-chain delegation and uncollateralized lending.
Moderate risk involves standard treasury curators and liquid restaking structures. They exercise allocation decision power, but capital flows are transparently recorded on-chain and subject to governance mechanisms like timelocks and guardian roles.
Lower risk, closest to compliance, includes immutable protocol deployments without a controlling party, and financial products already registered under securities laws.
The parties best able to accurately assess their own legal risk are the operators themselves. This is why curators and adjacent market participants had already begun developing tailored responses before the Commissioner's statement, including investor qualification restrictions, third-party compliance arrangements, and formal private placement exemptions.
Four Design Approaches to Mitigate Regulatory Risk
The responses formulated so far do not address the underlying legal issues. They primarily focus on reducing the probability of regulatory application and limiting the legal liability of the operating entities.
Two analytical dimensions differentiate these approaches: whether a recognized legal exemption has been obtained, and whether actual asset allocation authority has changed. Measured against these standards, the market's current responses fall into four categories.
Direct Investor Qualification Screening: Pre-verify and restrict sales to qualified investors only.
Establishing Regulated Distribution Channels: Distribute through exchanges or regulated entities that have already performed user KYC.
Collateral-Level Whitelisting: Control permissible collateral assets by coordinating with asset issuers.
Structural Separation of Permissoned Lending and Permissionless Yield Tokens: Split institutional lending execution from retail-accessible yield exposure.
4.1 Investor Qualification Screening: Grove and GLDY
The most direct way to mitigate regulatory risk is to control investor qualification before accepting any capital.
Steakhouse Financial launched Grove in June 2025 as an institutional-only on-chain capital allocation channel. Access is restricted to institutional RWA investors who pass advance qualification screening.
Orca partnered with Streamex Corp (NASDAQ: STEX) in May 2026 to open GLDY pools exclusively to qualified investors. GLDY is a yield-bearing tokenized security backed by physical gold reserves, explicitly issued under Rule 506(c) of Regulation D (private placement exemption) of the U.S. Securities Act. Investor accounts are initially frozen for on-chain transfers, unlocking only after passing KYC and accredited investor verification through Streamex.
Both approaches target institutional and qualified investors, establishing a logical basis for using private placement exemptions rather than full public registration.
However, investor qualification does not eliminate the product's characterization as an investment contract under the Howey Test. Accredited investor status relates more directly to the distribution path than to the fundamental question of whether a security exists. This is a practical risk management approach under the current legal framework, not a fundamental change in legal nature.
The curator's core function of selecting assets and setting allocation weights within the treasury remains unchanged—a structural limitation that these access controls cannot address.
4.2 Utilizing Existing KYC and Compliance Infrastructure: Sentora
Instead of building its own qualification framework, Sentora combines existing KYC-based distribution channels with regulated asset issuance infrastructure.
Kraken's DeFi Earn product is the clearest example. Veda provides the treasury infrastructure; Chaos Labs manages the Balanced and Boosted treasuries; Sentora acts as the risk manager for the Advanced treasury, overseeing capital allocation across on-chain protocols and managing risk and liquidity.
This arrangement was later more broadly adopted. Coinbase, in conjunction with Morpho and Steakhouse Financial, launched USDC lending via Prime and High Yield treasuries. Binance connected its users to Morpho treasuries managed by Steakhouse and Gauntlet.
KYC at the exchange level confirms user identity, and the issuer compliance framework supports reserve and redemption structures. Neither addresses who decides which assets and markets receive how much capital. External compliance infrastructure reduces risk at the asset and distribution layers, but cannot absorb the regulatory risk or legal liability of the risk manager making allocation decisions.

Figure: Sentora’s structure leveraging existing KYC and compliance infrastructure – Users enter via CeFi exchanges (Coinbase/Kraken/Binance), are managed by risk curators like Steakhouse/Sentora/Gauntlet, and are ultimately deployed into lending pools like Morpho. Source: Tiger Research
4.3 Asset-Level Whitelisting: Aave Horizon
Aave launched Aave Horizon in August 2025, an institutional RWA lending market. The product is structurally separated from the core protocol and designed to the specifications required for institutional asset management.
Aave Horizon's unique design choice is to share control of allowable collateral with asset issuers, rather than directly restricting user access at the distribution stage. Whitelisting of tokenized collateral assets is managed by the issuers themselves: Circle, Ripple, Superstate, and Centrifuge (including Janus Henderson products). The protocol itself remains permissionless for any wallet holding whitelisted assets.
The core control is not *who* accesses the market, but *which assets* are eligible. Risk parameters follow recommendations from LlamaRisk, with collateral valuations supported by Chainlink NAV data verified in real-time. Aave Horizon is built on existing Aave lending infrastructure, not a new chain or standalone protocol.
Sharing verification responsibility with asset issuers does not eliminate Aave Horizon's legal and operational liability for its risk parameter decisions.

Figure: Aave Horizon Pool operational structure – RWAs like tokenized treasuries, equities, and private credit enter a shared stablecoin pool as collateral, with issuers managing the whitelist, LlamaRisk handling risk parameters, and Chainlink NAV providing price data. Source: Tiger Research
4.4 Structural Separation of Permissioned Lending and Permissionless Yield: Maple Finance
In April 2024, Maple Finance converted its entire platform into a whitelist structure. All loans are now fully overcollateralized, with Maple Direct (its internal credit team) conducting direct borrower due diligence, ongoing monitoring, and margin calls. Access is restricted to approved institutional borrowers and lenders.
The most notable aspect of Maple's design is the separation between the permissioned lending operation and the permissionless yield access. In 2024, Maple launched the Syrup protocol, where retail users can deposit USDC and receive SyrupUSDC without KYC. These deposits flow into the same institutional lending pools managed by Maple Direct with its qualified borrowers. Lending itself operates under strict institutional compliance. The yield rights generated from lending are packaged into permissionless tokens, open to any user.
This structure repositions regulatory risk rather than eliminating it. Maple Direct's discretion in due diligence and management (including borrower selection, collateral terms, and margin calls) remains unchanged. The arrangement where institutional lending returns are passed to SyrupUSDC holders creates a new question of whether the token constitutes an investment contract under the Howey Test, and raises separate distribution liabilities.
The structural separation of permissioned lending and permissionless yield is a deliberate repositioning of where regulatory scrutiny lands. It does not change the legal liability of the entity managing the capital or the fundamental nature of the product.

Figure: Maple's separation structure of permissioned lending and permissionless yield tokens – Retail users deposit USDC via Syrup to get SyrupUSDC; Maple Direct handles due diligence, monitoring, and margin calls for institutional borrowers. Source: Tiger Research
The above cases involve different regulatory touchpoints but share a common limitation. They are operational defense structures designed to manage regulatory risk by segregating investors, assets, and distribution channels. They are not ultimate solutions for eliminating legal risk.
According to the two analytical dimensions introduced earlier:
One approach obtained a clear legal exemption: the Orca/GLDY structure, directly applying Regulation D Rule 506(c).
The remaining approaches manage and limit regulatory risk: Grove, Sentora, Aave Horizon, and Maple Finance, through a combination of institutional qualification restrictions, third-party compliance infrastructure, and collateral whitelisting.
Restricting distribution and screening qualifications does not resolve the underlying legal liability attached to the discretionary asset selection and allocation decisions made by the curator or protocol.
5. What History Shows Works
The future of the on-chain asset management market will be determined not by the surface appearance of the code, but by the institutional frameworks established to manage discretionary scope, disclosure transparency, and legal liability allocation.
The measures examined above reduce immediate regulatory risk and provide space to use existing private placement exemptions. They do not answer the fundamental questions of the standards governing curators' allocation decisions and who bears responsibility when losses occur.
Historical precedent is consistent on one point: access restrictions alone have not produced durable institutionalization.
In the closed-end funds of the 1920s and 1930s, "blind pool" structures were widely abused, with managers not disclosing their investment objectives. The Investment Company Act of 1940 addressed this not by restricting access, but by institutionalizing the asset management function itself.
In 2008, when the SEC determined that LendingClub's peer-to-peer loan notes were securities, the company suspended new registrations and re


