SEC Commissioner Hester Peirce speaking at an event in Las Vegas

Hester Peirce Warned Crypto Vault Builders About a ‘Painful Fall.’ Four Traps Sit Underneath

July 22, 2026 2:41 pm Comments

SEC Commissioner Hester M. Peirce has spent years arguing that American regulators should leave room for crypto to build.

That is precisely why her newest warning lands harder than the usual speech from Washington.

Peirce is not telling developers that every DeFi vault is a security. She is telling them that the word “vault,” a smart contract and an onchain address do not make the people exercising financial judgment disappear.

And once those people come back into view, four different parts of securities law can follow them.

In a statement published Wednesday, Peirce cautioned builders against twisting existing law until it appears not to apply, while restating that moving a regulated financial activity onchain does not carry it beyond the statute. Her blunt conclusion was that this kind of legal gymnastics can end in “a painful fall.”

The statement is not an SEC rule, order or enforcement action and carries no binding finding against a market participant. It is Peirce’s own analysis, and it does not name a single protocol or declare that all products sold as vaults share one legal structure.

That distinction matters. Nothing in it establishes that Aave, Morpho, Yearn or any other specific platform violated the law.

What it does establish is a framework for asking harder questions about the people behind automated yield.

Crypto vaults usually collect assets from users and deploy them into one or more strategies. Depending on the product, that may mean lending, staking, liquidity provision, leveraged positions or movement among several protocols in search of a return.

Some vaults operate according to rules locked into immutable code. Others give a curator, manager, committee or governance process broad power to choose where assets go and when the strategy changes.

Peirce treats that difference as central.

Her analysis follows discretion wherever it sits, including behind an administrator key, inside a curator mandate or in the hands of a group that can replace the strategy.

Automation can execute a financial decision without changing who made it or whose expertise attracted the deposit.

The more a person selects yield opportunities, reallocates deposits or chooses who will make those decisions, the harder it becomes to describe the product as neutral software carrying out a user’s independent instructions.

The first legal trap is the familiar investment-contract analysis.

A vault can begin to look like a common enterprise when users contribute value and reasonably expect profits from the managerial work of a deployer or curator. Code may execute the transactions, but a human can still be the source of the strategy that users are buying.

Peirce stops short of concluding that every pooled vault passes the legal test. Courts and regulators will examine the economic reality rather than the label attached to the interface.

Peirce points to United Housing Foundation v. Forman, a Supreme Court decision emphasizing that substance controls when an arrangement is tested as an investment contract.

The 1975 case involved shares tied to apartments in a housing cooperative. The Court found that purchasers were seeking a place to live, not profits from the managerial efforts of others, despite the “stock” label on the instrument.

The comparison cuts both ways for DeFi. A familiar software label cannot remove a profit-seeking arrangement from securities law any more than a familiar financial label can pull a consumer transaction into it.

A developer who calls a product “non-custodial” or “permissionless” therefore has not answered who designed the profit-seeking strategy, who can replace it and whose judgment depositors rely upon.

The second trap is investment-company law.

If a vault holds securities or allocates user assets into securities, its structure may resemble a regulated pooled investment vehicle. Peirce says the comparison can change with the design.

A largely fixed portfolio may resemble a unit investment trust. An actively adjusted strategy may look closer to a management investment company. A product tailored to an individual customer can begin to resemble a separately managed account.

Those are materially different legal forms, even when all three are delivered through the same kind of wallet connection.

The smart contract tells only part of the story. The assets held, the discretion exercised and the relationship promised to the customer matter just as much.

The third trap sits inside onchain lending.

It is tempting to assume that a loan cannot become a security when the collateral and repayment logic live on a public blockchain. Peirce rejects that shortcut.

Under Reves v. Ernst & Young, a note can be a security depending on factors such as why the borrower and lender entered the transaction, how the instrument is distributed, what the public reasonably expects and whether another regulatory regime reduces the risk.

The Supreme Court begins with a presumption that a note is a security, then asks whether it closely resembles a recognized category of ordinary non-security notes. The test is commonly called the family-resemblance approach.

Peirce’s citation places an onchain loan inside that same inquiry. Automatic liquidation and crypto collateral can change the facts without erasing the repayment promise being sold.

That inquiry does not necessarily turn on whether the deposited token is itself a security.

A lending arrangement can create its own legal issue through the note or promise to repay. The blockchain rail does not erase the character of the obligation traveling over it.

The fourth trap is adviser regulation.

A person who chooses supported assets, sets interest rates, changes loan-to-value limits or determines liquidation thresholds is making decisions that can directly shape another person’s financial outcome.

If those decisions involve securities and are made for compensation, investment-adviser questions can arise even if the service is marketed as protocol curation.

This may be the most consequential part of Peirce’s statement because it moves the analysis beyond the token and into the operating role.

A project can spend years arguing that its asset is not a security and still face a separate question about whether someone is managing a securities portfolio, offering a security-like note or providing regulated advice.

There is no single switch that resolves all four.

A vault might avoid one category and enter another. A lending market could involve non-security collateral while creating notes that require their own analysis.

A passive contract can become more legally complicated after an upgrade adds human discretion.

Peirce repeatedly returns to specific facts and circumstances for exactly that reason.

The statement also contains an important limit on the SEC’s reach.

Peirce says any analysis must respect the jurisdiction Congress actually gave the agency and protect developers’ free-speech rights. She leaves open the possibility that a vault or lending strategy falls outside federal securities law altogether.

The caveat keeps her warning from becoming a declaration that software developers are automatically financial intermediaries.

Writing code, publishing an interface and actively managing other people’s assets are not the same activity. A serious analysis has to separate them.

The difficult cases will be the products that blur those boundaries.

Consider a vault whose strategy is set by an offchain team, whose parameters can be changed through an administrator key and whose marketing promises professional risk management. Calling the resulting transaction “automatic” does not remove the decisions made before the code executes.

Now consider a contract with immutable rules, no curator, no upgrade path and no party selecting investments after deployment. That structure presents a different set of facts, though it still does not receive an automatic exemption.

The distance between those designs is where much of the legal risk lives.

Builders now have a clearer list of facts they will need to document.

Who can change the strategy? Who chooses eligible assets?

Who collects fees? Who can pause withdrawals?

Who sets lending terms? Who replaces a curator?

What happens if governance participants vote to take an action that a traditional portfolio manager would make?

Each question locates judgment, control and economic dependence inside the product.

Marketing will matter too.

A protocol that sells access to a fixed piece of software is making a different representation from a service that promises experts will hunt for the best yield, rotate positions and protect customers from changing markets.

The second description invites customers to rely on managerial skill. That reliance is exactly what several of the legal tests are built to find.

Peirce’s position is not that innovation should stop until every old rule has a clean onchain equivalent.

She explicitly asks whether SEC regulations should be modified to accommodate vaults, lending and other new tools without abandoning investor protection, orderly markets or capital formation.

She also invites market participants to approach the agency about compliant paths.

That invitation fits the broader stance she took in a 2025 statement on tokenization: changing the technological wrapper does not change the legal nature of the thing inside it.

Her earlier warning focused on tokenized stocks and other instruments whose rights remain securities rights after they move to a blockchain. A faster settlement rail can improve the product without rewriting the statute that governs it.

The same principle now reaches beyond tokenized stocks and bonds. It reaches the layer of smart contracts that pools assets, allocates risk and turns somebody’s financial judgment into yield for somebody else.

For DeFi, the dividing line is becoming less about whether code is involved and more about what work the code is carrying out, who chose that work and who retains the power to change it.

Peirce has not closed the door on crypto vaults.

She has made clear that walking through it requires more than placing a familiar financial function onchain and declaring the old law unable to follow.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.