Bottom Line: This Is Not a Rule That Every DeFi Vault Is a Security
On July 22, 2026, SEC Commissioner Hester M. Peirce published Headstands and Summervaults: A Statement on Crypto Vaults and Lending Strategies. Her central point was that moving activity that already falls within federal securities law onchain generally does not move it outside that law.
The statement is Peirce's own view, not a Commission rule, court judgment, enforcement order or blanket classification of DeFi. She also acknowledged that many crypto assets and activities are outside federal securities law. Whether a particular vault or lending strategy is inside depends on its specific facts and circumstances.
What Is a DeFi Vault?
A DeFi vault generally accepts users' crypto assets and uses smart contracts to deploy them into lending, staking, liquidity pools or other yield strategies. A depositor may make one deposit while the vault performs several underlying steps. “Vault” has no single legal or technical definition, however, and control differs substantially among products.
| Structure | Who makes key decisions? | Beginner takeaway |
|---|---|---|
| Fixed and fully automated | Immutable contracts allocate under prewritten rules, with little or no power to rebalance discretionarily | Reliance on ongoing managerial effort may be lower, but automation is not an automatic exemption |
| Upgradeable or governed | Governance, an admin or multisig can change code, parameters, markets or pause rules | Analyze actual control and upgrade powers, not merely the “DAO” label |
| Actively curated or managed | A curator or team selects yield markets, reallocates assets and sets exposures or risk parameters | Reliance on professional judgment is more visible, making securities, fund and adviser questions more prominent |
“Executed by code” therefore does not necessarily mean “unmanaged.” Strategy selection, reallocation, appointment of decision-makers, asset-list changes and emergency withdrawal controls can all matter.
Why Does Active Management Matter?
Peirce identified selecting yield activities, reallocating among them and selecting the people who make those decisions as examples of vault management. For lending strategies, she pointed to setting rates, selecting supported assets, setting loan-to-value limits and establishing liquidation thresholds.
These actions do not automatically make a product unlawful or a security. They sharpen the factual question of whether depositors reasonably expect profit from a deployer's, curator's or other person's entrepreneurial or managerial efforts. A genuinely immutable vault that follows mechanical rules without ongoing discretion may show less reliance, but pooling, marketing, fees, underlying assets and other facts still matter.
Four US Securities-Law Questions in Plain English
1. Investment contract
A vault arrangement may raise an investment-contract question when users commit money or assets to a common enterprise and reasonably expect profit derived from others' entrepreneurial or managerial efforts. The inquiry looks past the “decentralized” label to who designs, promotes, adjusts and sustains the strategy and whether users rely on that work.
2. Investment company
A vault that holds securities or allocates assets to securities investments may enter investment-company territory. Peirce noted that vaults could resemble a unit investment trust holding a fixed portfolio with little management, an actively managed investment company, or a separately managed account offering individualized treatment. A non-security underlying token does not necessarily resolve the status of the whole arrangement.
3. Investment adviser
Choosing strategies or managing allocations for compensation can raise adviser questions when the service concerns securities. Management fees, performance fees or protocol incentives make it important to examine what the curator does, how much discretion it has, how it is paid and what assets it manages. Recording decisions onchain does not by itself prevent them from being advice or management.
4. Lending and notes
Onchain lending analysis does not depend only on whether the borrowed asset is itself a security. Depending on the parties' motivations, distribution plan, public expectations and other facts, a loan or lending program can bear characteristics of a note that is a security. Fixed rates, overcollateralization or automatic liquidation do not create one universal answer.
What Risks Do Vault Users Face?
- Smart-contract risk: bugs, upgrade keys, admin privileges, integrations and bridges can cause losses; an audit is not insurance.
- Curator risk: a manager may choose a weak market, concentrate exposure, exit too slowly or face fee and related-party conflicts.
- Liquidation risk: falling collateral, changed LTV settings or thin liquidity can trigger rapid liquidation, penalties and slippage.
- Rehypothecation risk: assets may be lent, pledged again or deployed through several protocols, adding counterparties and hidden contagion paths.
- Oracle risk: delayed, incorrect or manipulated prices can cause wrongful liquidations, bad debt or unfair conversions.
- Regulatory and access risk: front ends may geofence users, providers may change US eligibility, or deposits, yield features and markets may pause after legal review. A reachable contract does not guarantee lawful eligibility or continued website and fiat access.
Liquidity also matters. Displayed APY is not guaranteed, and withdrawals can be constrained by queues, utilization, lockups, bad debt, price impact and gas costs.
Eight Checks Before Depositing
- Who can upgrade contracts, pause withdrawals or replace the curator?
- Does a fixed rule generate the strategy, or does a team continually select and rebalance markets?
- Which protocols receive deposits, and can assets be rehypothecated or bridged?
- Who changes rates, LTV, collateral lists and liquidation thresholds?
- How is the curator paid, and does it have related-party or market-specific incentives?
- Which oracle is used, and what happens during failures or extreme markets?
- Can users exit immediately, or must they wait for repayment or a withdrawal queue?
- Is the product available where the user lives, and do terms address regulatory and access changes?
What Did the SEC Statement Not Say?
- It did not classify every DeFi vault, curator or onchain loan as a security.
- It did not say every automated smart contract is outside securities law.
- It did not create a safe harbor for a whole product merely because an underlying token is not a security.
- It did not replace case law, formal rules, exemptions or product-specific legal analysis.
The careful conclusion is that onchain is a technology rail, not a legal classification. More ongoing human discretion over yield selection and customer assets generally makes the securities-law questions more important, but every conclusion remains fact-specific.
Read next: what DeFi is, the CLARITY Act market-structure update, how to revoke wallet approvals, and exchange custody risks.