Could Some Vaults Trigger Securities Law? Yes, but It's Case by Case
Sunday, 9 August 2026 · 3 min read · Listen to the episode ↗
SEC Commissioner Hester Peirce's observation that some vaults could implicate federal securities laws under the Howey test is the sharpest regulatory signal the vault sector has received, and it arrives just as products from Robinhood, Coinbase, Kraken, and MetaMask are pulling mainstream retail users into DeFi for the first time.
Vaults are on-chain vehicles that pool user assets and deploy them across DeFi strategies including lending, real-world asset baskets, and trading. Three parties are required to operate one: an infrastructure provider that builds the smart contracts, a curator that manages risk decisions such as collateral selection and liquidity buffers, and a distributor that owns the user relationship. Total value locked in vaults stood at approximately 67 billion dollars at the time of recording. VEDA is an institution-focused vault infrastructure provider whose design priorities are access to on-chain primitives, compliance guardrails, and continuous verifiability of assets and strategies.
Most net new DeFi users are now arriving through fintech platforms rather than engaging directly with underlying protocols. Robinhood, Coinbase, Kraken, and MetaMask are all building vault products. Robinhood launched an earned program shortly before the recording, with many of its users likely never having touched DeFi before. VEDA launched as infrastructure partner to Kraken DeFi Earn in January with three stablecoin products, later adding BTC Earn, and has grown to over 600 million dollars in assets across more than 80,000 users, with Centora serving as curator for those products.
The risk spectrum for vaults runs from smart contract risk through operational risk to economic and collateral risk. Smart contract risk has declined meaningfully over the past six to twelve months due to better coding practices, improved auditing tools, and stronger security capabilities. Operational and key management risk has increased and is now where risk is most concentrated in DeFi. The Kelp incident and the Drift exploit are cited as major recent examples of failures rooted in operational weaknesses rather than smart contract flaws. Economic and collateral risk arises when collateral value falls faster than it can be liquidated to repay users.
The Stream Finance incident in November created approximately 285 million dollars of exposure across vaults. Curators chasing high yields contributed to that exposure, and after the incident there was a significant pullback in on-chain risk taking. The underlying structural problem is that curators competing on yield tend to move further down the risk curve on behalf of users who are often unaware this is happening. A similar incident is expected to recur because DeFi is an open system where long-tail assets can become composable with a much broader universe of products.
Insurance programs for vaults exist but no major claim has been processed yet, making it difficult to assess their real effectiveness. Rating agencies including crypto-native firms like Credora within Redstone and traditional players like S&P are beginning to rate vaults. Key management best practices center on securing critical keys with multisig arrangements using time locks where every signer uses a hardware key. Blind signing on non-isolated devices is identified as falling below acceptable standards.
SEC Commissioner Hester Peirce stated that some vaults could potentially implicate federal securities laws because they may constitute a common enterprise in which users invest money with a reasonable expectation of profits derived from the managerial efforts of others. That language maps directly to the Howey test used in the United States to determine whether an instrument is subject to securities regulation. Whether a specific vault triggers securities law depends on its particular structure, analogous to the facts-and-circumstances analysis Howey requires. VEDA's position is that vaults conducting only on-chain lending through protocols like Aave and Morpho are not taking exposure to underlying securities, but as more securities migrate on chain, vaults will increasingly implicate securities laws directly.
Regulatory attention is intensifying now precisely because vault products are reaching mainstream retail users rather than only sophisticated participants. Lack of regulatory clarity is currently preventing financial institutions and fintechs from fully committing to the vault space. VEDA has been engaging with regulators for several months, with its general counsel working to educate them on vault structures and the design tradeoffs involved in building compliant products.
This summary was generated from the episode transcript and can contain mistakes.