Learn from the past.
Prepare for the future.
Tracking the global digital assets ecosystem

Vaults, the Securities Laws, and the Architecture of Trust

By TuongVy Le, General Counsel, Veda

Vy Le, Veda

Recently, SEC Commissioner Hester Peirce issued a thoughtful statement on decentralized finance, including decentralized lending protocols and “vaults” – software that allows users to deploy digital assets according to predefined strategies. Whether one agrees with every aspect of the statement, it raises an increasingly important question: How should the federal securities laws apply to these new forms of financial infrastructure?

As digital assets become increasingly integrated into mainstream finance, that question will only grow in importance. The answer should begin with a principle that is neither new nor unique to crypto: the federal securities laws regulate legal and economic relationships, not technology. The inquiry is therefore not whether blockchain or smart contracts are involved, but whether they create, eliminate, or materially alter the legal and economic relationships that the securities laws regulate.

Technology has always changed financial markets. What makes blockchain distinctive is not simply that it automates existing processes. It changes where authority and trust reside.

For nearly a century, securities regulation has addressed a recurring problem: investors entrust assets to intermediaries who exercise legally significant authority on their behalf. Because that authority creates opportunities for abuse, the law imposes fiduciary duties, governance requirements, disclosure obligations, custody rules, and other protections. Much of the federal securities laws can be understood as a response to the need for investors to trust intermediaries with continuing authority over their assets.

Modern software presents a different possibility. Some forms of authority that once had to be entrusted to an intermediary can now be constrained or eliminated through system architecture. Investors may still rely on markets, pricing, counterparties, and the integrity of the software itself. But they need not rely on an intermediary to exercise the same degree of continuing authority over their assets.

That does not make the securities laws less relevant. It changes the threshold question. Before asking which regulatory regime applies, we should ask a simpler question: Where do investors still have to trust a third party with legally significant authority over their assets? That question lies at the heart of the analysis.

The word vault is not a legal category but a technological one. In practice, vaults encompass a wide range of architectures. Some simply automate participation in decentralized markets according to predetermined rules. Others retain substantial discretion over investor assets after they have been committed. Those differences matter because they create fundamentally different legal relationships.

The relevant question is therefore whether the vault recreates the same intermediary authority that existing securities-law doctrine addresses or materially changes that relationship. Although Reves, Howey, and the Investment Company Act address different legal questions, each begins from a common premise: an intermediary has acquired legally significant authority over investor assets.

Take Reves v. Ernst & Young. Before asking whether a note is a security, one must identify the repayment obligation that allegedly exists. Traditional financialintermediaries borrow customer assets onto their own balance sheets and assume an independent obligation to repay them. That debtor-creditor relationship is the foundation on which Reves rests.

By contrast, many decentralized lending protocols facilitate collateralized lending among market participants pursuant to predetermined protocol rules. If neither the protocol nor the vault has become the borrower or assumes an independent repayment obligation, the legal relationship to which Reves applies may not exist.

The same principle applies under SEC v. W.J. Howey Co. Historically, investment contracts involved investors transferring assets to a common intermediary that acquired authority to deploy those assets on behalf of the enterprise. That transfer of authority has traditionally provided the foundation for the “common enterprise” prong of the Howey test.

Many vault architectures instead automate participation in an underlying market while leaving each participant’s custody, ownership, and legal relationship to their assets materially unchanged. If neither the protocol nor the vault acquires the sort of authority over investor assets that historically accompanied a common enterprise, the legal relationship on which Howey rests may be absent.

The same insight extends beyond Reves and Howey. The Investment Company Act addresses another familiar form of intermediary authority. Investors entrust assets to a fund whose managers and service providers exercise continuing authority over those assets and honor investors’ economic and redemption rights pursuant to contractual and statutory obligations. The Act responds by imposing an extensive framework of governance, custody, valuation, disclosure, and fiduciary protections.

But software may change that relationship too. To the extent ownership interests, redemption rights, investment constraints, and other operational protections can be enforced through system architecture rather than entrusted to an intermediary’s continuing discretion, the nature of the legal relationship changes. That does not determine how the Investment Company Act applies in every case. It does suggest that the analysis should begin by asking what authority the intermediary actually possesses, not what authority intermediaries historically had.

None of this means vaults deserve special treatment. They deserve the same facts-and-circumstances analysis that courts have long applied to every other form of financial innovation.

As blockchain-based financial infrastructure evolves, regulators will continue to encounter architectures that look unfamiliar. The temptation will be to treat technological novelty as though it requires a new legal framework. It does not.

Blockchain changes financial architecture by changing where legally significant authority over investor assets resides. Sometimes software will recreate the same intermediary relationships that have long been subject to the federal securities laws. Sometimes it will materially constrain or eliminate them. Existing securities law doctrine is fully capable of distinguishing between those possibilities because it has always focused on legal and economic substance rather than technological form.

Vaults are simply the latest example. They may change how financial markets are organized. They should not change how we analyze them. The right place to begin is not with the technology itself. It is with a simpler question: Where do investors still have to trust a third party with legally significant authority over their assets, and what legal consequences follow?

 

MOST READ

PODCAST