Share:
The SEC Has a New Theory for Crypto. Now It Has to Make It Work
Josh Riezman
Chief Legal & Strategy Officer
For years, the digital asset industry's North Star was decentralization. In a 2018 speech, then-SEC Corporation Finance Director William Hinman suggested that a token on a sufficiently decentralized network might no longer be a security. The SEC staff's 2019 Framework turned that idea into guidance, suggesting a token could shed that status because purchasers would no longer be relying on a central team to drive the network's success, answering that reliance question by measuring how decentralized the network had become. The Framework was never binding, the courts never adopted it, and the Gensler SEC functionally rejected it, opting instead for regulation by enforcement. But for lack of anything better, projects reverse-engineered themselves around it. That distorted a lot of decisions by entrepreneurs. Roadmaps got vaguer and projects spent a lot of effort proving nobody was responsible for the thing everyone was working hard to build.
The SEC has now replaced that North Star. In March 2026, it issued an interpretive release that expressly distinguishes the crypto asset from the investment contract through which it may be sold. In August, it proposed a new rule called Regulation Crypto Assets, which would create a framework for raising capital through those investment contracts and a path for the investment contract to end once the issuer's essential managerial efforts have been completed. In September, Corp Fin published a set of FAQs applying the framework to specific practices like token buybacks. Together, the three point toward a different organizing idea. What matters is no longer how decentralized a network is, but whether the issuer has finished the work it promised, with functionality serving as the staff's marker for when that is likely true. Nothing in Howey required the SEC to read it this way. That was an interpretive choice at some level, and answering the question case by case means drawing the securities boundary one exception and one edge case at a time.
The SEC has chosen a theory that may be workable, but only if it builds enough certainty around it for the secondary market to function. The key distinction is that the SEC is not necessarily saying the token itself is a security that later becomes a non-security. Its theory is that a non-security crypto asset can be sold as part of an investment contract. The investment contract arises from the surrounding promises and expectations, particularly what an issuer has promised to build and the managerial efforts purchasers expect it to undertake. In our comment letter on the March release, we referred to this, as others have, as attachment and separation. The investment contract attaches to the token when the issuer sells it, and separates once the promised efforts are complete or abandoned. Proposed Rule 400 would formalize one way to make that separation effective by allowing an issuer to file a transition report once its promised managerial efforts are complete.
The basic token lifecycle is therefore straightforward. A project raises capital, builds the network or application, separates from the investment contract and ends up with a non-security token. The difficulty begins when that token has to trade in a global, fungible market while the attachment persists.
If the token remains subject to an investment contract, venues and intermediaries need a regulatory framework for handling it, much of which does not exist today. The SEC's answer appears to be that many projects can avoid that problem by reaching functionality and staying within the boundaries of the new guidance. But the market still has to know which tokens have separated from their investment contracts and which have not.
This is the central tradeoff in the SEC's approach. An asset-level framework, of the kind CLARITY would have created, puts the facts and circumstances judgment on the issuer, where the capital raise is regulated, and gives everyone else a stable answer about what they are dealing with. An attachment model cannot do that as cleanly. The legal analysis follows the issuer's relationship with purchasers, so every party in the chain has to reach its own view of it.
The blockchain does not tell a market maker like GSR whether an investment contract is attached to a token. To know, we may need to reconstruct what the issuer promised, what buyers understood those promises to mean, which efforts were essential, whether they have been completed and whether something since has created a new contract. It may not even be obvious whose statements matter. Is it the foundation, an affiliated lab, a venture backer with governance rights or a third-party promoter? Doing that across hundreds of assets and thousands of trades a day is not feasible.
There is also a perverse incentive. A project that publishes a detailed roadmap and clearly describes its future plans may stay attached for longer, and with more uncertainty, than one that says very little, meaning the more transparent project can become the harder asset to trade. That is one reason GSR asked the Commission in our comment letter for a broker-dealer registration safe harbor for firms trading non-security crypto assets as principal, regardless of whether an investment contract may at some point have attached.
Once the SEC chooses the attachment path, it has to give the market enough certainty to function. Otherwise every exchange, custodian, lender and market maker is left trying to solve a facts-and-circumstances analysis for every asset. There are two ways to avoid that outcome: the Commission can provide broad relief for secondary trading, or it can make the safe zones broad and objective enough that market participants can become reasonably comfortable that a token is outside the securities perimeter when certain conditions are met.
The recent FAQs suggest the Commission understands this. Corp Fin says that once a system is functional, continued development, funding of network effects and promotion of existing utility do not, without more, involve the essential managerial efforts that create an investment contract. That is important for issuers, but arguably more important for intermediaries. If ordinary post-launch activity does not recreate an investment contract, the risk perimeter becomes much more manageable.
There is a legitimate criticism of this approach, and the buyback question shows exactly why. Some have argued that if a company can sell a token, reach functionality, continue developing and promoting the network and engage in economic activity like buybacks that benefits token holders, securities laws can start to look optional. An automatic mechanism embedded in a protocol looks different from a management team deciding when and how much revenue to spend buying its own token, and the SEC's original FAQ turned only on functionality, not on who was still in control. The Commission tightened that on September 28, adding that the safe zone also requires no central party implementing the mechanism. It is a real limit, though where an active development company crosses into being a central party will still get tested, and each version of the line answers one question and opens another.
This underlying logic is why I remain sympathetic to CLARITY's basic architecture, which answers by statute how a token is treated in the market and leaves the subjective managerial efforts question with the issuer rather than with everyone downstream. Either way, the SEC's approach could create a very different design space for new crypto projects in the United States. A founder would not need to pretend that a startup is already a decentralized network. The project could acknowledge that it needs capital, that investors are funding a team to build something and that those investors should receive the protections that come with an investment contract. Regulation Crypto Assets proposes a tailored framework for raising that capital, as well as a conditional safe harbor that would allow an issuer to establish that its investment contract has ended once the relevant managerial efforts have been completed.
After, the people who built the network or application do not necessarily have to disappear. They can continue developing the software, fund ecosystem projects and promote the utility of the project without automatically recreating an investment contract. That is potentially a much wider lane than the decentralization era allowed.
There are still real limitations. The issuer's determination that an investment contract has ended can be challenged. Proposed Rule 400 is not yet final, the FAQs are staff views with no legal force or effect, and courts could take a different view of Howey. A future Commission could also narrow the framework. Chairman Atkins himself has called legislation “indispensable” for a durable framework.
That is why CLARITY's stalling out in the Senate does not make legislation irrelevant. The latest text, released by Senate Republicans on September 14, would have answered the same reliance question by statute rather than case by case. Congress can ultimately provide a durable statutory answer and greater certainty for third parties. But with little prospect now of a comprehensive framework in the near term, the SEC is trying to make the existing Howey framework work for a market that was never contemplated when Howey was decided.
For GSR, these changes are significant. We want clear asset classification. Market makers, exchanges, custodians and institutional investors should not have to reconstruct years of issuer communications every time they evaluate whether they can handle a token.
At the same time, we work closely with teams building networks and applications, and the opportunity created by this framework is hard to ignore. If founders can raise capital here under rules designed for crypto, give early investors meaningful protection, build toward functionality and ultimately support a liquid non-security token, the universe of projects that can responsibly launch in the United States gets much larger. It opens room for experimentation, more applications and potentially an entirely new generation of token designs that the previous regulatory environment made difficult or impossible to pursue here.
There will be difficult cases at the margins, and courts will have to decide how far the SEC's interpretation can go. But the SEC has chosen this path, and it has a strong practical reason to make it work. The recent FAQs, and the correction to them three days later, suggest it is willing to build the safe zones the secondary market needs while giving projects room to keep developing after functionality.
That may not be the certainty CLARITY could have provided. It may nevertheless be enough to start building.