September 29, 2026:


Three days after publishing its first-ever FAQ on crypto asset classification, the U.S. Securities and Exchange Commission’s Division of Corporation Finance quietly rewrote the most consequential sentence in it — and the edit turned a simple functionality check into a governance architecture test that DeFi protocol teams will now have to pass in order to run buybacks without triggering securities law. The FAQ is available on the SEC’s official crypto FAQ.
On Sept. 28, staff added four words — “and has no central party” — to the answer to Question 2.5, which addresses whether announcing a token buyback constitutes a promise of “essential managerial efforts” under the 1946 Howey test. The revised text now reads: where a crypto system is functional and has no central party, an issuer’s announcement of a non-security crypto asset buyback program would not constitute a representation or promise to undertake essential managerial efforts. The SEC also posted a comparison document showing the exact before-and-after text alongside the revision, a transparency step that observers called unusual for staff-level guidance.
That single condition — no central party — is what transforms the guidance from a functional threshold into a structural one. A protocol whose software runs but whose foundation, company, or development team retains the ability to modify parameters, pause operations, or otherwise intervene in outcomes does not qualify. A protocol where all treasury operations are governed by on-chain code, with no human actor holding override authority, does. The line between these two categories is not always visible to users, but it is now, in staff’s view, the line between a permissible treasury operation and a potential securities offering.
The Howey test originated in a 1946 Supreme Court case involving Florida citrus groves: the court held that an “investment contract” — and therefore a security under the Securities Act of 1933 — exists when a person invests money in a common enterprise and expects profits “solely from the efforts of the promoter or a third party.” Courts later softened “solely” to “predominantly,” but the essential inquiry remained: is the investor passive, depending on someone else’s managerial work to generate returns?
That prong is the tripwire for token buybacks. When a protocol announces that it will deploy revenue to repurchase its own tokens, critics and compliance teams have long warned that the announcement could be read as a promise to undertake the kind of essential managerial effort that brings a token back within the securities framework — even if the token itself was already classified as a non-security. The question was especially live for protocols that had already shed their investment-contract status by completing their promised development roadmap: could a new announcement recloak the token as a security?
The Division of Corporation Finance’s answer, as of Sept. 28, is no — but only on networks where no single party retains control. The neighboring FAQ answer (Question 2.4) explains the legal logic: once a functional crypto system has no central party, issuer statements about the system “likely would not create a new investment contract because neither the issuer nor any other person has control of the functional crypto system that would allow them to take any action which would affect the failure or success of the crypto system.” In other words, the investment-contract analysis asks whether purchasers depend on a third party’s essential efforts — and if no third party has meaningful control, that dependency cannot exist.
When the Division first published the FAQ on Sept. 25, the buyback answer required only that the crypto system be “functional.” That initial framing drew immediate scrutiny from legal observers who warned it could be read to give a broad pass to any issuer whose product was live — even if the team still held admin keys or controlled governance through off-chain mechanisms. Coverage of the revision by Unchained Crypto on Sept. 29 documented the timeline and expert reaction.
Miles Jennings, general counsel and head of policy at a16z crypto, had raised concerns about the original wording before the revision, warning that the earlier text could “empower an issuer to announce the buyback program without that announcement then creating an investment contract” even in cases where the issuer retained meaningful control over the protocol, per Unchained Crypto’s Sept. 29 report.
After the Sept. 28 update, Jennings reversed course and praised the change publicly. “The narrowing of Friday’s guidance will bolster its durability, while guarding against attempts to misconstrue it by those that wish to circumvent securities laws,” he wrote on X on Monday. “Pragmatic and clear rules are all crypto needs to succeed, and the SEC just delivered again.” His comments were reported by Unchained Crypto.
The FAQ’s revised answer draws a practical compliance line that splits the current DeFi buyback market into two categories:
Protocols where buybacks are executed entirely by on-chain code — where funds flow automatically from a smart contract treasury into market purchases without requiring human authorization at any step — are the clearest beneficiaries. Hyperliquid’s Assistance Fund, which automatically channels 99% of eligible trading fees into HYPE token purchases and then burns them, is the structural archetype the FAQ appears designed to accommodate. Allium Labs data tracked by the Financial Times shows the scale of the buyback market this architecture has driven, as reported by Cointelegraph.
Protocols where a foundation or development team makes discretionary decisions about timing, amounts, or implementation — even if the underlying network is technically operational — face a harder question. If the team is making calls about how the buyback proceeds, and announcing those calls to holders, the staff’s concern that this looks like essential managerial effort has not been resolved by the network’s mere functionality.
Pre-launch projects face the most significant constraint, and the FAQ makes clear that the revision does not help them. Where a crypto system is not yet functional, an announcement of a buyback program can still constitute a promise of essential managerial efforts “if the issuer presents the buyback as creating yield or return for token holders,” per the revised FAQ Question 2.5.
This is the question the FAQ answers without using those words. By making “no central party” a condition of the buyback clarification, the Division has embedded a technical architecture requirement inside a legal test — and in doing so, created an incentive structure that reaches into how protocols are built, not just how they announce things.
A protocol that wants to conduct buybacks without securities-law exposure now has a specific engineering target: it must achieve a state where no single actor, including its own founding team, can determine outcomes. That means on-chain-only governance, no emergency pause mechanisms controlled by a human administrator, no off-chain multisig with binding authority over protocol treasury parameters. The FAQ does not use any of these specific terms, but the logical consequence of the “no central party” condition is that protocols must be designed to eliminate exactly these points of control.
The prior enforcement record makes clear why this matters. The SEC’s first DeFi enforcement action, against Blockchain Credit Partners and its founders Gregory Keough and Derek Acree in August 2021, turned on the fact that investors in DeFi Money Market were relying entirely on the company’s managerial decisions — despite the word “decentralized” in the platform’s name. The SEC’s DeFi Money Market press release details how the agency found the platform was centralized in practice regardless of its branding. A later settlement with Mango DAO’s associated entities similarly found that the MNGO governance tokens were unregistered securities and imposed a $700,000 fine. The common thread: calling something “decentralized” is not the same as actually removing central control.
The buyback question drew the most immediate market attention, but the Sept. 25 FAQ addressed several other areas that have created legal uncertainty for live protocols.
On liquid staking, staff said a staking receipt token can be classed as a “digital tool” when it represents a digital commodity not subject to an investment contract. The key technical distinction is that a receipt — as the FAQ defines it — does not change any of the rights, obligations, or benefits of the deposited asset, and does not provide the holder with any additional financial incentives or benefits. The issuer of a receipt also cannot transfer, lend, pledge, or rehypothecate the deposited asset. That structural limit is what separates a staking receipt from a financial product that would require registration. The relevant guidance appears in FAQ Questions 1.2 and 1.3.
On ongoing development, staff clarified that once a crypto system is functional, “services to secure, maintain, improve, or enhance such a system or its functionality, or to facilitate network effects” do not count as essential managerial efforts for Howey purposes. This references the proposed Regulation Crypto Assets rule (Release No. 33-11434, Aug. 18, 2026) directly. Protocols that continue shipping upgrades, funding grants, and expanding ecosystem support after mainnet launch can do so without those activities being cited as evidence of continuing essential managerial efforts — a clarification that removes a significant overhang from post-launch development.
On trading platforms, staff said a secondary-market platform qualifies as a “promoter” for investment-contract purposes only if it independently meets the definition under Securities Act Rule 405. Facilitating secondary trading alone does not make a platform an issuer or promoter.
The FAQ does not arrive in isolation. It is the third major regulatory document in a sequence that began when the SEC and CFTC jointly published a landmark interpretive release on March 17, 2026. The joint SEC-CFTC interpretive release (Release Nos. 33-11412; 34-105020) was a 68-page document establishing a five-category taxonomy for crypto assets — digital commodities, digital collectibles, digital tools, stablecoins, and digital securities — and named 16 specific tokens, including Bitcoin, Ether, Solana, and XRP, as digital commodities not subject to securities law.
The second document, the proposed Regulation Crypto Assets rule (Release No. 33-11434, Aug. 18, 2026), proposed a formal offering framework for covered investment contracts, including a conditional safe harbor for issuers that complete their promised essential managerial efforts and wish to formally delink their token from investment-contract status. The public comment period for that proposal is scheduled to close around October 20. The FAQ is the third document — staff-level guidance that fills in specific operational questions the interpretive release and proposed rule left open.
Together, the three documents sketch a legal lifecycle for crypto protocols: a fundraising phase where investment-contract treatment may apply; a development phase where promised efforts must be delivered; and a mature phase where a sufficiently decentralized, functional network can conduct ordinary treasury operations without securities constraints. The Sept. 28 revision makes clear that reaching the mature phase requires not just technical functionality but genuine removal of central control.
It bears emphasis, as it does in the FAQ itself, that the guidance reflects staff views and is not a Commission rule. The Division of Corporation Finance stated explicitly that its responses have no legal force or effect, and the Commission has neither approved nor disapproved them. Protocol teams and their counsel cannot treat the FAQ as a binding safe harbor; outcomes will still depend on the specific facts of how a project was marketed, who controls it, and whether purchasers reasonably expected profit from others’ efforts.
The FAQ’s timing carries additional weight because of what just failed on Capitol Hill. The Digital Asset Market Clarity Act — which would have drawn statutory lines between SEC and CFTC authority, required digital commodity exchange asset segregation, and given market participants enforceable rules rather than interpretive guidance — failed a Senate procedural vote on Sept. 15, when a cloture motion received 49 votes in favor and 50 against, short of the 60-vote threshold required to advance. The Defiant reported the full vote. All voting Democrats opposed the motion, along with Republican Senators Susan Collins, Josh Hawley, Jerry Moran, and Thom Tillis.
With the CLARITY Act effectively dead for the 119th Congress, both agencies have signaled they will continue shaping digital-asset policy through existing authority. The September FAQ is the latest expression of that approach — building regulatory architecture through interpretation, in the absence of the legislative foundation the industry has long sought.
The guidance lands in the middle of the largest crypto buyback cycle since 2022, when the SEC’s posture under then-Chair Gary Gensler effectively froze revenue-sharing mechanisms across the DeFi ecosystem. Crypto projects spent a record $638 million on token buybacks between January 1 and August 31, 2026, up 17% from $545 million in the same period of 2025 and dramatically higher than the $366,000 in buybacks recorded for all of 2024, according to Allium Labs data via Cointelegraph. Two protocols — Hyperliquid, with roughly $370 million, and Pump.fun, with nearly $200 million — accounted for nearly 90% of that total.
For protocols whose architecture already meets the “no central party” standard, the FAQ removes a significant compliance overhang: a revenue-funded repurchase on a genuinely decentralized, functional network is now, in staff’s view, an ordinary treasury operation. For protocols that do not yet meet the standard — where a team or foundation retains governance authority — the FAQ clarifies the risk without resolving it. The September 28 revision made the line between those two categories precise, and the market for decentralized-protocol governance architecture will now be shaped by which side of that line a team wants to be on.
Ethena, which proposed a buyback program in late August under which 95% of net revenue paid to the Ethena Foundation would be used to repurchase ENA tokens, represents exactly the kind of protocol whose compliance picture the Sept. 28 revision changes. Whether Ethena’s specific structure meets the “no central party” condition will depend on a facts-and-circumstances analysis — which the FAQ explicitly acknowledges it cannot provide in advance. The Cointelegraph report on Ethena’s proposal provides background on its structure.
The shift in regulatory framing between the Gensler era and the Atkins era is worth naming explicitly: where the prior administration asked “do you share profit?” the current framework asks “who controls the code?” The Sept. 28 revision codifies that shift at the level of staff guidance — making the control structure of a protocol, not just its financial outputs, the operative legal test.
No. The guidance applies only to protocols that are both functional — meaning the native token can be used as the system’s programmatic utility allows — and have “no central party” — meaning no single entity retains control capable of affecting the system’s success or failure. Pre-launch protocols, protocols with foundation or team override authority, and any token that itself qualifies as a security are excluded. The guidance also reflects staff views only and has no binding legal force.
The FAQ does not provide a technical checklist, but the legal standard implies that no single entity — including the founding team or associated foundation — should be able to unilaterally determine the outcome of treasury operations or protocol governance. Protocols that achieve this through on-chain-only governance, with no off-chain override mechanisms or admin keys that any central actor controls, are the clearest beneficiaries. Protocols that retain such control points — even if the network is technically live — remain in legal territory the FAQ does not address.
The Howey test, established by the Supreme Court in 1946, determines whether an asset qualifies as an “investment contract” and therefore a security under US law. The relevant prong asks whether purchasers reasonably expect profits from the essential managerial efforts of a third party. A buyback announcement can trigger this prong if it signals that the issuer will deploy capital on behalf of holders in a way that drives token value. The FAQ says this concern does not apply when no central party has the control needed to make that kind of promise credible.
The Digital Asset Market Clarity Act failed a Senate procedural vote 49-50 on Sept. 15, 2026, leaving both the SEC and CFTC to continue building crypto policy through existing authority. The FAQ is staff guidance, not law, and could be revised or withdrawn by a future SEC administration. However, the joint SEC-CFTC interpretive release from March 17, 2026, which the FAQ builds on, is a more durable document — jointly signed releases are harder to reverse unilaterally than informal staff guidance.