WASHINGTON — The U.S. Securities and Exchange Commission's Division of Corporation Finance revised its crypto asset classification FAQ on Sept. 28, adding a new condition for decentralized finance protocols to conduct token buybacks without triggering securities law. The revision occurred three days after the FAQ's initial publication.
Staff added four words, "and has no central party," to the answer for Question 2.5. This question addresses whether an issuer's announcement of a token buyback constitutes a promise of "essential managerial efforts" under the 1946 Howey test.
The original text said that if a crypto system was functional, a non-security crypto asset buyback announcement would not represent a promise of managerial efforts. The revised text specifies this only applies where "a crypto system is functional and has no central party."
The SEC also released a comparison document detailing the changes, a transparency measure observers said was unusual for staff-level guidance. This addition shifts the guidance from a functional requirement to a structural one for DeFi protocols.
Protocols whose underlying foundation, company or development team retains the ability to modify parameters, pause operations or intervene in outcomes do not meet this new condition. Conversely, protocols where all treasury operations are governed by on-chain code, with no human actor holding override authority, now qualify.
This distinction draws the line between a permissible treasury operation and a potential securities offering in the view of SEC staff. While users may not always perceive this line, it now dictates regulatory compliance.
The Howey test, established by a 1946 Supreme Court case involving Florida citrus groves, defines an "investment contract"—and thus a security under the Securities Act of 1933—when investors expect profits "predominantly from the efforts of the promoter or a third party."
The "essential managerial effort" prong of Howey has long been a concern for token buybacks. Compliance teams warned that a protocol's announcement to use revenue for repurchasing its own tokens could be interpreted as a promise of such managerial effort.
This concern was acute for protocols that had already shed their investment-contract status by completing their development roadmaps. The question was whether a new buyback announcement could reclassify an otherwise non-security token as a security.
The Division of Corporation Finance's Sept. 28 answer specifies that such an announcement would not recloak a non-security token, but only for networks where no single party retains control. This mandates a fully decentralized governance and treasury architecture for protocols engaging in token buybacks.