ASTRÆA COUNSEL
  • Home
    • Team
    • How We Work
    • Speaking
    • Press & Recognition
    • Results & Case Studies
    • Pricing
    • Litigation & Disputes
    • Business Partner Disputes
    • Commercial Litigation
    • Crypto Litigation
    • SEC Enforcement Defense

    • Crypto & Digital Assets
    • AI & Emerging Tech
    • DAOs
    • Fund Formation

    • Browse All Practice Areas
  • Insights
  • Contact
(310) 800-1780Book a Call

ASTRAEA COUNSEL

Trial and regulatory counsel for high-stakes disputes and digital-asset, fintech, and AI companies.

info@astraea.law

(310) 800-1780

Beverly Hills, CA

Practice Areas

  • Digital Assets & Blockchain
  • Litigation & Disputes
  • Artificial Intelligence & Emerging Tech
  • Securities Enforcement & Investigations
  • Fintech & Payments
  • Corporate & Transactions
  • Regulatory Compliance

Litigation

  • Litigation & Disputes
  • Business Partner Disputes
  • Commercial Litigation
  • Crypto Litigation
  • SEC Enforcement Defense
  • Results & Case Studies

Resources

  • Latest Insights
  • Token Classifier
  • GENIUS Act Compliance Clock
  • Our Team
  • Press & Recognition
  • Contact

The Firm

  • DAO & Governance
  • How We Work
  • Pricing
  • Speaking

© 2026 Astraea Counsel, APC. All rights reserved.

Privacy PolicyTerms of Use

Attorney Advertising. Attorney Advertising. The material on this website is for informational purposes only and does not constitute legal advice. No attorney-client relationship is created by accessing or using this website. Any result portrayed on this website was dependent on the facts of that case, and the results will differ if based on different facts. Astraea Counsel, APC is a California Professional Corporation. Chanté Eliaszadeh (State Bar No. 335803) and Brandon Orewyler (State Bar No. 324391) are licensed to practice law in California only. The firm is not certified by the State Bar of California as a specialist in any field.

This site uses Google Analytics to improve user experience. See our for details.Privacy Policy for details.

Skip to main content
  1. Home/
  2. Insights/
  3. The DeFi Decentralization Test Under CLARITY: A Mechanics Guide to Section 309's Control-Surface Analysis
Thought Leadership

The DeFi Decentralization Test Under CLARITY: A Mechanics Guide to Section 309's Control-Surface Analysis

White & Case|Dechert|U.S. Securities and Exchange Commission, Cyber Unit|UC Berkeley Law

May 20, 2026•Updated September 5, 2026•Chanté Eliaszadeh
CLARITY ActH.R. 3633Section 309DeFiDAO LiabilityDecentralizationControl SurfacesProtocol Governance
“Section 309 of H.R. 3633 is the most-analyzed, most-contested, and most-misread provision of the CLARITY Act, and it is not yet law. The House passed the bill on July 17, 2025, Senate Banking advanced it on May 14, 2026, and the Senate's first cloture vote is set for September 15, 2026; floor passage, reconciliation, and signature still lie ahead. The current text is enough to plan against, and Section 309 is the provision most likely to shift.”
Chanté Eliaszadeh · Principal Attorney, Astraea Counsel APC

Key Takeaways

  1. Section 309 protects six enumerated activities, not assets: compiling and validating transactions; computational work and node or oracle services; read-and-access user interfaces; developing or maintaining a blockchain system or DeFi trading protocol; DeFi messaging systems and liquidity pools for spot digital-commodity trades; and self-custody wallet software.

  2. Developer exemption is not token exemption: the protocol’s native token is classified separately under Section 201 and can still be a security.

  3. Seven control surfaces decide the question: who controls a fee switch, a frontend, or a multisig matters more than whether the feature exists.

  4. Decentralization theater is disqualifying: the effective-control test in Section 101(24) responds to operations, not optics.

  5. The exclusion runs to the two Acts, with anti-fraud carved out: the Commissions’ anti-fraud and anti-manipulation authorities are preserved by the text, state-law claims sit outside it, whether it defeats private claims is unresolved, and the bill is not yet law.

I. Bill on the Verge: The § 309 Exemption Sits in a Bill That Hasn’t Been Enacted Yet

Section 309 of H.R. 3633 is the most-analyzed, most-contested, and most-misread provision of the CLARITY Act—and not yet law. The House passed the bill 294-134 on July 17, 2025.1 Senate Banking advanced it May 14, 2026 on a 15-9 vote.2 Senate Ag’s parallel S. 3755 carries a CFTC-side developer exemption of its own (Section 207, adding CEA § 4v) but no securities-side exclusion, so the Banking text governs the SEC-side question in reconciliation.3 Cloture on the motion to proceed was filed August 8, 2026, with the first procedural vote set for September 15, 2026; floor passage, reconciliation, and Presidential signature still lie ahead.4 Section numbers in this article are the House-engrossed text’s; the Senate Banking substitute renumbers the developer protection to its Section 601 and makes its Section 309 a study of digital asset mixers.5

The current text is enough to plan against—but § 309 is the provision most likely to shift. The Senate Banking substitute already moves the ground: it keeps the Blockchain Regulatory Certainty Act money-transmitter carveout at Section 604 and adds, at Section 302, a Treasury-guidance mandate for DeFi front-ends; Senator Warren opposed the committee’s DeFi changes as insufficient half measures, and the floor is where a tighter AML or sanctions overlay would come from.6 Industry policy voices push the other direction. My estimate: Senate Banking language stands at 50-55%, with material-change probability in the 35-45% range. The §XI record survives floor amendments either way.

The article’s thesis: § 309 protects activities, not tokens. [“The activity exemption is not a token exemption.”] Protocols claiming § 309 must independently survive what I call [“The Seven Control Surfaces”]—upgradeability, fee switches, frontend control, oracle dependencies, sequencer ownership, treasury concentration, governance distribution. [“Decentralization Theater vs. Structural Decentralization”] is the distinction enforcement counsel will probe first. Most protocols claiming § 309 today have done the theater. Their counsel are not yet building the structural record.

II. What Section 309 Actually Protects: The Statutorily-Enumerated Activities

Section 309 is not a doctrinal break from the regulatory tradition that precedes it. It is the codification of a decade-plus administrative architecture that began with FinCEN’s 2013 Guidance separating users of convertible virtual currency from administrators and exchangers, and was extended to software publication in FinCEN’s 2019 Guidance, which holds that an anonymizing software provider is not a money transmitter and that a DApp developer is not a money transmitter for the mere act of creating the application.7 The pre-existing framework already carved non-custodial publishers out of money-transmitter status. § 309 takes that carveout, expands it to SEC and CFTC intermediary registration, and writes it into positive law.

The activities § 309 enumerates are statutorily protected from SEC intermediary registration; § 409 provides parallel CFTC treatment.89 The Arnold & Porter advisory summarized them as four—compiling or otherwise validating network transactions; providing computational work; providing user interfaces for a blockchain system; developing a trading protocol or software system, including wallets.10 The House-passed text enumerates six numbered paragraphs at new Exchange Act Section 15H(a): (1) compiling, relaying, searching, sequencing, or validating network transactions; (2) providing computational work, operating a node or oracle service, or providing network bandwidth; (3) providing a user interface that enables a user to read and access data about a blockchain system; (4) developing, publishing, constituting, administering, maintaining, or otherwise distributing a blockchain system or a decentralized finance trading protocol; (5) doing the same for a decentralized finance messaging system, or operating or participating in a liquidity pool, for the purpose of executing a spot digital-commodity transaction; and (6) developing or distributing software or systems, including wallets, facilitating an individual user’s own self-custody.11 The analysis below groups them into five functional categories with internal overlap. Substantive coverage is the same either way.

Activity (i) covers writing, deploying, and publishing software—smart contract code, protocol logic, frontend interfaces published non-custodially. The boundary case is the frontend that retains custody, routes order flow, or extracts fees. That frontend is published software in form but intermediary in operation. The CFTC’s September 7, 2023 trilogy—Deridex, Opyn, ZeroEx—is the enforcement posture on that boundary: Deridex and Opyn were each charged with operating as an unregistered swap execution facility, with engaging in activity reserved to a registered futures commission merchant, and with failing to adopt a customer identification program, alongside the off-exchange leveraged retail commodity offense; ZeroEx was charged only with that retail commodity offense under CEA § 4(a); and in each case the respondent did more than publish software.121314

Activity (ii) covers validating transactions. PoS validators, PoW miners, and supporting infrastructure are protected. The boundary case is the validator that bundles MEV-extraction services or runs a centralized sequencer with discretionary ordering. Validation is exempt; discretionary intermediation around it is not.

Activity (iii) covers operating nodes—full nodes, archive nodes, light clients, computational infrastructure. This is the activity furthest from intermediary function. The boundary case is the node operator who simultaneously runs a custodial staking pool or a centralized RPC endpoint with discretionary access controls.

Activity (iv) covers publishing wallet software—non-custodial wallets, hardware wallet firmware, self-custodial account abstraction. Non-custodial is the load-bearing term. A wallet that takes custody—even briefly, even for routing—is not wallet software for this section. FinCEN’s December 2020 unhosted-wallet NPRM (RIN 1506-AB47) cut the other way: it proposed to require banks and money services businesses to report, keep records, and verify customer identity for convertible-virtual-currency transactions involving unhosted wallets, while restating that a person conducting a transaction through an unhosted wallet to purchase goods or services on their own behalf is not a money transmitter. § 309 answers the pressure that proposal represented rather than continuing it.15

Activity (v) covers developing or maintaining blockchain systems and decentralized finance trading protocols—consensus research, cryptographic protocol design, infrastructure work. The boundary case is the developer who is also the protocol’s largest treasury holder, an upgrade-multisig signer, or an off-chain governance gatekeeper.

The activity test in § 309 is functional, not nominal. A “publisher” who retains operational control over user funds, parameter changes, or fee routing is not the publisher the statute means.

III. What Section 309 Does NOT Protect: The Protocol’s Token, the DAO’s Governance, the Frontend Operator, the Corporate Sponsor

A textual distinction does most of the work. § 309 reaches whoever is “engaging in” a covered activity—a threshold test. Section 101(24) operates as the substantive limit, defining “decentralized governance system” through an effective-control inquiry within the engaged-in scope.16 Conflating them produces the Single-Test Binary Read the more aggressive industry analysis advances—§ 309 protects whoever is engaged in covered activity, categorically, and seven-surfaces is litigator’s prudence rather than statutory requirement. I read the bill differently. “[E]ngaging in” gets you across the doorway. Section 101(24) governs the room.

A minority position is worth naming at full strength. A reading advanced in parts of the industry policy bench treats § 309 plus Van Loon as creating categorical protection for non-custodial protocol developers without further factual inquiry.17 On this view, the Howey analysis is functionally displaced for tokens issued through covered protocols. I’d push back. § 201’s investment-contract-asset framework is jurisdictional, not classificatory; pre-CLARITY secondary-market sales remain Howey-analyzed; and § 309(b) and § 409’s anti-fraud carveouts presuppose Howey still operates downstream.18 SEC v. LBRY rejected the proposition that token utility alone defeats an investment-contract offering—LBRY’s offer of LBC was an investment contract where the team retained an economic stake and promised managerial development, though the court declined to rule on whether LBC itself is a security.19 LBRY is the live precedent against the Howey-Displacement Lite reading.

Three independent things § 309 does not reach.

First, the protocol’s native token. Section 201 governs whether the token was sold as an investment contract asset—a digital commodity transferred pursuant to an investment contract—with the maturity question running through Section 205’s certification requirements.2021 A § 309-exempt protocol can issue a token that is a security. The joint SEC-CFTC March 17, 2026 interpretive release (Release Nos. 33-11412; 34-105020) supplies the sharper definition: for purposes of that release, a crypto system is “decentralized” if it “functions and operates autonomously with no person, entity, or group of persons or entities having operational, economic, or voting control of the crypto system.”22 That definition is sharper than the bill’s text, and it is the one the agencies will bring to any classification question. The activity exemption does not move that needle.

Second, the DAO’s governance treasury management. Section 101(24) contains no percentage: a decentralized governance system is one “where participation is not limited to, or under the effective control of, any person or group of persons under common control.”16 The 20 percent line lives in Section 205, which denies mature-blockchain status where an issuer, related person, or affiliated person beneficially owns 20 percent or more of the digital commodity’s units.21 A treasury manager exercising effective control—through delegate aggregation, multisig dependency, or upgrade authority—defeats the Section 101(24) characterization at any ownership level. Below 20 percent on raw metrics, the surfaces still matter; protocols at 18 percent should not assume they’re clear. Tier audit recommendations by proximity to threshold.

Third, the frontend operator with custody, order-routing, or fee-extraction features. Those are intermediary functions, regardless of whether the underlying smart contracts are immutable. Opyn settled for $250,000 in September 2023 on findings that blocking users with U.S. internet protocol addresses was not sufficient to exclude U.S. users and that Opyn retained a degree of control through its ability to impose transaction fees and to effect a shutdown of the protocol.13 ZeroEx settled $200,000 the same day on a theory that frontend operators bear regulatory responsibility for products offered through their interface, even when they did not develop the underlying contracts.14 The Matcha-frontend precedent is now floor doctrine.

A fourth omission—and the most common factual pattern in 2024-2025 SEC enforcement—is the corporate sponsor. [“Does the developer exemption extend to the developer’s employer?”] The Uniswap Labs question. The Aave Companies question. The pattern repeats across virtually every protocol with meaningful traction. The answer requires three sub-distinctions.

(a) Employer-as-developer. A corporate entity employing the engineers who write protocol code is publishing software through them. The activity is exempt under the employer’s name as well as the developers’. This is the cleanest case and the strongest version of the § 309 defense for corporate sponsors. Uniswap Labs in its core engineering capacity sits here.

(b) Employer-as-operator. The same entity that operates the canonical frontend, captures the fee switch, or directs the treasury is doing intermediary activity. § 309 does not reach that conduct. Risley v. Universal Navigation tested this fact pattern—pre-CLARITY plaintiffs sued Uniswap Labs as an exchange operator under federal securities law, and the Second Circuit, in a non-precedential summary order, affirmed dismissal of the federal securities claims on the reasoning that the smart contracts are “standardized computer codes that allow the Protocol to fill in the terms for individual trades between and controlled by its users” and were collateral to the third parties’ scam-token activity; the state-law claims were vacated and remanded, and dismissed on remand in March 2026.23 But Risley is a private-plaintiff case, not a § 309 immunity ruling. The SEC and CFTC are not Risley plaintiffs; their enforcement theories run through Opyn/ZeroEx.

(c) Employer-as-issuer. Where the corporate sponsor conducted the initial token sale, retains issuer status, or makes managerial commitments tied to holder profit expectations, the analysis is Section 201. The activity exemption is irrelevant to the issuer analysis. This is the LBRY pattern.19 § 309 has no purchase on it.

Employer-as-developer is arguably exempt. Employer-as-operator is arguably not. Employer-as-issuer is separately analyzed under § 201. A corporate sponsor that sits in all three boxes does not get a single answer from Section 309.

Section 309 reaches an activity. It does not reach the protocol’s token, the DAO’s governance treasury, the frontend operator, or the corporate sponsor’s intermediary conduct. Four independent surfaces; four independent analyses; none collapsed into the activity exemption.

IV. Decentralization Theater vs. Structural Decentralization

Some protocols have done the structural work: years spent redistributing governance, formalizing voting frameworks, and building genuinely independent foundations, and in a few cases serious institutional design around public-goods funding and multi-chamber councils. A meaningful subset of L1/L2 projects has invested in real cessation of managerial efforts. The diagnostic in this section is aimed at the larger set that has moved the labels without moving the substance.

The joint SEC-CFTC March 17, 2026 interpretive release supplies the operative definition: a crypto system is “decentralized” if it “functions and operates autonomously with no person, entity, or group of persons or entities having operational, economic, or voting control of the crypto system.”22 Three dimensions, conjunctive. A protocol with diffuse voting but concentrated economic ownership flunks. Diffuse economic distribution but a founder-controlled upgrade key flunks. Both, but a foundation-controlled treasury flunks.

The foundational SEC authority on operational-vs-nominal is the DAO Report—the 2017 Section 21(a) report of investigation concluding that DAO Token holders’ profits were to be derived from the managerial efforts of others, and that the holders’ voting rights did not defeat that prong because the Curators controlled which proposals could be submitted to a vote.24 The DAO Report’s central proposition survives in Release No. 33-11412: form (token-holder voting) does not satisfy substance (effective control) if discretionary gatekeepers remain. The Hinman speech of June 14, 2018 introduced the colloquial “sufficiently decentralized” framing the trade press still uses; the SEC v. Ripple court cited the speech only as evidence bearing on the defendants’ state of mind, not as a legal standard.25 Rely on the DAO Report and Release No. 33-11412.

The industry policy literature anticipated this regulatory direction by half a decade. Walden’s “Progressive Decentralization” (2020), Jennings’s “Principles & Models of Web3 Decentralization” (2022), and Boiron’s “Sufficient Decentralization” (2022) are the published industry consensus the Seven Control Surfaces synthesizes.26 These frameworks are industry policy work, not legal authority. They map the operational dimensions a project must distribute to reach the regulatory floor Release No. 33-11412 codifies.

The diagnostic—[“Decentralization Theater”]—covers cosmetic moves that do not change operational reality. Foundation-held governance tokens marketed as community-distributed. Two-of-three multisigs where two signers are correlated employees. “Community grants” that route in a circle and fund the founding team. Off-chain governance that requires founder approval to execute on-chain votes. Time-locks the founding team can override under self-defined “emergency” provisions. None moves the seven surfaces. They move the optics. Theater does not survive an enforcement audit.

§ 309 will reward protocols that built decentralization architecture in advance of the bill. It will not reward protocols that built decentralization marketing in advance of the bill. The seven control surfaces are the test.

V. The Seven Control Surfaces

[“The Seven Control Surfaces”] are an analytical organizing tool, not a codified test. The bill does not name them. The SEC’s March 2026 release does not list them. They are the operational map of where § 101(24)‘s effective-control inquiry and §§ 309(b)/409’s preserved anti-fraud authority bite—synthesized from the industry frameworks in §IV, calibrated against the enforcement record, and ordered by audit-priority. Each surface anchors to a specific statutory hook. The taxonomy is my contribution; the doctrinal weight is the statute’s.

A. Upgradeability

The first surface is upgradeability. Admin keys, proxy contract architecture, multisig thresholds, time-lock parameters. The threshold question: can the protocol be upgraded—substantively, not just parametrically—without token-holder consent? If yes, the team retains operational control over the protocol’s core logic, and that control reaches every other surface downstream.

The In re Deridex settled order (September 7, 2023) is the sharpest enforcement articulation of what developer “control” means.12 Deridex paid $100,000 on findings that it “held custody of users’ assets” through the smart contracts and “retained substantial control over the Deridex Protocol,” including the ability to update the code to suspend trading or prevent users from depositing collateral. The order’s legal discussion rests on the registration violations; the control findings sit in the facts. The lesson is that upgrade authority and custody travel together in the CFTC’s telling: the developer who can suspend trading by code update is operating the facility, not publishing it. Upgrade authority is operational control. Time-locked upgrades with adequate notice (typically 7-14 days) and multisig governance with diffuse, non-correlated signers move the analysis. Immediate-effect upgrades by a foundation-held key do not. The Uniswap question—can Uniswap Labs upgrade v4 without governance vote—is the diagnostic for every protocol claiming § 309.

Time-locked, governance-gated, multisig-distributed upgrade authority moves the analysis. Foundation-held emergency keys do not. Document the upgrade architecture as if a CFTC enforcement attorney will read it first.

B. Fee Switches

The second surface is the fee switch. The classic Uniswap question—and the question most protocols have not finished answering. Who controls the switch? Who receives the fee? Is the routing transparent in code or discretionary through governance? Pro rata distribution to token holders without managerial discretion looks structurally different from discretionary treasury allocation through a foundation-controlled vote.

Section 101(24)‘s inquiry treats the fee switch as a paradigm of operational economic authority. A fee that flows automatically to holders pro rata through immutable code, with no team discretion over rate or recipient set, is consistent with structural decentralization. A fee that flows to a treasury managed by a 4-of-7 multisig with three foundation signers is operational economic control. The question is not whether the fee switch exists—most successful protocols will eventually monetize. The question is who exercises managerial authority over how it operates.

The boundary case is the parameter-only fee switch—governance sets the rate, but routing is hard-coded to token holders. The team is no longer the economic beneficiary, only the rate-setter, and that authority is distributed across holders. The closer the fee mechanic moves toward parameter-only governance with mandatory holder routing, the cleaner the § 309 record.

Fee switches are not disqualifying. Discretionary control over the switch is. The structural test is whether managerial effort is required to operate the fee mechanic—and who supplies it.

C. Frontend Control

The third surface is frontend control. This is the surface most contested in trade press and most consequential in enforcement. Post-Van Loon, immutable smart-contract code is not property subject to OFAC sanctions.27 But the frontend operator who routes order flow, charges access fees, or retains custody is doing something different from publishing software.

The minority position deserves its full strength. Parts of the industry policy bench read § 309 plus Van Loon as creating categorical protection for non-custodial developers—frontends with no custody and no fee extraction are exempt without further inquiry.17 The reading has First Amendment force, within limits: Universal City Studios v. Corley holds that computer code can merit First Amendment protection while affirming an injunction against posting and linking to the code at issue, which is the measure of how far that protection runs.28 My view: the categorical reading is defensible if the frontend is genuinely non-custodial, non-fee-extracting, and non-order-routing. The seven-surfaces audit is the prudent posture even if the minority view prevails—frontend operator residual responsibilities (KYC, sanctions screening, anti-fraud monitoring) still attract regulatory attention.

The enforcement record is consistent on the operational side. Opyn established that blocking U.S. IP addresses is insufficient to exclude U.S. users, and that a developer who deploys its own protocol and retains the ability to impose fees and shut it down is operating it.13 ZeroEx established that a front-end operator bears regulatory responsibility for products offered through its interface even where it did not develop the underlying leveraged contracts.14 The Second Circuit’s summary order in Risley v. Universal Navigation is the most favorable circuit-level treatment to date—smart contracts as “standardized computer codes” collateral to third-party scam-token sales—but it is non-precedential, it is a private-plaintiff case, and the SEC and CFTC have not been Risley plaintiffs.23 The mixed record requires the audit.

U.S. v. Roman Storm is the post-Van Loon limit case. Storm was convicted on August 6, 2025 of conspiring to operate an unlicensed money-transmitting business in connection with Tornado Cash, with the jury deadlocking on the money-laundering and sanctions counts.29 His motion for acquittal, argued in April 2026, remains undecided, and retrial on the deadlocked counts is set for April 26, 2027. The doctrinal point survives whichever way the retrial goes: even where smart contract code is immutable (as Van Loon established), a developer’s role in operating an ongoing service can create criminal exposure independent of the code’s property status. Van Loon protects publish-and-walk-away. It does not protect the developer who keeps operating the surface.

A frontend with no custody, no order-routing, and no protocol-external fee extraction has the strongest version of the § 309 defense. A frontend with any of those features is doing something the activity exemption does not protect.

D. Oracle Dependencies

The fourth surface is the oracle. This is the article’s most novel analytical territory; no specific § 309 guidance addresses oracle architecture, and the doctrinal scaffolding has to be built from analogy. If the protocol depends on a price oracle the team operates, the team controls liquidations. The team controls margin calls. The team controls the inputs that determine when collateral is seized, when positions close, and when penalty fees accrue. That is operational economic control, by a different name.

The closest enforcement analogue is CFTC v. Eisenberg (Mango Markets).30 The CFTC’s civil complaint charged oracle price-feed manipulation as market manipulation under CEA § 6(c)(1), in what the agency called its first action involving a scheme “sometimes called ‘oracle manipulation’“—operating on the inputs side (manipulating the feed) rather than the control side (the team running the oracle). The parallel criminal convictions were vacated on May 23, 2025 on the defendant’s Rule 29 motion, on insufficiency and venue grounds.31 A complaint establishes nothing, but it shows that the CFTC reads oracle architecture as a regulated surface for anti-manipulation purposes—which implies analogous regulatory interest in team-operated oracle architecture.

The structural distinction is between externally-sourced oracles (Chainlink, Pyth, RedStone) and team-operated oracles. An externally-sourced oracle the team has no managerial influence over is operationally neutral. A team-operated oracle, or an external dependency where the team retains discretionary parameter authority (heartbeat intervals, deviation thresholds, fallback feeds), is operational control over price-discovery inputs. The closer to Chainlink-style decentralized oracle networks, the cleaner the § 309 record.

Externally-sourced, non-team-influenced oracles move the analysis. Team-operated price feeds—or team-discretionary parameter authority over external feeds—does not. Oracle architecture is the surface most protocols underestimate.

E. Sequencer Ownership

The fifth surface is L2-specific and novel territory; no specific regulatory guidance addresses sequencer architecture as a § 309 question. The analytical work has to be done from first principles against § 101(24). If the team runs the sequencer, the team controls transaction ordering. The team controls MEV extraction. The team controls the practical inclusion guarantees the network’s users actually receive. Theoretical forced-inclusion mechanisms backed by L1 data availability matter less than the operational reality of a centralized sequencer running with team-controlled software, team-set parameters, and team-discretionary upgrade authority.

Most rollup teams have published decentralized-sequencer roadmaps targeting multi-year migration from team-operated to shared-sequencer architecture, and the shared-sequencer initiatives now in the market are real attempts to migrate this surface. § 309 reliance on Day 0 is harder for rollup teams whose sequencers still run on team-controlled infrastructure. A centralized sequencer whose operator sets ordering and captures MEV is a candidate for “effective control” by a “person or group of persons under common control” under § 101(24)—but the bill does not name sequencers, and § 309(a)(1) lists “sequencing” among the protected activities, so the analysis runs by application rather than by text, and it turns on the discretion the operator retains rather than on the function itself.16 The decentralization roadmap matters less than the snapshot at the moment of regulatory inquiry.

A centralized sequencer is operational control. A decentralized sequencer with no team discretion is not. The roadmap matters for trajectory; the snapshot matters for § 309. Plan to be on the decentralized side of the snapshot before enactment, not after.

F. Treasury Concentration

The sixth surface is treasury concentration. The question Section 101(24) anchors here is whether treasury management amounts to “effective control” by a “person or group of persons under common control,” or to the “centralized management” that § 101(24)(C) says disqualifies a legal-entity wrapper.16 If the DAO funds core contributors directly, the funding flow looks structurally like compensation—and compensation by the protocol to the people running it implies the people are running it. If the treasury composition is dominated by foundation-held tokens that vest over a multi-year window into the same foundation, the treasury is operationally controlled regardless of nominal token distribution.

Three diagnostic dimensions: composition, vesting, and discretionary authority. Composition—foundation-held versus broadly distributed in multisigs with diffuse signers. Vesting—do schedules transfer effective control to broader holders over time, or recycle into foundation custody at unlock. Discretionary authority—signer-set distribution. A 5-of-9 multisig with three foundation employees, two contractors, and four independent signers is foundation-controlled because the foundation controls a working majority. A 5-of-9 with no more than two correlated signers across nine independent parties is operationally distributed.

A protocol three years into a four-year vest is closer to structural decentralization than one six months in, at identical raw concentration. Section 101(24) reads as a snapshot, but audit-priority calibration should consider trajectory for protocols claiming sub-threshold compliance through near-term vest unlocks.

Treasury concentration is the surface most protocols can fix between now and enactment. Distributed multisig signers, transparent disbursement policies, and time-bound vesting unlocks move the analysis. Foundation-controlled custody does not.

G. Governance Distribution

The seventh surface is the headline test most protocols already track. Vote-locked tokens. Delegation patterns. Foundation-held tokens. The 20 percent distributed-ownership criterion under Section 205’s mature-blockchain requirements is the most-cited number, but the § 101(24) effective-control inquiry operates as a substantive overlay regardless of the 20 percent line.1621

A minority position deserves engagement. A trajectory reading has currency in the industry policy bench: initial governance concentration over 20 percent is not disqualifying so long as tokenomics trajectory reverses the concentration inside the § 202 four-year window.32 On this view, the snapshot is misleading; the trajectory matters. I’d push back. The § 101(24) test reads as a snapshot inquiry, and Release No. 33-11412 is sharper still—a crypto system is decentralized only with “no person, entity, or group of persons or entities having operational, economic, or voting control of the crypto system.”22 The release does not say “will hold.” It says “having.” The trajectory matters for the § 202 maturity pathway, but § 309 reliance on Day 0 requires the snapshot.

Dimensions to track: vote-locked aggregation (addresses delegating to one foundation-aligned voter, creating effective control below raw thresholds); quorum mechanics (low quorum lets small concentrated blocs pass proposals); on-chain vs. snapshot governance (snapshot with off-chain execution leaves team discretion at the execution step); foundation-held token visibility (foundations frequently hold across multiple wallets to disguise concentration).

The 20% line is a useful audit prompt. The § 101(24) effective-control inquiry is the substantive test. Distribute votes through diffuse, non-correlated holders; resist delegate aggregation that recreates the same effective control through a different surface; and document the analytics that show effective distribution.

VI. The Anti-Fraud Carveout: What § 309 Preserves for the SEC (and § 409 for the CFTC)

§ 309 excludes covered activities from the Exchange Act while expressly preserving “the anti-fraud and anti-manipulation authorities of the Commission”—which is where Securities Exchange Act § 10(b), 15 U.S.C. § 78j(b), lives.33 § 409 does the same under the Commodity Exchange Act, preserving the CFTC’s anti-fraud, anti-manipulation, and false reporting enforcement authorities—CEA § 6(c)(1), 7 U.S.C. § 9(1), for manipulative or deceptive devices, alongside the criminal manipulation provision at CEA § 9(a)(2), 7 U.S.C. § 13(a)(2).3435 Both statutory frameworks are explicit. The activity exemption does not displace the fraud carveout.

The minority position worth engaging: the anti-fraud preservation is a paper tiger. No SEC win against a pure non-custodial protocol on a clean § 10(b) theory exists. The SEC’s recent DeFi record has run mostly through registration theories the post-CLARITY architecture forecloses. On this reading, the anti-fraud language looks consequential but operates as residual sweeping. I’d push back on three grounds.

First, resource concentration. Post-CLARITY, § 10(b) is the SEC’s only remaining DeFi hook for activity that survives the § 309 exemption test. With registration theories foreclosed for covered activity, resource concentration on § 10(b) is the predictable consequence. Treating preservation as paper-tiger doctrine assumes enforcement priorities remain static. They will not.

Second, MEV exposure. MEV extraction at scale through team-controlled infrastructure plausibly implicates § 10(b) on the theory that the team materially misrepresented the fairness of execution to retail users. The SEC has pressure-tested fairness-of-execution arguments in equities for two decades; the doctrinal vocabulary maps onto DeFi. Protocols that built MEV-extraction features into team-controlled validator or sequencer infrastructure are exposed on a surface the activity exemption does not protect.

Third, the private-plaintiff vector. § 309 says a person “shall not be subject to this Act” based on the enumerated activities; it says nothing about state-law claims, and whether it defeats a private Exchange Act claim predicated on those activities is unresolved. Risley’s federal claims were dismissed and the dismissal affirmed on statutory-seller and Section 29(b) grounds, with token status assumed arguendo rather than decided; the state-law claims were revived on jurisdictional grounds and dismissed on remand. Plaintiffs are already developing parallel theories targeting MEV, oracle dependency, and frontend operator conduct.23 Build the record for both regulator-facing defense and private-plaintiff deposition exposure.

Two enforcement records confirm the carveout’s bite outside pure custodial cases. BlockFi Lending LLC (2022 SEC settlement, $50 million to the SEC plus $50 million to 32 states) applied Howey and Reves v. Ernst & Young’s family-resemblance test to crypto lending products and found them both investment contracts and notes.36 BlockFi was custodial, not § 309-protected, but the mechanic—managed yield products are not the § 15H(a)(4) activity of developing, publishing, administering, maintaining, or otherwise distributing a blockchain system or a decentralized finance trading protocol—applies to any protocol bundling yield features alongside protected developer activity. In re Blockratize, Inc. (Polymarket) ($1.4 million settled order, Jan. 3, 2022) found that operating an unregistered facility for event-based binary options violated CEA §§ 4c(b) and 5h(a)(1); the order reached the corporate operator on findings about its control over market creation, resolution, and access, not the code itself.37

§ 309 is an activity exemption from intermediary registration. It is not a shield against well-pleaded fraud claims, anti-manipulation actions, or private-plaintiff securities litigation. Build the evidentiary record for all three.

VII. Cross-Reading § 309 with the Innovation Exemption Safe Harbor’s Cessation Test

§ 309 and the SEC’s Innovation Exemption Investment Contract Safe Harbor are different doctrinal instruments on overlapping protocols. § 309 is an activity exemption from intermediary registration. The Safe Harbor, proposed in Regulation Crypto Assets on August 18, 2026 and not yet adopted, would be a token-status pathway under which a token initially offered as a security transitions to non-security status when the issuer’s essential managerial efforts cease.38 The two regimes are independent. A protocol can be § 309-eligible without qualifying under the proposed Safe Harbor. A token can satisfy cessation without its operators being § 309-protected.

The joint March 17, 2026 interpretive release supplies the cessation-test definition: a crypto system is “decentralized” if it “functions and operates autonomously with no person, entity, or group of persons or entities having operational, economic, or voting control of the crypto system.”22 That definition informs both the proposed Safe Harbor’s exit trigger and § 101(24)‘s effective-control inquiry where they intersect. A token cannot satisfy cessation if the seven surfaces still register team control.

Three practical consequences. A § 309-exempt protocol may still issue a token whose holders rely on managerial effort the team performs through other surfaces—treasury, parameter governance, fee distribution. A token that satisfies cessation will, by construction, have passed the seven-surface audit. Protocols planning § 202 maturity should treat the seven surfaces as the joint audit framework. The Innovation Exemption Founders Guide explores cessation mechanics in detail.39

§ 309 protects what developers do. The proposed Safe Harbor would govern what the token becomes. The seven surfaces are the joint audit framework that produces a defensible record in both regimes.

VIII. The Ooki DAO and Van Loon Lessons

A. Van Loon: Immutable Code Is Not Property

Van Loon v. Department of the Treasury, 122 F.4th 549 (5th Cir. 2024), is the high-water-mark federal authority for the proposition that immutable smart-contract code is not property subject to OFAC sanctions.27 On November 26, 2024, the Fifth Circuit reversed and remanded with instructions to grant the Tornado Cash users partial summary judgment on their APA claim, holding OFAC exceeded its statutory authority. IEEPA does not define “property”; the court gave the term its ordinary meaning—something capable of being owned—and held that immutable smart contracts, once deployed, cannot be owned, controlled, or excluded from. The opinion invoked Loper Bright Enterprises v. Raimondo, 603 U.S. 369 (2024), interpreting the statute independently rather than deferring to OFAC’s reading.40

Two doctrinal caveats. Van Loon is IEEPA-specific; SEC and CFTC anti-fraud and anti-manipulation authority operates under different statutory grants, and the Fifth Circuit’s reasoning is persuasive scaffolding outside IEEPA, not binding precedent. Van Loon protects publication of immutable code; it does not protect the developer who keeps operating the surface—running the frontend, controlling deployment, accepting fees. Storm tested that limit.29 The acquittal motion is undecided and the retrial is set for April 2027; the doctrinal limit survives whatever they produce.

Publish-and-walk-away is the cleanest pattern. Publish-and-keep-operating is the Storm limit case. Protocols claiming § 309 should structure the developer-activity record to look like Van Loon’s immutable-publication pattern. Where the two coexist—immutable contracts plus an active canonical frontend—the seven-surface audit governs whether the operational layer is exempt or whether the frontend is separately analyzed under Opyn/ZeroEx.1314

B. Ooki DAO: DAO-As-Unincorporated-Association

CFTC v. Ooki DAO, No. 3:22-cv-05416 (N.D. Cal. June 8, 2023), produced a $643,542 default judgment against the unincorporated Ooki DAO for acting as an unregistered futures commission merchant, offering unlawful off-exchange leveraged and margined retail commodity transactions, and failing to implement a customer identification program.41 The doctrinal proposition is narrower than the bottom line suggests. The CFTC successfully pleaded that a DAO is a legal “person” for CEA entity liability, treating governance token voting as the functional equivalent of membership in an unincorporated association under both California and federal definitions. The court accepted that theory on default; no defendant appeared, the entity-liability question was briefed and opposed only by amici, and the court adopted it on well-pleaded allegations taken as true.

That posture matters. The theory has never been tested by an appearing adversary with discovery and appeal rights. A defendant DAO that appeared, argued against the unincorporated-association analogy, and pressed the First Amendment associational rights of holders would test the theory’s doctrinal limits. The case stands as enforcement precedent—the CFTC has used the theory; counsel cannot ignore it—but not as merits-tested doctrine. Treat Ooki as an available CFTC theory untested by an appearing adversary, and structure DAO governance to limit exposure on the entity-liability and membership-attribution sides.

The interaction with § 309 is the load-bearing move. § 309 exempts developer activities from SEC and CFTC intermediary registration. It does not exempt the DAO entity from CFTC anti-manipulation, anti-fraud, or commodity-pool-operator authority where the DAO is the actor engaging in regulated commodity activity. A developer who publishes code under § 309 and a DAO that operates a margined-trading facility through that code are two different legal subjects. Ooki reaches the second; § 309 does not displace it.

C. What § 309 Helps and Where Pre-CLARITY Doctrine Survives

The boundary line is clean. § 309 helps developers. It protects publishing software, validating transactions, operating nodes, publishing wallets, and developing or maintaining blockchain systems from SEC and CFTC intermediary registration. It does not unwind Ooki DAO. It does not eliminate DAO-as-unincorporated-association entity liability for DAOs that themselves engage in regulated commodity activity. It does not displace Van Loon’s limits in Storm-pattern ongoing-service cases.

The dual-track defense is the practical implication. Build the § 309 evidentiary record for developer activity per §XI. And build the legal-wrapper structure that limits DAO entity exposure for downstream regulated activity. Wyoming SF 50’s DUNA (eff. July 1, 2024) supplies a U.S. entity-status framework with limited liability and DLT-based governance.42 Cayman foundation, Swiss Stiftung, and Marshall Islands DAO LLC structures supply alternative wrapper architecture. Section X addresses the wrapper question on its own terms.

§ 309 protects what developers do. It does not protect the DAO entity that uses what they built to engage in regulated commodity activity. The dual track is mandatory.

IX. How Likely Is This to Change Before It Becomes Law: Reconciliation Forecast

Trade-press analyses treat the bill text as fixed. It is not. Reconciliation between Senate Banking’s reported substitute, Senate Ag’s parallel S. 3755, and the House-passed text still has to clear the floor and a conference; the first cloture vote is set for September 15, 2026.54 One development is already in the text: the Senate Banking reported substitute adds Section 302, which directs Treasury, within 360 days of enactment, to issue sanctions and AML/CFT guidance for “distributed ledger messaging systems”—DeFi front-ends—owned or operated by U.S. persons.43 The calibrated probabilities below are my own judgment on the provisions still subject to change, formed against the filed texts and reported reconciliation positions.44

ProvisionLikelihood of Material ChangeDirection if ChangedDrivers
§ 309 (DeFi activity exemption)MEDIUM (35-45%)Tighter (floor AML/sanctions overlay)Floor pressure for AML/sanctions integration (Sen. Warren opposed the committee’s DeFi changes as insufficient); the Senate text already keeps BRCA at § 604; industry policy pushback the other way
§ 101(24) (decentralized governance system definition)LOW-MEDIUM (20-30%)Clarifying or tighterClarifying amendments probable; material tightening of effective-control inquiry unlikely but possible
§ 202 ($50M maturity-pathway exemption)MEDIUM (30-40%)TighterThe joint March 2026 release’s decentralization definition is stricter than the § 202 pathway assumes (author’s inference); amendments unlikely to bundle cleanly

The Senate Banking Section 302 provision is the development most overlooked in industry analysis. It directs Treasury to issue sanctions and AML/CFT guidance for “distributed ledger messaging systems”—web-hosted applications that let a user submit instructions to a DeFi protocol—owned or operated by U.S. persons, and it expressly disclaims expanding or contracting existing illicit-finance law.43 It layers a Treasury-guidance obligation on front-end operators rather than narrowing the developer exclusion itself. Even where the activity exemption holds, U.S.-operated frontends will face Treasury-side guidance the exemption does not displace.

The BRCA reconciliation question is the second wildcard. The Blockchain Regulatory Certainty Act, H.R. 1747 (Emmer/Soto, 118th Congress), is the direct statutory ancestor of the money-transmitter carveout, which the Senate Banking substitute carries at Section 604.45 A floor amendment striking it is the scenario to plan against. If that happens, § 309’s securities-and-commodity exemption survives, but developers lose the BSA money-transmitter safe harbor—and the FinCEN compliance burden returns. The surface to watch is whether the developer’s role brushes against custody, fee collection, or transaction routing in ways that re-trigger FinCEN MSB analysis.

Translation. Build the seven-control-surfaces evidentiary record on the assumption § 309 lands roughly as drafted with the Section 302 guidance mandate alongside it. Reserve fallback plans against § 101(24) and § 202 tightening. Monitor BRCA reconciliation; the developer’s BSA exposure may shift independently of the § 309 securities-and-commodity exemption. The record in §XI survives the amendments in either direction.

X. If This Version Becomes Law: Operational Posture for Protocols Claiming § 309

Assume for purposes of this section that the Senate Banking reported substitute (EHF26374), including its Section 302 illicit-finance guidance mandate for distributed ledger messaging systems and its Section 601 developer protection, becomes law unchanged.5 § 309 provides narrow but defensible protection for non-custodial developers, validators, and open-source contributors. Protected activities (per §II): writing and publishing smart-contract code, validating transactions, operating nodes and oracle services, publishing self-custody wallet software, providing read-and-access user interfaces. Not protected: managing governance treasuries under effective control, running centralized frontends with order-routing or custody, operating DAO-level commodity-trading infrastructure that engages CEA-regulated activity.

Day 0 (enactment). Audit governance against § 101(24) using the seven surfaces. Prepare a dilution and distribution roadmap if issuer-side ownership sits at or above Section 205’s 20 percent line—or anywhere § 101(24) could reach team-controlled architecture. Audit frontends against Opyn/ZeroEx/Risley; segregate custody, fee-extraction, and order-routing features from protected developer activity. Document the entity stack: repository, foundation ownership, wrapper jurisdiction.

Day 90. Implement anti-fraud controls regardless of the developer exemption. § 309(b) and § 409 reach MEV-extraction features, team-controlled oracle dependencies, and frontend operator conduct that could be characterized as misrepresenting fairness of execution. Developer-activity defense under § 309 plus anti-fraud controls under § 10(b) and CEA § 6(c)(1)—both records matter independently.

Day 180-270. Track SEC and CFTC rulemaking on the “digital commodity” definition as applied to the native token under § 201. The activity exemption protects the publisher; token status is separately analyzed under § 201 and § 202 maturity. Build the joint audit framework per §VII; refine against the rulemaking as it publishes.

The extraterritoriality question is the elephant the bill does not address. If a non-U.S. developer publishes open-source code accessible from the U.S., is the developer in or out of § 309? Morrison v. National Australia Bank supplies the transactional test for the extraterritorial reach of Section 10(b): the antifraud provision reaches only domestic purchases and sales and securities listed on a domestic exchange.46 FinCEN’s U.S.-nexus approach in the 2019 Guidance supplies a parallel BSA-side framework.7 The Tornado Cash prosecutions show the exposure from two directions: Storm’s U.S. conviction shows that a developer who keeps operating the service faces U.S. criminal exposure, and the Dutch court’s May 14, 2024 money-laundering conviction of a Tornado Cash developer, with a 64-month sentence, shows non-U.S. developers face parallel exposure in their own jurisdictions.2947 Structure publication to minimize U.S. nexus (servers, financial accounts, marketing targeting), but do not assume non-U.S. residency provides categorical protection. § 309 is silent; pre-CLARITY extraterritoriality doctrine applies by default, and that doctrine is not protective.

California’s Digital Financial Assets Law adds a state-law surface CLARITY does not displace. DFAL (Cal. Fin. Code § 3101 et seq.) has required a license to engage in digital financial asset business activity with California residents since July 1, 2026.48 DFAL carries no developer exemption of § 309’s breadth: Section 3103(b)(7)(A) exempts only a person who “contributes only connectivity software or computing power to securing a network,” and Section 3103(b)(13) only a person who takes no compensation, direct or indirect; a protocol developer who publishes a front end, ships wallet software, or charges an access fee falls outside both. Protocols with material California-resident counts—most consumer-facing DeFi—face DFAL licensing obligations on a surface CLARITY does not preempt. Section 308’s state preemption reaches state securities laws for classified digital commodities; it does not preempt state money-transmitter licensing, state consumer-protection regimes, or DFAL.49 The July 1, 2026 license deadline has passed; Section 3201(b) preserved a safe harbor only for applicants who filed on or before that date, so a protocol serving California residents that neither filed nor qualifies for a Section 3103 exemption is operating outside the statute now.

Wrapper structures matter because the dual-track defense in §VIII.C runs through them. Wyoming SF 50’s DUNA (eff. July 1, 2024) provides U.S. entity status with limited liability and DLT-based governance.42 Cayman foundation companies supply offshore tax efficiency with tightening substance requirements. Swiss Stiftung provides robust civil-law foundation architecture with heavy substance obligations. Marshall Islands DAO LLC (MIDAO) provides U.S.-style LLC protection offshore. The choice depends on founder tax residency, holder geography, regulated-activity profile, and substance budget. None displaces § 309; each provides parallel entity-liability protection for downstream DAO activity.

Key risk: a floor amendment strips the BRCA carveout, and developers lose the BSA money-transmitter exemption—§ 309’s securities-and-commodity exemption survives, but custody-adjacent developers face FinCEN MSB analysis. Key opportunity: § 309 holds, the Section 302 guidance is calibrated proportionally, and protocols get runway to mature governance through the § 202 four-year window.

XI. Verification Architecture: Building a § 309 Evidentiary Record from Day Zero

A. The Evidentiary Record Concept

§ 309 reliance is not a one-time legal opinion. It is a continuing-compliance posture. The closest doctrinal analogue is DMCA § 512’s safe-harbor architecture, which conditions protection on continuing technical compliance—repeat-infringer policies, notice-and-takedown responsiveness, designated-agent registration, accommodation of standard technical measures.50 § 512 protections survive only as long as the operational posture survives. § 309 operates on the same architectural principle. The exemption attaches only as long as the developer-activity profile satisfies the test, and the evidentiary record must demonstrate satisfaction at any moment regulators choose to probe.

The bar is higher than most protocols realize. A § 309 record is not the docs-site governance summary. It is an archival, signed, timestamped, audit-quality dossier—repository commits, multisig signer disclosures, treasury snapshots, oracle architecture, sequencer ownership, governance-vote records, decentralization memos refreshed against the seven surfaces. The record needs to satisfy two audiences: an SEC enforcement attorney in 2030 looking at the protocol’s 2026 posture, and a private-plaintiff’s expert deposing the team in a Section 12(a)(1) rescission case. Both will read the same record.

B. Day Zero Documentation

At protocol launch (or at this article’s publication for existing protocols), the Day Zero set: (i) repository archive with cryptographic commit signatures; (ii) governance constitution, signed and timestamped; (iii) tokenomics whitepaper with allocation tables and vesting schedules; (iv) foundation entity documents; (v) multisig signer disclosures with relationship-to-foundation declarations; (vi) oracle architecture documentation; (vii) sequencer ownership disclosure (rollups); (viii) treasury composition snapshot; (ix) vesting schedule with cliff dates and unlock cadence.

Retention should be permanent and tamper-evident. Canonical archive on foundation-controlled cold storage with redundant off-site backup at a regulated third-party provider (law-firm escrow or notarized digital archive). Each document signed by the foundation’s general counsel or governance officer; multisig disclosures co-signed by each signer.

C. Annual Refresh

The annual refresh is the operational discipline most protocols underestimate. Each year: (i) decentralization memo against the seven surfaces, signed by counsel and dated; (ii) governance-vote records aggregated, with delegate-aggregation analytics; (iii) treasury composition updated for vesting unlocks and disbursements; (iv) multisig signer changes documented with succession records; (v) team-controlled changes audited against the seven surfaces. The annual memo is what an SEC or CFTC enforcement attorney reads first. Author it for that audience.

D. The Activity Exemption Is the Floor, Not the Ceiling

§ 309 is a floor. It protects what developers do. It does not clearly protect against private plaintiffs, it does not reach state-law claims (DFAL per §X), and it does not protect against DAO-entity liability for downstream activity (Ooki per §VIII) or anti-fraud actions under § 10(b) and CEA § 6(c)(1). Protocols serious about long-term U.S. compliance need three records in parallel: (i) the § 309 evidentiary record in this section; (ii) a DAO legal-wrapper structure (DUNA, Cayman, Swiss Stiftung, MIDAO) per §X; (iii) a § 202 maturity pathway for the native token, cross-read against the Safe Harbor’s cessation test per §VII.

Protocols that build the seven-control-surfaces record now—code, governance, treasury, oracles, sequencers, frontends, fees—are protected against both the unchanged-text scenario and the tightened scenarios in §IX. Protocols that wait for enactment will be building the record against the clock the bill starts: the CFTC must adopt an expedited-registration process within 180 days of enactment, and any intermediary registration the protocol’s operations turn out to need is due within 90 days of that adoption.51

Astraea Counsel works with DeFi protocol teams on the full § 309 readiness posture—control-surface audits, foundation entity formation and wrapper design (DUNA, Cayman, Swiss, MIDAO), oracle and sequencer architecture review for § 101(24) compliance, frontend-operator separation from protocol-publisher activity, and the annual-refresh discipline. The “Control-Surface Audit” is our entry-point engagement: a structured walk through the seven surfaces, with deliverable memoranda calibrated to SEC enforcement-attorney and private-plaintiff-deposition audiences. Intake signal: defi-309-readiness.

Most protocols claiming § 309 today have built the surface for the legend they want to be. We build the record for the protocol you actually are—and the case the regulator or private plaintiff actually brings. The activity exemption is the floor. The record is what holds.

Related Resources

  • The CLARITY Act Exchange Registration Roadmap: A 180-Day Compliance Calendar (Article 1 of this series)
  • The Stablecoin Issuer’s Dual-Framework Roadmap: GENIUS Act PPSI Compliance and the Pending CLARITY Act Yield Compromise (Article 3 of this series)
  • SEC Innovation Exemption and Token Safe Harbor: A Founder’s Guide to Regulation Crypto Assets (Section 202 maturity pathway and Investment Contract Safe Harbor cessation test)
  • The CLARITY Act: CFTC and SEC Jurisdictional Divisions Explained (foundational hub)

Footnotes

  1. H.R. 3633, Digital Asset Market Clarity Act of 2025, 119th Cong. (engrossed in the House, July 17, 2025), available at https://www.congress.gov/bill/119th-congress/house-bill/3633/text; Office of the Clerk, U.S. House of Representatives, Roll Call 199, On Passage, H.R. 3633 (July 17, 2025) (294 yea, 134 nay), available at https://clerk.house.gov/Votes/2025199. Section numbers in this article are the House-engrossed text’s unless the Senate text is named. ↩

  2. Jesse Hamilton, “Clarity Act Clears U.S. Senate Committee, on Its Way to a Final Test in Congress,” CoinDesk (May 14, 2026), available at https://www.coindesk.com/policy/2026/05/14/clarity-act-clears-u-s-senate-committee-on-its-way-to-a-final-test-in-congress. ↩

  3. S. 3755, Digital Commodity Intermediaries Act, 119th Cong. (reported by the Senate Committee on Agriculture, Nutrition, and Forestry, Feb. 2, 2026), available at https://www.congress.gov/bill/119th-congress/senate-bill/3755/text (§ 207, software developer protections, adding CEA § 4v; the bill carries no securities-side exclusion). ↩

  4. “Senate Keeps Clarity Act Alive With Crypto Bill Vote Set for September,” Decrypt (Aug. 8, 2026), available at https://decrypt.co/375174/senate-keeps-clarity-act-alive-with-crypto-bill-vote-set-for-september (Senate Majority Leader Thune filed the motion to proceed and cloture on H.R. 3633; first procedural vote set for 2:15 p.m. ET, Tuesday, September 15, 2026). ↩ ↩2

  5. Senate Banking Comm., Reported Substitute to H.R. 3633 (EHF26374, print undated; reported after the May 14, 2026 markup) (Title VI § 601, protecting software developers, adding Securities Act § 27C and Exchange Act § 15H; § 604, Blockchain Regulatory Certainty Act; § 309, study on digital asset mixers and tumblers; Title III § 302); Senate Banking Comm., Amendment in the Nature of a Substitute to H.R. 3633 (EHF26031, print undated; released Jan. 12, 2026), available at https://www.banking.senate.gov/imo/media/doc/market_structure_draft.pdf. ↩ ↩2 ↩3

  6. Jesse Hamilton, CoinDesk (May 14, 2026), cited at note 14 (reporting that the committee adopted amendments defining decentralization advanced by Senator Warner and that Senator Warren “argued that the changes amounted to insufficient half measures”); Senate Banking Comm., Reported Substitute to H.R. 3633 (EHF26374, print undated; reported after the May 14, 2026 markup) § 604 (Blockchain Regulatory Certainty Act, retained), § 302 (illicit finance obligations for distributed ledger messaging systems). ↩

  7. FinCEN Guidance FIN-2019-G001, Application of FinCEN’s Regulations to Certain Business Models Involving Convertible Virtual Currencies (May 9, 2019), available at https://www.fincen.gov/sites/default/files/2019-05/FinCEN%20Guidance%20CVC%20FINAL%20508.pdf (§ 4.5.1(b): an anonymizing software provider is not a money transmitter; § 5.2.2: the developer of a DApp is not a money transmitter for the mere act of creating the application; requirements apply equally to foreign-located CVC money transmitters doing business in whole or substantial part within the United States); see also FinCEN Guidance FIN-2013-G001, Application of FinCEN’s Regulations to Persons Administering, Exchanging, or Using Virtual Currencies (Mar. 18, 2013) (the user, exchanger, and administrator taxonomy; a person who creates units of convertible virtual currency and uses them to purchase goods or services is a user, not a money transmitter). Together, the FinCEN guidance documents create the pre-existing administrative framework for the non-custodial publisher carveout that § 309 codifies in expanded form. ↩ ↩2

  8. H.R. 3633 § 309 (adding Exchange Act § 15H, “Decentralized Finance Activities Not Subject to This Act”; excepts the Commission’s anti-fraud and anti-manipulation authorities). ↩

  9. H.R. 3633 § 409 (adding CEA § 4v, the parallel CEA exclusion; excepts the Commission’s anti-fraud, anti-manipulation, and false reporting enforcement authorities). ↩

  10. Adrien K. Anderson et al., Clarifying the CLARITY Act: What To Know About the House Crypto Market Structure Bill and Its Path to Law, Arnold & Porter (Aug. 26, 2025), available at https://www.arnoldporter.com/en/perspectives/advisories/2025/08/clarifying-the-clarity-act. ↩

  11. H.R. 3633 § 309 (adding Exchange Act § 15H(a)(1)–(6)); the six-paragraph enumeration in the text follows the House-engrossed print. ↩

  12. In re Deridex, Inc., CFTC Docket No. 23-42, $100,000 civil monetary penalty (Sept. 7, 2023), available at https://www.cftc.gov/media/9221/enfderidexorder090723/download (findings that Deridex “held custody of users’ assets” through its smart contracts and “retained substantial control over the Deridex Protocol,” including the ability to update the code to suspend trading or prevent users from depositing collateral; violations of CEA §§ 4(a), 4d(a)(1), and 5h(a)(1): off-exchange leveraged retail commodity transactions, unregistered futures-commission-merchant activity, and operating an unregistered swap execution facility, with a customer-identification-program failure under the Bank Secrecy Act). ↩ ↩2

  13. In re Opyn, Inc., CFTC Docket No. 23-40, $250,000 civil monetary penalty (Sept. 7, 2023), available at https://www.cftc.gov/PressRoom/PressReleases/8774-23 (blocking users with U.S. internet protocol addresses “not sufficient” to exclude U.S. users; Opyn retained a degree of control through the ability to impose transaction fees and to effect a shutdown of the protocol). ↩ ↩2 ↩3 ↩4

  14. In re ZeroEx, Inc., CFTC Docket No. 23-41, $200,000 civil monetary penalty (Sept. 7, 2023), available at https://www.cftc.gov/media/9216/enfzeroexorder090723/download (the sole violation found is CEA § 4(a), 7 U.S.C. § 6(a); liability rests on deploying the 0x Protocol and operating a front-end user interface, Matcha, through which leveraged tokens developed and issued by an unaffiliated third party were offered); see also CFTC Press Release No. 8774-23 (Sept. 7, 2023), available at https://www.cftc.gov/PressRoom/PressReleases/8774-23 (Deridex and Opyn charged with unregistered SEF or FCM activity and customer-identification-program failures; all three charged with illegally offering leveraged and margined retail commodity transactions). ↩ ↩2 ↩3 ↩4

  15. FinCEN Notice of Proposed Rulemaking, Requirements for Certain Transactions Involving Convertible Virtual Currency or Digital Assets, RIN 1506-AB47, 85 Fed. Reg. 83840 (Dec. 23, 2020) (proposing to require banks and money services businesses to report, keep records, and verify customer identity for CVC transactions involving unhosted wallets; restating that “[a] person conducting a transaction through an unhosted wallet to purchase goods or services on their own behalf is not a money transmitter,” 85 Fed. Reg. at 83842); see Office of Information and Regulatory Affairs, RIN 1506-AB47, Spring 2021 Unified Agenda entry, available at https://www.reginfo.gov/public/do/eAgendaViewRule?pubId=202104&RIN=1506-AB47. ↩

  16. H.R. 3633 § 101 (adding Securities Act § 2(a)(24), “decentralized governance system”: “any transparent, rules-based system permitting persons to form consensus or reach agreement in the development, provision, publication, maintenance, or administration of such blockchain system, where participation is not limited to, or under the effective control of, any person or group of persons under common control,” with § 2(a)(24)(C) providing that a legal entity qualifies only if it “does not operate pursuant to centralized management”). The definition is single-homed at § 2(a)(24); §§ 103 and 105 incorporate it by reference, and § 110 is the “Application of the Bank Secrecy Act” provision. The definition contains no percentage. ↩ ↩2 ↩3 ↩4 ↩5

  17. The categorical-exemption reading is contested industry-side policy work, not legal authority, and is described here without attribution to any named organization; cited for completeness of the doctrinal landscape. ↩ ↩2

  18. H.R. 3633 § 309(b) (“Subsection (a) shall not apply to the anti-fraud and anti-manipulation authorities of the Commission”); H.R. 3633 § 409 (CFTC parallel exclusion; excepting the Commission’s anti-fraud, anti-manipulation, and false reporting enforcement authorities). ↩

  19. SEC v. LBRY, Inc., 639 F. Supp. 3d 211 (D.N.H. 2022) (summary judgment for SEC; parallel cite 2022 WL 16744741), final judgment, 2023 WL 4459290 (D.N.H. July 11, 2023) ($111,614 penalty). The court held that LBRY offered LBC as an investment contract where the team retained an economic stake and promised managerial development, and declined to rule on whether LBC is itself a security. ↩ ↩2

  20. H.R. 3633 § 201 (“investment contract asset”: a digital commodity that can be exclusively possessed and transferred person to person without necessary reliance on an intermediary and is recorded on a blockchain, sold or otherwise transferred pursuant to an investment contract; the section excludes the asset, not the investment contract, from the definition of “investment contract”). ↩

  21. H.R. 3633 § 202 (exempted primary transactions in digital commodities; $50,000,000 cap, annually adjusted by the Commission, over a rolling twelve-month period; four-year window to reach mature blockchain system status); H.R. 3633 § 205 (adding Exchange Act § 42, mature blockchain system requirements, including the distributed-ownership criterion at § 42(c)(2)(G): no digital commodity issuer, related person, or affiliated person “beneficially owns, in the aggregate, 20 percent or more of the total amount of units of the digital commodity”). ↩ ↩2 ↩3

  22. SEC & CFTC, Application of the Federal Securities Laws to Certain Types of Crypto Assets and Certain Transactions Involving Crypto Assets, Release Nos. 33-11412; 34-105020, 91 Fed. Reg. 13714 (Mar. 17, 2026) (effective Mar. 23, 2026), available at https://www.sec.gov/files/rules/interp/2026/33-11412.pdf (n.50: “For purposes of this release, a crypto system is ‘decentralized’ if the crypto system functions and operates autonomously with no person, entity, or group of persons or entities having operational, economic, or voting control of the crypto system”). ↩ ↩2 ↩3 ↩4

  23. Risley v. Universal Navigation Inc., No. 23-1340 (2d Cir. Feb. 26, 2025) (summary order), aff’g in part and vacating in part 690 F. Supp. 3d 195 (S.D.N.Y. 2023), on remand, 2026 U.S. Dist. LEXIS 41885 (S.D.N.Y. Mar. 2, 2026) (dismissed) (affirming dismissal of the federal securities claims on statutory-seller and Section 29(b) grounds—the smart contracts are “standardized computer codes that allow the Protocol to fill in the terms for individual trades between and controlled by its users” and were “at best, collateral to the third parties’ scam token activities”; vacating and remanding the state-law claims; token status assumed arguendo). ↩ ↩2 ↩3

  24. Report of Investigation Pursuant to Section 21(a) of the Securities Exchange Act of 1934: The DAO, Exchange Act Release No. 81207 (July 25, 2017) (concluding that DAO Token holders’ profits were to be derived from the managerial efforts of others—Slock.it, its co-founders, and the Curators—and that holders’ voting rights did not defeat that prong because the Curators “maintained ultimate control over which proposals could be submitted to, voted on, and funded”). ↩

  25. William Hinman, Dir., SEC Div. of Corp. Fin., Digital Asset Transactions: When Howey Met Gary (Plastic) (June 14, 2018), available at https://www.sec.gov/newsroom/speeches-statements/speech-hinman-061418. The speech introduced the “sufficiently decentralized” framing; in SEC v. Ripple Labs, Inc., 682 F. Supp. 3d 308, 334 (S.D.N.Y. 2023), it appears only as evidence of the defendants’ state of mind on scienter, not as a legal standard. Cited with caveat. ↩

  26. Jesse Walden (a16z), Progressive Decentralization: A Playbook for Building Crypto Applications (Jan. 2020); Miles Jennings (a16z Crypto), Principles & Models of Web3 Decentralization (Apr. 2022); Marc Boiron (Variant Fund), Sufficient Decentralization: A Playbook for web3 Builders and Lawyers (Aug. 2, 2022). Industry-published policy frameworks the Seven Control Surfaces synthesizes; cited as policy work, not legal authority. ↩

  27. Van Loon v. Dep’t of the Treasury, 122 F.4th 549 (5th Cir. 2024) (No. 23-50669, decided Nov. 26, 2024) (reversing and remanding with instructions to grant partial summary judgment on the APA claim; immutable smart contracts are not “property” because they are not capable of being owned). ↩ ↩2

  28. Universal City Studios, Inc. v. Corley, 273 F.3d 429, 449 (2d Cir. 2001) (computer code “can merit First Amendment protection”; affirming the injunction against posting and linking to DeCSS). ↩

  29. United States v. Storm (S.D.N.Y.) (jury verdict Aug. 6, 2025 convicting the defendant of conspiring to operate an unlicensed money transmitting business; jury deadlocked on the money-laundering and sanctions counts); see U.S. Attorney’s Office, S.D.N.Y., Founder of Tornado Cash Crypto Mixing Service Convicted of Knowingly Transmitting Criminal Proceeds (Aug. 6, 2025), republished by IRS Criminal Investigation, available at https://www.irs.gov/compliance/criminal-investigation/founder-of-tornado-cash-crypto-mixing-service-convicted-of-knowingly-transmitting-criminal-proceeds; Tornado Cash Developer Roman Storm’s Retrial Pushed Back to April 2027, The Block (Aug. 26, 2026), available at https://www.theblock.co/news/regulation/2026-08-26-tornado-cash-roman-storm-retrial-april-2027-412761 (retrial set for April 26, 2027; motion for acquittal argued April 2026 and undecided). ↩ ↩2 ↩3

  30. CFTC v. Eisenberg, No. 1:23-cv-00173 (S.D.N.Y. filed Jan. 9, 2023) (complaint charging oracle price-feed manipulation as market manipulation under CEA § 6(c)(1), 7 U.S.C. § 9(1), and Regulation 180.1); CFTC Release No. 8647-23 (Jan. 9, 2023) (describing the action as the agency’s first involving a scheme “sometimes called ‘oracle manipulation’”); SEC v. Eisenberg, No. 1:23-cv-00503 (S.D.N.Y. filed Jan. 20, 2023) (complaint alleging that MNGO was offered and sold as an investment contract). ↩

  31. TRM Labs, BREAKING: Federal Judge Overturns All Criminal Convictions in Mango Markets Case Against Avraham Eisenberg (May 23, 2025), available at https://www.trmlabs.com/resources/blog/breaking-federal-judge-overturns-all-criminal-convictions-in-mango-markets-case-against-avraham-eisenberg (reporting Judge Subramanian’s order granting the Rule 29 motion and vacating the April 2024 convictions on insufficiency and venue grounds in United States v. Eisenberg; the docket number, No. 1:23-cr-00010 (S.D.N.Y.), is stated at Complaint ¶ 16, SEC v. Eisenberg, No. 1:23-cv-00503 (S.D.N.Y. Jan. 20, 2023)). ↩

  32. The trajectory reading is industry policy posture, described here without attribution to any named firm; Release Nos. 33-11412; 34-105020, nn. 50 and 54, define decentralization and a “central party” in the present participle (“having … control”). ↩

  33. Securities Exchange Act § 10(b), 15 U.S.C. § 78j(b) (manipulative and deceptive devices; the SEC anti-fraud authority the § 309(b) exception preserves). ↩

  34. Commodity Exchange Act § 6(c)(1), 7 U.S.C. § 9(1) (prohibiting “any manipulative or deceptive device or contrivance”; the CFTC’s civil anti-fraud and anti-manipulation hook). ↩

  35. Commodity Exchange Act § 9(a)(2), 7 U.S.C. § 13(a)(2) (criminal felony liability for manipulation, cornering, false reporting, and knowing violation of enumerated CEA sections). ↩

  36. BlockFi Lending LLC, Securities Act Release No. 33-11029 (Feb. 14, 2022) (settled order; $50 million SEC penalty; SEC applied Howey and the Reves v. Ernst & Young family-resemblance test to crypto lending products, finding them both investment contracts and notes); SEC Press Release No. 2022-26 (Feb. 14, 2022), available at https://www.sec.gov/newsroom/press-releases/2022-26 (BlockFi agreed to pay $50 million to the SEC and “an additional $50 million in fines to 32 states”). ↩

  37. In re Blockratize, Inc. d/b/a Polymarket.com, CFTC Docket No. 22-09 (Jan. 3, 2022) (settled order entered without admitting or denying; $1,400,000 civil monetary penalty; operating an unregistered facility for event-based binary options violated CEA §§ 4c(b) and 5h(a)(1) and Regulations 32.2 and 37.3(a)(1); respondent a Delaware corporation that created, defined, and resolved the markets). ↩

  38. Paul S. Atkins, Chairman, U.S. Sec. & Exch. Comm’n, Regulation Crypto Assets: A Token Safe Harbor, Remarks at the DC Blockchain Summit (Mar. 17, 2026), available at https://www.sec.gov/newsroom/speeches-statements/atkins-remarks-regulation-crypto-assets-031726. The April 6, 2026 OIRA-submission date is press-reported, with no OIRA docket record publicly confirming it; the Commission issued the proposing release, Regulation Crypto Assets, Release Nos. 33-11434; 34-106150, on August 18, 2026 (see the founders guide cited at note 38). ↩

  39. See SEC Innovation Exemption and Token Safe Harbor: A Founder’s Guide to Regulation Crypto Assets (Astraea Counsel APC, July 18, 2026, updated Aug. 19, 2026), /insights/sec-innovation-exemption-founders-guide (the Loper Bright APA-challenge analysis and the cessation-test mechanics). ↩

  40. Loper Bright Enters. v. Raimondo, 603 U.S. 369 (2024) (overruling Chevron; the APA requires courts to exercise independent judgment on questions of law, and where a statute delegates discretionary authority the court’s role is to fix the boundaries of that delegation); Van Loon cited Loper Bright in interpreting IEEPA’s undefined term “property” independently. ↩

  41. CFTC v. Ooki DAO, No. 3:22-cv-05416 (N.D. Cal. June 8, 2023) (default judgment; DAO liable as an unregistered futures commission merchant, for unlawful off-exchange leveraged and margined retail commodity transactions, and for failing to implement a customer identification program; $643,542 civil monetary penalty; entity-liability theory opposed only by amici). ↩

  42. Wyoming SF0050, Wyoming Decentralized Unincorporated Nonprofit Association Act, 2024 Wyo. Sess. Laws ch. 50 (Enrolled Act No. 23) (signed Mar. 7, 2024; eff. July 1, 2024), codified at Wyo. Stat. §§ 17-32-101 to -129, available at https://www.wyoleg.gov/2024/Enroll/SF0050.pdf (limited liability, § 17-32-107; governance through distributed ledger technology, § 17-32-121). ↩ ↩2

  43. Senate Banking Comm., Reported Substitute to H.R. 3633 (EHF26374, print undated; reported after the May 14, 2026 markup) § 302 (illicit finance obligations for distributed ledger messaging systems: Treasury guidance within 360 days of enactment, § 302(b); definition at § 302(a)(1)(A); rules of construction disclaiming any expansion or contraction of existing illicit-finance law, § 302(d)). ↩ ↩2

  44. The § IX forecast is the author’s calibrated judgment. Inputs: the House-engrossed text; Senate Banking’s January 12, 2026 manager’s amendment and May 2026 reported substitute; S. 3755 as reported February 2, 2026; and reported reconciliation positions, including the CoinDesk markup coverage at note 14 and the August 8, 2026 cloture filing at note 49. ↩

  45. Blockchain Regulatory Certainty Act, H.R. 1747, 118th Cong. (introduced Mar. 23, 2023 by Rep. Emmer for himself and Rep. Soto), available at https://www.congress.gov/bill/118th-congress/house-bill/1747; carried forward at Senate Banking Comm., Reported Substitute to H.R. 3633 (EHF26374) § 604. ↩

  46. Morrison v. Nat’l Austl. Bank Ltd., 561 U.S. 247, 253–54, 267–70 (2010) (adopting the transactional test and rejecting the Second Circuit’s conduct-and-effects tests; the reach of § 10(b) is a merits question, not one of subject-matter jurisdiction). ↩

  47. Rechtbank Oost-Brabant, 14 mei 2024, ECLI:NL:RBOBR:2024:2069 (conviction of a Tornado Cash developer for money laundering (witwassen); 64-month prison sentence; the published judgment anonymizes the defendant), available at https://uitspraken.rechtspraak.nl/details?id=ECLI:NL:RBOBR:2024:2069. ↩

  48. California Digital Financial Assets Law, Cal. Fin. Code § 3101 et seq. (added by Stats. 2023, ch. 792 (AB 39), effective Jan. 1, 2024; licensure required for digital financial asset business activity with California residents on or after July 1, 2026, § 3201; exemptions at § 3103(b), including (b)(7)(A) and (b)(13)). ↩

  49. H.R. 3633 § 308 (state preemption; covered-security treatment under NSMIA for classified digital commodities; does not reach state money-transmitter, consumer-protection, or DFAL-analogue regimes). ↩

  50. Digital Millennium Copyright Act, 17 U.S.C. § 512 (safe-harbor architecture conditioning ongoing intermediary protection on continuing technical compliance: repeat-infringer policies, § 512(i)(1)(A); notice-and-takedown responsiveness, § 512(c)(1)(C); designated-agent registration, § 512(c)(2); accommodation of standard technical measures, § 512(i)(1)(B); § 512(m) imposes no duty to monitor). Cited as doctrinal analogue for the continuing-compliance posture § 309 reliance requires. ↩

  51. H.R. 3633 § 106(a) (the CFTC “shall adopt, by rule, regulation, or order, a process for expedited registration” within 180 days of enactment; a person “shall not act as” a digital commodity broker, dealer, or exchange “after the end of the 90-day period beginning on the date the process … is adopted” unless registered). ↩

On This Page

  • Key Takeaways
  • I. Bill on the Verge: The § 309 Exemption Sits in a Bill That Hasn't Been Enacted Yet
  • II. What Section 309 Actually Protects: The Statutorily-Enumerated Activities
  • III. What Section 309 Does NOT Protect: The Protocol's Token, the DAO's Governance, the Frontend Operator, the Corporate Sponsor
  • IV. Decentralization Theater vs. Structural Decentralization
  • V. The Seven Control Surfaces
  • VI. The Anti-Fraud Carveout: What § 309 Preserves for the SEC (and § 409 for the CFTC)
  • VII. Cross-Reading § 309 with the Innovation Exemption Safe Harbor's Cessation Test
  • VIII. The Ooki DAO and Van Loon Lessons
  • IX. How Likely Is This to Change Before It Becomes Law: Reconciliation Forecast
  • X. If This Version Becomes Law: Operational Posture for Protocols Claiming § 309
  • XI. Verification Architecture: Building a § 309 Evidentiary Record from Day Zero

Frequently Asked Questions

What activities does Section 309 actually protect?

Six statutorily enumerated activities: compiling, relaying, sequencing, or validating network transactions; providing computational work, node or oracle services, or bandwidth; providing a user interface for reading and accessing blockchain data; developing, publishing, or maintaining a blockchain system or DeFi trading protocol; developing or maintaining a DeFi messaging system or operating a liquidity pool for spot digital-commodity transactions; and publishing self-custody wallet software. The exemption is activity-based—it protects the developer doing those things. It does not classify the protocol’s token, which is a separate analysis under Section 201.

Is a Uniswap-style fee switch fatal to Section 309 eligibility?

Not automatically, but it is one of the seven control surfaces regulators will probe. A fee switch that routes revenue to a centralized treasury managed by a small group is materially harder to defend than one that distributes pro rata to token holders without managerial discretion. The question is who controls the switch, not whether the switch exists.

Does running my own frontend disqualify the protocol?

§ 309 protects publishing self-custody wallet software and providing a user interface that enables a user to read and access data about a blockchain system. But a frontend that retains custody of user assets, routes order flow, or extracts trading fees outside the protocol’s transparent rules looks more like an intermediary than a publisher. The seven control surfaces frame the analysis—frontend operation is one surface, not the whole test.

If the bill says my protocol is exempt from intermediary registration, why does my token's status still matter?

Because Section 309 exempts the activity, not the asset. The protocol’s native token is a digital commodity; whether its sale was an investment contract asset transaction turns on Section 201, and whether the blockchain system is a ‘mature blockchain system’ turns on Section 205’s certification requirements. A Section 309-exempt protocol can still issue a token that is a security. Developer exemption is not token exemption.

What is 'decentralization theater' and why is it disqualifying?

Cosmetic decentralization—foundation-held governance tokens marketed as decentralized, two-of-three multisigs where two signers are correlated, ‘community grants’ that actually fund the founding team—moves the labels without moving the seven control surfaces. CLARITY’s verification regime is operational, not nominal. The theater is disqualifying because the seven-control-surface audit is operational. Section 101(24)‘s effective-control test does not respond to optics.

Does Section 309 protect against private plaintiffs, or only the SEC and CFTC?

Section 309 provides that a person is not subject to the Exchange Act based on the enumerated activities, and Section 409 does the same under the Commodity Exchange Act; both except the Commissions’ anti-fraud and anti-manipulation authorities by their terms. The exclusion says nothing about state-law claims, and whether it defeats a private Exchange Act claim predicated on those activities is unresolved. Build the Section 309 evidentiary record for both regulator-facing defense and private-plaintiff deposition exposure.

How likely is Section 309 to change before the bill becomes law?

Medium (35-45% probability of material change, my estimate). The Senate Banking substitute already moves the developer protection to its Section 601, keeps the Blockchain Regulatory Certainty Act carveout at Section 604, and adds a Section 302 Treasury-guidance mandate for DeFi front-ends; Senator Warren opposed the committee’s DeFi changes as insufficient. Senate Agriculture’s S. 3755 carries a CFTC-side developer exemption (Section 207) but no securities-side exclusion, so the Banking text governs the SEC-side question in conference. Most likely outcome: Senate Banking language stands (~50-55%).

What is the 'mature blockchain system' test and how does it interact with § 309?

Section 101 defines ‘decentralized governance system’ and ‘mature blockchain system’; Section 202 builds a $50 million (CPI-adjusted, rolling twelve-month) issuer exemption conditioned on the blockchain system being certified mature or the issuer intending it to reach that status within four years; and Section 205 sets the maturity requirements, including the 20 percent distributed-ownership criterion. A protocol can be § 309-exempt today while its native token’s path under Section 202 depends on satisfying Section 205’s criteria inside the four-year window. Plan for both: activity exemption now, token maturity over time.

What did Van Loon and Ooki DAO settle that the CLARITY Act now codifies or displaces?

Van Loon (5th Cir. 2024) held that immutable code is not property subject to OFAC sanctions—a foundational precedent for DeFi developer protections, persuasive but IEEPA-specific. Ooki DAO (N.D. Cal. 2023) imposed CFTC liability on an unincorporated DAO on a default-judgment posture; the entity-liability theory was briefed by amici and adopted on the pleadings, never tested by an appearing adversary. § 309 builds on Van Loon’s developer-protective posture but does not displace Ooki DAO’s authority over DAOs that engage in regulated commodity activity.

Does § 309 protection extend to a developer's employer (Uniswap Labs as corporate sponsor)?

It depends on which role the employer plays. Employer-as-developer (publishing code through employees) is arguably exempt—the employer is doing what the developers are doing. Employer-as-operator (running the canonical frontend, capturing the fee switch, directing treasury) is arguably not exempt—that conduct is intermediary activity outside the developer exemption. Employer-as-issuer (the corporate sponsor that conducted the initial token sale) is separately analyzed under § 201, where § 309 has no purchase. A corporate sponsor that sits in all three boxes does not get a single answer.

If I'm a non-U.S. developer publishing open-source code, am I in or out of § 309?

The bill is silent on extraterritoriality. The default is that pre-CLARITY doctrine applies—Morrison’s transactional test for the reach of Section 10(b), FinCEN’s U.S.-nexus approach on the BSA side, and the Tornado Cash prosecutions: Storm’s U.S. conviction shows that a developer who keeps operating the service faces U.S. criminal exposure, and the Dutch conviction of a Tornado Cash developer shows non-U.S. developers face parallel exposure in their own jurisdictions. Non-U.S. residency is not categorical protection. Structure publication to minimize U.S. nexus (servers, financial accounts, marketing targeting), but do not assume the activity exemption picks up where Morrison leaves off.

Is § 309 reliance an affirmative defense or a jurisdictional limit, and who bears the burden?

The bill does not resolve the question. Statutory exemptions of this structure have historically been treated as affirmative defenses (defendant pleads and proves), but § 309’s textual posture—a person ‘shall not be subject to this Act’ based on the enumerated activities, ‘[n]otwithstanding any other provision of this Act’—could support a jurisdictional-limit reading where the agency bears the burden of showing the conduct falls outside the exemption. Recommend protocol counsel build the record to satisfy both burdens. The seven-control-surfaces evidentiary record in §XI does that work regardless of how courts resolve the burden question.

Share

Follow this firm’s analysis on Google — see our commentary first when a story like this one breaks.

Stay Informed on Digital Asset Law

Practical legal analysis on crypto regulation, AI compliance, and fintech law—delivered when it matters.

No spam. Unsubscribe anytime.

Chanté Eliaszadeh profile picture

Chanté Eliaszadeh

Principal Attorney, Astraea Counsel APC

Chanté Eliaszadeh is the principal attorney of Astraea Counsel APC, advising crypto, AI, and fintech companies on securities and digital-asset regulation. She is named to the 2026 Lawdragon 500 X — The Next Generation guide for Crypto Regulation, Disputes, and Blockchain; won the 2024 Law360 Distinguished Legal Writing Award from The Burton Awards as co-author at White & Case; is recognized in The Legal 500 USA (White & Case LLP, 2023); and served as a summer SEC Honors Program intern in the SEC's Cyber Unit. Her firm is ranked in Chambers USA: Spotlight 2026 — Fintech (Los Angeles). She is an invited speaker at venues including ETHDenver, Korea Blockchain Week, the American Bar Association Business Law Section, Art Basel Miami, and Berkeley Law, and keynote speaker at the Computational Law & Blockchain Festival.

Get in Touch →

Legal Disclaimer: This article provides general information for educational purposes only and does not constitute legal advice. The law changes frequently, and the information provided may not reflect the most current legal developments. No attorney-client relationship is created by reading this content. For advice about your specific situation, please consult with a qualified attorney.

Related Articles

Regulatory Alert

The CLARITY Act Exchange Registration Roadmap: A 180-Day Compliance Calendar for Centralized Exchanges, Brokers, and Dealers

With H.R. 3633 awaiting a Senate cloture vote set for September 15, 2026, U.S. exchanges face two registrations, not one—and a 90-day compliance clock that starts the moment the CFTC adopts its expedited-registration process, after which operating unregistered is barred. Here is the operational calendar.

May 20, 2026 · 47 min readRead More →
Legal Update

The CLARITY Act (H.R. 3633) Explained: How It Would Split SEC and CFTC Jurisdiction

The CLARITY Act—H.R. 3633, the Digital Asset Market Clarity Act of 2025 — passed the House and is now before the Senate. It would give the CFTC authority over digital commodities, including spot markets, and turn on a "mature blockchain" test rather than a named Bitcoin/Ether carve-out. Here is what the actual bill says, and what it does not.

June 14, 2026 · 10 min readRead More →
Thought Leadership

Smart Contract Legal Enforceability: When Code Isn't Law

The 'code is law' ethos collapsed with The DAO hack. Smart contracts face contract formation requirements, oracle problems, and dispute resolution challenges—but hybrid approaches like Ricardian contracts bridge law and technology.

September 6, 2026 · 22 min readRead More →
View All Articles

Need Counsel for Your Digital Asset Business?

Token classification, regulatory strategy, and transactional support from attorneys who work in this space every day.

Talk to an Attorney