SEC/CFTC Finally Name 16 Cryptos as Digital Commodities—But How Long Until Clarity on the Other 25,000 Tokens?

On March 17, 2026, the SEC and CFTC did something the crypto industry has been waiting for since 2011: they actually told us which digital assets are commodities and which aren’t.

In a joint 68-page interpretation, they explicitly named 16 crypto assets as digital commodities under federal law—not securities. The list includes Bitcoin, Ethereum, Solana, XRP, Dogecoin, Cardano, Avalanche, Chainlink, Polkadot, Hedera, Litecoin, Bitcoin Cash, Shiba Inu, Tezos, Aptos, and Algorand.

They also clarified that staking, mining, and airdrops are classified outside securities law. This is huge. For years, builders worried that proof-of-stake itself might trigger securities regulations. That fear is now officially resolved.

The Five-Category Taxonomy

The interpretation creates a coherent framework dividing digital assets into five groups:

  1. Digital commodities (BTC, ETH, SOL, etc.)
  2. Digital collectibles (NFTs)
  3. Digital tools (utility tokens)
  4. Stablecoins
  5. Digital securities

This taxonomy is the most structured regulatory framework the U.S. has produced for crypto. It replaces the enforcement-first “regulation by litigation” approach with actual guidance.

Six days earlier, the SEC and CFTC signed a Memorandum of Understanding establishing a Joint Harmonization Initiative to coordinate oversight. This isn’t just policy—it’s institutional commitment to regulatory clarity.

But Here’s the Problem

It took 15 years of enforcement actions, billions in legal fees, Congressional pressure, and regime change at the SEC to define 16 assets.

There are over 25,000 tokens in the market.

That’s 0.06% clarity.

What About Everything Else?

The interpretation clarifies the big names, but what about:

  • Governance tokens: If token holders vote on protocol upgrades, does that trigger investment contract analysis? Is Uniswap’s UNI a tool, a commodity, or a security?
  • Liquid staking derivatives: If ETH is a commodity, is stETH also a commodity? What about rETH, cbETH, or any other liquid staking token?
  • Yield-bearing stablecoins: If USDC is a stablecoin, what is sUSDe that pays 4% yield from perpetual funding? Is it still a stablecoin, or did it become a security?
  • LP tokens: Tokens representing liquidity positions that accrue trading fees—are these tools, securities, or something new?
  • Wrapped and bridged assets: Is wBTC a commodity because BTC is a commodity? What about WETH on L2s?
  • DAO treasury tokens: Tokens that represent ownership in decentralized treasury assets—Howey test or not?

The framework says “digital tools” are non-securities, but it doesn’t define what makes a token a “tool” versus a “security.” The investment contract analysis still applies on a case-by-case basis.

My Take: Progress, But Just the Beginning

As someone who spent years at the SEC before moving to the private sector, I can tell you this interpretation represents real institutional change. The agencies are finally committed to providing notice rather than surprises.

But we can’t wait another 15 years for clarity on the next batch of assets.

DeFi builders need to know now whether governance tokens are legal. Liquid staking protocols need to know now whether their derivatives are securities. Yield aggregators need to know now whether vault tokens trigger registration requirements.

The positive: The joint interpretation shows the agencies can coordinate and issue guidance. The taxonomy framework is extensible—they can add subcategories for DeFi primitives without starting from scratch.

The risk: If the SEC applies the same case-by-case, enforcement-first approach to the other 24,984 tokens, we’ll be right back where we started.

What Happens Next?

I’m cautiously optimistic. The regulatory posture has shifted from “crypto is fraud” to “crypto needs rules.” That’s progress.

But the industry needs urgent guidance on:

  1. Governance tokens and decentralization thresholds: When is a protocol “sufficiently decentralized” that its governance token isn’t a security?
  2. Yield-bearing instruments: Clear classification for liquid staking, yield-bearing stablecoins, and auto-compounding vaults
  3. DeFi primitives: LP tokens, wrapped assets, synthetic assets, and derivative instruments
  4. Cross-chain assets: How classification works for bridged and wrapped tokens

The 16-asset list is a milestone. But it’s the first page of a very long book.

Legal clarity unlocks institutional capital. Let’s not spend another 15 years writing the next chapter.

What do you think? Is this framework enough to build on, or do we need more specific guidance before DeFi can scale safely in the U.S.?

:balance_scale: Compliance enables innovation—but only if the rules are clear.

This is exactly the anxiety I feel every day working on our DeFi protocol.

We launched our governance token six months ago, and I still wake up at 3am wondering if we’re going to get a Wells Notice. The 16-asset list helps—knowing that ETH is officially a commodity means our smart contracts are safe. But our governance token? Total uncertainty.

Here’s what keeps me up at night:

Our governance token holders can:

  • Vote on protocol upgrades
  • Decide fee distribution
  • Approve treasury spending
  • Whitelist new collateral assets

Does that make it a security under the Howey test? There’s no direct profit-sharing, but token holders effectively control how protocol revenue gets used.

The interpretation says “digital tools” are okay, but what makes a token a “tool”? Is voting a utility? Or is governance inherently an investment contract because token holders expect the protocol to succeed and their tokens to gain value?

The liquid staking question terrifies me even more.

We’re integrating stETH as collateral. ETH is a commodity (confirmed), but stETH is a derivative that:

  • Represents staked ETH
  • Accrues staking rewards
  • Can be traded or used as collateral
  • Has value that fluctuates with ETH

Is stETH also a commodity? Or did Lido create a security when they issued liquid staking derivatives?

Same question for rETH, cbETH, frxETH, and every other liquid staking token. If those are securities, half of DeFi’s collateral base just became potentially illegal.

Rachel, I have to ask:

What should builders do right now with governance tokens and liquid staking derivatives?

Should we:

  1. Just launch and hope we’re in the “digital tools” category?
  2. Get legal counsel to argue we’re sufficiently decentralized?
  3. Wait for more guidance and risk losing first-mover advantage?
  4. Move to Europe or Asia where MiCA and other frameworks are clearer?

I love that we finally have clarity on the top 16 assets. But I’m building in the edge cases where there’s still zero guidance. And I can’t afford to guess wrong.

The 15-year timeline to clarify 16 assets is genuinely scary. At that pace, we won’t have governance token clarity until 2041. By then, all the innovation will have moved offshore.

Help us figure out how to build safely without waiting another decade.

Let me break down why this 0.06% clarity number should scare everyone.

I run trading bots that interact with dozens of DeFi protocols. The 16-asset commodity list is great for my spot trading—I can confidently trade BTC, ETH, SOL without wondering if Coinbase or Kraken will get shut down for offering unregistered securities.

But here’s the problem: DeFi doesn’t run on BTC and ETH alone. It runs on protocol tokens, governance tokens, LP tokens, and yield-bearing derivatives.

Let’s look at the numbers:

  • 16 assets have clarity (BTC, ETH, SOL, etc.)
  • ~25,000 tokens exist on-chain
  • Top 100 tokens by market cap include governance tokens (UNI, AAVE, CRV, MKR)
  • Liquid staking derivatives: stETH ($15B), rETH ($5B), cbETH ($3B)
  • Yield-bearing stablecoins: sUSDe, sUSDS, ENA, and others growing to $50B supply by year-end

None of those have classification clarity.

The Edge Cases That Matter Most

1. Yield-bearing stablecoins

If USDC is classified as a “stablecoin” (category 4), what is Ethena’s sUSDe that offers 4% yield from perpetual funding rates?

  • Is it still a stablecoin because it’s pegged to $1?
  • Or did it become a security because it pays yield?
  • What about Maker’s sUSDS or Angle’s USDA?

If yield-bearing stablecoins are securities, DeFi protocols can’t use them as collateral without SEC registration. That kills the entire yield aggregation sector.

2. Liquid staking derivatives

ETH is a commodity. But what about stETH, which is:

  • A receipt token representing staked ETH
  • Accrues staking rewards automatically
  • Tradeable and usable as collateral

Does stETH inherit commodity status from ETH? Or is it a derivative that needs separate classification?

If liquid staking tokens are securities, DeFi loses $25B+ in core collateral overnight.

3. LP tokens and vault shares

When I provide liquidity to Uniswap and receive UNI-V2 LP tokens that earn trading fees, what am I holding?

  • A digital tool (utility to redeem liquidity)?
  • A security (I’m earning passive income from others’ efforts)?
  • A commodity derivative?

Same question for Yearn vault shares, Convex positions, and Balancer pool tokens.

4. Governance tokens for major protocols

UNI has a $5B market cap. AAVE is $1.5B. CRV is $800M.

None of them are on the 16-asset list.

If UNI is a security, does that mean Uniswap Labs sold unregistered securities? What happens to DEX governance across the entire DeFi ecosystem?

The Real Risk: Case-by-Case Uncertainty

The framework says each token gets analyzed individually under the investment contract test. That means:

  • 25,000 tokens × case-by-case analysis = regulatory chaos
  • Protocols don’t know their legal status until the SEC investigates
  • Builders either risk enforcement or abandon U.S. users

At 16 assets per 15 years, we’ll have full clarity in the year 25,437.

We Need a Faster Process

Here’s my proposal:

Tier 1: Named commodities (the 16 assets) - Fully clear
Tier 2: Derivative/wrapped tokens - Inherit classification from underlying (wBTC = commodity, stETH = commodity)
Tier 3: Protocol tokens over $1B market cap - Fast-track classification (30-day review)
Tier 4: New token launches - Safe harbor registration (notify SEC, default to “digital tool” unless challenged within 90 days)

Without a tiered system, the SEC can’t possibly analyze 25,000 tokens. And we can’t build DeFi waiting for individual rulings.

The 16-asset list is progress. But if every other token stays in limbo, the only winners are jurisdictions with clearer frameworks.

I’m building a zkEVM Layer 2 right now, and the governance token question is an existential issue for our entire architecture.

Here’s the technical problem: Our protocol NEEDS governance to function.

We can’t build a credibly neutral, decentralized zkEVM if a central company controls:

  • Sequencer upgrades
  • Prover network changes
  • Fee structure adjustments
  • Security council membership
  • Bridge contract modifications

So we designed a governance token that lets token holders vote on protocol parameters. It’s the only way to achieve “Stage 2 decentralization” (per L2beat’s criteria).

But now we have no idea if our governance token is legal.

The Howey Test Nightmare

Under the Howey test, something is a security if there’s:

  1. Investment of money :white_check_mark: (people buy the token)
  2. In a common enterprise :white_check_mark: (the protocol)
  3. With expectation of profits :white_check_mark: (token price appreciation)
  4. Derived from the efforts of others ??? (this is the key question)

The SEC interpretation says the “efforts of others” prong depends on whether the protocol is sufficiently decentralized.

But what does that actually mean?

Decentralization checklist (my best guess):

  • Token holders control protocol upgrades (not a foundation or company)
  • No single entity operates majority of infrastructure (sequencers, provers, validators)
  • Source code is open and forkable
  • Treasury is controlled by DAO, not company
  • Core team doesn’t have admin keys or special privileges

Even if we hit all those criteria, there’s no legal test or safe harbor.

The Timing Problem

Here’s where it gets impossible:

Launch Day: Protocol is centralized (one sequencer, one prover, foundation controls everything)

  • Governance token = definitely a security

12 Months Later: Protocol has 50+ sequencers, decentralized provers, DAO controls treasury

  • Governance token = maybe not a security?

At what exact moment did the token transition from security to non-security?

The SEC interpretation mentions that tokens can “cease to be subject to” an investment contract—but it doesn’t say when or how that happens.

Do we need:

  • A formal legal opinion?
  • An SEC no-action letter?
  • A certain percentage of decentralized governance participation?
  • A time threshold (12 months? 24 months?)?

Without clear criteria, every L2 governance token exists in legal limbo.

The Uniswap Precedent

UNI is the clearest example. Uniswap is:

  • One of the most decentralized protocols in DeFi
  • Open source and forkable
  • DAO controls treasury and protocol upgrades
  • No single company operates the infrastructure

If UNI is a security, then every governance token is a security.
If UNI isn’t a security, we need to know what criteria made it safe.

My Proposal: Decentralization Score Threshold

The SEC should create a decentralization score framework:

Score 0-2 (Centralized): Governance token = security

  • Foundation controls upgrades
  • Single sequencer/operator
  • Admin keys exist

Score 3-4 (Progressive Decentralization): Governance token = conditional safe harbor

  • Must file notice with SEC
  • 24-month transition plan to full decentralization
  • Public disclosure of centralization risks

Score 5+ (Sufficiently Decentralized): Governance token = digital tool

  • DAO controls all upgrades
  • No admin keys
  • Distributed infrastructure (20+ independent operators)
  • Open source and forkable

With objective criteria, protocols can self-assess and work toward decentralization targets. Without it, we’re all guessing.

The Cost of Uncertainty

Every day we don’t have governance token clarity, projects either:

  1. Launch without governance (stay centralized forever)
  2. Launch with governance and risk SEC enforcement
  3. Move to jurisdictions with clearer rules

Ethereum’s Layer 2 scaling roadmap depends on rollups achieving decentralization. But you can’t decentralize without governance. And we can’t build governance without legal clarity.

Rachel, genuine question: Has the SEC given any informal guidance on what “sufficiently decentralized” means? Or are we really supposed to just guess and hope we get it right?

Because if proving decentralization requires a court case and years of litigation, we’ve just made decentralization legally impossible.

As someone building a yield optimization protocol, I’m most worried about yield-bearing assets getting caught in regulatory limbo.

Our entire business model depends on clarity around tokens that generate returns. And right now, we have none.

The Yield-Bearing Stablecoin Problem

Here’s the scenario: USDC is clearly a “stablecoin” under the new taxonomy (category 4). It’s pegged to $1, fully reserved, and doesn’t pay yield.

But what about:

sUSDe (Ethena’s yield-bearing stablecoin)

  • Pegged to $1 :white_check_mark:
  • Backed by delta-neutral positions (ETH + short perps) :white_check_mark:
  • Pays ~4% yield from perpetual funding rates :red_question_mark:

Is sUSDe still a “stablecoin” because it maintains $1 peg?
Or is it a “security” because it pays yield to holders?

If yield = security, then every stablecoin that pays interest becomes a regulated financial product.

That would include:

  • Maker’s sUSDS (yields from treasury T-bills)
  • Angle’s USDA (yields from RWA investments)
  • Mountain Protocol’s USDM (yields from U.S. treasuries)
  • Any stablecoin that shares revenue with holders

The entire $50B+ yield-bearing stablecoin sector is undefined.

The LP Token Classification Nightmare

When users provide liquidity to Uniswap, Curve, or Balancer, they receive LP tokens representing their position. Those tokens:

  • Accrue trading fees continuously
  • Can be traded or used as collateral
  • Represent ownership in a revenue-generating pool

Are LP tokens:

  • Digital tools (utility = redeem liquidity)?
  • Securities (passive income from others’ trading)?
  • Something entirely new that needs its own category?

Our yield aggregator deposits user funds into 20+ liquidity pools. We receive LP tokens, stake them in gauge contracts, harvest rewards, and auto-compound yields.

If LP tokens are securities, our entire protocol is operating an unlicensed securities exchange. If they’re tools, we’re fine.

We literally don’t know which one it is.

Vault Shares and Auto-Compounding Strategies

Yearn Finance pioneered vault tokens: users deposit assets, the vault executes yield strategies, and users receive vault shares that auto-compound returns.

Vault shares are:

  • Tokens representing proportional ownership in a strategy
  • Continuously accruing value from yield farming
  • Tradeable and composable in other DeFi protocols

Is a Yearn vault share:

  • A digital tool (it’s programmable and compositional)?
  • A security (it’s literally an investment in an actively managed strategy)?

If vaults are securities, every yield aggregator becomes an unlicensed investment fund.

Liquid Staking: The $25B Question

The SEC interpretation clarifies that staking is not a security. That’s huge.

But what about liquid staking?

When I stake 32 ETH with Lido, I receive stETH that:

  • Represents my staked ETH (1:1 peg)
  • Accrues staking rewards automatically (~3-4% APY)
  • Can be traded, used as collateral, or transferred

The interpretation says staking ETH directly = not a security.
But does issuing a liquid staking derivative = creating a security?

If stETH is a security:

  • Lido would need to register as a securities issuer
  • Every DeFi protocol using stETH as collateral would need compliance
  • The entire liquid staking sector ($25B+ TVL) becomes legally questionable

The DeFi Primitive Problem

DeFi is built on composability: tokens stack on tokens. My protocol uses:

Layer 1: ETH (commodity) :white_check_mark:
Layer 2: stETH (liquid staking derivative) :red_question_mark:
Layer 3: wstETH wrapped into fixed-rate vaults :red_question_mark:
Layer 4: Vault shares used as collateral in lending markets :red_question_mark:
Layer 5: Debt positions tokenized as yield-bearing instruments :red_question_mark:

Every layer after ETH has zero regulatory clarity.

If any layer is a security, the entire stack becomes legally unstable.

What We Need: DeFi-Specific Subcategories

The five-category taxonomy is a start, but DeFi needs subcategories within “digital tools”:

Category 3a: Yield Instruments

  • Yield-bearing stablecoins (sUSDe, sUSDS)
  • Liquid staking derivatives (stETH, rETH, cbETH)
  • Auto-compounding vault shares (Yearn, Convex)

Category 3b: Liquidity Tokens

  • LP tokens from AMMs (Uniswap, Curve, Balancer)
  • Gauge tokens and boosted positions
  • Single-sided liquidity receipts

Category 3c: Governance Tokens

  • DAO voting tokens (UNI, AAVE, CRV, MKR)
  • Conditional on “sufficient decentralization” threshold

Category 3d: Synthetic and Wrapped Assets

  • Wrapped tokens (wBTC, wETH)
  • Bridged assets (cross-chain representations)
  • Synthetic assets tracking external prices

Right now, all of these are just “tools” with case-by-case analysis. That’s not good enough.

The Urgency

We can’t wait 15 years for clarity on DeFi primitives.

Builders are making decisions today about:

  • Whether to launch yield-bearing products
  • Whether to integrate liquid staking as collateral
  • Whether to build in the U.S. or move offshore

If the SEC doesn’t provide urgent guidance on yield instruments, LP tokens, and vault shares, the innovation moves to Europe (MiCA has clearer DeFi frameworks) or Asia.

The 16-asset commodity list is progress. But DeFi needs the next chapter now, not in 2041.

Can we get an expedited review process for the top 100 DeFi primitives? Because without it, we’re building blind.