On July 22, SEC Commissioner Hester Peirce published a statement on crypto vaults and lending strategies. The industry read it as a compliance question: are vaults securities? The test Peirce applies is Howey: a vault may be a common enterprise in which users invest money expecting profits from the deployer's and curator's managerial efforts.
Strip the legal language, and you get something simpler: your money, someone else’s decisions. This sentence describes where every fee in DeFi lives.
In a curated vault, the curator sets the allocation, chooses the asset exposure, tunes the parameters, and earns a performance fee on capital that depositors funded.
In Aave V4's Hub-and-Spoke architecture, all liquidity on a network sits in shared Hubs. Supplying and borrowing happen through Spokes, each one with its own risk parameters, asset listings, and fee schedule. The Spokes expose capital from the shared Hubs. So, whoever configures a Spoke is pricing risk on the liquidity the whole system funded.
In restaking, the operator earns yield on collateral that stakers posted and stakers get slashed on.
Run the test yourself on any architecture you already use. Trace where the fee goes, and where the loss goes. You’ll find the pattern: the fee gets captured wherever risk is priced but not borne.
This is not an accusation
Before anyone reaches for the comment section: the separation of risk-pricing from risk-bearing isn't a scam. It's specialization. Pricing risk is a skill. Bearing risk is a balance sheet. Unbundling the two gave us fund management, insurance underwriting versus reinsurance, and originate-to-distribute lending.
A depositor with idle stablecoins can't evaluate collateral quality across forty lending markets. A curator can. The fee is the price of renting that skill. Renting it is why passive capital can access sophisticated strategies at all. Kill the gap, and you kill the product.
So, the gap itself is legitimate. The gap is where the incentive problem lives, which makes it the first thing to inspect in any architecture. However, the current mechanisms for disciplining it are weaker than they look.
The discipline problem
Traditional finance patches this gap with hard mechanisms: regulation, capital requirements, clawbacks, and mandated retention. The 5% risk-retention rule that came out of Dodd-Frank is the direct precedent.
DeFi's current solution is reputation. Curators bear their name and their future fee flow. If a curator blows up a vault, the argument goes, no one deposits into their next one. The constraint is real, and it does bind some actors some of the time. But reputation is a soft constraint against a hard loss. It fails in two specific ways.
First, it only binds actors who expect to be around next cycle. The depositor's loss is instant, certain, and denominated in their own capital. The curator's penalty is delayed, probabilistic, and (in a market with short memory and pseudonymous re-entry) frequently avoidable. Reputation prices the expected cost of failure to the decision-maker. It does nothing about the realized cost to the capital.
Second, reputational discipline scales with scrutiny, and scrutiny evaporates exactly when yields are high. The constraint is weakest in the periods it's needed most.
We've run this experiment before, at civilizational scale. In the run-up to 2008, mortgage originators priced the risk, MBS holders bore it, and reputation constrained approximately nobody once the music sped up. Everyone in the chain was compensated on the volume of decisions made, not on the outcomes of capital deployed.
The fee accrued at the pricing layer. The loss landed on the bearing layer. The gap between them was the crisis. DeFi didn't invent this failure mode. It inherited it, removed the regulator, and added composability.
And the regulator has noticed. Notice who’s speaking: Peirce is the most crypto-friendly voice the Commission has, and this statement is her warning the industry politely, before a less friendly colleague does it with enforcement actions instead of invitations. Her point is that moving an activity onchain doesn't move it outside the securities laws. Take that as a fact about the environment, not a verdict on how things should be.
Regulation is the clumsy version of the fix: Howey can't tell a curator from a rent extractor. Both are "managerial efforts," both register, and the immutable-code end of the spectrum gets caught in the same net.
The gap is real, but the registration regime is a blunt instrument for closing it. Architecture can do it with precision.
The architectures closing the gap
The good news is that the better designs are already converging on mechanisms that re-couple pricing and bearing, each one fixing a different failure mode.
Timelocks give depositors an exit window before a parameter change binds their capital, but they assume depositors are watching, which most aren't.
Guardian vetoes and depositor governance move final authority over risk parameters to the people funding the risk. Steakhouse runs the clean implementation, a DAO of depositors acting as the guardian. The curator proposes, the capital disposes. This fixes the authority mismatch, but brings latency and voter apathy.
Exposure caps and credit lines bound the blast radius instead of the incentives. Aave V4's Hub grants each Spoke a credit line it can throttle, freeze, or cut, so shared liquidity doesn't have to mean shared risk. The worst pricing decision in the system now reaches only as far as its cap. A cap sized wrong, though, doesn't bound the gap. It joins it.
Curator co-investment and first-loss tranches are the hard version. The fee-taker holds a junior position that gets impaired before depositor capital. DeFi is rediscovering risk retention here, a decade and a half after Congress mandated it for securitizers. It's the only deployable mechanism on this list that changes what pricing risk feels like rather than what it's allowed to do. The objection is capital gating. Require 5% of a $50 million vault up front, and only whales and institutions can curate. Underwriting and fee escrow address this without softening the mechanism.
Finally, slashing that reaches the decision-maker, the penalties that land on whoever set the parameters, not an operator's stake posted as theater, is the theoretical limit. It requires an onchain mechanism that can tell a negligent parameter choice from an unforeseeable market event, which no current oracle can do. Treat any protocol claiming to have solved it with suspicion proportional to the claim.
Reading the gap
A party that prices risk without funding it is a party whose incentives you're trusting rather than verifying. And the entire premise of this industry was supposed to be the other way around.
So, here's the practical part. Before you deposit into anything, run these three questions.
- Who sets the risk parameters? Not who deployed the contract, but who has ongoing discretion over what your capital is exposed to.
- Whose capital absorbs the downside? Follow the loss waterfall to its end. That address is the risk-bearer.
- Is the address collecting the fee also holding a loss-absorbing position? "Invested in the ecosystem" doesn't count. "Aligned long-term" doesn't count. A position that gets affected before or alongside yours counts.
Conveniently, a securities regulator has already written the checklist. Peirce enumerates the managerial activities that may implicate securities laws in lending strategies: setting interest rates, deciding which assets to accommodate, setting loan-to-value limits, and establishing liquidation thresholds. Read it as an inventory of risk-pricing decisions rather than a compliance list. Every item is a parameter someone chooses on behalf of capital they didn't post. When you run question one, this is what you're looking for.
Question two has an aspect people skip: the loss waterfall includes exploits. A curator can set flawless parameters, and the capital still dies to a low-level vulnerability in a protocol they chose. Execution risk obeys the same law as allocation risk. Someone selected the contracts and integrations, someone else funded them, and the fee-taker's exposure to an exploit is usually zero. One more thing the yield is silently paying you for.
If the answer to the third question is no, what you've found is a price, not necessarily a red flag. The yield you're earning includes compensation for an unmonitored agency gap. You sold an option on the decision-maker's judgment, whether or not you knew you were writing it.
Peirce also gives us the axis to measure against. Her statement describes vaults as ranging from programmatic allocations determined solely by immutable smart contracts, at one end, to allocations at the sole discretion of a person or group, at the other. That spectrum is exactly the variable that matters: how much risk-pricing discretion sits outside the capital.
At the immutable end, there's no gap. The code prices risk once, at deployment. Everyone can read it, and nobody collects an ongoing discretion premium. Move toward sole discretion, and the gap widens, the fee grows, and, per Peirce, the securities laws loom larger. Regulatory exposure and fee capture grow along the same axis because they're measuring the same thing.
So, here’s the bet: architectures that force the fee-taker into a loss-absorbing position will outcompete those that don't. Once depositors learn to run the three questions, verifiable skin-in-the-game becomes the only credible signal left.
A second effect rides along. The further an architecture pushes toward Peirce's programmatic end, the weaker the "profits from the efforts of others" story gets. Skin-in-the-game doesn't move that needle. Co-investment never made a fund not a security, but it fixes the incentive problem the test can't see. Two moves, two problems smaller, and only one of them needed Washington's opinion.
The gap is only readable if it's observable
None of this works in the dark. The three questions assume you can actually see the risk topology: who can change which parameters, what the current allocation is, where the loss waterfall runs, whether the curator's co-investment is still there or was quietly withdrawn last Tuesday.
Today that information is technically public, but practically invisible, scattered across contract storage, governance forums, and a Dune dashboard someone maintains as a hobby.
Reading the gap requires expertise. It becomes a market norm only when the parameter changes, position composition, and tranche structure of these systems are continuously legible to the people funding them. This is the same operational visibility any institution would demand before running a system this consequential.
The architectures that win the trust argument will be the ones that make their gap inspectable in real time, because "trust me" is precisely the claim this entire industry was built to retire.
Follow the fee
Peirce closed her statement with an invitation to come talk to the SEC. That conversation will happen at the industry's pace and Washington's discretion. Her test is more useful than her invitation, precisely because you can run it without her.
A market of depositors asking the three questions is faster, more granular, and more honest than any registration regime, and it doesn't require anyone at the Commission to agree with this article.
Follow the fee. Where it accrues without a matching loss position, you've found the gap. And the gap is always one of three things: priced into your yield, disciplined by the architecture, or yours.