Home » Regulatory » The DeFi Regulatory Trap

The DeFi Regulatory Trap


In June 2022, Celsius Network halted withdrawals. By July, it had filed for bankruptcy. The proximate cause was bad risk management and over-leveraged positions. But the regulatory cause was something that had been visible years earlier: Celsius was offering unregistered securities to retail investors, and the structure that created that exposure was hiding in plain sight the entire time.

Celsius was not alone. BlockFi settled with the SEC for $100 million in February 2022 before filing for bankruptcy that December. Genesis filed for bankruptcy in January 2023. Nexo exited the US market. Coinbase’s planned Lend product was shut down before it ever launched after the SEC signaled it would take action. Gemini Earn wound down following the Genesis collapse. All of them were doing variations of the same thing: pooling client assets and offering a return on those pooled assets, and every one of them believed — at least publicly — that their structure was defensible until a regulator or a bankruptcy court concluded otherwise.

Key Takeaways

  • Pooling client assets and paying a return on the pool creates a common enterprise — the second prong of the Howey Test — which triggers securities classification.
  • Celsius, BlockFi, Genesis, Nexo, Coinbase Lend, and Gemini Earn all failed or faced enforcement within roughly a two-year window, doing structural variations of the same thing.
  • The DeFi protocols still standing — Aave, Compound, MakerDAO — use the same pool-based structure; the risk hasn’t gone away, it just hasn’t been enforced in the decentralized context yet.
  • SmartCredit.io’s peer-to-peer model matches each lender’s capital directly to a specific borrower — no pooling, no common enterprise, no securities classification.
  • The same matching structure that avoids securities risk is also what lets SmartCredit offer fixed-rate, fixed-term loans to borrowers.

The Howey Test and Why It Matters for DeFi

The US securities framework uses the Howey Test — established by the Supreme Court in 1946 — to determine whether a financial product qualifies as a security. The test has four prongs. A product is a security if it involves:

  1. An investment of money
  2. In a common enterprise
  3. With an expectation of profits
  4. Derived from the efforts of others

Most DeFi lending products satisfy three of the four prongs without any argument. Users invest money (prong 1), they expect returns (prong 3), and those returns are generated by the protocol’s matching algorithms and management — the efforts of others (prong 4).

The critical question is prong 2: is there a common enterprise?

For pool-based protocols, the answer is yes. When a lender deposits into an Aave pool, their funds are commingled with every other lender’s funds. The interest they receive depends not on the specific loans their individual deposit funded, but on the collective utilization of the entire pool. This is a common enterprise — the returns of any individual lender are tied to the fortunes of all lenders in the pool. Under the Howey Test, that makes the product a security, and it makes no difference whether the pooling happens through a bank-like custodial account or a permissionless smart contract.

Two Business Models, Two Regulatory Outcomes

There are two distinct structures in DeFi lending, and their regulatory treatment differs fundamentally.

Peer-to-pool-to-peer (P2P2P): The dominant model. Lenders deposit into a shared pool. Borrowers draw from the pool. Returns are derived from aggregate pool performance. Aave, Compound, and MakerDAO all use this model. Celsius, BlockFi, and Gemini Earn used custodial versions of the same structure.

Peer-to-peer (P2P): The direct match model. Each lender’s capital is matched to a specific borrower’s credit line. There is no pool, no commingling, and no common enterprise. Each lender-borrower relationship is independent. SmartCredit.io uses this model.

The regulatory consequence of the difference is significant:

Peer-to-Pool-to-Peer Peer-to-Peer
Assets pooled Yes No
Common enterprise (Howey Test) Yes No
Securities classification Yes No
SEC registration required Yes No
Investment company registration Yes No
Enforcement risk High — established precedent Low — structurally outside securities scope

The P2P2P model requires two regulatory licenses: a license to offer a security product, and a license to operate as an investment company. Securities compliance — an offering prospectus, independent audits, quarterly reporting, ongoing disclosure — is expensive, time-consuming, and operationally demanding. None of the major DeFi protocols that use pooling have these licenses. For decentralized protocols, obtaining them is practically impossible: securities registration requires an identifiable legal entity to stand behind the product, and many protocols were designed specifically to avoid having one in the first place.

Your Capital, Matched — Not Pooled

On SmartCredit, your deposit is matched directly to a specific borrower’s credit line. No common enterprise, no securities exposure.

See How P2P Lending Works →

The Enforcement Record

The regulatory risk of pooling is no longer theoretical. The enforcement record makes the exposure concrete.

Celsius Network pooled client assets and offered yield. It filed for Chapter 11 bankruptcy in July 2022, a month after freezing withdrawals, owing billions to depositors. Its bankruptcy estate revealed that the firm had been operating as an unlicensed securities issuer, among other violations.

BlockFi offered a yield-bearing account funded by pooling client deposits and lending them out. The SEC charged BlockFi with failing to register its retail crypto lending product as a security. BlockFi settled for $100 million and committed to restructure. It filed for bankruptcy ten months later.

Genesis Global Capital pooled institutional lender capital and deployed it in lending and trading activities. It filed for bankruptcy in January 2023. Its parent company, Digital Currency Group, faced regulatory scrutiny across multiple jurisdictions.

Nexo offered a high-yield crypto savings product to retail investors. Facing SEC enforcement risk, it announced it would exit the US market in December 2022 — paying $45 million to settle with US regulators as part of the process.

Coinbase Lend was announced in 2021 as a product that would pay users interest on USDC deposits. The SEC sent Coinbase a Wells Notice — a formal warning that enforcement action would follow — before the product launched. Coinbase cancelled it.

Gemini Earn routed user deposits through Genesis Global Capital. After Genesis’s collapse, Earn users were unable to withdraw approximately $900 million in assets.

The pattern is consistent: pooling client assets and offering a return on those assets triggers securities classification, and regulators have demonstrated repeatedly that they will act.

A Worked Example: What $25,000 in a Pool Actually Exposes You To

Consider a depositor with $25,000 earning yield on a pooled platform. That $25,000 is not a separate, ring-fenced position — it is one claim among thousands inside a common enterprise. When Gemini Earn’s underlying pool collapsed alongside Genesis, roughly $900 million in aggregate deposits was frozen — not because any specific loan behind any specific depositor’s funds had failed, but because the entire pool’s fortunes were tied together by design. A depositor’s $25,000 became inseparable from the fate of the other 899,975,000 dollars in the same enterprise.

Compare that to a $25,000 position matched individually to one specific borrower’s credit line. A systemic event affecting other, unrelated borrowers on the same platform has no direct claim on that specific matched position — there is no shared pool for a court, a liquidator, or a bankruptcy proceeding to freeze in a single action. The risk that remains is the risk of that one counterparty, not the risk of every participant in the enterprise at once. That difference — one claim among a common pool of fortunes, versus one independent, individually matched claim — is the entire regulatory and practical distinction this article is about.

MiCA and the Global Regulatory Shift

The regulatory exposure is not confined to the United States. The EU’s Markets in Crypto-Assets (MiCA) regulation became fully applicable in December 2024. MiCA brings crypto-asset service providers operating in the EU under authorization and conduct obligations — including KYC, AML procedures, and transaction monitoring.

It’s worth being precise about scope here: MiCA’s text currently carves out services provided in a “fully decentralized manner without intermediaries” from its core requirements, while directing the European Commission to keep assessing whether and how DeFi specifically should be brought into scope over time. In practice, this carve-out is narrow and shrinking — any platform with an identifiable operating entity, a pooled structure it manages, or discretionary control over user funds sits well outside the “fully decentralized” exemption regardless of how it markets itself. Platforms pooling assets and offering yield to EU retail investors, even ones built on public blockchains, face exactly this kind of scrutiny under MiCA.

The Financial Action Task Force (FATF) has similarly continued updating its guidance to address how its recommendations apply to DeFi arrangements, with its most recent targeted updates specifically tracking which platforms exercise sufficient control or influence over a protocol to be treated as a Virtual Asset Service Provider (VASP) — the same category that applies to banks and payment processors in FATF member jurisdictions.

The direction of travel is consistent even where the exact perimeter is still being drawn: regulators globally are increasingly applying traditional-finance-style frameworks to DeFi lending platforms, particularly when those platforms pool assets and offer yield to retail investors.

Why Peer-to-Peer Is Structurally Outside This Perimeter

SmartCredit.io’s peer-to-peer model was designed from the outset to operate outside the regulatory perimeter that catches pool-based platforms.

In the SmartCredit.io model, each lender creates a Personal Fixed Income Fund — an individual lending strategy — that is matched directly to specific borrowers’ credit lines. The lender’s capital is not commingled with any other lender’s capital. There is no shared pool. Returns depend on the specific loans the individual lender funded, not on the collective performance of a pool.

This directly avoids the common enterprise prong of the Howey Test. Without a common enterprise, there is no security. Without a security, there is no requirement for securities registration or investment company licensing. The consequence is structural regulatory safety — not as a compliance workaround bolted on after the fact, but as an inherent property of how the matching model itself works.

SmartCredit.io still operates within the VASP framework where applicable. The platform has implemented KYC procedures, runs AI-based continuous transaction monitoring in partnership with ChainAware.ai, and operates in compliance with MiCA 2024 and the FATF Travel Rule. Compliance with VASP obligations and freedom from securities registration requirements are compatible positions, not contradictory ones — the former applies to operating a service involving digital assets; the latter depends on whether the product structure creates a security.

The Same Structure Works for Borrowers Too

Direct matching isn’t just a regulatory answer — it’s what lets SmartCredit offer fixed rates and fixed terms agreed at origination, not variable pool-based pricing.

See Fixed-Rate Borrowing →

What This Means for Users and Builders

For lenders, the regulatory structure of the platform they use matters more than most people appreciate. A platform operating as an unregistered securities issuer faces existential regulatory risk. If enforcement comes, the platform may be forced to shut down, freeze assets, or exit markets without warning — often with little advance notice to the depositors who trusted it. The enforcement record shows that this is not a hypothetical: it happened to Celsius, BlockFi, Genesis, Nexo, Coinbase Lend, and Gemini Earn within a two-year period.

SmartCredit.io’s peer-to-peer structure eliminates this specific category of risk. The platform is not a securities issuer, and it was not designed to be one. There is no regulatory overhang waiting to be resolved.

For developers and protocol builders, the same principle applies. Building a pooling-based yield product and distributing it to retail users creates securities exposure that is increasingly difficult to contain through jurisdictional arbitrage or decentralization arguments. Regulators have shown they will look through protocol design to the economic substance — and the economic substance of pooled yield is a security.

Decentralization Is Not a Legal Shield

A common assumption is that sufficiently decentralized protocols escape enforcement because there’s no company to sue. The CFTC’s 2022 action against Ooki DAO tested this assumption directly, and it did not hold. The CFTC charged Ooki DAO — a decentralized autonomous organization governed by token-holder votes rather than a traditional corporate structure — as an “unincorporated association,” and pursued individual token holders who participated in governance as personally liable for the DAO’s violations. The court granted a default judgment against the DAO in 2023.

The legal theory the CFTC used — that voting governance tokens makes a holder an active participant in an unincorporated association, exposing them to the same liability as a partner in an ordinary business — did not depend on the protocol having a headquarters, a CEO, or a registered company. It depended only on demonstrating that a group of people collectively controlled and profited from the enterprise. That is a considerably lower bar than many DeFi participants assume protects them, and it applies with equal force to pool-based lending protocols governed by token votes.

No Governance Token, No Pool, No Common Enterprise

SmartCredit’s structure was built to sit outside this entire category of exposure — not to test its edges.

Explore Peer-to-Peer Lending →

Getting Started

Understanding a platform’s regulatory structure before depositing capital is not a niche concern — it’s a basic risk assessment step, the same as checking a bank’s deposit insurance status or a broker’s registration before opening an account. SmartCredit.io’s peer-to-peer business model is documented in detail for exactly this reason — so lenders and borrowers can verify the structure themselves rather than take a platform’s marketing at its word.

If you’re currently lending on a pool-based platform, it’s worth asking directly: is my capital commingled with other lenders’ capital, and does my return depend on the pool’s aggregate performance rather than a specific counterparty? If the answer is yes, you are, in substance, holding a security — regardless of what the platform calls the product, what chain it runs on, or how many tokens are involved in its governance.

Frequently Asked Questions

What is the Howey Test?

The Howey Test is the legal standard the SEC and US courts use to determine whether a financial arrangement is a security. It asks whether there is an investment of money, in a common enterprise, with an expectation of profit, derived from the efforts of others. If all four elements are present, the product is a security subject to registration requirements under US law.

Why does pooling specifically create securities risk?

Pooling creates a “common enterprise” — the second prong of the Howey Test — because a lender’s return depends on the collective performance of everyone’s combined deposits rather than on a specific, individual transaction. Direct one-to-one matching, where a lender’s return depends only on their own specific borrower, does not create this common enterprise.

Does this mean Aave and Compound are illegal?

It means they use the same pooled structure that has already triggered enforcement action against centralized platforms like BlockFi and Celsius. Enforcement against decentralized protocols has been slower, partly because there’s no single identifiable legal entity to charge in the way there was with BlockFi or Celsius — but the underlying economic structure that regulators have targeted is present in both models.

Is SmartCredit.io regulated at all?

Yes — SmartCredit.io operates within the Virtual Asset Service Provider (VASP) framework where applicable, including KYC procedures, AI-based transaction monitoring, MiCA 2024 compliance, and adherence to the FATF Travel Rule. What it avoids is securities classification specifically, because its peer-to-peer structure doesn’t create the common enterprise that triggers that classification.

Does MiCA apply to fully decentralized DeFi protocols?

MiCA currently carves out services provided in a fully decentralized manner without intermediaries, with the European Commission tasked to keep assessing whether that scope should expand. In practice, this exemption is narrow — platforms with an identifiable operating entity or pooled structure they control generally fall outside it regardless of how decentralized their marketing claims to be.

What happened to the $900 million in Gemini Earn deposits?

Gemini Earn routed user deposits through Genesis Global Capital. When Genesis filed for bankruptcy in January 2023, approximately $900 million in Earn user assets became frozen as part of the bankruptcy proceedings, since those deposits were commingled within Genesis’s broader lending operations rather than held as separate, individually matched positions.

In practice: the fastest way to check whether your own DeFi yield product carries this risk is to ask whether your funds sit in a shared pool. If yes, consider a peer-to-peer alternative where your capital is matched individually rather than commingled.

Can a peer-to-peer platform still fail?

Yes — peer-to-peer matching eliminates the specific risk of securities classification and pool-wide contagion, but it doesn’t eliminate ordinary counterparty or credit risk on the individual matched loan. Those risks are managed through collateralization, trust scoring, and mechanisms dedicated to that purpose — such as a dedicated loss reserve — which is a separate question from the regulatory structure discussed here.

Why did BlockFi still go bankrupt after settling with the SEC?

The $100 million SEC settlement in February 2022 addressed the securities registration violation specifically. It didn’t resolve BlockFi’s broader balance sheet exposure, including significant exposure to the FTX/Alameda collapse later that year, which is what ultimately drove the December 2022 bankruptcy filing. The two are related but distinct causes.

What should I actually check before using a crypto lending platform?

Ask whether deposits are pooled or individually matched, whether the platform has registered as a securities issuer or investment company (and if not, why it believes it doesn’t need to), and what jurisdiction’s VASP or AML framework it operates under. SmartCredit.io publishes documentation on how its fixed-term, fixed-rate matching model works specifically so this due diligence is possible.

Lend Without the Regulatory Overhang

Peer-to-peer matching means your capital is never commingled — no common enterprise, no securities exposure, no platform-wide freeze risk.

Start Lending on SmartCredit →

Further Reading