SEC Says Most Crypto Assets Aren’t Securities—But Token Sales Still Can Be

The SEC’s March 17, 2026 interpretation remains the agency’s current framework for applying federal securities law to crypto assets. Its central conclusion is narrower than the celebratory shorthand suggests: most crypto assets are not securities in themselves, but an offer, sale or continuing arrangement involving the same asset may still constitute an investment contract.
That distinction is the practical consequence for investors, issuers and trading platforms. The SEC’s March 17 announcement says the CFTC joined the interpretation and identifies five categories, while expressly covering the circumstances in which a non-security token can become subject to—and later separate from—an investment contract.
What the SEC actually classified
The framework divides crypto assets into digital commodities, digital collectibles, digital tools, stablecoins and digital securities. This is a five-part taxonomy, not a declaration that every token outside the digital-security category is automatically beyond securities regulation.
Digital commodities derive value principally from the operation and use of a functional crypto system and from supply and demand, rather than from an expectation of profit based on a promoter’s essential managerial work. The SEC’s examples include Bitcoin, Ether, Solana and XRP, but classification still depends on an asset’s characteristics rather than its ticker alone.
Digital collectibles are designed for collection or use and may represent artwork, music, game items or similar material. Digital tools perform a practical function such as serving as a ticket, membership, credential or identity badge. Fractionalizing a collectible or attaching an ownership interest can change the analysis, just as promoting a nominally functional token through profit-oriented promises can make the surrounding transaction legally significant.
The agency’s current crypto classification page also preserves an important stablecoin qualification: a payment stablecoin covered by the GENIUS Act is generally not a security, but other stablecoins may be securities depending on their features. A digital security, meanwhile, is a financial instrument that already meets the statutory definition of a security and is represented or recorded as a crypto asset.
The token and its sale are separate legal questions
The framework’s most consequential idea is that an asset and the contract through which it is distributed are not necessarily the same legal object. A token may lack the economic characteristics of a security while being sold alongside enforceable or promotional commitments that create an investment contract under the Howey analysis.
For an issuer, the label attached to the token is therefore less important than what purchasers are promised. Relevant questions include whether buyers contribute value to an enterprise, whether they are led to expect profits, and whether those profits depend on essential managerial efforts by the issuer or another identifiable group. Marketing, development road maps and representations about future functionality can all shape that assessment.
This also means a project cannot safely infer that an initial sale is exempt merely because the delivered asset is described as a commodity, collectible or utility token. If the offering is an investment contract, it must be registered or qualify for an exemption. A later separation of the token from that contract does not retroactively erase registration failures, misleading statements or potential anti-fraud liability arising while the contract existed.
An investment contract can end, but not automatically
The interpretation recognizes that a non-security crypto asset does not have to remain tied to an investment contract forever. Separation may occur when purchasers can no longer reasonably expect the issuer’s essential promises or managerial efforts to remain connected to the asset.
One route is fulfillment: the issuer completes the work it represented that it would perform, such as delivering specified functionality or reaching disclosed development milestones. Another is a clear failure or abandonment that leaves purchasers with no reasonable basis to expect the promised work. Neither situation creates an automatic, universal “decentralization switch”; the analysis turns on the issuer’s actual representations and what purchasers can still reasonably expect.
The framework consequently places unusual weight on a project’s own public record. Vague promises can make it harder to establish when obligations have ended, while a clearly defined development commitment creates a more identifiable point for assessing fulfillment. Public disclosure matters, but a declaration that work is complete does not control the outcome if the economic reality shows that essential managerial efforts continue.
Mining, staking and airdrops are not blanket safe harbors
The interpretation addresses protocol mining, protocol staking, certain staking-receipt tokens, wrapping and airdrops. Its treatment depends on the structure described in the guidance: protocol rewards generated through network participation are different from an operator promising returns through discretionary management, and a redeemable wrapped token representing a non-security asset is different from a receipt for a digital security.
The same caution applies to airdrops. Distributing a non-security asset without payment does not by itself make the asset a security, but the surrounding arrangement must still be tested for an investment contract. A project should not convert a fact-specific discussion into the broader claim that every staking service, wrapped asset or token giveaway lies outside SEC jurisdiction.
For users, the practical question is not simply whether an activity is called staking or mining. It is who controls the assets, who performs the work, what return is promised, whether managerial discretion affects that return and whether the underlying token is already tied to an investment contract.
Why the new line is clearer but not permanent law
The interpretation materially clarifies how the current SEC and CFTC leadership intend to administer existing statutes. It does not eliminate court review, replace the Howey test or enact a comprehensive congressional market-structure regime.
That limitation matters because an agency interpretation is not the same instrument as a statute or a final legislative rule. PwC’s analysis of the framework notes that it reflects the agencies’ current views, does not carry the force of a final rule and can be changed by future leadership; courts retain authority to decide whether particular arrangements fall under federal or state securities law.
The durable takeaway is therefore more precise than “crypto is no longer regulated.” The SEC has drawn a sharper boundary around the asset itself, but securities law can still govern the way that asset is financed, promoted, sold or bundled with continuing promises. Investors gain a clearer vocabulary; issuers gain a more structured analysis, not immunity from it.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.