Veda Has an Idea
Can vaults be Qualified Custodians?

Brogan Law provides top-quality legal services to individuals and entities with questions related to cryptocurrency. Cryptocurrency law is still new, and our clients recognize the value of a nimble and energetic law firm that shares their startup mentality. To help our clients maintain a strong strategic posture, this newsletter discusses topics in law that are relevant to the cryptocurrency industry. While this letter touches on legal issues, nothing here is legal advice. For any inquiries email info@broganlaw.xyz
I’m going to be at the HLS Blockchain & Fintech Initiative Conference next week, April 17th. Would love to chat with anyone else who will be around Boston that day. Reach out at aaron@broganlaw.xyz to find a time to talk or book a time here directly.
Investment Advisers
It’s annoying to be an RIA. Really a big pain. You’re just humming along, managing $149,999,999 as an exempt reporting adviser (ERA), and all of a sudden a fresh $2 comes in and you have to file a Form ADV.1 The next thing you know, the SEC is all up in your business, telling you what kind of compliance program to have, what books and records to keep, and, important for today, how you can custody those assets.
In the ideal world, operating a cryptocurrency vault is sort of like the opposite of being an RIA. You set up a smart contract on-chain that holds some assets and facilitates deposits, redemptions, and curation, and then you take it to your lawyers who take the view that you don’t fall within any regulatory regime. The vault can contain virtually unbounded assets and, in the ideal world, nobody who touches it has to register anywhere.
That’s decentralization, baby.
Or so the argument goes, at least.
As institutional capital and cryptocurrency markets meet, there is an increased need for regulatory imprimatur at points of contact. See, for the past hundred years or so, issuing securities and managing assets has been subject to prescriptive government oversight. We often discuss these regimes here in many contexts, as the rules governing the securities laws are a genuine maze.
Within the world of vaults, the Investment Advisers Act of 1940, and the SEC rules related therein, have become particularly important of late. Basically, a vault is a fund designed to sit outside of regulatory regimes through automaticity. To simplify, if you think of your vault as a box, depositors put in assets and receive a receipt token in return. That receipt token represents a share of the assets in the vault, and can be exchanged for the deposited asset, plus some yield, according to the terms of the vault. A third party, sometimes called a curator, “manages risk” by deploying the assets in the vault into some agreed strategy.
If the box was an LLC in Delaware, and it deployed into securities, it would be a fund covered by the Investment Company Act of 1940. If it deployed into commodity derivatives it would be a commodity pool regulated by the Commodity Exchange Act. The shares in the box would be securities. The curator would, unless exempt, be required to register as a registered investment adviser (“RIA”).
When the box is a smart contract, maybe these regimes don’t apply? I don’t know, only a judge can say for sure. But a lot of players in the space, including Coinbase, have gotten comfortable with the arguments, and vaults are popping up everywhere.
In fact, they’ve gotten so popular that some money in the old LLC-based system might be interested in nosing around them. This interface is the challenge we’re discussing today.
The Paper
Veda Tech Labs Inc. (“Veda”) is a developer of vault infrastructure. While I can’t speak for them or their products, my understanding is that this generally means that they put together the smart contracts that allow vaults to operate so that other third parties can deploy them.
In our experience, there are lots of firms that want access to this kind of product. Money wants to find yield and DeFi promises it, but if you are, say, managing the endowment of the Ford Foundation, you can’t possibly justify the risk of deploying directly into a DeFi strategy. Even if you did want that kind of smoke, you would have to hire someone with expertise to do it. Vaults provide the cover of a third party risk manager handling exposure.

But this institutional money in LLC world is generally managed by RIAs, and RIAs have rules. Specifically, 17 CFR § 275.206(4)-2(A) says that investment advisers are required to maintain client funds in segregated accounts with Qualified Custodians.2
This is actually a pretty big deal in the cryptocurrency economy. Qualified Custodians don’t grow on trees and it is far from certain that one will natively support novel cryptocurrency tokens. Most venture capital firms are RIAs, and buying access to new projects cryptocurrency tokens is a big part of what crypto VCs do. This is why, in most form token warrants that VCs ask startups to staple to the SAFEs they raise money with, the startup will covenant to something like the following:
Prior to any delivery of any Network Tokens, the Company shall exercise reasonable best efforts to, at the Holder’s option, (a) partner with a third-party custodian that is a “Qualified Custodian” under Securities and Exchange Commission rules so that such custodian will accept and support such Network Tokens with secure wallet and storage services promptly following such distribution; and/or (b) implement or impose programmatic transfer restrictions on such Tokens via technology that permits substantially similar restrictions and control of assets and that is not controlled by the Company or any Token Affiliate; provided, however, that the Holder shall always retain the right to self-custody of any Tokens acquired by the Holder hereunder.
This is fine, as far as it goes, but there is some take rate at any intermediated service, and it’s not very crypto after all to require a quasi-bank to hold tokens. And as vaults grow in importance, uncertainty about whether funds can deploy into them is a drag on the emerging medium. This is probably why Veda has a new proposal that it released a couple weeks ago on March 23, 2026.
The letter is titled “Recommendations Regarding Recognition of Vaults as Satisfying SEC Qualified Custody and CFTC Segregation Requirements for Digital Assets” and addressed to the SEC Division of Investment Management, the Crypto Task Force, the CFTC Division of Market Participants, and the Joint SEC-CFTC Harmonization Initiative.
Veda is arguing (along with their counsel Brian Forman and Jason Gottlieb at Morrison Cohen) that vaults should be qualified custodians. And it’s a pretty elegant point, I think.
What the Vault Hath Wrought
Veda argues that the Qualified Custodian rule is intended to implement certain principles, primarily (i) misappropriation of client funds, (ii) commingling of assets, and (iii) exposure of client property to adviser insolvency. Each of these, in their view, could be addressed equally well through vaults. Their point is that, with crypto, it is possible to programmatically protect against misappropriation directly. “Unlike traditional securities and commodities, digital assets are controlled through cryptographic signing authority, recorded on distributed ledgers, and can be governed by deterministic smart contract logic.”
This may be true. Much of what a custodian does could be done with a smart contract. The security of this endeavor would depend on the security of the smart contract, but it is not necessarily the case that managing custody through a programmable vault is per se riskier than doing so through a custodial system. One can imagine a vault structured in such a way as to prioritize client safety.
Such a system might have advantages over a custodial interface, not least that it might be less expensive, burdensome, and faster, which could redound to benefits for the client in the long term.
Veda points out that a vault could keep assets bankruptcy remote as well as a custodian, which may be true, though, ultimately, a vault is not a bankruptcy remote vehicle. It is entirely plausible that a bankruptcy court could order its assets frozen, especially where they are commingled, and a major depositor is insolvent. But Veda’s point is good that “[f]rom a functional perspective, vault custody more closely resembles a separately managed account than a pooled balance-sheet vehicle: assets remain attributable to the client and redeemable directly through the vault contract rather than through an intermediary’s discretionary release process.” And clients should be sufficiently sophisticated to evaluate these risks without a prohibition.
The firm also makes several points about the potential benefits of these systems for custody. They advance the theory that “RIAs may encounter assets to which clients are contractually entitled but for which no qualified custodian is technologically capable or available“ which they call an “infrastructure bottleneck.” They list off a parade of other benefits “vault redemptions execute on-chain in near real-time, 24/7, without wire cutoffs, T+1 settlement cycles, or custodian operating-hour constraints; on-chain vault balances are continuously verifiable by any authorized party, providing real-time proof of holdings that periodic account statements cannot replicate; and reduced custody costs at scale.” And all of this is probably right. At the margin these might be advantageous relative to custodial management of funds.
Of course, there are disadvantages as well, like smart contract and private key risk, which Veda also addresses. But these both are beside the point, in my view. Different custodial modalities present different security challenges and offer different advantages. Our regulatory state should not attempt to perfectly calibrate best practices in a professional industry, that is what the market is for. But from a broader perspective, the idea that a vault could provide as secure custody meeting the primary policy goals of the Investment Adviser’s Act is a necessary predicate to the kind of intermediation between traditional finance and cryptocurrency that will actually advance the economy.
This is what makes this paper so clever, and so effective. It relates a new proposition in a relatively arcane corner of the securities laws, in a way that if accepted would have a big impact. It’s the kind of advocacy that we try to do here, with real vision, executed well.
Le Sujet qui Fâche
Relative risks aside, though, absolute issues still exist in developing vaults designed to gain institutional (and regulatory) adoption. The elephant in the room, reading Veda’s paper, is that vaults do not always have a sterling track record.
Some of the regulatory arguments that we discussed above related to curators are, let’s say, speculative. Vaults’ use case as regulatory arbitrage machines may not endear them to all regulators (though the SEC may have signalled comfort with some of these arguments in private meetings). Veda addresses this in their Section VI arguing that “the existence of a strategy manager or curator exercising investment discretion over vault assets should not, in itself, disqualify a vault from this compliance pathway” and that “[t]he structural separation between custody infrastructure and investment strategy, as with traditional assets, is the feature that makes this compliance pathway analytically coherent and consistent with the rule’s existing framework.”
That may be the case, but real people don’t think like that, and if the SEC is convinced that vaults are used to illegally offer investment advice, it does seem less likely they would grant their blessing for their distinct but concurrent use as custodial tools. That said, if RIAs were permitted to use vaults for client funds, maybe more curators would be comfortable registering instead of relying on tricky arguments. Chicken and egg problem.
More importantly, theory aside, vaults do have an occasional tendency to blow up spectacularly in the real world. Just last week, the popular Drift Protocol’s primary vault on Solana was targeted by North Korean hackers and drained of a reported $270 million. This problem is not particular to vaults, but it is a point where the risk profile of DeFi might be ported into tradfi mediums that are accustomed to greater operational security.
The truth is, a qualified custodian like a bank has security advantages relative to smart contract controlled by a multisig wallet. These institutions have generations of operating practices and systems designed to prevent loss, and the most important of all is the practical reversibility of transactions made through heavily intermediated traditional finance rails. Wrench attacks are less effective when trades settle T+1. Vaults always sit one breach away from being drained, and regulators might justifiably be concerned about that.
But on the other hand, this is the nature of access to DeFi. A smart contract can be exploited regardless of how an RIA deploys client funds into it. The existence of an intermediate Qualified Custodian layer is no protection if funds are deployed into a protocol that is hacked.
Regulators should not prescriptively screen opportunities that sophisticated investors demonstrably want access to just because they are not accessible through traditional intermediaries. That is technological chauvinism, and while, yes, it does have the chilling effect that Veda identified, it is also simply a misapplication of regulatory authority.
To draw a normative conclusion about how regulation should address technologies like this, one must first be clear about the function regulation is meant to serve.
A popular academic model of regulation in the recent past is as a brake on industry, with the purpose of abstractly promoting consumer (or class) welfare. An economic model might suggest that regulators exist to enforce standards in an industry to internalize externalities and counterbalance information asymmetries. But in financial markets regulation is as much a partner to financial systems as anything else. It is good for securities markets that fraud is policed, and the same is likely true of RIAs and custodial rules. The government’s gloved hand prohibits marginal regulated actors from undermining the credibility of the industry as a whole, which makes third parties more comfortable, at the margin, having their assets managed.
Choosing between these models is a political question, but in our view, everyone is hurt when regulators overemphasize safety to the exclusion of innovation. Consumers should be protected, nobody wants to put the cocaine back in soda, but investors, particularly the accredited investors who would typically interact with RIAs, should not be treated like children.
DeFi is risky, this is well understood. But technical rules shouldn’t narrow access under the guise of procedure. The default should be that investors retain broad autonomy over their assets, with constraints imposed only where necessary to address identifiable risks like misappropriation, commingling, or intermediary insolvency. If the exceptions instead become the rule, we have lost sight of the system’s purpose.
Until next week.
Brogan Law is a registered law firm in New York. Its address and contact information can be found at https://broganlaw.xyz/
Brogan Law provides this information as a service to clients and other friends for educational purposes only. It should not be construed or relied on as legal advice or to create a lawyer-client relationship. Readers should not act upon this information without seeking advice from professional advisers.
This is not actually how it works but it would be funny if it did.
“Qualified Custodian” is defined in subsection (b)(6) of the rule and means, broadly, FDIC insured banks, SEC registered broker dealers, CFTC registered future commission merchants, and foreign financial institutions, each of which has to meet certain further criteria.




