The SEC's Division of Trading and Markets issued a staff statement on April 13, 2026, exempting certain non-custodial crypto user interfaces from broker-dealer registration under Section 15(a) of the Securities Exchange Act of 1934. The guidance, which covers DEX front-ends, wallet browsers, and ...
"The law is already clear that wallets and interfaces do not become 'brokers' solely because they enable users to create or control self-custody wallets." — Hester Peirce, SEC Commissioner
The SEC's Division of Trading and Markets issued a staff statement on April 13, 2026, exempting certain non-custodial crypto user interfaces from broker-dealer registration under Section 15(a) of the Securities Exchange Act of 1934. The guidance, which covers DEX front-ends, wallet browsers, and mobile applications that facilitate self-custodial transactions in crypto asset securities, carries a five-year sunset expiring April 13, 2031.
The statement defines a new regulatory category — the "Covered User Interface Provider" — and establishes seven core compliance conditions alongside a list of prohibited activities. It does not constitute formal rulemaking. It is non-binding, revocable, and explicitly temporary. Providers that take custody of user funds, negotiate terms, make recommendations, or receive payment for order flow remain subject to full registration obligations.
With Ethereum's total value locked near $118 billion and DeFi protocol front-ends serving as the primary access layer for on-chain trading, the guidance removes a regulatory overhang that had constrained institutional adoption and mobile app-store distribution since 2024.
The SEC staff introduced the concept of a "Covered User Interface" (CUI): a non-custodial, user-facing software tool — website, browser extension, or mobile application — that assists users in preparing and submitting transactions in crypto asset securities through their own self-custodial wallets. The definition covers the primary domain of a major DEX such as Uniswap, the dApp browser inside a wallet like MetaMask, or a standalone mobile trading application — provided the interface never takes possession of user funds or private keys.
The staff concluded that operators of these interfaces need not register as broker-dealers so long as they satisfy a cumulative set of conditions. The statement applies only to broker-dealer registration under the Exchange Act. It does not address national securities exchange registration, antifraud liability, or potential secondary liability related to MEV extraction and connected trading venues. Regulation NMS compatibility questions remain unaddressed.
The statement carries an explicit five-year expiration date of April 13, 2031, unless the full Commission takes permanent action before then.
To qualify for the staff's no-action position, a Covered User Interface Provider must satisfy all of the following:
1. User Customization. The interface must allow users to adjust default transaction parameters. It must also provide educational materials to help users formulate their own parameters. The provider cannot lock users into predetermined settings.
2. Venue Connectivity. The CUI must connect to one or more default execution routes — on-chain trading venues or distributed ledger trading systems — and provide transparent access to those routes.
3. Neutrality. The provider cannot comment favorably on any execution venue, label routes as "best price," or otherwise claim superiority of one route over another. If only one execution route is displayed, the interface must give users the ability to view additional routes. Where multiple routes appear, the CUI must offer filtering and sorting tools based on objective, pre-disclosed factors such as alphabetical order, price, or speed.
4. Objective Parameters. All software logic governing transaction preparation must use pre-disclosed, independently verifiable parameters. The provider may not exercise discretion over transaction outcomes, market information, or routing decisions.
5. Internal Controls. The provider must establish written policies and procedures to evaluate trading venues using objective factors: liquidity, latency, transparency, verifiability, neutrality, auditability, and security. These assessments must be periodically reassessed to address conflicts of interest.
6. Full Disclosure. The CUI must make prominent disclosures covering: its non-registration status with the SEC, transaction routing parameters, use of trading data, cybersecurity controls, and risks associated with transaction ordering — including maximal extractable value (MEV).
7. Fee Structure. Compensation must be limited to a fixed charge applied consistently across products, execution routes, venues, and counterparties. A percentage-based fee qualifies as "fixed" if applied uniformly — a departure from traditional broker-dealer fee analysis. The provider may not receive compensation from any source other than users, including payment for order flow.
The statement draws firm exclusion lines. A provider loses safe-harbor protection if it engages in any of the following:
Custodial wallet providers and operators of distributed ledger trading systems (the on-chain matching layer itself) are explicitly excluded from the scope of the statement.
The CUI statement did not arrive in isolation. In the span of 90 days — from late January to mid-April 2026 — U.S. regulators assembled the most comprehensive DeFi framework ever attempted:
The velocity is notable. After years of enforcement-first posture under previous administrations, the Atkins-led SEC has shifted toward regulatory guidance at a pace that the industry had not previously experienced.
The guidance has measurable implications for DeFi front-end operators:
Uniswap. The protocol's front-end, operated by Uniswap Labs, had faced a Wells Notice from the SEC in April 2024 — an enforcement action that was later dropped. The CUI statement now provides a defined compliance path for the interface layer. Uniswap's governance token carries a market capitalization of approximately $2.03 billion.
MetaMask and Wallet Providers. MetaMask's swap feature and dApp browser fall squarely within the CUI definition, provided the wallet does not take custody of user assets at any point in the transaction flow. The guidance effectively provides Apple and Google with regulatory clarity to allow more robust DeFi applications on their mobile app stores.
Institutional DeFi. With broker-dealer registration threats removed for qualifying interfaces, the compliance cost barrier for institutional-grade DeFi front-ends drops materially. The requirement for written policies on venue evaluation and cybersecurity disclosure mirrors elements of existing TradFi compliance frameworks, potentially easing onboarding for regulated firms seeking DeFi exposure.
Commissioner Hester Peirce, while commending the staff, argued for a "more permanent regulatory approach that addresses the broker definition in light of current market circumstances." She noted that treating software publishers as regulated intermediaries raises First Amendment questions: "Where regulation depends on treating the publisher of a tool as the 'missing middleman,' and thereby requiring changes to the content or architecture of the software itself, the First Amendment is directly implicated."
The Securities Industry and Financial Markets Association (SIFMA) urged the SEC to formalize the guidance through a public comment process. SIFMA President Kenneth Bentsen, Jr. testified that the industry "must do so on the basis of the legal and regulatory framework that we have."
The CUI statement is, by its own terms, not law. Several structural weaknesses merit attention:
Non-binding status. The statement is a staff-level position. It does not carry the force of a Commission rule, order, or regulation. The SEC can modify, revoke, or contradict it without notice-and-comment procedures.
Administrative Procedures Act concerns. Multiple legal commentators have noted that a staff statement of this scope — defining a new regulatory category, establishing cumulative compliance conditions, and creating a five-year exemption window — may constitute de facto rulemaking without complying with APA requirements.
Asymmetric scope. The statement applies only to interfaces facilitating crypto asset securities transactions. It does not extend to interfaces facilitating transactions in traditional, non-crypto securities under comparable conditions. If the underlying rationale is that non-custodial software tools are not brokers, the crypto-specific limitation lacks a clear legal basis.
Sunset risk. The five-year window creates a dependency on future Commission action. A change in administration, Commission composition, or policy priorities could result in non-renewal, leaving the industry without the guidance it has built compliance programs around.
Unresolved liability. The statement addresses only Section 15(a) broker-dealer registration. Antifraud liability under Section 10(b) and Rule 10b-5 remains fully applicable. CUI providers may face enforcement risk for front-end exploits, MEV extraction enabled by their interfaces, or misleading disclosures — even while operating within the safe harbor's broker-dealer exemption.
The SEC statement does not exist in regulatory isolation. The CFTC's conditions for similar crypto interface services differ materially. According to analysis by Sidley Austin LLP, CFTC guidance requires relationships with CFTC registrants and individualized relief requests — creating significant compliance friction for multi-regime providers.
A DEX front-end that facilitates transactions in both crypto asset securities (SEC jurisdiction) and crypto asset commodities (CFTC jurisdiction) must navigate two distinct compliance frameworks with different conditions, disclosure requirements, and fee restrictions. The SEC-CFTC coordination agreement under Project Crypto has identified this as a harmonization priority, but no unified framework has been published.
For providers operating across both jurisdictions, the practical result is parallel compliance programs with non-identical requirements — an outcome that raises operational costs and favors larger, better-capitalized teams.
The CUI statement represents the SEC's first attempt to define regulatory boundaries around DeFi's user-facing layer. It provides operational clarity for front-end developers and wallet providers that has been absent since the 2024 Uniswap Wells Notice. The conditions — neutrality, disclosure, objective parameters, and uniform fees — establish a compliance baseline that borrows from traditional market structure principles while accommodating on-chain architecture.
The statement's structural limitations are equally significant. Non-binding staff guidance with a five-year sunset is not the durable regulatory framework that Commissioner Peirce and industry participants have requested. The divergence between SEC and CFTC conditions adds compliance cost without delivering regulatory coherence. And the asymmetric scope — applying only to crypto, not traditional securities interfaces — invites legal challenge.
For the DeFi industry, the practical calculus is straightforward: five years of defined rules is better than zero years. The question is whether the Commission, Congress, or both will convert this interim position into permanent law before the clock runs out on April 13, 2031.