The SEC's Buyback Rule Lasted Three Days. That's Not Guidance, That's a Guessing Game
SEC staff told crypto projects on Sept. 25 that a functioning system was enough to announce a token buyback. Three days later, they added a "no central party" requirement. With $638 million in buybacks already on the books this year, someone has to explain who's allowed to pull the trigger.
Three days. That's how long the SEC's crypto buyback guidance survived before staff changed the answer.
On Sept. 25, the agency said a token issuer could announce a buyback without that announcement counting as a promise to manage the token's value. All the project needed was a functional system. Simple enough. On Sept. 28, staff tacked on another condition. The system also needs "no central party."
So which is it? Because projects spent a record $638 million on token buybacks through late August, and every one of them now has to figure out whether they've been accidentally promising something to their holders.
The Moving Goalposts
Here's what changed and why it matters. Under the Sept. 25 version, a project with a working chain and a treasury program was in the clear. Under the Sept. 28 version, that same project has to show nobody holds operational, economic, or voting control over the system.
The SEC defined "central party" back in March. It's a person, company, or group with control over the crypto system. That test covers the whole system, not just buybacks. So controlling a treasury doesn't automatically make you a central party. But it's evidence. Sometimes a lot of evidence.
Ask Aave. The Aave Finance Committee could move weekly AAVE buyback volumes up or down by 75%, weighing liquidity, volatility, timing, and protocol revenue. The DAO put $42 million to work buying over 205,000 AAVE across the program's first 10 months. Then buybacks stopped on April 19, one day after an rsETH bridge incident. A governance notice on April 22 confirmed the pause. TokenLogic said the halt gave the treasury room to breathe while people assessed the damage.
Months later, an August/September funding update listed AAVE among assets that could be purchased through new token budgets. Notice the word "could." No restart announcement. No record of completed purchases after the pause. The capacity existed. Whether anyone used it's anybody's guess.
That's the problem in miniature. Money earmarked isn't money spent. And a program that a committee can pause with a vote is a program run by people.
Pump.fun took a different route. Its April 28 disclosure said references to PUMP purchases and a "buyback program" described plans or smart-contract functions, not a firm promise to buy anything. The exception: purchases already programmed to execute automatically through on-chain code deployed before April 28, 2026 UTC.
The PUMP token page says 50% of defined platform revenue was programmatically locked and burned for one year starting April 28. It also says future purchases can generally be started, stopped, or changed. And the two pages don't agree on dates. One says April 28. The other says April 29.
Does that date gap matter legally? Probably not much. Does it suggest the disclosure wasn't drafted with someone checking every UTC timestamp? Yeah, kind of.
There's another wrinkle worth pulling on. If a system isn't functional yet, SEC staff says a buyback announcement could count as a managerial promise when the issuer pitches the purchases as a way to generate yield or returns. So buybacks for pre-launch tokens get read as marketing for a security. Buybacks for live tokens get read as.. what, exactly? Nobody's answered that with any precision.
Maybe the SEC Has a Point
Let me steelman the agency, because the pushback isn't crazy.
"Functional" is a low bar. A chain can process transactions while a foundation, a multisig, or three guys in a group chat decide where the money goes. If a project says it's buying back tokens and then buys back tokens, holders reasonably read that as management working to support the price. That's the theory underneath securities law. If buyers rely on someone else's efforts for returns, the token starts looking like an investment contract.
The SEC didn't invent that test. The Supreme Court handed it down in 1946, and it's been the standard ever since.
And the $638 million number cuts both ways. It's a record, and records invite scrutiny. When projects spend nine figures buying their own tokens, regulators want to know who's holding the checkbook. That's not paranoia. That's the job.
Fair enough.
My Verdict
But here's what bothers me. Not the rule. The whiplash.
Staff issued an answer on Sept. 25 and rewrote it on Sept. 28. Nobody litigated. No comment period. No enforcement action tested it in court. Three days, and a brand new condition appeared. The FAQ isn't binding, which the agency is quick to point out, but projects still build around it because their lawyers read it and their compliance teams follow it.
That's not how you write rules. That's how you write riddles.
Regulation by enforcement is still regulation. So is regulation by FAQ. The state isn't protecting you. It's protecting itself. Every clarifying memo that gets clarified four days later teaches builders that the safest move isn't compliance. It's not launching at all, or launching somewhere the staff can't reach.
Follow the incentives, not the press releases. The incentive here's to avoid buybacks entirely, or to structure them so no human can ever touch the dial. Not because that's better for holders. Because it's safer for founders. That's a real cost, and it lands on the people the rules claim to protect.
The counterargument holds up to a point. A committee with a 75% adjustment range over a $42 million program isn't decentralization. It's control with a governance forum attached. Naming that honestly is useful. I'd rather the SEC say it out loud than pretend otherwise.
But if the test is "does anyone have meaningful power," then say so once and stick to it. Publish the standard, give projects a real chance to meet it, and stop shifting the line. Permissionless means exactly what it sounds like. The code doesn't ask for a license, and it doesn't ask for a three-day grace period either. Self-custody and censorship-resistant systems don't get more decentralized because a staff memo changed its mind on a Tuesday.
For now, every project running a buyback has one question to answer. Not how much you spent. Who can start, stop, or change the next purchase, and what else do they control?
Answer that honestly and you know where you stand. Guess wrong and the SEC will tell you eventually, with a different answer than last time.