The CFTC is giving crypto wallets and DeFi interfaces a broader route into regulated derivatives without forcing them to become registered brokers.
The move builds on a decision the agency made for Phantom earlier this year. What was once a company-specific carveout is now being offered to a much wider category of software providers — provided they follow the same rules.
It arrives alongside a fresh push from the SEC around tokenized stocks, suggesting U.S. regulators are increasingly testing ways for crypto-native products to connect with traditional financial markets without forcing every piece of software to fit neatly into an old regulatory category.
The CFTC turns Phantom’s exception into a wider framework
Back in March, the CFTC gave Phantom a no-action position that allowed the wallet to create a frontend connecting users with CFTC-regulated derivatives, including event contracts and perpetuals.
The unusual part was that users did not need an existing relationship with a broker before accessing those products through the interface.
That setup did not neatly fit the agency’s older 2006–2008 no-action letters, known as TSV letters, which covered a narrower range of activity. So the CFTC created a new framework specifically for Phantom.
That protection came with conditions. The wallet had to meet requirements involving disclosures, risk warnings, recordkeeping and potential joint liability if something went wrong.
There was also a practical limitation: a no-action letter only protects the company named in it.
Phantom could rely on the agency’s position. Another wallet could not simply point to Phantom’s letter and assume the same protection applied.
The CFTC has now addressed that problem.
Its new Staff Letter 26-25 extends the same framework to what it calls Passive Software Providers, or PSPs. These are frontends and wallets that connect users to a regulated derivatives venue without holding customer funds, making trading recommendations or exercising discretion over orders.
For companies that fit that definition and satisfy the conditions laid out by the agency, the protection is no longer unique to Phantom.
That distinction matters because the regulatory question is no longer just about one popular wallet. It is becoming a question of how a whole category of software can interact with regulated financial products.
And while the letter is especially relevant to crypto, the CFTC says the framework is not limited to crypto.
The same conditions can apply to other software designed to passively route trades. Crypto simply happens to be one of the clearest places to see why that matters, particularly as wallets and DeFi interfaces increasingly become gateways to perpetuals and other derivatives.
For developers, that creates a more defined path: connect users to a regulated venue, stay within the boundaries of passive software, and potentially avoid taking on the full obligations of a registered broker.
But there is an important catch hiding in the paperwork.
The CFTC is offering protection, not rewriting the law
A no-action letter is not a rule.
It is a commitment from agency staff that they will not recommend enforcement under the circumstances described in the letter. And that commitment can change.
The new protection lasts only until the effective date of a Commission rulemaking, meaning the agency could later narrow or replace the approach through formal regulation.
The timing is notable because the CFTC has already started another process. The agency recently sent a proposed rule titled Regulation Crypto Asset Transactions and Regulation Crypto Asset Markets to the White House Office of Information and Regulatory Affairs for review.
The proposal is still at the earliest prerule stage, and the agency has not disclosed what it contains.
So the current framework may be useful, but it should not be confused with a permanent settlement of the bigger regulatory questions facing crypto software.
One of those questions sits well outside the CFTC’s jurisdiction: whether developers of noncustodial software can face criminal charges simply for creating and publishing that software.
Coin Center raised that issue in a recent op-ed, arguing that open-source software being difficult to stop does not necessarily protect the people who build it.
The group pointed to Roman Storm’s case involving Tornado Cash. Storm was convicted last year on one count related to building the privacy tool, while a retrial on more serious money-laundering and sanctions charges was recently pushed to April 2027.
Separately, Coin Center’s Michael Lewellen is suing the Department of Justice, seeking a declaration that writing noncustodial open-source software is not itself a crime.
Those questions underline the limits of the CFTC’s latest decision.
The agency can shape how passive software interacts with regulated derivatives. It cannot dictate what the DOJ prosecutes, and it does not control the SEC’s separate regulatory agenda.
Still, the CFTC’s move changes something important for crypto infrastructure. A compliance framework that began as a bespoke solution for Phantom is now available to a broader class of software providers.
For wallets and DeFi interfaces, that could make the path toward regulated derivatives more predictable. For developers, it offers something the industry has often struggled to find: clearer boundaries around what passive software can do.
It just does not answer every question waiting on the other side.
