Where the law starts. In July 2017 the Commission published a report of investigation on an unincorporated organization called The DAO, which had sold tokens to raise a pool of assets that would be used to fund projects, with holders standing "to share in the anticipated earnings from these projects as a return on their investment". The Commission "determined that DAO Tokens are securities under the Securities Act of 1933 and the Securities Exchange Act of 1934", applying the Howey test, and stressed "that those who offer and sell securities in the U.S. are required to comply with federal securities laws, regardless of whether those securities are purchased with virtual currencies or distributed with blockchain technology". It also, and this is usually left out, "determined not to pursue an enforcement action in this matter based on the conduct and activities known to the Commission at this time". The report was published as guidance rather than as a case.
What followed is described by the Commission itself in its 2026 interpretation: "In the years following publication of The DAO Report, the Commission applied the Howey test, mostly in the context of enforcement actions, to determine whether crypto assets were offered and sold as investment contracts and therefore as securities." The release adds that "Some Commissioners and other commentators expressed concerns about the Commission's approach to crypto assets during this period" and that "Some described that approach as 'regulation by enforcement'". That phrase is worth attributing carefully: the release reports it as a criticism made of the Commission, not as the Commission's own description of what it did.
Where the law stands now. The operative document is the interpretation the SEC issued in March 2026, which the CFTC joined, and two things about its status matter. It "supersedes the Commission staff's Framework for 'Investment Contract' Analysis of Digital Assets (Apr. 3, 2019)", so that 2019 framework, which a great deal of older commentary is built on, is no longer the reference. And it "does not supersede or replace the Howey test, which is binding legal precedent"; it states the Commission's views on how parts of that test apply. The crypto token page sets out the five categories the interpretation uses and is the place to start on classification.
On offerings specifically, the interpretation supplies the analysis directly. A non-security crypto asset "becomes subject to an investment contract when an issuer offers it by inducing an investment of money in a common enterprise with representations or promises to undertake essential managerial efforts from which a purchaser would reasonably expect to derive profits". It then names the ICO as one of two delivery patterns: "In an offering involving immediate delivery, such as through an 'initial coin offering', the issuer agrees to deliver newly generated non-security crypto assets immediately to investors in exchange for their investment", against delayed delivery "such as through a 'simple agreement for future tokens'". In either case, "the sale of the non-security crypto assets occurs at the time of entry into the agreement with the investors", at which point they become subject to an investment contract "regardless of when they are delivered". So the promises made in the marketing, and when they were made, do the work; the delivery schedule does not.
The interpretation also explains how such an asset can stop being subject to the investment contract, which is the part that makes the analysis time-dependent rather than permanent. Where the issuer has fulfilled the essential managerial efforts it represented it would undertake, "the issuer is no longer offering or selling an investment contract and the investment contract itself ceases to exist". The same is true where a purchaser would no longer reasonably expect the issuer to be able to fulfill them, for example where the issuer "effectively 'abandons' the development of a crypto system". One consequence a reader should hold onto: the status of the same token can differ between its original sale and a later trade.
What is proposed and not law. In August 2026 the Commission proposed Regulation Crypto Assets, "new rules to create a tailored offering regime for certain investment contracts involving crypto assets". As proposed it would create two exemptions from the registration requirement of Securities Act section 5: a "startup exemption" permitting offerings of up to $5 million over a four-year period, and a "fundraising exemption" permitting up to $75 million in each 12-month period. Both would require principles-based narrative disclosure, the fundraising exemption would add financial statements and ongoing reporting, and the proposal also includes a conditional safe harbor from the term investment contract. Issuers relying on either "would remain subject to the antifraud and antimanipulation provisions". None of that is in force, the figures are proposal figures rather than current limits, and a proposal can be changed or dropped.
The buyer's position, in the regulator's own words. The SEC's investor bulletin sets out what to establish before participating, and it reads as a list of things an ICO does not automatically supply. Ask "whether the virtual tokens or coins are securities and whether the persons selling them registered the offering with the SEC", and check EDGAR if the answer is yes. Ask "what your money will be used for and what rights the virtual coin or token provides to you", noting that a promoter "should have a clear business plan that you can read and that you understand". Ask "specifically about how and when you can get your money back", including whether there is any right to a refund and any limit on resale. Note that secondary trading may happen on venues that "may not be registered securities exchanges or alternative trading systems regulated under the federal securities laws", so "you may not have the same protections that would apply in the case of stocks listed on an exchange". And note the bulletin's blunt point about recovery: "Investing in an ICO may limit your recovery in the event of fraud or theft. While you may have rights under the federal securities laws, your ability to recover may be significantly limited." The bulletin lists why, and the reasons are structural rather than about anyone's good faith: tracing money is harder without banks in the chain, participants span jurisdictions, there is no central authority holding user information, and crypto in an encrypted wallet is difficult for law enforcement to freeze or secure.
A final point of substance rather than of law. What an ICO buyer is usually buying is a promise about software that does not exist yet, priced by the promise. The DAO Report records how that can go wrong even when everyone is sincere: after the tokens were sold "but before The DAO was able to commence funding projects, an attacker used a flaw in The DAO's code to steal approximately one-third of The DAO's assets". The bulletin's own advice on that front is to ask "whether the blockchain is open and public, whether the code has been published, and whether there has been an independent cybersecurity audit", and the limits of an audit are covered on the smart contract page.