Skip to main content

Senator Cynthia Lummis posted 630 pages of revised CLARITY Act text on Thursday, five days before a procedural vote that needs sixty senators to go anywhere. Most of the coverage went where you would expect: the ethics section that did not move, the stablecoin yield fight, whether the Democrats who asked for 114 provisions will vote for the bill containing them.

Buried in the additions is something more interesting than any of that. For the first time, a US legislature is proposing to write down, in statute, what counts as decentralised. The bill calls the failures “non-decentralized finance trading protocols” and hands the CFTC and Treasury the job of regulating whoever controls them.

Read that as a gaming story, because it is one. The word this industry has used as a marketing adjective for a decade is about to get an official version, and an official version is a badge.

TL;DR

  • Lummis released the revised CLARITY Act on 10 September 2026, 630 pages, with a first procedural Senate vote set for 15 September requiring 60 votes.
  • New language targets “non-decentralized finance trading protocols”: anyone with authority to control or materially alter a protocol’s rules, plus protocols whose controllers can restrict users or whose transactions are not governed solely by transparent, pre-established code.
  • The drafting is genuinely good. It asks mechanism questions, not vibes questions, which is more than most crypto legislation manages.
  • It is still a test about who can change the rules. It says nothing about who chooses the inputs, and a rigged game needs only the second.
  • A coinflip can be immutable, unupgradeable, open to everyone, and fed its random number by a server in the operator’s cupboard. It passes the statutory test and is rigged.
  • Satoshie names the input in public before it is used: Chainlink VRF, proof verified by the coordinator before the callback may deliver, outcome and payout in the same transaction.

What the bill actually says

The new section reaches persons or groups acting in concert with authority to control or materially alter the functionality, operation or rules of a DeFi protocol, directly or indirectly through contracts or arrangements. It also reaches protocols whose controllers can restrict users, and protocols whose transactions are not governed solely by transparent, pre-established code. Anything caught has to register with the CFTC. The SEC and CFTC then write activity-based rules covering registration, conduct, disclosure, recordkeeping and supervision, and Treasury works out how Bank Secrecy Act obligations apply to the controllers.

That is a better test than this industry deserved. “Materially alter”, “restrict users”, “transparent, pre-established code” are questions about a mechanism. They can be answered by reading a contract rather than by reading a press release. Compare it to the prevailing standard in crypto gaming, which is a Curaçao licence number and an RNG certificate dated 2019, and the drafting looks close to enlightened.

This blog has said for months that permissionless is not the same as legal. A statutory definition of decentralisation beats no definition at all, and none of what follows is a complaint about the bill.

The half the test does not reach

It is also the fifty-seventh time this series has found the same seam, and this one is unusually clean.

Every clause in that definition is about who can change the machine. Upgrade authority, control, the ability to restrict users, whether the rules are fixed in advance. Not one clause is about what the machine is fed.

So build this. A coinflip contract, deployed immutable on a public chain, source verified, no proxy, no admin key, no pause function, no ability to exclude anyone, every rule of the game fixed in advance and readable by a stranger. Transactions governed solely by transparent, pre-established code. It passes, comfortably.

Now have that contract fetch its random number from an endpoint the operator runs. Nothing was materially altered. No rule changed. No user was restricted. The number simply arrived, and it arrived from a place where somebody could see your bet first and pick accordingly.

That is the oldest rig in gambling wearing next year’s compliance language. A loaded die does not break the rules of craps; those rules are published, unchanged and perfectly transparent. The rig lives entirely in an input nobody thought to name.

Why this ends up in a footer

Once “decentralised” has a legal definition, it becomes the most marketable word in the business, because for the first time the certificate comes from a government rather than from a licensing mill in the Caribbean. Expect the footers within a year of passage, sitting next to the audit badge they have already trained you to ignore.

The specific move to watch is scoping. A casino does not need its whole stack to qualify. It needs one component that does. Put the settlement contract in scope, register it, describe it accurately as a non-custodial protocol governed by pre-established code, and keep the number that decides whether you won in a backend nobody outside the company has ever seen. Every word of the marketing is true. The compliant component is simply not on the path that decides your result.

Legal status attaches to a protocol and is assessed in the present tense by a regulator. Fairness attaches to a draw and is assessed in the past tense by the person who lost. The coming twelve months will sell you the first as an answer to the second.

Three questions that survive the statute

  • Where did the number come from, and can I watch it arrive? A VRF request and its fulfilment are two transactions with hashes. A server call is a claim.
  • Who could have known the number before my stake was committed? If the answer includes anyone at the company, the rules being immutable is decoration.
  • If the law changed on Monday, which claims on this page change with it? Anything downstream of legal status was never a property of the mechanism.

Where we sit, honestly

Satoshie would not sail through that test, and pretending otherwise would be the exact behaviour this post is complaining about. We are a company. We run a front end, which is an ordinary web app and the least trustworthy thing we ship. Base has a sequencer operated by a company. If an authority told us to restrict who can load the interface, the interface is a thing we control.

Our claim was never the adjective. It is the list. The stake is escrowed by the contract. Randomness is requested from Chainlink VRF, named in the deployed code before any of it happens. The coordinator verifies the proof before the callback is permitted to deliver anything. The outcome is computed inside that callback transaction and the payout moves in the same transaction, with no admin key and no window where a human sees the result and decides differently.

The input is named in public, in advance, and the proof that it was not chosen is a number a hostile stranger can check in four years without asking us for permission, an account, or a support ticket.

A statute can tell you who to sue. It cannot tell you whether last night’s flip was honest. Only one of those answers is still true after the next election.

📷 Photo by Mick Haupt on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna