The Ooki Protocol is a decentralized, tokenized margin trading and lending protocol on Ethereum. The protocol allows users to participate in trading strategies such as leverage, short selling, and traditional borrowing and lending services. On Aug. 23, 2021, the Ooki DAO founders celebrated the successful transfer of the Ooki Protocol from bZeroX, LLC to bZx DAO (since renamed to “Ooki DAO”). The founders' motivation for the transition originated in moving protocol outside legal reach. Explicitly, their goal was to “make sure that when regulators ask us to comply, that we have nothing we can really do because we’ve given it all to the community.”
On Sep. 22, 2022, the Commodity Futures Trading Commission (“CFTC”) issued an order against the Ooki Protocol and its governing entities. The CFTC filed charges against bZeroX, LLC, the company’s founders Tom Bean and Kyle Kistner, and the Ooki DAO for illegally offering leveraged and margined retail commodity transactions for digital assets. The charges, which imposed a $250,000 penalty on the Ooki DAO, focus on three primary allegations:

A History of the CFTC and Crypto
Since the CFTC fined BitFinex $250,000 for facilitating off-exchange retail commodity transactions in 2016, unregistered crypto commodity exchanges have been subject to regulation. Despite this regulatory trend, the CFTC has proceeded cautiously with direct interference with DAOs, partly due to the lack of regulatory frameworks defining DAOs. The CFTCs most recent order represents a historic first move in charging individual members within a DAO structure.
The Ooki DAO CFTC order challenges the Ooki founders’ original vision that their DAO was outside the purview of traditional regulatory oversight. The order could establish an avenue for regulators to penetrate a DAO’s declared or undeclared legal status and punish the individuals it finds liable for legal missteps.
At the core of the CFTC's order is the question of a DAO's legal definition, status, and liability. The CFTC refers to the Ooki DAO as an unincorporated association: "a voluntary group of persons, without a charter, formed by mutual consent for the purpose of promoting a common objective." The CFTC argues that Ooki DAO was an unincorporated association operating the Ooki Protocol for profit, without adhering to CFTC regulations.
The liability of an unincorporated association is inherently vague as, by definition, it lacks a registered incorporated status. The CFTC leverages several cases to support its argument. The order points to Heinold Hog Market, Inc. v. McCoy (1983) to position Ooki DAO as operating for profit (where it charges for its services to buy and sell commodities) to establish it as an unincorporated association under partnership law. The CFTC then establishes the personal liability of the members of the Ooki DAO association by pointing to Karl Rove & Co. v. Thornburgh (1994). This case distinguishes the liability of individual members of for-profit unincorporated associations. The CFTC uses these cases to position the Ooki DAO as an unincorporated association comprised of token holders that govern the DAO. According to CFTC Docket No. 22-31:
Once an Ooki Token holder votes his or her Ooki Tokens to affect the outcome of an Ooki DAO governance vote, that person has voluntarily participated in the group formed to promote the common objective of governing the Ooki Protocol and is thus a member of the Ooki DAO unincorporated association.
In the case of Ooki DAO, the CFTC utilizes this definition to charge Bean and Kirstner by binding them to unlawful activity, not only during the bZeroX, LLC timeframe but also during their time as participants within the Ooki DAO. If unchallenged, the CFTC may establish regulatory precedence using a DAO member’s governance actions as grounds to assign personal liability to the actors the CFTC feels are responsible for a DAO’s regulatory violations.
Additionally, the order could impact the legal definition of smart contracts as autonomous and decentralized operation tools. Due to the autonomous and self-running nature of the blockchain, the authors and publishers of smart contracts on decentralized networks could be lawfully distanced from the actual settlement of transactions the code might produce, according to Tessera General Council Adam Sternbach.
The legal status of software code has a complex and nuanced history in the United States. In Bernstein v. United States (1996), the United States District Court for the Northern District of California established that software source code is speech protected by the First Amendment. Assuming a court upholds that Ooki DAO’s authorship of the code is protected by freedom of speech, it could be argued that Ooki DAO is a publisher of the code and that the decentralized Ethereum network is responsible for operating the code and settling unlawful transactions.
In a separate case through the United States Court of Appeals for the Ninth Circuit, MGM Studios v. Grokster (2005), the district court ruled that software distribution companies were not liable for copyright violations that stemmed from their software because the software could be used lawfully. Due to the permissionless nature of decentralized networks, an open protocol launched within legal bounds (i.e., to exchange lawful digital assets) could be seen as not liable for violations arising from their protocol.
Ultimately, these decisions may come down to the judge’s understanding of Ooki DAO’s intent to publish the code on the Ethereum Network. Given the Ooki protocol's intent of providing leverage and margin commodity trading without a license, it could be argued they intended to break CFTC law from the outset. An example of a more nuanced case can be found in the Treasury’s Office of Foreign Assets Control (OFAC) sanctions against Tornado Cash. The Tornado Cash case differs from the Ooki protocol in that Tornado Cash provided a privacy service that from the outset may not have been illegal, but that was then used unlawfully by malicious actors. For Ooki DAO, the team's actions and outright acknowledgment of adopting a DAO structure to avoid regulation may not play as favorably in court.
At the end of the day, the Ooki Protocol CFTC order boils down to a cease and desist order with a $250,000 fine. Should the order stand, the more significant impact is likely to concern the aforementioned framework by which the CFTC defined the Ooki DAO as an unincorporated association and the order's definition of token-holding voters as the entity's liable decision-makers.
The details of the order could place token voters, and to some extent all governance participants, in the cross-hairs of the CFTC. The order details the Ooki DAO's governance process across community forums, Snapshot votes, and proposal voting via the Compound Bravo Governance Module. To be fair, Ooki DAO participation was hardly robust, with an average of just seven participants on their published Snapshot votes and only four for on-chain votes.
While the CFTC explicitly calls out Bean and Kirstner, the means through which they execute their order applies to all governance participants. The actions establish guidance for imposing sanctions, civil monetary penalties, and cease-and-desist orders to any DAO member based solely on their token holder status.
In response to the CFTC’s order, Commissioner Summer K. Mersinger published a Dissenting Statement that reprimanded the CFTC for its approach to determining liability for a DAO based on governance voting participation. The dissent referred to the order as "regulation by enforcement" and claimed that the approach does not rely on any legal authority in the Commodity Exchange Act (“CEA”). Instead, Mersinger offered an alternative for the CFTC to pursue aiding and abetting liability by tying Bean and Kistner's actions in transitioning their company towards a new structure with the intent to perform the unlawful activity.
However, Mersinger’s dissent also supported the CFTC’s settlement order against both bZeroX, LLC, as a limited liability company, and the personal liability of Tom Bean and Kyle Kistner for violations of the CEA. Further, the statement supported the claim that Ooki DAO committed similar violations of the CEA and CFTC rules, and acted illegally.
Many venture capitalists have pontificated on the dangers of DAO governance and regulation, and many have attempted to remove themselves as participants by strategically delegating their votes to external delegates and university clubs.
The crux of the CFTC's order was the assertion that DAOs lacking legal status could be targeted as unincorporated associations. Therefore, the classification may extend liabilities of the DAO to each participating member's liability. With this order we could see more DAOs moving to incorporate. Inherent in the definition of an unincorporated association is the lack of a charter, allowing DAOs to avoid this specific avenue of token holder liability by adopting any number of legal wrappers. These include a corporation, nonprofit, or even a more experimental status such as a Wyoming DAO LLC.

While the implications of personal liability for all participating token holders could be seen as extreme, the practical ramifications of the CFTC's actions align with the goals of the recently drafted Lummis-Gillibrand Responsible Financial Innovation Act. The proposed legislation outlines a regulatory definition for DAOs, including the requirement of incorporation or organization under a state or foreign entity jurisdiction.
Unsurprisingly, throughout 2022, the adoption of legal wrappers has been a notable trend. To date, Messari has covered over a dozen DAO proposals that either establish or discuss the adoption of a legal wrapper.

DAOs have employed several strategies when adopting legal wrappers. From Caribbean island entities to nonprofits to Delaware Corporations, the lack of specific DAO legislation has DAOs registering across a spectrum of options. The best legal wrapper for a given DAO largely depends upon each DAO’s characteristics and goals. If the DAO aims to achieve a true not-for-profit, it will adopt a different legal status than an investment or profit-driven protocol DAO.
Following the CFTC filing, an Ooki DAO representative is expected to respond within 21 days or risk a default judgment against the DAO. While formalities are already being discussed around the serving of the CFTC order, various interest groups on the legal side of blockchain technology are expected to step in and support establishing guidelines that protect DAO voter liability. Given Commissioner Mersinger’s dissent and the stakes of the order, the nature of the order could be challenged in court.
Ultimately, the fate of the current CFTC order, if it stands, could serve as a legal avenue for regulators to target DAOs under the status of an unincorporated association. As the law stands, the specific strategy implemented by any corporate charter would transition the DAO from the unincorporated association standing, in theory protecting it from the specific regulatory logic the CFTC has exercised to attack DAO Voters. Regardless of the case's outcome, the increased uncertainty for DAOs will likely fuel the DAO legal wrapper adoption trend or spur similar protective measures.
Traver is a Research Analyst at Messari. Previous to Messari, Traver studied Economics and Environmental Studies at Northeastern University. He is most interested in protocol governance.
Tomas Molin is the research lead of Messari Governor. Prior to joining Messari, Tomas worked at Ardian in the Growth Equity team focusing on technologies. At Messari, he began within the Intel team covering DeFi and governance related topics before taking the lead of the Governor team when the product was launched.