Self-Certification's Blind Spot: Event Contracts, Single-Issuer Swaps, and the SEC-CFTC Fault Line

MetaMeta
Technology
Citadel Securities has formally urged the U.S. Securities and Exchange Commission to claim jurisdiction over event contracts tied to public companies. The framing suggests a market maker managing its own regulatory exposure. The substance is larger. The request exposes a structural flaw that has sat unresolved since the Dodd-Frank Act partitioned derivatives into "swaps" and "security-based swaps" in 2010 β€” a partition drafted for interest-rate and credit instruments, not for contracts that pay out on whether a CEO is fired. Under Section 5c(c) of the Commodity Exchange Act, a designated contract market can self-certify a new product into existence with no prior approval, provided it does not violate the Act. If that product settles on a single issuer's stock price or corporate event, the securities statutes arguably govern β€” and self-certification becomes a procedural bypass around a jurisdiction the CFTC may not own. Event contracts β€” binary instruments that pay a fixed amount if a defined outcome occurs β€” have moved from the margins of academic forecasting to the center of U.S. market-structure debate. Platforms such as Kalshi, ForecastEx, and the U.S. entity of Polymarket list them under CFTC oversight. The mechanism that permits this is self-certification: a designated contract market files with the CFTC, and unless the agency objects within its review window, the contract trades. The CFTC retains a narrow veto under CEA Β§5c(c)(5)(C) for contracts involving illegal activity, gambling, or outcomes "contrary to the public interest" β€” a standard broad enough to be contested and narrow enough to be litigated. The counterweight sits in the Securities Exchange Act. Section 3(a)(10) defines a security, and the Howey test (SEC v. W.J. Howey Co., 328 U.S. 293 (1946)) captures "investment contracts." More precisely, Section 3(a)(68) defines a security-based swap to include agreements referencing a single issuer where the event "directly affects the issuer's financial statements, financial condition, or financial obligations." Dodd-Frank Title VII then split oversight: security-based swaps to the SEC, swaps to the CFTC, mixed swaps to both. The statute assumes regulators can tell which is which. Event contracts dissolve that assumption. The legal environment has shifted underneath both agencies. In Loper Bright Enterprises v. Raimondo (2024), the Supreme Court ended Chevron deference, stripping agencies of the presumption that their statutory interpretations deserve judicial deference. Neither the SEC nor the CFTC can now lean on institutional habit; each must ground its claim in the text of the statute. That change favors the party holding the clearer textual anchor β€” and Β§3(a)(68)'s single-issuer clause is a far more concrete hook than the CFTC's amorphous "public interest" standard. The fight is not about whether prediction markets should exist. It is about which agency gets to define the boundary. The CFTC has operated DCM self-certification as a quasi-sandbox: list first, litigate later. The SEC's framework is the opposite β€” register first, trade second, with registration carrying the full weight of broker-dealer obligations, manipulation surveillance, and disclosure. Citadel's intervention is an attempt to force a product category it considers securities into the heavier regime. The real doctrinal lever is not "public interest." It is Section 3(a)(68)(A)(iii) β€” the single-issuer event provision. A contract that pays out on whether Company X's stock reaches $200, or whether Company X completes a merger, references a single issuer and an event that plausibly affects its financial condition. Fold that into the security-based swap definition, and SEC jurisdiction is not discretionary; it is textual. The CFTC cannot validly self-certify what Congress placed in the SEC's domain, because self-certification extinguishes the SEC's authority by procedural default. Whoever invokes 3(a)(68) first frames the entire debate. There is a second layer. Even if a listed-company event contract is not a security-based swap, it may be a security in the form of a binary option, or a security future. The classification is not mutually exclusive and does not depend on how the platform names the instrument. That is the CFTC's exposure: it has widened its practical control over event contracts through self-certification plus special rules, and the structural legitimacy of that expansion is now in question. The Kalshi litigation reinforced this. The courts held that the CFTC could not arbitrarily block an event contract on congressional-control outcomes β€” a decision that constrained the agency's veto power. What that case did not establish is that the SEC lacks jurisdiction. Citadel appears to be exploiting precisely that gap: if the CFTC cannot block and the SEC has never claimed, there is a jurisdictional vacuum, and vacuums invite intervention. The enforcement trend here is best described as a jurisdiction race rather than a crackdown on wrongdoing. The CFTC expands practical control through self-certification and special rules; the SEC, previously quiet on prediction markets, may now be pulled off the sidelines. The most probable SEC tool is not an enforcement action but a rule proposal β€” which simultaneously asserts jurisdiction and freezes the listing pipeline while comment periods run. That is a slower, quieter way to stop a market than litigation, and it is more effective. From a compliance-risk standpoint, the exposed population is wider than the platforms. A DCM that lists an equity-linked contract without SEC registration faces a procedural violation β€” listing a securities product without the required registration β€” layered on a substantive one if the contract itself is later held unlawful. For a market maker like Citadel, the exposure is derivative: participating in an unregistered securities transaction carries its own liability. But the most insidious risk is what I would call a continuing-operation violation. The contract is already trading. If it is re-characterized as a security months after launch, there is no established rulebook for unwinding existing positions. Open interest, hedges, and client claims all sit in limbo. The damage from that scenario is not a fine; it is the legal zeroing-out of a live market β€” far more lethal to a platform than any penalty. The same logic applies to the clearing layer, which is often the neglected node. If a contract referencing a single issuer's equity is a security, the clearinghouse and the data provider feeding the settlement price may inherit their own registration and compliance questions. Market makers, clearinghouses, and index suppliers form a chain, and the weakest compliance link can drag the whole structure down. Market structure follows. The immediate commercial pressure on event-contract platforms is to de-equitize their product lines β€” pull the single-company contracts, keep macro, sports, and climate events, and remain inside the CFTC perimeter. That is a compliance-driven reshaping of product architecture, not a strategic preference. The deeper consequence is that compliance cost does what compliance cost always does: it concentrates the industry. If dual regulation becomes the standard, platforms need SEC-level surveillance infrastructure β€” insider-information firewalls, abnormal-trade detection, manipulation monitoring. That favors balance-sheet-heavy operators and squeezes small ones. The entry ticket for a regulated venue is denominated in compliance capacity, and that ticket keeps getting more expensive. I have watched this pattern before. After Binance settled its $4.3 billion enforcement action, the consensus expected the exchange to be crippled. It emerged more entrenched, because the settlement converted an unlicensed offshore operator into a compliance-heavy venue the rest of the market could no longer credibly exclude. The lesson generalizes: in mature jurisdictions, a license is the deepest moat, and the capital required to buy one is the barrier that keeps the field small. There is a plausible endgame that receives too little attention. Traditional exchanges β€” CME, ICE, Nasdaq β€” hold existing SEC and CFTC registrations and mature surveillance systems. If the SEC asserts jurisdiction over listed-company event contracts, those venues can absorb the product line into frameworks they already operate, co-opting rather than destroying the category. Citadel, a major participant in both traditional and event-based markets, may be positioning for exactly that outcome. A compromise path is also worth flagging. The SEC could offer a limited testing or exemptive framework β€” a sandbox in exchange for jurisdiction. That would preserve innovation space while pulling listed-company contracts into the SEC's field of view. It is the most likely de-escalation scenario, and it would still favor capitalized platforms able to staff a supervised pilot. There is a further layer that platforms consistently underestimate: the states. When federal jurisdiction is unsettled, state regulators move first. Several states already police event contracts under gambling statutes, and if the federal boundary stays ambiguous, the result is federal uncertainty layered on state enforcement. A platform can be CFTC-approved, SEC-doubted, and state-banned simultaneously β€” three different legal characters attached to one instrument. That fragmentation is not temporary; it is the natural state of a category that no legislature actually designed. The monitoring problem, though, is harder than the registration problem. Equity-linked event contracts require securities-grade surveillance, but the analytical core β€” deciding whether a piece of information is "material" to an issuer β€” resists automation. Materiality under securities law is contextual and judgment-intensive. No off-the-shelf RegTech solves it. The realistic near-term answer is human-plus-machine review, which means this product line stays labor-heavy and expensive. In 2017, leading the post-incident audit of the Parity wallet, I reviewed more than 400 ERC-20 contracts against a checklist designed to catch reentrancy and standardization failures before launch. The discipline that mattered was not spotting the exploit; it was refusing to let a contract ship until every risk control was verified. Product classification demands the same posture. A contract should not reach a live order book until its legal character is settled β€” not after. We do not predict the wave; we engineer the hull. In 2024, building compliance frameworks for a Hong Kong digital asset fund after the spot Bitcoin ETF approval, I cut onboarding time by roughly 60 percent by automating KYC and AML checks. The gain did not come from forecasting the market. It came from engineering the process so the firm could absorb institutional flows the moment the door opened. The same principle applies here: platforms that pre-build dual-regime compliance will capture flow when the SEC finally speaks; those that wait will be locked out. The deeper point is that event contracts expose how U.S. financial law handles novelty. Congress built a two-agency derivatives framework around products that existed in 2010; anything invented afterward falls into the seams. Self-certification was an administrative shortcut for commodity-style products, not a jurisdictional solvent. Stretched across securities, the seams become stress fractures β€” and stress fractures are where the next enforcement cycle will concentrate. The consensus reads Citadel's move as defensive β€” a market maker trying to avoid exposure to unregistered securities. The counter-intuitive read is that the move is offensive, and that regulatory uncertainty is being weaponized rather than feared. Consider the incentive structure. If the SEC declines to act, nothing changes and Citadel loses nothing. If the SEC asserts jurisdiction, the listed-company event-contract business shifts into a regime that requires registration, surveillance, and capital. Citadel can afford all three. Most of its would-be competitors in that niche cannot. The opacity of the current boundary β€” the same ambiguity that makes platforms nervous β€” is precisely what lets a well-capitalized incumbent shape the eventual rule in its favor. Kalshi established that the CFTC cannot freely block; it did not establish that the SEC is out. That residual gap is not a bug for Citadel. It is the point. The blind spot in most coverage is to treat this as a fight between prediction markets and regulators. It is a contest over who writes the product specification. The party that defines the classification dictates the cost of entry β€” and the cost of entry is the moat. We do not predict the wave; we engineer the hull. Watch three signals over the next twelve to eighteen months. First, whether the SEC issues conceptual guidance or opens a rulemaking on whether listed-company event contracts are securities. Second, whether platforms pre-emptively de-equitize their product lines. Third, whether Congress moves to clarify a division of labor that Dodd-Frank never anticipated. The window before the SEC speaks is the window in which product architecture β€” and competitive position β€” gets decided. The question is not whether event contracts survive. It is who can afford to be in them once the boundary is drawn β€” and who has the hull to take the crossing.