How to Defend an SEC Crypto Subpoena: A Guide for Founders

If you just received an SEC subpoena tied to a crypto matter, your first move is to preserve every relevant record, stop any routine deletion, and contact counsel who has actually handled SEC crypto investigations before you respond to anyone at the agency. Do not answer questions informally, do not send documents on your own initiative, and do not assume the subpoena is a formality. It isn’t. Below is the checklist to work through in the first hours after service.

  • Read the subpoena in full. Note the return date, the custodians named, and the exact date range requested. Missing the deadline creates its own problem separate from the underlying investigation.
  • Preserve everything now. Suspend auto-delete settings on messaging apps, halt routine document retention purges, and image relevant devices before anyone touches them.
  • Say nothing you don’t have to. Do not volunteer additional records, explanations, or informal statements to SEC staff without counsel present.
  • Call specialized counsel today. General business attorneys rarely know how blockchain evidence, custody structures, or the Howey test interact with subpoena scope.

Pro Tip: Preserve native files, not screenshots. A screenshot of a Slack thread strips out the metadata, timestamps, and message IDs that forensic examiners and courts rely on to authenticate evidence.

A subpoena is a demand for evidence, not a verdict. Receiving one does not mean the SEC has concluded you violated securities law. Treating it that way, however, from hour one, is what separates a contained matter from a prolonged enforcement fight.

Key Takeaways

Successfully defending an SEC crypto subpoena depends on preserving native evidence immediately, engaging crypto-specific counsel before any contact with SEC staff, and narrowing scope through privilege review and negotiation rather than outright refusal.

Point Details
Preserve before anything else Stop auto-delete, image devices, and export native files within hours of service, not days.
Silence beats improvisation Avoid informal conversations with SEC staff until counsel has reviewed the subpoena’s scope.
Privilege requires structure Route document review through outside counsel from day one to avoid inadvertent waiver later.
Classification drives exposure Howey-test analysis of the underlying asset shapes the entire scope of an SEC crypto investigation.
Murphy’s Law handles urgent intake Murphy’s Law Crypto runs preservation, forensics, and scope negotiation as a standard part of subpoena defense engagements.

Primary Sources for SEC Subpoena Procedure

For procedural verification, bring these directly to your attorney rather than relying on secondhand summaries:

This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

Table of Contents

What an SEC Crypto Subpoena Actually Demands

The SEC issues two kinds of subpoenas. A subpoena duces tecum compels production of documents, communications, and data. A subpoena ad testificandum compels a person to appear and testify under oath. Crypto matters frequently involve both, often served on the same entity within weeks of each other.

In practice, the agency’s document requests tend to cover a predictable set of material:

  • Email and internal messaging (Slack, Telegram, Discord) tied to token sales, marketing, or investor communications
  • Exchange account records, trading history, and withdrawal logs
  • Wallet addresses, custody agreements, and multisig signer records
  • Smart contract source code, deployment history, and audit reports
  • Device images and forensic metadata from executives or key employees

Receiving a subpoena launches a formal SEC crypto investigation, but it does not, by itself, establish that any securities law was broken. The SEC’s investigative process exists specifically to determine that, and the outcome depends heavily on how the response is handled from the outset.

How Does the SEC’s Crypto Investigation Process Work?

Most matters start quietly. Staff sends informal requests for information, sometimes framed as a routine inquiry, before any formal order exists. If staff believes there’s enough smoke, the SEC issues a formal order of investigation, which is the document that actually authorizes subpoenas.

From there, the sequence generally looks like this:

  • Informal inquiry or voluntary request for documents
  • Formal order of investigation issued internally (not always disclosed to the subject)
  • Subpoenas for documents and, often, testimony under oath
  • Staff evaluates evidence and drafts a recommendation
  • Commission decides: close the matter, negotiate a settlement, or authorize enforcement action

The SEC’s Crypto Task Force now coordinates much of this work, focusing staff attention on classification questions and registration pathways, which means crypto subpoenas increasingly get routed to examiners with specific digital-asset experience rather than generalists.

One detail catches people off guard: if you refuse to comply with a subpoena, the SEC cannot simply force the issue on its own. Under its enforcement guidance, staff must go to federal court and obtain a judicial order compelling compliance. That step takes time, but it also means a company that stalls without a legitimate legal basis is usually just delaying an outcome that arrives anyway, with a judge now watching.

What to Do in the First 24 to 72 Hours

The early window after service is where most defensible positions are won or lost. Work through these in order.

  1. Read the subpoena and calendar the deadline. Confirm the exact custodians, systems, and date ranges named. Ambiguity here is a negotiating point later, not now.
  2. Issue a legal hold immediately. Every employee, contractor, and system named or plausibly relevant needs written notice to stop deleting anything.
  3. Isolate native files before anyone edits them. Wallet exports, exchange transaction ledgers, and device images need to be pulled and preserved in their original format.
  4. Preserve on-chain records with provenance intact. Transaction hashes, block heights, and wallet signatures matter for authentication later; export directly from the ledger rather than copying figures by hand.
  5. Loop in internal compliance and legal leads. Whoever manages your data retention policy needs to know a hold is in effect before the next automated purge runs.

A few operational details get missed constantly. Disappearing-message settings on Telegram and Signal need to be turned off the same day, not the same week, because auto-delete after a hold is arguably worse than not preserving in the first place. Cloud backups and third-party vendor logs (custodians, cloud infrastructure providers, payment processors) need their own preservation notices. And someone should keep a written log of every preservation step taken, with dates, because that log becomes evidence of good faith if the SEC or a court ever questions your production later.

Do not talk to SEC staff informally “to clear things up.” Every conversation, even a friendly one, can become part of the record. Do not sanitize, reformat, or “clean up” files before production; altering records after a subpoena is served can create exposure that has nothing to do with the underlying investigation.

Pro Tip: Bring in a blockchain forensics vendor early, before you produce anything. A qualified vendor can create authenticated, reproducible exports of on-chain data and, if your data volume is large, help negotiate rolling productions with SEC staff so you’re not dumping everything at once under a single deadline. For general guidance on responding to the initial inquiry, see how to respond to a crypto regulatory inquiry.

Can You Use Privilege or the Fifth Amendment?

Two legal protections shape almost every SEC subpoena response, and understanding what they actually cover, and what they don’t, is where inexperienced counsel gets clients into trouble.

Attorney-client privilege protects confidential communications made for the purpose of obtaining legal advice. Work-product protection covers materials prepared in anticipation of litigation. Neither is automatic. Documents withheld on privilege grounds typically must be logged on a privilege log describing each item generally enough for the SEC to evaluate the claim without revealing its content.

The Fifth Amendment protects individuals, not companies, against compelled self-incrimination. It applies question by question during testimony, not as a blanket refusal to appear. A witness can answer some questions and invoke the privilege on others, though invoking it broadly during a deposition often draws its own scrutiny and strategic tradeoffs worth discussing with counsel before the session starts.

Beyond privilege, several procedural tools shape how a subpoena actually gets resolved:

  • Meet-and-confer sessions with SEC staff, often the fastest way to narrow an overly broad request
  • Negotiated scope, trimming custodians or date ranges that sweep in irrelevant material
  • Rolling productions, spreading a large data set across multiple deadlines instead of one crushing deadline
  • Protective orders, limiting how produced material can be used or disclosed
  • Motions to quash, filed in federal court when a subpoena is genuinely overbroad, unduly burdensome, or improperly issued

The typical flow runs from counsel review, to a privilege assessment, to negotiated narrowing, and only then to either a limited production or a formal court motion if negotiation fails.

Pro Tip: Run privilege review as an outside-counsel-directed process from day one, not an afterthought bolted onto document collection. Curating privilege calls after the fact, once non-lawyers have already read and tagged files, tends to create waiver arguments that didn’t need to exist. For a related scenario, the firm’s guide on defending SEC whistleblower complaints covers similar objection and privilege-log mechanics.

Why Crypto Evidence Changes the Defense Strategy

Standard subpoena defense doesn’t fully translate to crypto matters, because the underlying facts, custody structures, token mechanics, on-chain data, raise questions a generalist litigator simply hasn’t dealt with before.

Classification is the first fight. Whether a token or program counts as a security under the Howey test determines the entire scope of exposure. The SEC’s 2026 interpretive release walks through how staff analyze different crypto asset categories, and that framework now shapes how subpoenas get drafted and how aggressively staff pursues certain theories.

Custody role matters enormously. A custodial exchange holding customer assets faces different recordkeeping obligations than a protocol developer who never touched user funds, or a liquidity provider operating a smart contract nobody controls unilaterally. Counsel needs to establish early which role your business actually occupied, because the SEC’s theory of the case often assumes more control than the facts support.

On-chain evidence needs to be handled like evidence, not like a screenshot. Preserve native ledger exports with transaction provenance intact rather than pasting a wallet balance into a memo. Chain-state snapshots and native wallet exports carry authentication value that a screenshot simply cannot replicate.

Hands holding evidence bag with USB drive for blockchain export

The Genesis and Gemini matter is the clearest illustration of how this plays out. The case shows how the agency frames a lending or “earn” product, one that promises a return and depends on managerial effort by the issuer, as a securities offering regardless of what the product is called internally.

Pro Tip: Use a forensics vendor with actual courtroom experience, not just a blockchain analytics dashboard. Reproducible, court-ready chain evidence needs to survive cross-examination, not just look convincing in a slide deck.

How Long Does an SEC Subpoena Investigation Take?

There’s no fixed clock, but the shape of the timeline is predictable. Informal inquiries can run for months before a formal order is even issued. Once subpoenas go out, staff typically works through document review and testimony over a period that can stretch well beyond a year for anything involving substantial trading data or multiple custodians. The SEC’s enforcement manual outlines the procedural steps staff follows, and the Cyber, Crypto Assets and Emerging Technology unit’s public actions list shows a steady stream of crypto matters moving through this pipeline.

Outcomes range widely:

  • No action, if staff concludes there’s insufficient evidence
  • A negotiated settlement, often involving disgorgement and civil penalties without an admission of wrongdoing
  • An administrative proceeding before an SEC judge
  • A civil suit filed in federal court, seeking injunctions, penalties, and disgorgement
  • In rare, aggravated cases, referral for criminal investigation

Noncompliance carries its own risk profile. The SEC cannot hold you in contempt on its own; it must first obtain a court order compelling production, and contempt exposure only attaches after that order exists and is violated. But getting to that point is itself reputationally damaging and often triggers business disruption, lost banking relationships, and investor concern, long before any court weighs in.

Cost drivers to budget around: data volume and number of custodians tend to dominate the bill, followed by forensics vendor fees for chain-of-custody work, deposition preparation, and any motion practice if negotiation with staff breaks down. A single-founder startup with clean records faces a very different cost curve than a multi-entity exchange with years of trading data spread across custodians.

How Murphy’s Law Crypto Defends SEC Crypto Subpoenas

How Murphy's Law Crypto Defends SEC Crypto Subpoenas — overview diagram

Defending against an SEC crypto subpoena calls for a workflow built specifically around digital-asset evidence, not a generic litigation playbook retrofitted for crypto. Murphy’s Law Crypto structures every engagement around five phases: immediate incident response and preservation, privilege review, negotiated scope narrowing with SEC staff, blockchain forensics to authenticate on-chain evidence, and, where a matter escalates, deposition preparation and litigation strategy.

The firm was founded by Liam Murphy, Esq., a Penn Law graduate who previously practiced at Paul Hastings, Selendy Gay, and McKool Smith before litigating some of the most closely watched matters in the crypto industry, including cases touching Celsius, Terraform Labs, and BitMEX. That courtroom background matters in an SEC subpoena fight specifically because staff attorneys negotiate differently with counsel who has actually tried crypto cases before a judge, versus counsel who has only handled corporate filings.

Regulatory defense in crypto isn’t about stalling. It’s about knowing which fights are worth having, narrowing scope where the law supports it, and building an evidentiary record that holds up if the matter ever reaches a courtroom.

For prospective clients, engagement typically moves through intake, an immediate preservation protocol, scope negotiation with SEC staff, a structured production plan, and litigation representation if the matter escalates. Before an initial call, gather the subpoena itself, a list of custodians and systems involved, and a rough sense of your data volume. Visit the firm’s services page to see the full range of regulatory defense and litigation support available.

What Ten Years of Crypto Litigation Teaches About Subpoena Defense

The pattern repeats across nearly every crypto subpoena matter: the companies that get hurt worst aren’t the ones with the weakest legal position, they’re the ones that treated preservation as an IT afterthought. I’ve watched founders hand over screenshots because pulling native exports felt slower, then spend months explaining gaps in metadata that a forensic vendor could have closed in a day. Chain-of-custody documentation feels bureaucratic until the moment someone questions whether a wallet export is authentic, and by then it’s too late to reconstruct.

The other recurring mistake is waiting to bring in specialized counsel until after informal SEC contact has already happened. Whatever gets said in that first “informal” conversation rarely stays informal.

Pro Tip: An internal investigation directed by outside counsel, launched the moment a subpoena arrives, protects far more than a post hoc privilege review ever can. Privilege is easier to preserve than to reclaim.

Get Emergency Representation for an SEC Crypto Subpoena

Murphy’s Law Crypto is built for exactly this moment: a founder, exchange, or executive who just got served and has hours, not weeks, to get preservation right. Unlike a general business litigation shop billing by the hour while someone gets up to speed on blockchain forensics, Murphy’s Law already runs the on-chain evidence, custody, and Howey classification analysis as a standard part of every crypto subpoena engagement, so you’re not paying to educate your own lawyer.

Common triggers for urgent intake include a looming production deadline with preservation not yet locked down, high-volume data spread across multiple exchanges or custodians, or a request for executive testimony that needs prep before anyone sits down with SEC staff. The firm handles urgent, time-sensitive subpoenas as a matter of course.

Before your consult, gather the subpoena itself, a list of custodians and systems it touches, and any prior communication with SEC staff. Then reach out through the firm’s crypto fraud recovery and legal options page or visit Murphyslawcrypto directly to start an intake conversation.

Sources

FAQ

Does the SEC investigate crypto companies and individuals?

Yes. The SEC’s Cyber, Crypto Assets and Emerging Technology unit actively pursues crypto-related matters, and the agency’s crypto enforcement actions list shows a steady volume of ongoing cases.

Is an SEC subpoena legally enforceable?

An SEC subpoena carries legal force, but if a recipient refuses to comply, the agency must ask a federal court to issue an order compelling compliance rather than enforcing it unilaterally, according to the SEC’s own investigative guidance.

Did the SEC sue Gemini and Genesis over crypto lending?

Yes. The SEC’s complaint against Genesis and Gemini alleged the Gemini Earn program involved unregistered securities offered to roughly 340,000 investors, illustrating how the agency treats crypto lending and “earn” products.

Does the SEC consider cryptocurrency a security?

It depends on the asset and the transaction. The SEC’s 2026 interpretive release applies the Howey test case by case, meaning some tokens or programs qualify as securities while others do not, depending on how they’re structured and marketed.

Should I hire a specialized crypto defense attorney instead of general counsel?

Specialized counsel understands on-chain evidence, custody structures, and Howey classification issues that shape scope negotiations from the outset. Murphy’s Law Crypto structures its subpoena defense work specifically around these crypto-specific evidentiary and legal questions.

Contact Liam Murphy

Fill out the form below, and we will be in touch shortly.
Tell us Who You Are
How Can We Help?