EST · MMXXVI
Home/Clients/Legal Counsel for Web3 Startups: Legal Counsel for Crypto Firms
Token Offerings & Securities

Legal Counsel for Web3 Startups: Legal Counsel for Crypto Firms

Legal Counsel for Web3 Startups. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Legal Counsel for Web3 Startups: Legal Counsel for Crypto Firms

A token launch that crosses the wrong jurisdictional line can convert a product release into an unregistered securities offering overnight. For Web3 startups, the legal question is rarely one issue in isolation. It is a stack: how the token is classified, which regulatory regime applies to that classification, what the licensing obligation looks like in the markets where users sit, and whether the banking and tax treatment compound or neutralize the exposure. Token offerings and securities law sit at the center of that stack, and the classification analysis must happen before the whitepaper is drafted – not after. This page maps the legal lifecycle of a Web3 startup, identifies where each risk bites hardest, and explains how OBOLUS advises founders and general counsel through it.

Why Token Classification Is the First Decision, Not a Later One

Token classification determines every subsequent legal obligation a Web3 startup faces. Get it wrong and the downstream consequences range from forced restructuring to regulatory enforcement. The analysis turns on the substance of rights the token confers, not the label applied in the marketing deck or the whitepaper.

The dominant analytical error we see in practice is treating the classification question as a one-jurisdiction exercise. A token distributed to users in the EU, the UK, Singapore and the UAE is simultaneously subject to MiCA (the EU Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities), the FCA's cryptoasset financial-promotion rules in the UK, MAS classification under Singapore's Payment Services Act, and VARA's activity-based framework in Dubai. Each regime approaches the security/utility divide differently.

Under MiCA, the classification splits into three categories: asset-referenced tokens (ARTs), e-money tokens (EMTs), and "other" crypto-assets. An ART or EMT triggers issuer-authorisation obligations and reserve requirements. Tokens that fall outside those two buckets face lighter whitepaper obligations – but only if they are not also securities under local law. That "but" does a great deal of legal work. A token that looks like a utility token in Amsterdam may look like a security to the SEC, the SFC in Hong Kong, or FINMA in Switzerland, depending on the rights it confers and the manner of its distribution.

In our practice, we assess classification against the economic substance of the instrument: the rights to profit, governance, redemption, or income that the token encodes, not the name given to it. A utility label on a whitepaper does not settle the legal classification anywhere that matters.

How Should a Web3 Startup Structure Its Legal Entity?

The right entity structure for a Web3 startup depends on where the token sits in the regulatory stack and where the business intends to generate revenue. There is no universal answer, but there are clear patterns tied to the token's legal character.

Startups issuing tokens that are unlikely to be classified as securities in any major market frequently use a foundation model – a non-profit foundation in Switzerland, the Cayman Islands, or the BVI holding the protocol IP and issuing the token, alongside an operating company handling commercial services. FINMA's token taxonomy (payment, utility, and asset tokens) provides a relatively developed framework for that analysis in Switzerland. The BVI FSC and the Cayman CIMA each offer their own registration tracks for the service-company layer under the applicable VASP regimes.

Where the token carries rights that could be read as securities interests – particularly governance tokens conferring economic entitlement, or tokens backed by real-world assets – the entity design must account for that characterization from the start. Domiciling the issuer in a jurisdiction that has not yet adopted a clear token-securities regime does not remove the exposure; it simply shifts enforcement risk to the jurisdictions where the token is offered or traded.

The cross-border reality is straightforward: the entity sits in one place, the users are everywhere, and the banking lives somewhere else. Each of those three locations generates its own set of legal obligations. We structure them as a single mandate. The formation decision and the licensing question are the same decision, made at the same time.

If you are at the entity-design stage and the token is part of the plan, contact OBOLUS before the structure is locked in. The cost of restructuring after a classification opinion or a regulator inquiry is substantially higher than building the right structure initially. For a scoped assessment of your formation and token design, contact OBOLUS at info@oboluslaw.com.

What Licensing Does a Web3 Startup Actually Need?

Most Web3 startups need at least one regulated licence, and many need several across different jurisdictions. The obligation follows the activity and the user base, not the company's registered address.

Operating an exchange, providing custody, running a lending facility, or offering investment advice over digital assets triggers licensing obligations in virtually every developed market. The specific requirement varies: a CASP authorisation (crypto-asset service provider) under MiCA for EU-facing services; a VARA licence in Dubai for mainland UAE activities; a Digital Payment Token (DPT) service licence from MAS in Singapore; a VATP licence from the SFC in Hong Kong; and AML registration from the FCA in the UK. Operating without the applicable licence in any of these markets is an enforcement risk, not a compliance grey area.

For early-stage Web3 startups, the licensing decision is often shaped by banking as much as regulation. EU CASP authorisation unlocks passporting across the EU/EEA – one authorisation, access to the bloc – but the application process and capital requirements vary in substance by activity category. Lithuania has historically been a faster EU entry point for VASP and now CASP applications during the MiCA transition. Malta's MFSA operates its VFA framework as the MiCA transition continues. The AIFC in Kazakhstan, supervised by the AFSA, operates a common-law regime that offers a distinct channel for digital-asset trading facilities and custody operations in the Central Asian and CIS market.

The mistake we see most often at this stage is selecting a jurisdiction for reasons of speed without accounting for where the banking will live, whether passporting rights extend to the actual user base, and whether the licence category covers all the activities the business actually performs. A licence that covers advisory but not custody, or exchange but not lending, leaves gaps that regulators will find.

How Does a Regulated Token Offering Work in Practice?

A regulated token offering under MiCA requires an approved whitepaper before any tokens are offered to the public. The whitepaper must satisfy ESMA-prescribed disclosure requirements covering the issuer, the project, the token's rights and obligations, the underlying technology, and the risks. It must be notified to the competent national authority before publication. For ARTs and EMTs, the regime is stricter: issuer authorisation, reserve requirements and redemption right obligations apply before distribution begins.

Outside the EU, the disclosure and approval requirements differ. FINMA in Switzerland requires a FINMA enquiry for any offering that may involve securities; the substance-based assessment of the token rights drives the outcome, and a legal opinion supporting the characterization is standard. Under the Singapore Payment Services Act, MAS licensing is required before DPT services are offered, and the financial-promotion rules bite on the marketing side before the service itself launches. The SFC in Hong Kong applies a comparable gatekeeping function to token offerings through its VATP licensing regime.

One area that consistently generates complexity is the treatment of pre-sale instruments – SAFTs (Simple Agreements for Future Tokens) and convertible notes with token rights. In several major jurisdictions, the SAFT itself may be a security even if the underlying token is not. We advise startups to treat the pre-sale documentation with the same analytical rigor applied to the token classification itself.

In a recent matter, a startup had completed a private pre-sale round using documentation drafted without legal advice. By the time the public offering was being prepared under MiCA, it became apparent that the pre-sale instruments had been offered to EU retail investors without the required whitepaper. We restructured the offering, re-engaged the affected investors, and brought the documentation into compliance ahead of the public launch. The whitepaper was published on schedule. No regulatory action was taken.

What AML and Travel Rule Obligations Apply to a Web3 Startup?

AML and counter-terrorist financing compliance under the FATF framework applies to virtually every Web3 startup that handles transfers of value on behalf of users. The Travel Rule – the obligation to pass originator and beneficiary information with a virtual-asset transfer – is now implemented or in the process of implementation in Singapore, the UK, the EU, Hong Kong, Switzerland, and a growing number of other jurisdictions.

For token issuers, the AML obligation depends on the nature of the service. Pure token issuance without ongoing transfer services may sit outside the direct Travel Rule scope in some regimes. Operating an exchange, a custodian wallet, or a transfer facility brings the startup squarely within it. The data threshold triggering the Travel Rule obligation varies by jurisdiction and should be assessed against each market the platform serves.

A common gap in early-stage compliance programs is that the AML policy is written for the jurisdiction of incorporation, not for the jurisdictions of the user base. A startup incorporated in the BVI but serving users in the EU, UK and Singapore faces AML obligations imposed by each of those markets' supervisory authorities – not by the BVI alone. The BVI FSC's VASP Act 2022 sets the local baseline; it does not displace the extraterritorial reach of MiCA's AML integration, the FCA's MLR requirements, or MAS expectations. We build compliance programs that address the full perimeter.

If your AML program was built for one jurisdiction but your user base spans several, a gap assessment is overdue. To map the compliance obligations across your actual user footprint, write to OBOLUS at info@oboluslaw.com.

Decision Matrix: Which Legal Package Fits Your Stage?

The right legal mandate for a Web3 startup shifts as the business matures. These four profiles capture the most common configurations we advise on.

Profile A – Pre-launch, token in design: The primary need is a classification opinion, an entity structure recommendation, and a jurisdiction selection that accounts for the token type, the expected user geography, and the banking environment. The timeline for this work is typically a matter of weeks. The key risk at this stage is locking in an entity structure before the token classification is settled, which forces restructuring at a significantly higher cost later.

Profile B – Token offering imminent (MiCA scope): The mandate expands to whitepaper drafting and review, competent-authority notification, and legal opinions on the classification of any pre-sale instruments. If the token has ART or EMT characteristics, issuer authorisation must begin well before the offering date. The timeline for CASP authorisation and whitepaper review in the EU varies by member state and activity category. Starting this process late is the single most common reason for delayed launches.

Profile C – Post-launch, multi-market operation: The focus shifts to ongoing compliance: AML/CFT program maintenance, Travel Rule implementation, licensing in additional jurisdictions as the user base expands, and banking relationship management. Many startups in this category also face their first regulatory correspondence – licensing queries, AML supervision visits, or financial-promotion compliance notices. We act as standing counsel for businesses at this stage.

Profile D – Token restructuring or enforcement response: Where a prior launch was conducted without adequate legal advice, or where a regulator has opened a supervisory inquiry, the mandate involves a rapid assessment of exposure, a remediation plan, and representation before the relevant authority. The DIFC Courts, England and Wales, and Singapore courts are the principal forums where asset-related disputes arising from token projects are litigated. Speed matters; the first 48 hours of a regulatory contact or a dispute often determine the available response options.

How Do Banking and Tax Interact With a Token Structure?

Banking for Web3 startups remains one of the highest-friction points in the legal lifecycle. A token structure that is legally coherent and regulatory-compliant can still fail at the banking stage if the entity and activity profile do not align with the risk appetite of accessible financial institutions.

The practical reality is that most mainstream banks in the EU, UK and Singapore apply enhanced due diligence to crypto-facing businesses regardless of licensing status. A licensed CASP under MiCA faces fewer barriers than an unlicensed entity – but "fewer" is not "none." We work through the banking question as part of the initial structuring mandate, not as an afterthought. Jurisdiction selection is partly a banking decision.

On the tax side, the treatment of token issuance proceeds, staking rewards, and token-for-services arrangements varies significantly across jurisdictions. Most of the major crypto hubs have published guidance, but the guidance is not uniform and the interaction between the token's legal classification and its tax treatment can produce unexpected results. A token characterized as debt for accounting purposes, a security for regulatory purposes, and a utility asset for tax purposes may satisfy each analysis individually while creating structural incoherence that surfaces during due diligence or an audit. We assess these questions in parallel, not in sequence.

Does a Utility Label on the Whitepaper Settle the Classification?

A common assumption among early-stage founders is that labeling a token as a utility token in the whitepaper resolves the classification question. It does not, in any jurisdiction that matters. Regulators and courts in the EU, the UK, Singapore, Hong Kong, Switzerland, and the United States assess the economic substance of the instrument. The marketing label is noted; it is not determinative.

The classification analysis asks what rights the token confers, how those rights operate in practice, and whether the typical purchaser acquires the token in expectation of a profit derived from the efforts of others. If the answer to that last question is yes, the token has characteristics that most major regimes treat as indicative of a security interest – regardless of what the whitepaper calls it. Under MiCA's ART and EMT tests, the question is whether the token is designed to maintain a stable value or is backed by a fiat currency or basket of assets; neither analysis cares about the utility label.

We assess classification against the full matrix of rights encoded in the token, the distribution mechanism, the offering structure, and the jurisdictional reach of the offering. That assessment drives the legal opinion, the whitepaper structure, and the entity and licence design. It is the starting point of every token engagement we take.

Related at OBOLUS

FAQ

Is my token a security?

No single factor settles the question. The analysis examines the economic substance of the rights the token confers: profit entitlement, governance control, redemption rights, and whether purchasers expect returns from the issuer's or a third party's efforts. This assessment must be run separately against each jurisdiction where the token will be offered or traded, as the security/non-security threshold varies between MiCA, the FCA regime, MAS, the SFC, FINMA, and US securities law. A classification opinion should precede any public or private offering.

Do I need a MiCA whitepaper?

If you are offering a crypto-asset to the public within the EU or EEA and the token does not qualify as a financial instrument under MiFID II, a MiCA whitepaper is required before the offer is made. The whitepaper must be notified to the relevant national competent authority prior to publication. ART and EMT issuers face additional obligations beyond the whitepaper, including issuer authorisation from the relevant authority and compliance with reserve and redemption requirements under the applicable MiCA provisions.

How should an airdrop be structured legally?

An airdrop of tokens with economic value may constitute a public offer in several jurisdictions, triggering whitepaper, financial-promotion, or AML obligations depending on the mechanism and recipient profile. The risk is highest where the airdrop is conditional on an action (a "conditional airdrop"), where recipients are in MiCA-regulated territories, or where the token itself has characteristics that make it an ART or EMT. Structure should be assessed against the token classification and the geographic scope of distribution before the airdrop is executed.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise Web3 startups, exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams, and we assess every classification question against the substance of rights – not the marketing label. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – advises Web3 startups and protocol teams on token structuring, classification opinions, and the intersection of smart-contract architecture with securities and licensing obligations across multiple jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours