What Recent Enforcement Actually Tells Operators
Regulators across every major financial hub have shifted from licensing guidance to enforcement action. Operating a crypto exchange (a platform that executes spot or derivative trades in digital assets for customers) without the right regulatory authorisation no longer draws a warning letter. It draws asset freezes, banking terminations and, in the most serious cases, criminal referrals. The lesson recent enforcement cycles teach is not that compliance is expensive. It is that non-compliance has become existential.
This analysis examines what regulators are targeting, how the cross-border reality of digital-asset businesses complicates the licensing calculus, and what a defensible licence structure looks like heading into the current regulatory cycle. We draw on our cross-border practice to map the enforcement signals that matter most for operators making licensing decisions now.
Why Enforcement Is Escalating Now
Enforcement is accelerating because regulators in the leading hubs have completed their legislative work and are now executing against it. MiCA (the EU's Markets in Crypto-Assets Regulation), the VARA regime in Dubai and the SFC's VASP licensing regime in Hong Kong all moved from consultation to live supervision within a concentrated period. That convergence means the gap between "operating in a market" and "licensed in a market" is now both measurable and actionable.
In our practice, we have seen a consistent pattern: enforcement actions cluster around exchanges that built user bases in regulated markets while relying on an offshore registration that was never designed for that scope. The Bank of Lithuania, the FCA in the United Kingdom and MAS in Singapore have each issued public statements making clear that substance in the target market – not just a legal entity in a permissive registration state – determines whether an operator is caught by the local regime.
The structural reason is jurisdiction-by-jurisdiction nexus analysis. Where your users are located, where their funds are held and where the exchange matching engine operates are three separate questions. Each one can trigger a licensing requirement independently of the others. Recent enforcement confirms that regulators are examining all three.
For a scoped assessment of your current licence exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard enforcement pattern. Your facts – the entity structure, the user geography, the banking stack – change the analysis materially.
What Regulators Are Actually Targeting
Recent enforcement actions share a consistent target profile: platforms that accept customers from a regulated jurisdiction without holding the authorisation that jurisdiction requires. The activity-based framing of modern VASP regimes means that an operator does not need a physical presence in a market to be caught. Providing access to exchange services over the internet to residents of the EU, the UAE, Singapore or the United Kingdom is enough.
Under MiCA, a CASP (crypto-asset service provider) authorisation is required before offering exchange or transfer services to EU customers. ESMA and the national competent authorities have made clear that the transition period did not create indefinite permission to operate unlicensed. Under the VARA rulebooks applicable to mainland Dubai, exchange and brokerage activities require an activity-specific licence before any customer-facing operation begins.
Three enforcement themes recur across jurisdictions. First, unlicensed operation in the target market – the most common basis for action. Second, inadequate AML and Travel Rule controls – addressed below. Third, misleading disclosures about regulatory status, particularly where platforms describe themselves as registered or compliant without holding the relevant authorisation. That third category draws the most severe responses because it combines regulatory breach with a consumer-protection dimension.
In our cross-border advisory work, we have seen operators assume that a BVI FSC registration or a Cayman VASP Act registration satisfies the authorisation requirement in a European or Asian market. Neither does. Those offshore registrations serve a legitimate structural purpose for fund domicile and entity holding. They do not confer authorisation to offer exchange services to customers in a market governed by MiCA, the FCA regime or MAS.
The Cross-Border Licensing Problem: One Exchange, Multiple Obligations
A single crypto exchange typically has at least three distinct legal personas operating simultaneously, and each one may trigger a separate licensing requirement. The entity that holds customer assets is a custodian. The entity that executes trades is an exchange operator. The entity that moves funds between accounts is a payment service provider. Modern VASP regimes have different authorisation tracks for each of these functions, and an exchange that performs all three functions under one corporate vehicle may need to satisfy all three regulatory tests.
This is the cross-border licensing problem in its most concentrated form. MAS in Singapore distinguishes between a standard payment institution and a major payment institution based on transaction volumes, with different capital and safeguarding obligations at each level. The SFC in Hong Kong imposes dedicated requirements for a licensed VATP (virtual-asset trading platform) that go beyond what a simple VASP registration in another jurisdiction satisfies. VARA in Dubai structures licences around the specific activity – custody, exchange, advisory, lending – so an operator conducting multiple activities needs to authorise each one.
The cross-border reality compounds this. An exchange licensed under MiCA via a Lithuanian or Maltese CASP authorisation can passport across the EU/EEA. But that passport does not extend to Hong Kong, Singapore or the UAE. An operator serving all three markets needs separate authorisations, or a carefully constructed exemption analysis for each market, supported by legal opinion. We regularly advise operators on how to sequence those authorisations so that the entity structure does not create unnecessary capital duplication or banking friction.
AML and the Travel Rule as an Enforcement Lever
AML deficiencies are now the enforcement entry point for regulators who lack direct sanctioning power over an unlicensed foreign platform. The Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary information alongside a virtual asset transfer) is increasingly the specific pressure point.
Under the applicable VASP provisions in most FATF member jurisdictions, a licensed exchange is required to collect and transmit customer data at the point of transfer, and to refuse or suspend transfers from counterparty VASPs that cannot demonstrate equivalent compliance. That last requirement is the lever. A regulated exchange that receives transfers from an unlicensed platform faces its own regulatory risk. The practical result is that unlicensed platforms find themselves progressively cut off from the on-ramp and off-ramp relationships that make their service viable.
In our practice, we have watched this dynamic accelerate over the past two years. Banks and payment processors that service exchanges are themselves subject to AML oversight. When a correspondent relationship with an unlicensed exchange is discovered during a regulatory examination of the bank, the bank terminates the relationship – sometimes without notice – to protect its own regulatory standing. The exchange then loses fiat rails with very little legal recourse, because the bank's decision was regulatory self-protection, not contractual breach.
The answer is to obtain the authorisation that makes the exchange a recognized counterparty before the banking relationship is threatened. Retroactive applications filed under regulatory pressure rarely receive the same treatment as applications made proactively.
Decision Matrix: Which Operator Profile Needs Which Authorisation
Licence strategy is not uniform across operator types, and the right entry point depends on the exchange's user geography, product scope, and stage of build. Here is how we frame the analysis for the four most common profiles we advise.
Profile A – EU-focused spot exchange, retail and institutional customers. The anchor authorisation is a CASP licence under MiCA, typically pursued through a member state with an established supervisory track record. Passporting then covers the remaining EU/EEA markets. The key risk is that MiCA imposes own-funds requirements that vary by the scope of services offered, and capital must be in place before authorisation is confirmed. Timeline is a matter of months, with pre-application engagement with the NCA often shortening the formal review period.
Profile B – Dubai-based exchange targeting GCC and international institutional flow. A VARA exchange licence is required for mainland Dubai operations. The VARA rulebooks impose activity-specific capital and governance requirements. A Dubai structure does not substitute for CASP authorisation if the platform actively markets to EU retail customers – both may be needed. Timeline is governed by VARA's application process, which rewards complete and well-structured submissions.
Profile C – Singapore-licensed platform targeting Southeast Asia. The relevant authorisation is a Major Payment Institution licence under the Payment Services Act, covering Digital Payment Token services. MAS applies a robust vetting process; timeline and capital requirements vary by business model. An MAS-licensed entity does not satisfy SFC requirements for Hong Kong customers and should not be marketed as doing so.
Profile D – Offshore-registered exchange seeking to regularise its EU exposure. The most common pattern we see. The entity holds a BVI or Cayman registration that was appropriate at formation but is inadequate for the current user base. The right move is a MiCA-track authorisation in the near term, combined with a transitional user-access analysis to map which EU markets are being actively served and whether any transitional provisions apply. Delay increases the risk that the regulator acts first.
What a Defensible Licence Structure Looks Like
A defensible licence structure answers three questions before the regulator asks them: which entity holds which authorisation, which entity holds customer assets, and which entity transacts with the banking system. Each function should have a clear regulatory home.
In practice, this means separating the exchange operating entity from the custody entity in jurisdictions where custody is a separately regulated activity. Under MiCA, the provision of crypto-asset custody and administration is a CASP service category that requires specific authorisation – an exchange CASP authorisation does not automatically cover it. FINMA in Switzerland makes a similar distinction: the activity of holding assets for clients may require a banking licence or fintech licence depending on scale, not just an exchange authorisation.
The banking layer is the third element. Operators we advise routinely discover that their entity structure, even when correctly licensed, creates difficulties with correspondent banking because the entity that holds the licence is not the entity that the bank recognises as the account holder. Aligning the licensed entity with the banking entity – and ensuring that the AML/KYC posture of the licensed entity satisfies the bank's own compliance standards – is a step that is often deferred and almost always regretted when it causes a problem.
A recent matter illustrates the point. In a cross-border licensing engagement, a payments-adjacent exchange operator had obtained authorisation in one jurisdiction but conducted almost all its institutional customer activity through an associated entity in a second jurisdiction. The second entity held no licence and had no direct relationship with the authorising regulator. When the banking partner in the second jurisdiction identified the structural mismatch during its own compliance review, the operator faced a choice between an accelerated application in the second jurisdiction or losing the banking relationship entirely. We structured the application and coordinated with allied counsel in the relevant jurisdiction; the application was submitted complete and the banking relationship was preserved while the review proceeded. The margin between a managed outcome and an operational crisis was the speed of the structural analysis.
A Common Assumption: "My Offshore Registration Covers This"
A common assumption among operators approaching their first regulated market is that an existing BVI FSC or Cayman VASP Act registration functions as a global permission slip. It does not. The BVI FSC's VASP registration and the Cayman CIMA regime serve different regulatory purposes from the CASP, VATP or DPT licensing regimes in the EU, Hong Kong or Singapore.
Offshore registrations are legitimate structural tools. They provide a regulatory home for the fund management or holding function, a recognised governance framework for token issuance in some contexts, and a compliant entity for certain institutional-to-institutional transactions. What they do not provide is authorisation to offer retail exchange services in any market that has enacted its own VASP or CASP regime. ESMA, MAS, the SFC and VARA have each stated, in public guidance, that their regimes apply based on where the customer is located and where the service is directed – not where the provider is incorporated.
This matters for enforcement because regulators can act against a foreign entity's access to their market even without jurisdiction over the entity itself. The mechanism is the prohibited-activity notice, the market-access restriction or the warning list publication – all of which destroy banking relationships and institutional counterparty confidence without requiring the regulator to issue a formal sanction against an offshore entity it cannot reach.
Self-Assessment: Six Questions Before Filing an Application
Operators considering a licensing application benefit from answering six questions before engaging with any regulator. These are not a substitute for legal analysis; they are a diagnostic that identifies where the analysis needs to go deepest.
First: which jurisdictions generate more than a defined threshold of your current user base or transaction volume? Each one is a potential licensing trigger. Second: does your current entity structure separate the exchange function, the custody function and the payment function? If they are co-mingled in one entity, the capital and governance implications of each function need to be assessed together. Third: which entity is the contracting party with your banking partner, and does that entity hold the licence? Fourth: does your Travel Rule compliance programme satisfy the requirements of the jurisdiction you are applying in, not just the jurisdiction where your current registration sits? Fifth: do your marketing materials correctly describe your regulatory status in each market where you operate? Sixth: have you obtained a legal opinion on whether any exemption or transitional provision applies to your current user base in the target market?
An honest answer to all six questions typically reveals that the application-ready position is two to four preparatory steps away from where the operator currently sits. We map those steps in a scoped pre-application engagement before the formal application process begins.
If a prior application stalled or a banking relationship was terminated, a structured second read often surfaces the underlying reason. Write to info@oboluslaw.com to discuss a recovery strategy for your application or your banking stack.
Related Practices at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – end-to-end VASP and CASP authorisation strategy across 70+ jurisdictions
- Economic Substance for Licensed VASPs in Nigeria – substance requirements and ongoing compliance for African market entry
- DeFi Protocol Legal Structuring in Estonia – EU-domiciled structuring for decentralised protocol operators under MiCA transition
FAQ
How long does a crypto licence take to obtain?
Timeline varies significantly by jurisdiction, licence category and the completeness of the application at submission. In our experience, well-prepared applications in EU member states operating under MiCA typically take several months from formal submission to authorisation. More complex applications – particularly those requiring capital structure changes or cross-border entity reorganisation – take longer. Incomplete or reactive applications consistently take the longest. Pre-application engagement with the relevant regulator, where available, is the most reliable way to shorten the formal review period.
Which jurisdiction is best for licensing my crypto business?
There is no single answer. The right jurisdiction depends on the operator's user geography, product scope, institutional counterparty requirements and banking access. MiCA passporting makes an EU CASP licence efficient for operators focused on European markets. VARA suits operators building in and around the Dubai financial ecosystem. MAS fits Singapore-anchored Southeast Asian operations. For most serious operators, the answer is a primary licence in the most important target market, supported by a deliberate entity structure for other functions. We map this stack before any application is filed.
Do I need a separate custody licence?
In most leading jurisdictions, yes – or at minimum, the custody activity must be separately authorised within the CASP framework. Under MiCA, custody and administration of crypto-assets is a defined CASP service category. Under VARA, custody is a separately licensed activity. MAS similarly distinguishes safeguarding from exchange. An exchange licence that does not cover custody leaves the operator exposed if it holds client assets without separate authorisation. The answer requires a specific analysis of the applicable regime in each jurisdiction where custody is being provided.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – not after the regulator calls. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications when matters move into disputes. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Glen Sorensen, Disputes & Recovery Analyst – specialising in cross-border enforcement exposure and the structural licensing issues that drive regulatory and banking-termination risk for digital-asset operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.