EST · MMXXVI
Home/Insights/Glossary/Security Token: A Legal Guide for Digital-Asset Businesses
Token Offerings & Securities

Security Token: A Legal Guide for Digital-Asset Businesses

Security Token: A Legal Guide for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to

A security token (a digital token that confers rights equivalent to a traditional security – equity, debt, profit participation or collective investment exposure) sits at the intersection of crypto mechanics and securities law. That intersection is regulated, increasingly aggressively, across every major financial hub. Mis-classifying a token can convert a product launch into an unregistered securities offering, exposing founders, issuers and platforms to enforcement, disgorgement and, in some jurisdictions, criminal liability. This guide explains how regulators draw the line, how that line moves across borders, and what a business must do when its token lands on the wrong side of it.

What Is a Security Token, and Why Does the Label Matter?

A security token is a digital token whose economic substance – the rights it confers on the holder – is functionally equivalent to a traditional security, regardless of how the issuer labels it. The legal classification turns on substance, not marketing. A token that promises profit participation, represents a debt claim, grants equity-like governance rights, or pools investor capital toward a common enterprise is, in most regimes, a security – and the fact that it runs on a blockchain is legally irrelevant to that determination.

This matters immediately because securities are the most regulated asset class in the world. An issuer that sells an unregistered security faces the full weight of capital-markets law: mandatory disclosure, investor-protection rules, distribution restrictions, secondary-market controls, and, in the United States, the combined oversight of the SEC and CFTC plus state money-transmitter regimes. In the European Union, the same token triggers MiCA (Markets in Crypto-Assets Regulation) if it qualifies as an asset-referenced token (ART) or, in practice, the pre-existing prospectus and MiFID II regimes where the token maps to a transferable security or financial instrument.

In our practice, the first question every token issuer asks is whether their token is a utility token. The honest answer is almost always: it depends on the facts, not the whitepaper.

The process above describes the standard classification path. Your token's specific rights structure – and where you are selling it – change the analysis materially. To get a scoped assessment of your token's legal classification before launch, contact OBOLUS at info@oboluslaw.com.

How Do Regulators Classify Tokens Across Major Regimes?

Every major financial regulator applies a substance-over-label test, but each regime has its own analytical framework, and a token can be a security in one jurisdiction while falling outside that definition in another – creating genuine cross-border legal risk for any issuer with a global user base.

United States. The SEC applies the Howey test: an investment of money in a common enterprise with an expectation of profits derived from the efforts of others. The test is famously fact-intensive. A token sold in a public sale with promises of platform growth, secondary-market appreciation, or team-driven development almost invariably satisfies all four elements. The SEC has consistently treated such tokens as securities, and the CFTC may assert parallel jurisdiction over tokens it characterises as commodity derivatives. FinCEN layered anti-money-laundering obligations apply at the distribution layer regardless of securities classification.

European Union. Under MiCA, the primary security-equivalent token categories are the asset-referenced token (ART) and the e-money token (EMT). A token that references multiple assets or rights – including a basket of fiat currencies, commodities or other crypto-assets – requires ART authorisation under MiCA and is supervised by ESMA and the relevant national competent authority. Where the token maps more precisely to a transferable security under MiFID II, the prospectus regulation and MiFID II apply instead of MiCA, meaning a separate prospectus filing and potentially a full investment-firm licence for distribution. ESMA has issued technical standards and Q&A guidance to assist national competent authorities in drawing this boundary.

United Kingdom. The FCA applies the regulated activities order: does the token constitute a specified investment, including a share, debt instrument or collective investment scheme interest? Tokens with equity-like or fund-like characteristics almost always meet this test. Since the UK diverged from the EU post-Brexit, the FCA's MLR registration regime for cryptoassets does not resolve the securities question – a firm may be AML-registered and still be carrying on unauthorised regulated activity by dealing in, arranging, or advising on a security token.

Singapore. The MAS applies the Securities and Futures Act to digital tokens. A token constituting a capital-markets product – a share, debenture, unit in a collective investment scheme, or derivative – requires either an exemption or a full capital-markets licence. The MAS has published detailed guidance and is widely regarded as one of the more rules-transparent regulators for token issuers.

Switzerland. FINMA's 2018 token taxonomy – payment tokens, utility tokens and asset tokens – remains influential internationally. An asset token under FINMA's framework represents an asset or a profit right and is treated as a security for Swiss regulatory purposes, triggering prospectus and securities-dealer requirements. Hybrid tokens attract analysis under both utility and asset lenses.

Hong Kong. The SFC regulates security tokens under the existing securities framework and has clarified that tokenised securities do not create a new asset class – they are securities, with all attendant obligations. The SFC's VASP licensing regime governs exchange-layer activity but does not displace the securities regime at the issuance layer.

What Cross-Border Classification Risk Does a Security Token Create?

A token sold globally is subject to the securities laws of every jurisdiction in which it is offered, not merely the issuer's home market. This is the single most underestimated legal risk in token launches. An issuer domiciled in a MiCA-passported EU state that geo-blocks US IP addresses but still reaches US persons through VPNs, secondary exchanges or targeted Telegram groups may still face SEC enforcement on a "directed into" theory.

We regularly advise issuers who assumed that a Cayman Islands or BVI vehicle insulated them from US securities law. It does not. The relevant question is where the security was offered and sold, and to whom – not where the issuer is incorporated. The CIMA and BVI FSC regimes provide excellent structuring flexibility, but they do not constitute US exemptions.

The cross-border filing picture for a compliant security token offering is consequently complex. A Regulation S / Regulation D exemption structure addresses the US layer. A prospectus or equivalent document addresses the EU/EEA layer under MiCA or the prospectus regulation. A Singapore capital-markets exemption, a Swiss banking or securities-dealer analysis, and an SFC position paper in Hong Kong each address their own layer. Running those analyses in parallel – not sequentially – is essential. Issuers who layer them sequentially often discover that a structural decision made for one jurisdiction creates a problem in another.

In a recent cross-border matter, a token issuer had structured its offering around a Cayman foundation and assumed a utility classification globally. On review, the token's rights structure – tiered profit participation and governance votes whose value moved with platform revenue – satisfied the Howey test in the US and the asset-token definition under FINMA's guidance simultaneously. We restructured the offering terms and the distribution perimeter before launch, separating the governance mechanism from the economic rights to achieve defensible utility status in most target markets, while flagging the residual US analysis for allied counsel in that jurisdiction.

How Does a Compliant Security Token Offering Work in Practice?

A compliant security token offering (STO) follows the same fundamental architecture as a traditional securities offering, adapted for on-chain mechanics. The issuer must first establish a legally permissible offering vehicle – typically a regulated entity or a special-purpose vehicle in a recognised financial jurisdiction – and then satisfy the disclosure, registration or exemption requirements of each target market.

The process involves, at minimum: a legal opinion on token classification in each target jurisdiction; a disclosure document (prospectus, information memorandum, or MiCA whitepaper as applicable); AML/KYC onboarding for investors that meets the FATF (Financial Action Task Force) Travel Rule and the applicable jurisdiction's VASP obligations; a custody arrangement for the issued tokens that satisfies regulated custody requirements where they apply; and a secondary-market plan that accounts for the securities restrictions on resale in each jurisdiction.

Under MiCA, an ART issuer requires authorisation from its home-state national competent authority and must publish a compliant whitepaper. The whitepaper is not merely a disclosure document – it is a regulated instrument whose content, review process and ongoing update obligations are specified by ESMA technical standards. A token issuer that publishes a whitepaper for a non-ART crypto-asset is also subject to MiCA whitepaper obligations, though under a lighter-touch regime. The critical structural decision – whether the token is an ART, an EMT, a utility crypto-asset, or a MiFID II financial instrument – determines the entire regulatory path.

Operator profile determines the practical path:

Early-stage startup, EU-based, token with utility features but profit-participation economics: analysis under MiCA (ART or financial-instrument track); whitepaper preparation; possible passporting via a MiCA-authorised CASP in a fast-track EU member state; timeline varies by jurisdiction and NCA caseload.

Established platform, US-excluded offering, targeting institutional investors: Regulation S structure via Cayman or BVI SPV; Singapore capital-markets exemption; FINMA no-action letter or asset-token securities-dealer analysis for Swiss investors; SFC position in Hong Kong. Parallel timeline across four jurisdictions, typically managed through allied local counsel under a coordinating mandate.

Tokenised real-world asset (RWA) issuer – property, private equity, infrastructure: securities classification is almost certain in every target market; full prospectus or exempt offering documentation; regulated custodian or trustee; secondary trading on a licensed ATS (Alternative Trading System) or regulated multilateral trading facility. This profile carries the heaviest compliance burden and the longest timeline.

Does a Security Token Need a MiCA Whitepaper?

Whether a security token requires a MiCA whitepaper depends on which MiCA category – if any – applies to it. MiCA's scope is defined in part by exclusion: tokens that qualify as financial instruments under MiFID II are excluded from MiCA and instead regulated under the existing securities framework. A token that is clearly a transferable security, therefore, will require a prospectus (or a prospectus exemption) rather than a MiCA whitepaper – and will be regulated by national securities law plus ESMA guidance, not by MiCA's CASP regime.

For tokens that fall within MiCA – ARTs, EMTs, and "other" crypto-assets – whitepaper requirements are mandatory, though the obligations differ by category. ART and EMT whitepapers require NCA pre-approval. Whitepapers for other crypto-assets must be published and notified to the NCA but are not subject to pre-approval. All whitepapers must contain prescribed content, including a description of the token's rights, the issuer's financial position, and the applicable risk factors.

The practical trap we see most often: an issuer drafts a whitepaper under MiCA's "other crypto-assets" regime, does not seek a legal classification opinion, and later discovers the token's economics trigger the ART definition, requiring NCA approval the issuer never obtained. We assess classification against the substance of rights, not the marketing label – and the MiCA/MiFID II boundary is the most consequential classification decision an EU token issuer makes.

If a prior application stalled or a classification opinion came back ambiguous, a structural review can identify the specific point of divergence and the route to a defensible position. Write to OBOLUS at info@oboluslaw.com or message t.me/oboluslaw.

An airdrop – a gratuitous distribution of tokens to wallet addresses, typically as a marketing or community-building mechanism – is not automatically exempt from securities law simply because recipients pay nothing. The legal analysis turns on whether the distributed token is a security and, if so, whether the distribution constitutes a "sale or offer for sale" under the applicable regime.

In the United States, the SEC has signaled that value is not the only consideration: a token distributed for free but conditioning future economic benefit on holding (or staking or voting) may still constitute an offer of a security on a value-in-kind theory. The absence of monetary consideration does not foreclose securities analysis. This is not a settled area of US law, but the enforcement posture warrants caution.

In the EU, a MiCA whitepaper obligation attaches to any public offer of crypto-assets above the applicable threshold, and a gratuitous distribution to a sufficiently large public may constitute a "public offer" for MiCA purposes. The small-offering and private-placement exemptions built into MiCA provide limited headroom – and they do not apply to ARTs or EMTs, which require NCA authorisation regardless of offering size or consideration.

The structurally cleanest airdrop is one distributed to existing ecosystem participants, behind a verified wallet gate, after a legal opinion confirms the token's non-security status in each target jurisdiction, with volume and recipient caps calibrated against any applicable small-offering exemption. A blanket global airdrop to anonymous wallets is, in our view, the single highest-risk distribution mechanism a token issuer can use.

What Secondary Market Restrictions Apply to Security Tokens?

Secondary-market trading of a security token is as regulated as primary issuance – often more so, because it occurs across a wider population of participants and platforms. An exchange or trading platform that lists a security token without the appropriate licence is, in most jurisdictions, operating an unlicensed securities exchange or multilateral trading facility.

In the United States, trading platforms must register as national securities exchanges or operate as broker-dealers on an ATS. The SEC has brought enforcement actions against platforms that listed tokens it classifies as securities without these registrations. In the EU, the MiCA CASP regime permits token trading but explicitly excludes tokens that qualify as MiFID II financial instruments – those require an authorised MTF or regulated market. Under the EU's DLT Pilot Regime (a regulatory sandbox for tokenised securities trading), certain operators may conduct secondary trading under temporary exemptions, but the regime is limited in scope.

In Hong Kong, the SFC requires that security tokens be traded only on SFC-licensed platforms. The SFC's VASP licensing regime for virtual-asset trading platforms expressly contemplates security token trading as a separately authorised activity. The practical result: a global token issuer must assess not only where it issues, but where its token will trade – and work with exchanges in each jurisdiction to confirm their regulatory permission to list.

We have seen issuers complete a legally sound primary offering, then watch the token migrate onto unregulated offshore exchanges. That migration creates its own risk: if a regulator later characterises the offshore platform as offering the security to its domestic users, the issuer may face secondary liability for facilitating an unlicensed distribution. Exchange-listing strategy is therefore a legal decision, not merely a commercial one.

What Are the Most Common Legal Mistakes in Security Token Projects?

Across the projects we have reviewed, a consistent set of structural and process errors recurs – most of them avoidable with early legal input.

Over-reliance on the utility label. A token labelled "utility" in a whitepaper does not become a utility token. Regulators look at the economic rights conferred, the marketing materials, the team's public statements, the tokenomics model, and the reasonable expectation of purchasers. We have reviewed whitepapers titled "utility token" whose rights schedules read like a preference-share term sheet.

Single-jurisdiction analysis. A classification opinion from one jurisdiction does not travel. An EU legal opinion does not address the US, Singapore or Hong Kong position. Issuers who rely on a single-jurisdiction opinion frequently launch into markets where they lack legal cover.

Whitepaper as the full compliance programme. A MiCA whitepaper is a disclosure document. It is not an AML programme, a custody agreement, a distribution agreement, or a secondary-market compliance plan. Each of those is a separate legal instrument with its own regulatory requirements. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams – and token compliance is no different.

Ignoring the Travel Rule at the distribution layer. The Travel Rule (the FATF obligation to pass originator and beneficiary identification data with each virtual-asset transfer above the applicable threshold) applies to VASPs involved in security token transfers. Token issuers who rely on exchange platforms to handle Travel Rule compliance without contractually confirming that the exchange is, in fact, compliant, take on residual risk.

No post-launch monitoring. Token classification is not a one-time event. A token that launches as a utility token may acquire security characteristics if the project's economic model evolves – staking rewards that function as dividends, governance votes that control revenue allocation, buy-back mechanisms. Ongoing legal monitoring is part of the compliance obligation, not a luxury.

Related at OBOLUS

FAQ

Is my token a security?

Whether a token is a security depends on the substance of the rights it confers on holders, assessed against the applicable legal test in each jurisdiction where it is offered. In the United States the Howey test governs; in the EU, the MiFID II financial-instrument definition and MiCA's ART/EMT categories are the primary reference points; other major hubs – Singapore, Hong Kong, Switzerland – each apply their own statutory frameworks. A utility label in a whitepaper does not determine the answer. A formal classification opinion, reviewed against the actual tokenomics and distribution plan, is the only reliable basis for a defensible position.

Do I need a MiCA whitepaper?

If your token is offered to the public in the EU or EEA and falls within MiCA's scope – as an ART, an EMT, or another crypto-asset above the applicable small-offering threshold – a MiCA-compliant whitepaper is mandatory. Tokens that qualify as financial instruments under MiFID II are excluded from MiCA and require a prospectus or prospectus exemption instead. ART and EMT whitepapers require NCA pre-approval before publication; other crypto-asset whitepapers require notification. The classification decision between ART, EMT, financial instrument, and other crypto-asset must be made before drafting begins.

How should an airdrop be structured legally?

A legally defensible airdrop begins with a classification opinion confirming the token is not a security in each target jurisdiction. In the EU, a gratuitous distribution to a sufficiently large public may still constitute a MiCA public offer, so volume and recipient caps should be calibrated to available exemptions. Recipients should be verified ecosystem participants where possible, and global blanket distributions to anonymous wallets should be avoided. AML/KYC obligations may apply at the distribution layer depending on the jurisdiction and the VASP status of the distributing platform. Legal review before distribution is essential, not optional.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your token project, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – advises on token classification, smart-contract legal architecture and the multi-jurisdictional regulatory position of protocol-layer digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours