Staking sits at the intersection of protocol mechanics and regulated financial activity. Whether a digital-asset business offering staking rewards is running a software utility or conducting a regulated service depends not on what the business calls it, but on what it actually does — and under which jurisdiction's law that activity is assessed. As supervisory expectations converge across the leading hubs, the classification question has become one of the most consequential a token issuer, exchange or protocol operator will face.
The core legal issue is consistent across regimes: staking (the act of locking or delegating digital assets to participate in a proof-of-stake consensus mechanism, or in a pooled yield-generating structure, in exchange for rewards) may constitute a collective investment scheme, a securities offering, a lending arrangement, or a regulated custody service — depending on the structure of the reward, the degree of control exercised by the intermediary, and the rights conferred on the participant. No single framework governs globally. This guide maps the principal regulatory positions across the major supervisory environments and draws out the cross-border implications for operators.
The sections below move from definition to regulatory classification to cross-border structuring, closing with the practical implications for businesses and the licensing and disputes questions staking most commonly triggers.
What Is Staking, and Why Does the Legal Definition Matter?
Staking is not one activity — it is a spectrum of arrangements that share a surface similarity but diverge sharply in legal character. At one end sits native protocol staking: a validator locks its own tokens to participate in consensus, earning inflationary rewards with no intermediary involved. At the other end sits pooled or custodial staking offered by an exchange: the exchange accepts tokens from multiple users, pools them, operates the validator infrastructure, and distributes a portion of rewards — effectively acting as a financial intermediary between the user and the network.
The legal definition matters because the same economic outcome — a user deposits assets and receives a return — maps onto very different regulatory categories depending on the intermediary's role. Protocol-native staking, where the operator runs a validator on behalf of token holders, looks structurally similar to asset management. Pooled staking through an exchange resembles a deposit-taking or collective investment arrangement. Liquid staking derivatives, where the deposit is tokenized and the resulting instrument trades freely, introduce a further layer: the derivative itself may be a transferable security.
In our practice advising protocols and exchange operators across multiple jurisdictions, the question we are asked most frequently is not "is staking regulated?" but "which regulatory category applies to our specific structure?" That distinction determines both the licensing path and the disclosure obligations.
A common assumption is that attaching a "utility" label to staking rewards on a whitepaper resolves the classification question. It does not. Regulators and courts in every major jurisdiction assess substance over form. The rights conferred, the expectation of profit, and the degree of managerial effort by the offeror are the operative factors — not the marketing characterization. We assess classification against the substance of rights, not the label. That discipline is the starting point for any serious staking legal review.
How Does MiCA and EU Law Treat Staking?
Under MiCA, staking as an activity offered by a crypto-asset service provider is directly in scope, and the regime administered by ESMA and national competent authorities treats it as a service requiring CASP authorisation. The relevant question under MiCA is whether the staking arrangement involves the custody and administration of crypto-assets on behalf of clients — an activity for which a CASP must be authorised in an EU member state and may then passport across the EEA.
MiCA does not resolve every question, however. It governs the service layer — the intermediary offering staking to customers. It does not directly regulate the protocol-level activity of a validator operating on its own account. That distinction matters for protocol developers and node operators who may be tempted to conclude that because they are not offering a client-facing service they fall outside ESMA's perimeter. The analysis is more nuanced: if a protocol developer exercises ongoing managerial discretion over a pooled staking product accessible to retail participants, ESMA's supervisory expectations — and those of the relevant national competent authority — will likely apply.
The MiCA whitepaper regime also imposes disclosure obligations where a crypto-asset is offered to the public. Liquid staking tokens — where the staked position is represented by a transferable derivative — warrant particular care. If the derivative meets the criteria of an asset-referenced token (ART) or if its transferable character and the expectation of returns bring it within securities law, the issuer faces a layered obligation: MiCA CASP authorisation for the service, and potentially prospectus or ART requirements for the instrument itself.
Operators considering an EU staking product should also note that Lithuania, historically a fast entry point for VASP registration, now transitions to the full MiCA CASP authorisation track. Malta's MFSA, similarly, is moving legacy VFA authorisations to MiCA alignment. The passporting benefit of a single EU authorisation is real — but the authorisation threshold under MiCA is materially higher than the prior national VASP regimes it replaces.
To scope your MiCA CASP authorisation for a staking product and map the passporting strategy across EU member states, contact OBOLUS at info@oboluslaw.com. The process above describes the standard regulatory path. Your entity structure, user base geography and reward mechanism will each shift the analysis.
Is Staking a Security Under US Law?
In the United States, the SEC has taken the position — reinforced through enforcement action rather than rulemaking — that certain staking services constitute the offer and sale of investment contracts and are therefore securities subject to federal registration requirements. The central analytical tool remains the investment-contract test applied by the SEC and the federal courts: whether there is an investment of money in a common enterprise with an expectation of profit derived from the efforts of others.
Pooled staking services offered to retail customers by centralised exchanges score against each element of that test. The customer invests tokens; the pool is managed by the exchange (the common enterprise); the customer expects rewards; and those rewards depend on the exchange's operational and managerial effort in running the validator. The SEC's enforcement posture has been explicit on this point, and several major exchange operators have entered settlements or consent orders without contesting the analytical framework.
What the US framework does not do is provide a clear safe harbor for protocol-native or decentralized staking. The CFTC's jurisdiction over commodity derivatives adds a further layer for staking products that involve leverage or synthetic exposure. FinCEN's money-transmission analysis applies to any entity that moves, converts or transmits value — an exchange running a staking pool for customers in the US will almost certainly need to engage the state money-transmitter licensing grid, with NYDFS's requirements among the most demanding.
The cross-border tension is acute. A non-US exchange offering pooled staking to US persons faces the same SEC analysis as a domestic operator. Geofencing is a partial mitigation at best. Operators we advise routinely discover that their US-person traffic is larger than their compliance team assumed — and that the staking product is the exposure point.
How Do VARA and the ADGM Treat Staking?
In the UAE, the regulatory treatment of staking splits between two frameworks. VARA — the Virtual Assets Regulatory Authority, which governs mainland Dubai — operates an activity-based licensing regime. Staking offered as a commercial service to customers falls within VARA's managed categories, most naturally under the management and investment services activities. An operator offering pooled staking products in Dubai must hold the relevant VARA activity authorisation and comply with VARA's applicable rulebooks on disclosure, custody and client-asset treatment.
In Abu Dhabi, the FSRA within the ADGM applies its own framework for regulated virtual asset activities. The FSRA's recognised-virtual-asset concept and its regulated-activities perimeter mean that a staking product offered through an ADGM entity must be mapped against the FSRA's activity categories before launch. Custody obligations — which apply to any arrangement where a financial intermediary holds or controls client assets — are particularly relevant: VARA and the FSRA both impose strong safeguarding expectations, and a staking product that involves transfer of custody to the operator (as pooled products typically do) triggers those requirements immediately.
In a recent matter, we advised a digital-asset management business seeking to launch a staking product for institutional clients through a Gulf-based entity. The key structural question was whether the reward-distribution mechanism constituted a managed investment service requiring a specific VARA activity licence or whether it could be structured as a principal arrangement outside that perimeter. The analysis turned on the degree of ongoing managerial discretion exercised by the operator — a fact-specific question that required both a technical review of the smart contract architecture and a regulatory mapping exercise under the applicable VARA rulebooks. The business restructured its reward mechanism before launch, materially reducing its regulatory exposure.
What Is the Regulatory Position on Staking in Singapore and Hong Kong?
Singapore's MAS approaches staking through the lens of the Payment Services Act and, where the staked asset or the derivative instrument meets the criteria of a capital markets product, through the Securities and Futures Act. A DPT (digital payment token) service licence is required for dealing or facilitating the exchange of digital payment tokens — but the staking of DPTs by an intermediary on behalf of customers sits in a space where MAS has signalled expectations through guidance and supervisory correspondence rather than a specific staking rule. The practical position is that any exchange or custodian offering a customer-facing staking product in Singapore should assume the activity requires licensing and obtain formal confirmation from MAS before launch.
Liquid staking tokens present a sharper question in Singapore. If the derivative instrument confers rights that bring it within the definition of a capital markets product — particularly a collective investment scheme unit — then the full Capital Markets Services licence framework applies. MAS has been explicit that it assesses the substance of the arrangement, not the label attached to the token.
In Hong Kong, the SFC's VASP licensing regime for virtual-asset trading platforms covers exchanges that offer staking as an ancillary or bundled service. The SFC's approach mirrors its securities-law analysis: where a staking product involves the pooling of assets and a managed return, it is assessed against the collective investment scheme perimeter. Custodial obligations — including the requirement to segregate client assets — apply to any arrangement where the VATP holds or controls client tokens during the staking period.
For cross-border businesses operating between Singapore, Hong Kong and a Gulf hub, the staking classification question must be run separately against each regime before the product is offered in any market. If you need a multi-jurisdictional classification memo, contact OBOLUS at info@oboluslaw.com. If a prior application stalled or a product was pulled after regulatory contact, a second read of the structure can surface the route back.
How Does Staking Interact With Tax and Cross-Border Structuring?
The tax treatment of staking rewards is jurisdiction-specific and unsettled in most regimes. The central question in income tax terms is whether rewards received on staking are income at the point of receipt, capital gains on disposal, or neither — and the answer differs materially between the US, the UK (where HMRC's guidance treats staking rewards as miscellaneous income in most cases), and low-tax environments such as the ADGM or the AIFC in Kazakhstan.
For a business — rather than an individual — the tax position is layered further. A protocol entity, an operating company running a validator, and a fund distributing staking yields to investors each face different characterization questions. Value-added tax and goods-and-services tax treatment of staking reward payments also varies: some jurisdictions treat them as outside the scope of VAT; others have not yet addressed the question. We advise structuring the reward mechanism with the tax position mapped before launch, not after the first distribution.
The cross-border structuring question for a staking business typically turns on three axes: where the entity is incorporated, where the validator infrastructure operates, and where the customers are located. A business that incorporates in a low-regulatory-friction jurisdiction — BVI or Cayman, for instance — but offers staking services to EU or US persons will be assessed under EU (MiCA) or US (SEC/CFTC) law regardless of the incorporation point. The entity's jurisdiction of registration is one factor; the jurisdictions where the service is made available are equally operative.
In our cross-border practice, we regularly advise token issuers and exchange operators who have built their staking product in one jurisdiction and discovered — after going live — that their user acquisition has created regulatory exposure in three or four others. Remediation at that point is more expensive and more disruptive than a pre-launch mapping exercise. The standard engagement for a new staking product covers: (1) token/reward classification in target markets; (2) licensing requirement analysis; (3) tax characterization at the entity and distribution level; and (4) banking and custody structuring to support the reward mechanism.
Does Staking Trigger AML and Travel Rule Obligations?
The FATF framework — specifically Recommendation 15, which extends AML/CFT obligations to virtual asset service providers — applies to entities that provide staking as a commercial service. A VASP operating a pooled staking product will typically fall within the FATF definition of "transfer" or "exchange" services, depending on the mechanics of the reward distribution and whether the underlying tokens are moved between wallets in the process.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) is triggered by transfers above the applicable de-minimis threshold in each jurisdiction. For a staking product that involves the periodic movement of rewards from a validator wallet to customer wallets, the operator must assess whether those distributions constitute "transfers" for Travel Rule purposes — a question that several national regulators have addressed in guidance and that remains live in others.
The AML/KYC program requirements that apply to a licensed staking service provider are substantively the same as those applicable to an exchange: customer due diligence, transaction monitoring, sanctions screening, and suspicious-activity reporting. An exchange adding staking as a feature does not need a separate AML program, but it must ensure that its existing program covers the staking customer journey — including the onboarding of high-value stakers and the monitoring of reward withdrawals as outflows.
When Does Staking Trigger a Dispute or Enforcement Action?
Staking disputes cluster around four scenarios: (1) protocol-level slashing events that reduce a user's staked balance; (2) exchange or protocol insolvency, where users argue that staked assets are held in trust rather than as general creditor claims; (3) regulatory enforcement for unlicensed staking services; and (4) smart-contract failures that cause reward miscalculation or loss of principal.
The insolvency characterization question is legally significant. In jurisdictions that treat staked assets as held on trust, users may rank above unsecured creditors in a liquidation. In jurisdictions — or under contract terms — where staked assets are treated as loaned or transferred to the operator, users rank as unsecured creditors. Several major exchange insolvencies have raised this question; the outcome has turned heavily on the specific wording of the staking terms and the law governing those terms.
In England and Wales, courts have developed a sophisticated body of analysis treating crypto-assets as property capable of supporting proprietary claims, injunctions and tracing orders. A user who can establish that staked assets are held on constructive trust may obtain a proprietary injunction — including a worldwide freezing order — against an insolvent or fraudulent operator before the assets are dissipated. The DIFC Courts have similarly demonstrated willingness to grant urgent interim relief in crypto-asset disputes.
In a recent disputes matter, a digital-asset fund engaged us after an exchange offering staking services suspended withdrawals and entered administration proceedings in an offshore jurisdiction. We worked with allied counsel in the relevant jurisdiction to assess the trust characterization under the applicable law, filed a proprietary claim, and secured a disclosure order requiring the administrator to identify and segregate the fund's staked assets. The matter was resolved before a contested hearing, and the fund recovered substantially all of its staked position — a result that would not have been achievable had the action been delayed by more than a few weeks.
Enforcement risk is the second major disputes vector. Regulators — particularly the SEC, and increasingly ESMA-aligned NCAs — have shown willingness to pursue exchanges offering staking services without the applicable authorisation. The enforcement exposure for an unlicensed staking provider is not limited to fines: it includes disgorgement of revenues, remediation orders, and reputational damage that can impair the operator's ability to obtain future licences in any major market.
Which Staking Structure Is Right for Your Business Profile?
The appropriate staking structure depends on the operator's profile, target markets, and tolerance for regulatory engagement. The decision is not binary — it is a matrix of entity type, market access, instrument design and licensing commitment.
Profile A — Protocol developer offering native staking to token holders, no pooling, no intermediary custody. This profile sits closest to the protocol-utility end of the spectrum. The main regulatory exposures are: token classification (is the staked asset a security or commodity in target markets?); whitepaper disclosure under MiCA if offered to EU persons; and the treatment of rewards as income or otherwise under the applicable tax regime. Licensing is typically not required at the entity level, but the token classification analysis is non-negotiable before any public launch.
Profile B — Centralised exchange adding pooled staking as a product for retail customers in multiple jurisdictions. This profile faces the highest regulatory complexity. MiCA CASP authorisation for the EU user base, SEC analysis for any US-person traffic, VARA or FSRA authorisation for Gulf customers, and MAS licensing for Singapore — each runs in parallel. The AML, Travel Rule and custody obligations apply in full. The timeline to full multi-market compliance is measured in months rather than weeks, and the capital and operational requirements are material.
Profile C — DeFi protocol with a liquid staking derivative that trades freely on secondary markets. This profile adds a securities-law dimension that profiles A and B do not necessarily face. The liquid staking token must be classified under each relevant regime: is it an ART under MiCA, a security under US federal law, a capital markets product under Singapore's Securities and Futures Act? If any of those classifications attach, the issuance and distribution of the token triggers a separate authorisation and disclosure regime on top of any service-layer licence required for the staking function itself. The smart-contract architecture should be reviewed against the applicable legal test before deployment — not after.
DeFi (decentralized finance — financial services delivered through self-executing smart contracts rather than licensed intermediaries) protocols offering staking cannot assume that the absence of a corporate intermediary removes regulatory exposure. Where the smart contract is deployed, maintained and upgraded by an identifiable team, and where the rewards flow to participants who have not exercised meaningful governance over the protocol, the "efforts of others" element of the investment-contract test may still be met.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – our core practice covering DeFi legal structure, token design and smart-contract review for digital-asset businesses
- Smart-Contract Legal Review in Bermuda – jurisdiction-specific analysis of smart-contract enforceability and regulatory treatment under the Bermuda regime
- Airdrop Legal Structuring in Malta – legal treatment of token distributions under the MFSA framework as Malta transitions to MiCA
FAQ
Can a DeFi protocol be regulated?
Yes — the absence of a corporate intermediary does not automatically place a DeFi protocol outside the regulatory perimeter. Where an identifiable team deploys, maintains and upgrades the protocol, and where participants earn returns dependent on that team's effort, regulators in the US, EU and major Asian hubs have asserted jurisdiction. The relevant test in most regimes is substance over form: who actually exercises control and who benefits from the arrangement determines whether regulation applies.
What legal wrapper suits a DAO?
A DAO (decentralized autonomous organization) operating without a legal wrapper exposes its members to unlimited personal liability in most jurisdictions, because courts treat an unincorporated association's obligations as falling directly on its participants. Common structuring approaches include a Wyoming DAO LLC, a Marshall Islands DAO entity, a Cayman Islands foundation company, or a BVI structure. The right choice turns on the DAO's commercial activity, its token structure, the residency of its core contributors, and the jurisdictions where it operates or raises capital.
Who is liable when a smart contract fails?
Liability for a smart-contract failure depends on the nature of the failure and the legal characterization of the parties' relationship. Where the failure results from a coding error in a contract deployed and promoted by an identifiable team, that team may face claims in negligence, under consumer-protection regimes, or under securities law if the contract constitutes a regulated instrument. Where the failure is caused by an oracle error or an external exploit, liability analysis shifts to the oracle provider's terms and the contractual allocation of risk in the protocol's governing documents.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the DeFi structuring, tokenization and smart-contract analysis that sit around every product launch. We assess classification against the substance of rights — not the marketing label — and we have advised businesses across more than seventy licensing jurisdictions on precisely these questions. Digital assets are the whole of our practice. To discuss your staking structure or classification question, contact info@oboluslaw.com.
By Roman Levitt, Technology and DeFi Counsel — specialising in the legal analysis of smart-contract architecture, token classification and DeFi protocol structuring across multiple supervisory environments.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.