EST · MMXXVI
Home/Insights/Glossary/Token Classification: A Legal Guide for Digital-Asset Businesses
Token Offerings & Securities

Token Classification: A Legal Guide for Digital-Asset Businesses

Token Classification: A Legal Guide for Digital-Asset Businesses. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Token classification is the foundational legal question every digital-asset business must answer before it issues, lists, or distributes a token. Get it wrong, and a product launch can become an unregistered securities offering overnight – with regulatory enforcement, civil liability, and banking consequences that follow. With major regimes including MiCA in the European Union, the VARA regime in Dubai, and the Payment Services Act in Singapore now applying distinct rules to distinct token categories, a utility label on a whitepaper is not a legal answer. Classification turns on the substance of the rights a token confers, not on the name the issuer gives it.

This guide analyzes how the principal global regimes approach token classification, where the classifications diverge, how those divergences create cross-border risk for businesses operating across multiple markets, and what a properly structured classification analysis looks like in practice.

What Is Token Classification and Why Does It Determine Everything?

Token classification is the process of determining, under applicable law, which regulatory category a digital asset belongs to – and therefore which licensing obligations, disclosure requirements, and investor-protection rules govern it. The category a token falls into determines whether its issuer needs a securities licence, a payment-services authorization, a CASP (Crypto-Asset Service Provider) licence, or no licence at all. It also determines what intermediaries – exchanges, custodians, wallet providers – need in order to handle the token legally in a given market.

Regulators across every flagship jurisdiction have converged on one principle: substance prevails over label. A token that pays dividends, grants governance rights with economic effect, or promises profit from the efforts of an issuer is assessed against securities law regardless of whether the whitepaper calls it a "utility token." That principle is applied consistently under MiCA in the EU, under the SFC's regime in Hong Kong, under the FCA's framework in the UK, and under SEC/CFTC jurisdiction in the United States.

In our cross-border practice, we see classification errors concentrated at one point: the moment a founding team decides what to call the token before any legal analysis has been done. The commercial instinct to label a token as utility is understandable. The legal risk it creates is significant.

How Do the Major Regimes Map Token Categories?

Each major regime has its own taxonomy, but three broad functional categories appear across most of them: payment tokens, utility tokens, and security or investment tokens. The treatment of stablecoins and e-money tokens forms a fourth distinct category in several regimes. Understanding where these categories converge – and where they diverge – is critical for any business operating across borders.

Under MiCA, the EU's Markets in Crypto-Assets Regulation, the taxonomy is statutory. Tokens are classified as asset-referenced tokens (ARTs, which reference a basket of assets), e-money tokens (EMTs, which reference a single fiat currency), or "other" crypto-assets – a residual category covering most utility and payment tokens that do not qualify as financial instruments under existing EU financial law. CASPs handling any of these categories require authorisation from the relevant national competent authority, with the possibility of passporting across the EU/EEA once authorised in a single member state. ARTs and EMTs carry the heaviest obligations: issuer authorisation, whitepaper requirements, and reserve rules. Tokens that constitute financial instruments under the relevant EU financial law directive remain outside MiCA and inside the existing securities regime.

FINMA in Switzerland uses a three-tier taxonomy – payment tokens, utility tokens, and asset tokens – grounded in economic function. A token that entitles the holder to a share of future profits is an asset token regardless of how it is packaged. Under the FINMA framework, hybrid tokens (tokens with characteristics of more than one category) are assessed against each applicable category individually.

In the United States, the analysis at federal level runs through the Howey test for securities: an investment of money in a common enterprise with an expectation of profit primarily from the efforts of others. The SEC has applied this test aggressively to tokens that were marketed with return expectations, regardless of the utility label. The CFTC asserts jurisdiction over tokens it considers commodities. State-level money-transmitter licensing (MTL) and the NYDFS BitLicense apply additional layers for payment-adjacent tokens. The result is a layered, multi-regulator environment where the classification question is rarely binary.

The SFC in Hong Kong applies a security-or-not test: tokens that constitute "securities" or "collective investment scheme interests" under the applicable ordinance fall within the VASP licensing regime and trigger prospectus obligations. The MAS in Singapore similarly draws the line between tokens that are "capital markets products" under the Securities and Futures Act and digital payment tokens (DPTs) covered by the Payment Services Act.

Across all these regimes, the VARA activity-based licence structure in Dubai stands out for its emphasis on the activity being conducted rather than the token's intrinsic classification. An operator advising on, exchanging, or custodying a virtual asset needs the corresponding VARA licence regardless of whether that asset is a utility token or an investment token. The classification of the token still matters – VARA distinguishes virtual assets from financial instruments and securities, which fall under a different authority – but the activity lens adds a separate compliance obligation on top.

Why a Utility Label Does Not Settle the Legal Question

A common assumption among token issuers is that structuring a token as "utility" – access to a platform, a service, or a product – removes it from the securities perimeter. That assumption is consistently wrong in the hands of a regulator who looks at economic substance. Three factors regularly convert a nominally utility token into a regulated investment instrument: pre-sale with a return expectation, secondary market trading with a speculative basis, and governance rights that carry economic effect.

The problem is especially acute for early-stage tokens sold before the underlying platform exists. When a token is sold to fund development and the buyer's return depends on the issuer building something, the economic substance of the arrangement may satisfy a securities test even if the token will eventually provide genuine utility. In our practice, we see founders surprised to learn that the token's legal status at the point of sale is distinct from its legal status once the platform is live.

A second layer of complexity arises from governance tokens – tokens that grant holders voting rights over protocol parameters or treasury allocation. A governance token may look like utility. If the vote controls a treasury from which token holders benefit economically, the rights conferred may bring the token within the investment-instrument perimeter under several regimes. The analysis is fact-specific and must be done against the laws of every jurisdiction in which the token is offered or traded.

Whitepaper disclaimers do not resolve the question. A regulator assessing whether a token is a security does not read the whitepaper disclaimer first. It reads the economic rights, the marketing materials, the secondary market behaviour, and the reasonable expectation of a buyer. A legal classification opinion must map those facts against the applicable statutory tests – not merely assert a conclusion.

What Is the Cross-Border Classification Risk for a Multi-Jurisdiction Token Offering?

A token offered to buyers in multiple jurisdictions is simultaneously subject to the classification rules of every relevant market. This is the core cross-border risk: a token that is a utility token in one regime may be a security in another. The issuer is responsible for compliance in each jurisdiction where it offers the token to buyers – not just where it is incorporated.

In a recent advisory matter, a token issuer incorporated in a low-regulation jurisdiction structured what it considered a straightforward utility token for access to a data marketplace. The token was sold via a public sale with no geographic restrictions. Buyers in jurisdictions where the token met the local securities test were exposed to an unregistered offering. The issuer had not conducted a multi-jurisdictional classification analysis, and the distribution mechanism had not been restricted by reference to any legal assessment. The remediation required retroactive restructuring of the distribution, engagement with allied counsel in the relevant jurisdictions, and a revised offering document.

The cross-border angle creates a specific challenge at listing. A centralized exchange operating under the SFC in Hong Kong or the FCA in the UK will conduct its own classification analysis before listing a token. If the exchange's analysis and the issuer's analysis diverge, the exchange may refuse to list or may impose trading restrictions. An issuer that cannot demonstrate a documented, jurisdiction-specific classification rationale is at a competitive disadvantage at the listing stage.

For businesses operating between the EU and other markets, the MiCA classification framework creates a reference point. A token that qualifies as a CASP-covered "other crypto-asset" under MiCA may still be classified as a security in the US or a capital markets product in Singapore. The regimes do not harmonize. The issuer must hold a classification position for each relevant market, not a single global classification.

To map your token's classification across the markets where you intend to offer or list it, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your facts – the rights the token confers, the sale mechanism, the buyer profile, and the jurisdictions involved – will determine which regimes apply and how.

How Are Stablecoins and E-Money Tokens Classified?

Stablecoins occupy a distinct classification track in most flagship regimes, and the legal obligations they trigger are among the most demanding in the digital-asset space. Under MiCA, a token that references the value of a single official fiat currency and purports to maintain a stable value is an e-money token and the issuer must be authorized under the applicable e-money rules. A token that references a basket of assets – fiat currencies, commodities, or other assets – is an asset-referenced token, subject to a separate and more demanding authorization track that includes reserve requirements and redemption obligations.

In the United States, the regulatory treatment of stablecoins remains subject to ongoing legislative and regulatory development. The applicable analysis may involve the SEC, the CFTC, banking regulators, and state money-transmitter rules depending on the token's structure and the issuer's activities. NYDFS has issued guidance on stablecoin issuance applicable to entities operating under the BitLicense. In Singapore, a stablecoin pegged to a single fiat currency and issued by a MAS-regulated entity falls within the MAS stablecoin regulatory framework under the Payment Services Act.

Operationally, the major issuer-controlled stablecoins – USDT and USDC – carry contract-level freeze authority. Tether and Circle have the technical capability to freeze tokens at the smart-contract level, and they generally act on a court order or a law-enforcement or OFAC designation. For an issuer designing a new stablecoin, the reserve composition, the redemption mechanism, and the governance structure each carry classification implications that must be analyzed before launch.

Where Do NFTs and Fractionalized Assets Fall in the Classification Analysis?

Non-fungible tokens (NFTs) present a classification question that most early analyses deferred but regulators are now addressing directly. A genuinely unique digital collectible with no financial return mechanism and no secondary market liquidity expectation is generally outside the securities perimeter in most regimes. However, NFT projects that promise royalty distributions, fractionalized NFTs that allow shared economic exposure to an asset, and NFT collections marketed primarily on appreciation potential all attract scrutiny under securities and investment-instrument tests.

Fractionalized tokens – structures that divide ownership of an underlying asset into multiple on-chain tokens – are particularly susceptible to classification as securities or collective investment scheme interests. Each fractional token represents a proportionate economic interest in the underlying asset. The holder's return depends on asset performance rather than utility. That structure maps directly onto the investment-instrument tests in the EU, UK, US, and Asia-Pacific regimes.

FINMA's hybrid-token approach is instructive here. A token that has utility characteristics (access, governance) and investment characteristics (share of revenues, fractional ownership) is assessed against both tests. The presence of utility features does not cancel the investment analysis. In our advisory work on NFT and tokenized-asset projects, we apply the same substance-over-label discipline: the rights the token confers in law, not the category assigned by the project documentation, determine the regulatory treatment.

What Does a Properly Structured Classification Analysis Look Like?

A defensible token classification analysis has five components: a precise description of the rights the token confers, a mapping of those rights against the applicable statutory tests in each relevant jurisdiction, a conclusion by jurisdiction, a documented assessment of how the classification may change over the token lifecycle, and a set of structural recommendations for maintaining compliance.

The rights description is the foundation. It must go beyond the whitepaper summary. It must identify what a token holder can actually do with the token, what economic or governance rights attach to it, what the issuer has contractually or constructively committed to, and how the token is expected to trade on secondary markets. Vague rights descriptions produce unreliable classification conclusions.

The lifecycle analysis is frequently omitted. A token may be classified as utility at launch if it provides immediate access to a live platform with genuine utility. The same token may have been classifiable as a security during the pre-sale period, when buyers purchased based on future utility expectations. The issuer needs to understand the classification at every stage: pre-sale, primary distribution, secondary trading, and any planned token modification or upgrade.

Structural recommendations follow from the analysis. They may include geographic restrictions on the offering, eligibility criteria for buyers, platform controls at launch, restructuring of governance rights, modification of economic distribution mechanisms, or changes to the token's technical architecture. In some cases, the analysis concludes that a particular classification is unavoidable and the recommendation is to pursue the applicable licence rather than redesign the token.

If a prior classification opinion has been challenged or a listing was refused on classification grounds, OBOLUS can provide a second analysis – contact us at info@oboluslaw.com or via t.me/oboluslaw. If an earlier assessment stalled or a regulator raised concerns, a fresh review of the underlying facts can surface the structural issue and identify the route to resolution.

How Does Token Classification Apply to Airdrops and Incentive Distributions?

Airdrops – the distribution of tokens to wallets without direct monetary consideration – are sometimes assumed to avoid securities classification because no money changes hands. That assumption requires careful scrutiny. Several regulators, including the SEC, have taken the position that an airdrop may still constitute a securities offering if the tokens were previously sold to insiders at a discount, if the airdrop is conditional on actions that create an economic relationship, or if the overall distribution program was structured to create a market for a token that would otherwise fail a securities test.

The legal status of an airdrop depends on who receives the tokens, what they receive in exchange (even non-monetary consideration, such as social engagement or KYC participation, may be relevant), and the regulatory environment of the recipient's jurisdiction. A marketing airdrop to unverified wallets globally is a multi-jurisdictional distribution event, not a zero-consequence giveaway.

Practical structuring for airdrops involves defining the recipient criteria with legal precision, conducting a jurisdiction-specific eligibility analysis, imposing geographic restrictions where the classification analysis demands it, and documenting the legal basis for the distribution. The same discipline applies to staking rewards, referral bonuses, and other token-denominated incentive programs – each of which carries classification implications in at least some of the major markets.

Which Classification Profile Fits Your Token?

Different token architectures map to different regulatory profiles. Understanding your profile before launch determines the compliance path.

Profile A – Pure access utility token: The token provides on-chain access to a live, functional platform. No financial return mechanism exists. No pre-sale at a discount. No governance with economic effect. In most regimes, this token falls outside the securities perimeter. Under MiCA it is likely a "other crypto-asset" subject to a whitepaper requirement if offered publicly. Risk: regulators may still assess secondary market dynamics and marketing materials. Timeline to clarity: a focused classification opinion can typically be completed within a matter of weeks from engagement.

Profile B – Governance token with economic effect: The token grants voting rights over a treasury or a protocol revenue mechanism. Holders can direct funds to themselves or to projects they control. Under most securities-law tests, the economic effect of governance brings this token into the investment-instrument analysis. Multiple licensing or registration obligations may apply. Risk: classification as a security is material. Timeline: the structural changes needed to reduce that risk require legal and technical coordination and typically extend the pre-launch period.

Profile C – Stablecoin or ART/EMT: The token maintains a stable value by reference to one or more assets. Under MiCA, issuer authorisation is required. In the US, banking regulatory analysis is likely alongside securities analysis. Timeline: among the longest in the digital-asset space given the reserve, audit, and redemption obligations attached to these instruments. Risk: non-compliance carries significant regulatory exposure in every major market that has implemented a stablecoin regime.

Profile D – Pre-sale token for a to-be-built platform: Buyers fund development with a return expectation tied to the platform's future success. This is the highest-risk profile for securities classification across nearly every regime. Structural remediation or a registered offering is likely the only compliant path in the major markets.

For a scoped classification analysis aligned to your token profile and target markets, write to info@oboluslaw.com.

Related at OBOLUS

FAQ

Is my token a security?

The answer depends on the rights the token confers and the laws of each jurisdiction where it is offered or traded. Most regimes apply a substance-over-label test: if a token grants economic rights tied to an issuer's efforts – profit shares, revenue distributions, or governance rights with economic effect – it may qualify as a security regardless of how it is labeled. A formal classification opinion, reviewed against the applicable statutory tests in each relevant market, is the only reliable answer.

Do I need a MiCA whitepaper?

Under MiCA, most public offers of crypto-assets that are not financial instruments require a published whitepaper containing prescribed disclosures about the issuer, the token, the rights it confers, and the risks involved. Asset-referenced tokens and e-money tokens carry additional issuer-authorization requirements beyond the whitepaper. Certain exemptions apply – for tokens offered to fewer than a defined threshold of persons, for tokens directed exclusively to qualified investors, and for tokens that are freely given away without consideration. Whether an exemption applies requires a fact-specific assessment against the applicable MiCA provisions.

How should an airdrop be structured legally?

A legally sound airdrop requires, at minimum: a classification analysis confirming the token's status in each recipient jurisdiction, geographic eligibility restrictions where securities or distribution rules apply, clear documentation of the basis for the distribution, and an assessment of whether the receipt of tokens by participants constitutes consideration that creates a regulated relationship. In practice, unrestricted global airdrops carry multi-jurisdictional regulatory risk. Structuring the recipient criteria and the distribution mechanism with legal precision significantly reduces that exposure.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – the analysis that matters to regulators and to listing venues. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your token classification question, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialising in token architecture, classification analysis, and cross-border regulatory strategy for digital-asset projects.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours