On paper, a security token offering looks like a cleaner version of an ICO – a digital representation of a traditional financial instrument, wrapped in smart-contract efficiency and distributed over a blockchain. In practice, the legal question is considerably harder: which regulatory regime governs this instrument, in which jurisdictions, and what does compliance actually require before a single token is sold? Mis-classifying a token can convert a product launch into an unregistered securities offering, exposing the issuer to enforcement, rescission claims, and reputational damage that can outlast the capital raise itself.
A security token offering (a token that carries rights analogous to equity, debt, or a collective investment scheme interest, and is therefore treated as a regulated financial instrument in most major jurisdictions) sits at the intersection of capital-markets law, digital-asset regulation, and cross-border compliance. The steps that follow trace the legal architecture from initial classification through post-issuance obligations. Each step identifies the regime basis, the cross-border complication, and the mistake that most commonly derails an otherwise well-prepared deal.
Step 1 – Classify the token before you name it
Token classification is the foundational step, and the answer turns on the substance of the rights conferred, not the label applied in the whitepaper. Regulators in every major hub apply a substance-over-form analysis: a token marketed as a "utility" pass is still a security if it carries profit-participation rights, governance rights that confer economic benefit, or if investors purchase it with a reasonable expectation of return derived from the efforts of others. The U.S. Howey test, the U.K. FCA's financial-instrument analysis, the EU MiCA token taxonomy (which distinguishes asset-referenced tokens, e-money tokens, and "other" crypto-assets from instruments falling outside MiCA into MiFID II territory), and FINMA's token taxonomy in Switzerland all apply a similar substance-based logic, even if the mechanical tests differ.
In our cross-border practice, we classify against at least three regimes simultaneously: the issuer's domicile, the primary distribution market, and the jurisdiction of the exchange or platform on which secondary trading is anticipated. A token that avoids securities characterization in one jurisdiction may trigger it in another. The Howey analysis will apply to any U.S. person who acquires the token, regardless of where the issuer is incorporated.
The common mistake at this step is to treat classification as a marketing exercise. A utility label on a whitepaper does not settle the legal classification. Regulators and courts look through the label to the economic substance. If the token's value is reasonably expected to appreciate, and if that appreciation depends on the managerial or entrepreneurial efforts of the issuer's team, classification as a security is the likely outcome in most major markets.
A useful preliminary check: does the token give holders a share of revenues, a claim on profits, a redemption right at a formula price, or a vote that affects the economic terms of the instrument? If the answer to any of those questions is yes, treat it as a security until a qualified legal analysis says otherwise.
Step 2 – Map the applicable regimes across every distribution market
Once classification is determined, the issuer must identify every jurisdiction in which the offering will touch – directly or indirectly – and map the applicable regime in each. This is not a one-jurisdiction exercise. Under MiCA, a token that constitutes a financial instrument falls outside MiCA's scope and remains governed by MiFID II, meaning that a European distribution requires a prospectus, an investment firm authorization, or a relevant exemption from both. In the UAE, a security token offered within the Dubai financial perimeter falls under the DFSA framework; offered to retail clients in mainland Dubai, it falls under the Securities and Commodities Authority and potentially VARA's activity-based perimeter. In Singapore, a token constituting a capital-markets product is regulated by MAS under the Securities and Futures Act, with prospectus requirements and recognized-market-operator obligations for any trading facility.
The BVI and Cayman Islands are frequently used as issuer domiciles because their VASP regimes focus on service-provider activity rather than on token classification per se. However, domicile in an offshore center does not eliminate the need to comply with the securities laws of the jurisdictions into which the offering is distributed. U.S. persons require a Regulation D, Regulation S, or Regulation A exemption regardless of where the issuer is incorporated. English-law restrictions apply to financial promotions communicated to U.K. persons, with the FCA's financial-promotion regime carrying criminal penalties for non-compliant communications.
The cross-border note at this step is that the most common structural failure is designing for the issuer's domicile and ignoring the investor's domicile. The regime that governs the offering in a given market is the regime of that market, not the regime of the issuer's home jurisdiction.
Operators we advise routinely discover mid-process that their investor base includes residents of three or four additional jurisdictions not in the original plan – often through a token sale platform's broad user base or through secondary-market anticipation. A robust geo-fencing and jurisdictional-restriction architecture, built before the offering opens, is easier and cheaper than a retroactive compliance remediation.
For a scoped classification and regime-mapping assessment before you commit to a structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the token rights, the investor profile, the expected distribution channels – change the analysis materially. Map your options.
Step 3 – Choose the issuer structure and domicile
The issuer entity and its domicile determine which disclosure regime applies, how the token is taxed at the entity level, and which regulators have primary supervisory authority over the offering. Common issuer structures include a special-purpose vehicle in an offshore center (Cayman, BVI, or Channel Islands), a licensed entity in a regulated hub (ADGM, AIFC, or an EU member state), or a foundation model (frequently used in Switzerland under FINMA oversight or in Liechtenstein under the Token Act).
Each structure carries different compliance costs and different levels of investor credibility. A Cayman SPV offers structural flexibility and established fund-law precedent, but it does not itself confer regulatory authorization in the distribution markets. A licensed ADGM entity offers the credibility of FSRA supervision and a recognized common-law framework, but it requires full regulatory authorization before the offering can proceed. A Swiss foundation structure, overseen by FINMA where the token constitutes a financial instrument, has a mature supervisory track record for token issuances and benefits from Switzerland's established institutional-investor base.
The common mistake at this step is optimizing for tax efficiency alone while ignoring the regulatory footprint. A zero-tax domicile that creates a securities-law gap in the primary distribution market generates enforcement risk that is more expensive than the tax saving. Issuer structure, regulatory authorization, and distribution scope must be designed together.
In our practice, we evaluate the issuer structure against at least four criteria simultaneously: the regulatory authorization required in the distribution market, the capital and reporting obligations in the issuer domicile, the tax treatment of token proceeds and secondary-market transactions, and the insolvency and investor-protection implications of the chosen legal form.
Step 4 – Prepare the offering documents to the required standard
Offering documents for a security token must meet the disclosure standard applicable in each distribution jurisdiction, and that standard is materially higher than a standard whitepaper. Under MiCA, tokens classified as financial instruments require a prospectus compliant with the EU Prospectus Regulation rather than a MiCA crypto-asset whitepaper. In the U.S., a private placement memorandum (PPM) is required for any Regulation D exemption, and a Form 1-A or Form S-1 is required for public offerings. In Singapore, a prospectus registered with MAS is required unless a recognized exemption applies.
The offering document must accurately disclose the nature of the token rights, the economic structure of the offering, the use of proceeds, the risks material to the investment, the governance mechanism, the smart-contract architecture (including upgrade or pause rights), and the identity and background of the key personnel. Smart-contract audit reports are increasingly expected by institutional investors even where not legally mandated.
The cross-border note at this step is that each jurisdiction may require a locally tailored disclosure supplement, or may require local counsel sign-off on the disclosure's compliance with local standards. A single English-law document is rarely sufficient for a multi-jurisdictional offering.
The common mistake at this step is treating the whitepaper as the offering document. A whitepaper is a product description. An offering document is a legal instrument that allocates disclosure risk between the issuer and the investor. Conflating the two leaves the issuer without the safe-harbor protection that a properly structured disclosure affords.
Step 5 – Build the AML and Travel Rule infrastructure before the offering opens
A security token offering is also a capital-raising event that triggers anti-money-laundering and counter-terrorist-financing obligations in virtually every major jurisdiction. The issuer, or the placement agent acting on its behalf, will typically qualify as a virtual asset service provider (a VASP, meaning an entity conducting regulated virtual-asset activities including issuance or transfer of value on behalf of others) and must implement a risk-based AML/KYC program before the first subscription is accepted. FATF Recommendation 15 and the Travel Rule (the obligation to pass originator and beneficiary data with a transfer above applicable thresholds) apply to the transfer of security tokens on secondary markets and must be built into the token's technical architecture, not added retrospectively.
In practice, this means that the smart contract governing the token should include transfer restrictions that can be enforced on-chain – a whitelist of verified wallet addresses, a compliance-module hook that checks a permissioned registry before permitting a transfer, or a similar mechanism. The choice of architecture has secondary-market liquidity implications: a highly restrictive on-chain compliance module may limit the pool of trading venues willing to list the token.
The common mistake at this step is deferring AML infrastructure to the post-issuance phase. Regulators in the leading hubs increasingly expect AML systems to be tested and operational before investor onboarding begins. A gap between subscription opening and AML-system readiness is a reportable compliance failure in most supervised regimes.
Operators we advise in multi-jurisdictional offerings regularly find that Travel Rule thresholds differ across the distribution jurisdictions: the applicable de-minimis varies by regime, and the data fields required also differ. A single technical solution must accommodate the most demanding applicable standard.
Step 6 – Plan the secondary market and ongoing disclosure obligations
The post-issuance phase of a security token offering carries obligations that persist for the life of the instrument, and they are frequently underestimated at the structuring stage. Ongoing disclosure, periodic reporting, material-event notifications, and insider-trading restrictions apply to security tokens in the same way they apply to traditional listed securities in most major regimes. Where the token is admitted to trading on a regulated market or a multilateral trading facility, the full market-abuse regime applies.
Secondary-market trading of security tokens requires either a regulated trading venue (a recognized exchange, an ATS in the U.S., an MTF or OTF in the EU) or a sufficiently restricted bilateral-transfer mechanism that keeps secondary trading within a permissioned perimeter. Operating an unauthorized securities exchange by facilitating peer-to-peer trading of security tokens without authorization is a serious regulatory offense in most jurisdictions.
The cross-border note at this step is that secondary trading is where the multi-jurisdiction compliance burden is most acute. A token issued by a Cayman SPV, distributed primarily to European institutional investors, and traded on a Singapore-based platform simultaneously engages Cayman, EU, and Singapore regulatory perimeters. Counsel in each relevant jurisdiction must sign off on the trading-venue authorization and the ongoing-disclosure model before secondary trading commences.
A common oversight is failing to plan the investor-communication infrastructure – the mechanics by which material events are disclosed to token holders, voting is conducted on-chain, and corporate actions (such as a buyback or a distribution) are executed. These processes must be documented before issuance; retrofitting them after the token is live creates governance risk and potential liability.
If your security token structure is at an advanced stage and secondary-market authorization is the next decision point, a scoped review can surface the gaps before they become enforcement issues. Write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a distribution channel was closed, a second read can identify the structural reason and the route forward. Map your options.
A recent structuring matter
In a recent engagement, a fintech group had structured a revenue-participation token and was preparing to distribute it to professional investors in the EU and the Gulf. The team had obtained a marketing opinion characterizing the token as a MiCA crypto-asset. In our review, we identified that the revenue-participation right – a pro-rata share of platform fee income – placed the token squarely within MiFID II's transferable-securities definition for EU distribution purposes, outside MiCA's scope entirely. We restructured the offering: the EU tranche was converted to a private placement under the Prospectus Regulation's exemption for qualified investors, with a fully compliant PPM; the Gulf tranche was re-domiciled through an ADGM structure with FSRA authorization. Secondary-market transfer restrictions were embedded in the smart contract before launch. The offering completed without regulatory incident.
A common assumption is that offshore domicile removes the securities-law risk
It does not. The securities laws of the distribution jurisdictions apply to the offering regardless of where the issuer is incorporated. A Cayman SPV issuing tokens to U.S. persons must comply with U.S. securities law. A BVI entity distributing to EU investors must comply with the Prospectus Regulation. Offshore domicile is relevant to tax, insolvency ranking, and entity governance – it does not create an exemption from the investor-protection regime of the investor's home jurisdiction.
The related misconception is that restricting the offering to "non-U.S. persons" through a Regulation S structure eliminates all U.S. exposure. Regulation S is a safe harbor, not an absolute bar. If a token distributed under Regulation S flows back into U.S. markets within the applicable restricted period, the issuer faces Section 5 liability under U.S. securities law. The restricted period, the legend requirements, and the distribution-compliance procedures must be actively managed, not assumed.
Related at OBOLUS
- Token Offerings & Securities practice – the full regulatory and structuring scope for token issuances across jurisdictions
- Token sale agreement drafting in Guernsey – Channel Islands structuring for token issuances and the applicable legal framework
- VARA licence application in Malta – licensing pathway for virtual-asset service providers operating through Malta under MFSA and the MiCA transition
FAQ
Is my token a security?
The answer turns on the economic substance of the rights the token confers, not the label applied in your marketing materials. If the token gives holders a share of profits, a claim on revenues, a redemption right, or a reasonable expectation of return derived from the issuer's efforts, it will be analyzed as a security in most major jurisdictions. Classification must be assessed separately under each applicable regime – the U.S. Howey standard, MiFID II in Europe, the MAS framework in Singapore, and SFC criteria in Hong Kong all differ in mechanics even where the underlying logic is similar. Legal advice specific to your token's rights structure is essential before distribution begins.
Do I need a MiCA whitepaper?
Only if your token falls within MiCA's scope – meaning it is not a financial instrument, e-money, or a deposit. If your token is a financial instrument under MiFID II, MiCA does not apply and a MiCA whitepaper is neither required nor sufficient; you need a Prospectus Regulation-compliant offering document instead. For tokens that do fall within MiCA – typically utility tokens and certain asset-referenced tokens – a whitepaper that meets the MiCA content requirements must be notified to the relevant national competent authority before public distribution begins. The notification timeline and authority vary by EU member state.
How should an airdrop be structured legally?
An airdrop is not automatically exempt from securities law or AML obligations. If the distributed tokens constitute securities, the airdrop is a securities issuance and must comply with the applicable exemption or registration requirements in each distribution jurisdiction. If recipients provide any form of consideration – including prior purchases, promotional activity, or data – the airdrop may constitute a sale for securities-law purposes. AML/KYC obligations also apply if the distributing entity qualifies as a VASP. A legally sound airdrop requires classification analysis, recipient eligibility screening, and a documented compliance rationale before distribution.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – a discipline that has shaped every structuring engagement we conduct. Digital assets are the entirety of our practice. To discuss your security token offering, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – advising token issuers and digital-asset platforms on the legal architecture of security token structures, smart-contract compliance design, and cross-border offering documentation.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.