Cross-chain bridges sit at the sharpest intersection of DeFi protocol architecture and unresolved regulatory classification. A business deploying or integrating a bridge – an infrastructure layer that locks assets on one blockchain and mints representative tokens on another – faces simultaneous exposure across securities law, money transmission, AML/CFT obligations and custody regulation, often without a single licensing regime squarely designed for the activity. As regimes converge on the MiCA model and as VARA, MAS and the FCA tighten expectations for virtual asset intermediaries, the structural decisions made at formation increasingly determine whether a bridge operator is a regulated entity, an unlicensed one, or a target for enforcement. This analysis sets out the principal legal risks and the structuring angles that reduce them.
What Makes a Bridge Legally Distinct from Other DeFi Infrastructure?
A cross-chain bridge is legally distinct because it combines three regulated-adjacent functions in a single protocol: asset custody, token issuance and value transfer. When a user deposits ETH into a bridge contract on Ethereum and receives wrapped ETH on Arbitrum, the bridge has, in substance, accepted custody of an asset, issued a new instrument representing a claim on that asset, and facilitated a transfer of value. Each of those functions maps onto a regulated activity in at least one major jurisdiction. The fact that the mechanism is automated does not dissolve the legal analysis – regulators across MiCA, VARA and MAS are explicit that the substance of the activity, not its technical form, drives classification.
The custody component alone triggers scrutiny. Under MiCA, the custody and administration of crypto-assets on behalf of clients is a regulated service requiring CASP authorisation. A bridge that holds user assets – even temporarily, even in a smart contract – may fall within that definition depending on whether there is a legal person or entity exercising control over the contract's administrative keys. If a foundation or DAO-adjacent multi-sig holds upgrade authority, regulators will look at who controls the keys to determine whether a "service provider" relationship exists.
The issuance component raises a second and distinct set of questions. Wrapped tokens are not simply technical representations; they are instruments that grant the holder a claim – specifically, the right to redeem the underlying asset. Under MiCA, a wrapped token that represents a reference asset may qualify as an ART (asset-referenced token), triggering the most demanding authorisation track under that regime. The FSRA in Abu Dhabi and the MFSA in Malta apply analogous substance-over-form analysis to stablecoin-adjacent instruments. An operator who labels the wrapped token a "utility token" in its whitepaper has not settled the classification; it has stated a position that a regulator may or may not accept.
The process step that matters here is classification before deployment. Once a bridge goes live with real user funds, the window for voluntary rectification narrows sharply. In our practice, we regularly advise bridge operators to conduct a formal classification analysis – written, defensible, jurisdiction-specific – before the first token is minted on the destination chain.
For a scoped assessment of how your bridge architecture is likely to be classified under the regimes relevant to your user base, contact OBOLUS at info@oboluslaw.com. The process above describes the standard exposure map. Your facts – the entity structure, the admin key holders, the user jurisdictions – change the analysis materially. Map your options
The AML/CFT and Travel Rule Problem for Bridge Operators
Bridge operators face a structural AML problem: the Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary data with a virtual asset transfer) was designed for transfers between identified counterparties, not for protocol-mediated cross-chain movements. When a user sends assets through a decentralized bridge, the protocol has no built-in mechanism to collect, verify and transmit the data that the Travel Rule requires. The result is a regime mismatch that creates real enforcement exposure for any legal entity sitting behind the bridge.
The critical question is whether a legal entity associated with the bridge qualifies as a VASP (virtual asset service provider) in the relevant jurisdiction. If it does, Travel Rule obligations attach. The FCA in the United Kingdom, MAS in Singapore and the Bank of Lithuania under MiCA's transitional CASP regime all apply VASP classification to entities that provide virtual asset transfer services, regardless of whether those services are protocol-mediated. A foundation incorporated in a permissive jurisdiction that provides interface software, charges a fee, or exercises any discretionary control over the bridge may be caught even if the smart contract itself runs autonomously.
AML program requirements compound the Travel Rule problem. A classified VASP must maintain a written AML/CFT program, conduct customer due diligence, monitor transactions and file suspicious activity reports. A pseudonymous cross-chain bridge, by design, resists those obligations. This is not a technical problem with an easy technical fix; it is a structural mismatch between the protocol's architecture and the compliance expectations of the major financial centers. Operators who ignore it are not operating in a grey area – they are operating with an identified enforcement gap.
The practical structuring response is to separate the protocol layer from a licensed or registered service layer. The licensed entity handles onboarding, KYC and Travel Rule data collection; the protocol handles execution. This structure is imperfect – regulators may still argue that the protocol operator controls the licensed entity and therefore controls the transfer – but it is the most defensible available architecture where full decentralization is not yet achievable.
Does the Wrapped Token Create a Securities Law Problem?
A wrapped token issued by a bridge may constitute a security in certain jurisdictions, depending on the rights it confers and the expectations it generates. Under the securities analysis applied by the SEC and CFTC in the United States, the key question is whether purchasers of the wrapped token are investing in a common enterprise with an expectation of profit derived from the efforts of others. If the bridge charges a fee that accretes value to a governance token, or if the bridge's wrapped token trades at a premium to the underlying asset, a securities regulator may argue that economic substance supports classification as a security.
In the European Union, MiCA explicitly excludes instruments that qualify as financial instruments under MiFID II from its own scope. That exclusion creates a boundary, not a safe harbor: a wrapped token classified as a MiFID financial instrument falls under a more demanding regulatory regime, not outside regulation entirely. The MFSA and ESMA national competent authorities are actively working through this boundary question for bridge-issued instruments, and positions are not yet settled across member states.
In the UAE, VARA's activity-based licensing regime treats the issuance of virtual assets with investment characteristics as a regulated activity requiring a specific licence class. ADGM's FSRA maintains a list of "recognised" virtual assets and applies separate rules to instruments outside that list. An operator whose bridge issues a wrapped token in Dubai without mapping the token against VARA's classification criteria has assumed a regulatory risk that the licensing paperwork does not address.
The structuring angle here is entity segregation combined with jurisdictional optionality. A bridge operator who separates the token issuance function into a standalone legal entity – and who selects the jurisdiction for that entity based on a written classification opinion – has a far stronger position in a regulatory inquiry than one who issues through an undifferentiated protocol entity. This is not a theoretical preference; it is the approach we regularly recommend to clients preparing for institutional distribution of bridge instruments.
Who Controls the Bridge? The Legal-Entity Questions Regulators Ask First
Regulators, when they investigate a bridge, start with the same question a plaintiff's lawyer starts with: who is in control? Smart-contract automation does not eliminate the control question; it displaces it to the layer above the code. Admin keys, upgrade multi-sigs, DAO governance votes that can pause or modify the bridge – all of these represent control vectors that a regulator will trace to a legal person or entity.
The DAO structure (a decentralized autonomous organization that holds governance rights over a protocol) has become a default for bridge operators seeking to distribute control and reduce regulatory attribution. The legal reality is less tidy. In the United States, DAO governance tokens may themselves be securities, and the organization may be treated as an unincorporated association with unlimited joint-and-several liability among token holders. In the United Kingdom, the FCA has signaled that marketing DeFi products through a DAO wrapper does not exempt the marketing from financial-promotion rules. In the EU under MiCA, a DAO that issues or administers a crypto-asset service may be treated as a legal person for regulatory purposes where it has sufficient organizational structure to be identified.
The more defensible architecture couples a formal legal wrapper to the governance structure. A Marshall Islands DAO LLC, a Wyoming DAO LLC, a Cayman foundation company or a BVI legal entity under the VASP Act 2022 each provides a defined legal personality that can hold assets, sign contracts and engage with regulators. None of these automatically resolves the regulatory classification of the bridge's activities, but all of them create a defined counterparty that can be licensed, registered or supervised – which is materially better than operating through a structure that no regulator knows how to engage.
In our cross-border practice, we have seen enforcement agencies default to the most expansive available theory of liability when they cannot identify a clear responsible entity. A bridge with no identifiable legal person behind the admin key is not invisible to enforcement; it is vulnerable to the broadest possible attribution. Structuring a defined legal entity is a risk-reduction measure, not a compliance-avoidance device.
Cross-Border Regulatory Exposure: Where Does the Bridge Operate?
A cross-chain bridge with global users simultaneously touches the regulatory perimeters of every jurisdiction in which those users reside – and the operator's structural choices about entity domicile, server location and marketing activity all affect which regulators have a credible claim to jurisdiction. This is the hardest part of the bridge legal risk problem to manage, because the answer is not a single jurisdiction's licensing checklist.
Consider a bridge operator incorporated in the BVI, with a technical team in Europe, users across Asia, and a front-end hosted on infrastructure in the United States. The BVI FSC has authority over the entity under the VASP Act 2022. MAS may assert jurisdiction if the bridge provides services to Singapore-resident users. The SFC in Hong Kong has signaled willingness to pursue offshore operators who actively market to Hong Kong users. MiCA's CASP regime applies to services offered to EU-resident users regardless of where the provider is incorporated. And the SEC has long taken the position that US-person access to an offering triggers its jurisdiction, even absent a US entity.
The structuring response is not to incorporate everywhere. It is to make deliberate choices about which users to serve, to build geographic access controls and geoblocking infrastructure, and to document those choices as part of a written compliance program. A bridge that proactively excludes US-person access and maintains a defensible record of that exclusion is in a fundamentally different position from one that passively permits global access and claims not to know who its users are.
Allied counsel in the relevant jurisdiction are essential for the US, EU and APAC legs of this analysis. OBOLUS coordinates the multi-jurisdictional matrix and provides the cross-border structuring view, with allied counsel brought in for jurisdiction-specific opinion work where needed.
If your bridge has reached users across multiple regulatory perimeters without a formal access-control policy in place, a structured review can identify the exposures and the remediation path. Write to info@oboluslaw.com or message us via t.me/oboluslaw. Map your options
When the Code Fails: Smart-Contract Liability and the Legal Gap
Bridge exploits have produced some of the largest single-event losses in the history of digital assets. The legal question for operators, investors and users is who bears that loss. The answer turns on the contractual relationships, if any, that exist between the bridge entity and its users, and on the tort law of the jurisdiction whose courts are likely to hear a claim.
Most bridge protocols disclaim liability through terms of service that purport to exclude warranty and limit the provider's responsibility for code failures. The enforceability of those disclaimers depends on where the user is located and whether the relationship is characterized as a consumer contract or a commercial one. In the European Union, consumer-protection rules impose mandatory implied warranties that standard disclaimer language may not override. In the United Kingdom, the Unfair Contract Terms Act applies similar controls. In Singapore, the courts have shown willingness to analyze smart contract terms as binding agreements where the parties can be identified and the consideration is clear.
The more structurally significant liability question is whether the bridge operator owes a duty of care that exists independently of any contractual term. In common-law jurisdictions – England and Wales, Singapore, Hong Kong, the Caymans and BVI all operate common-law systems – a party who deploys infrastructure that others foreseeably rely upon may owe a duty to those relying parties even without a contract. Whether a bridge deployment creates that relationship turns on foreseeability, proximity and policy considerations that courts have not yet resolved uniformly for DeFi infrastructure.
The structuring implication is a clean separation between the entity that holds the admin keys and any entity that holds user-facing assets or distributes the bridge front-end commercially. If the protocol is genuinely non-custodial and the front-end is operated by a separate entity with its own terms, the liability chain is at minimum harder to trace. That is not immunity, but it is a structurally more defensible position than a single entity that controls the keys, operates the interface and holds the protocol treasury.
Structuring in Practice: A Bridge Operator's Pre-Launch Restructure
In a recent cross-border structuring matter, a payments-technology company had developed a bridge connecting two EVM-compatible chains and was preparing to open it to external users. The entity structure at the time placed protocol governance, the front-end interface and the fee treasury all within a single offshore company. We were engaged several weeks before the planned launch to assess regulatory exposure.
The classification analysis identified that the wrapped token issued by the bridge had ART-adjacent characteristics under MiCA and that the operator's user base included EU-resident addresses. The single-entity structure meant that CASP authorisation obligations, Travel Rule obligations and potential securities classification all attached to the same legal person. We advised a three-entity restructure: a foundation to hold the governance function, a licensed operating entity in a MiCA-transitional jurisdiction to manage EU-facing user onboarding and Travel Rule compliance, and a separate IP-holding entity to receive protocol fees. Geoblocking was implemented for US-person access, with documented controls.
The launch proceeded in a later season of that year. The client entered MiCA pre-application discussions with the relevant national competent authority from a position of structural clarity rather than remediation. The matter illustrates the value of a classification-first approach: the cost of restructuring before deployment was a fraction of what retroactive remediation would have required.
Decision Matrix: Which Structure Fits Which Bridge Operator Profile?
Bridge operator profiles vary materially, and the right structure depends on the operator's user base, the nature of the wrapped instrument, the degree of decentralization achieved and the jurisdictions in focus. The following analysis maps four common profiles to the structural response we most frequently recommend.
Profile A – Institutional bridge with identified counterparties: The operator is an institution-facing infrastructure provider whose counterparties are licensed VASPs or financial institutions. The appropriate structure centers on a licensed entity in a well-regulated hub – ADGM, Singapore, the DIFC, or a MiCA-authorized EU jurisdiction – with full AML/KYC on counterparties and a Travel Rule compliance solution. The wrapped token should be the subject of a written classification opinion filed with the relevant regulator before issuance. The timeline to operational status in this profile is typically measured in months rather than weeks, given the depth of the application process. The key risk is that the institutional counterparties impose their own compliance requirements on the bridge, which may exceed the minimum regulatory floor.
Profile B – Protocol-native bridge with retail user access and a governance token: This is the highest-risk profile. The retail user base in multiple jurisdictions creates multi-regulator exposure. The governance token may be classified as a security in the US and as a CASP-regulated instrument in the EU. The structuring priority is to separate governance from value accrual, to implement geographic access controls before launch, and to route EU-user interactions through an entity positioned for MiCA CASP authorisation. The timeline for full regulatory alignment is uncertain and varies by the NCA's backlog. The key risk is that partial compliance – licensing in one jurisdiction while ignoring others – is treated as an aggravating factor in enforcement, not a mitigant.
Profile C – Non-custodial bridge with no fee and no identifiable legal entity: The operator believes the fully decentralized structure removes all regulatory attribution. This belief is not currently supported by the enforcement posture of leading regulators. The structuring response is not to abandon decentralization but to document it rigorously, to structure a legal entity that can engage with regulators without assuming liability for the protocol, and to maintain legal opinions on why the bridge falls outside the VASP perimeter in the principal user jurisdictions. The timeline for this documentation process is shorter than a full licensing exercise, but the ongoing maintenance cost is real.
Profile D – Bridge subsidiary of a licensed exchange: The operator is a licensed VASP adding bridge functionality to its product suite. This is the most tractable profile. The existing CASP or VASP licence may extend to bridge activities, depending on the licence scope and the regulator's interpretation. A formal scope-extension application or a supervisory no-objection letter is the appropriate step before launch. The timeline depends on the regulator and the bridge's risk profile; a well-established exchange with a clean supervisory record will move faster than a new applicant. The key risk is that the bridge's DeFi characteristics – open accessibility, anonymous users – conflict with the exchange's KYC obligations and create a compliance gap that the regulator identifies on its next inspection.
The Utility Label Does Not Settle the Classification
A common assumption in bridge development teams is that labeling the wrapped token as a "utility token" in the whitepaper resolves the securities and MiCA classification questions. It does not. Regulators across every major jurisdiction – ESMA, VARA, MAS, the FCA and the SEC – apply substance-over-form analysis. The rights the token confers, the economic expectations it generates, and the degree to which those expectations depend on the efforts of an identifiable development team or foundation all feed the classification analysis. The label in the whitepaper is a starting position, not a conclusion.
Under MiCA, the category of "other crypto-assets" – those that do not qualify as ARTs or EMTs – still requires a whitepaper filing for public offerings of significant scale, and the whitepaper must accurately describe the instrument's economic rights. A whitepaper that describes a token as a utility instrument when its actual function is to represent a claim on bridged assets may itself constitute a misleading disclosure under the applicable regime.
The practical corrective is a written classification opinion from qualified counsel, produced before the whitepaper is finalized and updated whenever the token's functional characteristics change. That opinion does not eliminate regulatory risk, but it documents the analytical basis for the classification position and demonstrates good-faith engagement with the legal question – which matters materially in a supervisory inquiry or enforcement proceeding.
We assess classification against the substance of rights, not the marketing label. That approach is more conservative in the short term and significantly more defensible over the regulatory cycle.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – our core practice covering the full lifecycle of protocol and token structuring
- NFT Project Legal Structuring in Ireland – entity and regulatory considerations for digital-asset projects in an EU common-law jurisdiction
- Airdrop Legal Structuring: The Compliance Burden in Practice – classification, AML and cross-border distribution obligations for airdrop programs
FAQ
Can a DeFi protocol be regulated?
Yes, in substance if not always in form. The leading regulators – ESMA under MiCA, VARA in Dubai, MAS in Singapore and the FCA in the United Kingdom – apply substance-over-form analysis. Where a legal person or entity exercises meaningful control over a DeFi protocol, including through admin keys, upgrade authority or fee capture, that person or entity is likely to be treated as a regulated service provider. Full, documented decentralization may reduce that exposure, but it does not currently eliminate it in most major regulatory regimes.
What legal wrapper suits a DAO?
The appropriate legal wrapper for a DAO depends on the DAO's function and the jurisdictions in which it operates. Common options include a Cayman Islands foundation company, a BVI legal entity, a Marshall Islands DAO LLC and a Wyoming DAO LLC. Each provides legal personality – the ability to hold assets, enter contracts and engage with regulators – while accommodating tokenized governance. None of these automatically resolves the regulatory classification of the DAO's activities; that analysis is separate and must be conducted for the relevant jurisdictions.
Who is liable when a smart contract fails?
Liability for a smart-contract failure follows the legal relationships that exist above the code. The entity that deployed the contract, held the admin keys or commercially distributed the front-end interface is the most likely defendant in a common-law claim. Disclaimer terms in a protocol's user interface may limit but do not eliminate that exposure, particularly where consumer-protection rules apply or where a court finds a duty of care owed to relying users. Structuring the deploying, operating and fee-receiving functions into separate entities is the primary mechanism for managing this risk.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess classification against the substance of rights, not the marketing label – and digital assets are the entirety of our practice. To discuss your bridge structure or token classification question, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specializing in the classification and cross-border regulatory positioning of DeFi protocols, bridge infrastructure and wrapped-token instruments.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.