Cross-chain bridges move value between incompatible blockchains by locking assets on a source chain and minting equivalent representations on a destination chain. That mechanical elegance conceals a legal minefield. A business operating or integrating a bridge may simultaneously touch securities law, money-transmission regulation, anti-money-laundering obligations and, in the worst case, sanctions compliance – across multiple jurisdictions at once. As major regulators converge on the view that substance governs classification rather than labels, bridge operators can no longer rely on architectural arguments to stay outside the perimeter.
The central question is straightforward: who bears legal responsibility when a cross-chain bridge locks, mints, routes or loses value? The answer turns on the bridge's design, the rights conferred on users, the operator's degree of control, and the regulatory regime of every jurisdiction whose users or assets touch the protocol. This analysis works through each dimension, maps the contrasting regulatory positions across the leading hubs, and identifies the decisions that carry the most legal weight for builders, integrators and investors.
What Is a Cross-Chain Bridge, and Why Does the Architecture Matter Legally?
A cross-chain bridge is a protocol that enables assets or data to move between separate blockchain networks – for example, from Ethereum to a layer-2 rollup, or from a proof-of-work chain to a proof-of-stake chain. Architecturally, bridges fall along a spectrum from fully custodial (a named entity controls the locked assets and operates the relayer) to fully decentralized (smart contracts execute every step, with no identified operator). The legal exposure tracks that spectrum closely.
A custodial bridge presents the clearest regulatory surface. The entity that holds locked assets may be conducting custody of digital assets – a regulated activity under MiCA (the Markets in Crypto-Assets Regulation), the VARA regime in Dubai, the MAS Payment Services Act in Singapore, and the SFC's VATP licensing framework in Hong Kong. If the bridge also facilitates exchange or transfer between chains of differing token types, it may simultaneously trigger exchange and transfer-and-settlement licensing requirements. In our cross-border practice, we regularly advise bridge operators who have structured their locking mechanism as a technical function rather than a custody service, only to find that regulators examine the substance of control, not the internal label.
A non-custodial bridge replaces the operator with smart-contract logic. But the absence of a custodian does not eliminate regulation. FATF's Recommendation 15 on virtual assets – which underpins AML regimes across the FATF member jurisdictions – asks whether a natural or legal person has sufficient control or influence over a virtual asset service to constitute a VASP (virtual asset service provider). A smart-contract deployer who retains an admin key, earns protocol fees, or controls upgrade authority may satisfy that test. The same analysis applies under the FCA's registration regime in the UK and under FinCEN's interpretive guidance in the United States.
The architectural choice – custodial, semi-custodial, or non-custodial – is a legal decision, not only a product decision. It determines which regulatory regimes apply, which entity (if any) bears AML/KYC obligations, and how liability is allocated when the protocol fails.
Does a Bridge Token Trigger Securities Regulation?
Many bridges issue a governance token or a liquidity-provider token to align incentives across validators, relayers and liquidity providers. That issuance is where securities risk enters the picture most sharply.
The prevailing classification logic – applied by the SEC and CFTC in the United States, by ESMA and national competent authorities under MiCA, and by the SFC in Hong Kong – evaluates whether a token confers rights equivalent to those of an investment contract or a financial instrument. A bridge governance token that entitles holders to a share of protocol fees, voting rights over treasury deployment, and a claim on residual assets on dissolution looks, in substance, like an equity security. A whitepaper labeling it a "utility token" does not resolve that analysis. This is precisely the myth that the most costly enforcement actions have dispelled: a utility label on a whitepaper does not settle the legal classification.
Under MiCA, the classification work is somewhat more structured. The regulation distinguishes asset-referenced tokens (ARTs), e-money tokens (EMTs) and "other" crypto-assets, each with distinct authorization and whitepaper obligations. A bridge-issued token that is neither an ART nor an EMT falls into the residual category – but it may still constitute a financial instrument under MiFID II if it confers investment-type rights. The two regimes sit in parallel; ESMA has signaled that the boundary requires a substance-over-form assessment. In our practice, we assess classification against the substance of rights, not the marketing label, and that exercise must be completed before a token is issued, not after a regulator raises a question.
Mis-classifying a token can convert a product launch into an unregistered securities offering. That is not a theoretical concern. The SEC has pursued enforcement actions against issuers of tokens that functioned as investment contracts regardless of how they were marketed. The CFTC has asserted jurisdiction over bridge-related instruments on the basis that they reference a commodity. Across the Atlantic, national competent authorities under MiCA are now building their own classification practices. A bridge issuing tokens to users in multiple jurisdictions faces each of those regimes simultaneously.
The practical consequence is that any bridge considering a token issuance – governance, LP, or wrapped-asset – needs a multi-jurisdiction classification opinion before the token contract is deployed. Retrofitting a classification after launch, or after regulatory inquiry, is materially harder and more expensive.
For a scoped classification analysis across the jurisdictions where your bridge token will be accessible, contact OBOLUS at info@oboluslaw.com. The process above is the standard path. Your token's specific rights structure, distribution mechanism and user base shift the analysis materially.
How Do AML and the Travel Rule Apply to Cross-Chain Bridge Transfers?
The Travel Rule – the obligation to pass originator and beneficiary information alongside a virtual asset transfer – applies to VASPs under FATF Recommendation 16 and is implemented, with varying de-minimis thresholds, across the major regulated jurisdictions. Its application to cross-chain bridges is contested but increasingly resolved in favor of coverage wherever a VASP-equivalent operator is identifiable.
The basic problem is architectural. A bridge does not always have access to the originator and beneficiary data that the Travel Rule requires. The locking transaction on the source chain identifies a wallet address. It does not identify the natural person behind that address, the beneficial owner of the funds, or the destination wallet's regulatory status. A bridge that transmits value between chains without capturing and transmitting that data is, in jurisdictions where the Travel Rule applies, potentially in breach of AML/CFT obligations if the bridge itself constitutes a VASP.
The FCA in the UK, the Bank of Lithuania operating under EU AML directives, and FinCEN in the United States have each signaled – through guidance, consultation papers and enforcement – that the Travel Rule applies to virtual asset transfers wherever a covered entity is involved. Under MiCA's companion regulation, the Transfer of Funds Regulation as extended to crypto-assets, originator and beneficiary information must accompany transfers involving CASPs. A bridge that routes value for a CASP's customers, or that is itself a CASP, sits squarely within that obligation.
The cross-border dimension is acute here. A bridge routing assets from a Singapore-regulated exchange to a VARA-licensed custodian in Dubai touches MAS obligations on one side and VARA AML expectations on the other. The Travel Rule implementation is not identical in those two jurisdictions. The data fields required, the de-minimis thresholds, and the counterparty verification standards differ. A bridge operator must understand each regime it connects, not only the regime where it is domiciled.
In practice, bridge operators we advise typically face one of three structural choices: embed Travel Rule compliance at the application layer (collecting and transmitting KYC data before the locking transaction executes); operate exclusively within a closed ecosystem of verified counterparties; or restrict access to jurisdictions where the operator has mapped its obligations and implemented controls. None of these is simple. The first raises user-experience and data-protection questions. The second limits addressable market. The third requires ongoing jurisdictional monitoring as Travel Rule thresholds and implementation timelines evolve.
What Sanctions Risk Does a Cross-Chain Bridge Create?
Sanctions risk is the category where bridge operators have faced the most dramatic enforcement actions to date – not through formal regulatory proceedings but through the direct, code-level consequences of being designated by OFAC, the US Treasury's Office of Foreign Assets Control.
When OFAC designates a smart-contract address under its Specially Designated Nationals (SDN) list, every US person – and any entity subject to US jurisdiction – is prohibited from transacting with that address. For a bridge, designation effectively terminates access for any US-nexus participant without a specific license. The legal theory is straightforward: the bridge's smart contract is treated as "property" in which a designated party has an interest, or as a facility through which sanctions evasion occurs. A bridge that processes transactions from wallets associated with sanctioned entities or jurisdictions may find that the locking address itself becomes the subject of designation.
The cross-border angle matters here. A bridge with no US entity, no US investors, and no US users may nonetheless have US-nexus exposure if its underlying infrastructure – RPC providers, cloud hosting, oracle services – is US-based. OFAC's jurisdiction extends to US persons and entities, not merely to US-domiciled contracts. A bridge operator structured in the AIFC in Kazakhstan or licensed under the ADGM framework in Abu Dhabi is not necessarily outside OFAC's reach if its technical stack has US dependencies.
FINMA in Switzerland and the FCA in the UK maintain their own sanctions regimes that partially overlap with OFAC but are not identical. A bridge operator that has mapped OFAC compliance has not automatically mapped UK or Swiss sanctions obligations. In our cross-border practice, we regularly advise operators who treat sanctions as a US-only question, which under-estimates the exposure by a material margin.
The practical response is a pre-launch sanctions-risk assessment that identifies: (a) the jurisdictions and counterparties the bridge will serve; (b) the US-nexus elements in the technical stack; (c) the screening obligations that attach in each relevant jurisdiction; and (d) the kill-switch or pause mechanism that the operator retains to respond to a designation event. That last element – the protocol governance tool that allows the operator to respond to a regulatory event – itself raises questions about the degree of operator control that may bring the bridge within VASP registration requirements.
Who Is Liable When a Cross-Chain Bridge Fails?
Smart-contract failure in a bridge context – whether from a logic exploit, a validator compromise, or an oracle manipulation – can result in the loss of locked assets running into hundreds of millions of dollars at market value. The legal question of liability is unresolved in most jurisdictions and actively contested in the few forums where it has been litigated or arbitrated.
The starting analysis is whether a legally cognizable duty of care exists between the bridge operator and users who suffer loss. In common-law jurisdictions – England and Wales, Singapore, Hong Kong, the Cayman Islands and the BVI – the tort of negligence requires a duty, a breach, and damage. A fully decentralized bridge with no identifiable operator is difficult to sue in tort because there is no defendant. A bridge with an identifiable deployer, a multisig controlled by named parties, or a foundation that published audited documentation may have a closer case to answer. The English courts have demonstrated a willingness to recognize novel duties in relation to digital assets in asset-recovery cases; those same principles are beginning to surface in loss-of-funds disputes.
Contract analysis applies where users enter into explicit terms of service. A bridge that requires users to accept terms before connecting a wallet creates a contractual relationship, and the scope of that relationship determines the basis for a damages claim. Exclusion clauses and limitation-of-liability provisions in those terms are subject to the applicable law's reasonableness test. In EU-facing products, consumer protection directives impose constraints on exclusion clauses even where the counterparty is not a consumer in the traditional sense.
Regulatory liability operates alongside private law liability. A bridge found to have conducted regulated activity without authorization – custody, exchange, transfer-and-settlement – may face enforcement action that compounds the civil exposure. Regulators in the leading hubs have shown a willingness to pursue enforcement against decentralized or partially decentralized protocols where a responsible party can be identified. The VARA regime in Dubai, the SFC in Hong Kong, and the FCA in the UK have each moved against entities that relied on decentralization as a regulatory shield.
In a recent matter, a payments infrastructure company suffered a seven-figure loss following a bridge exploit that rerouted locked assets to an attacker's wallet. Our disputes team worked with blockchain forensics partners to trace the transaction path across three chains, identified the attacker's consolidation addresses, and prepared a disclosure application in a leading common-law forum. The chain of evidence ran from the originating locking transaction to the bridge's validator set to the attacker's withdrawal address on a centralized exchange. That chain was sufficient to support a freezing application before the attacker moved the funds off-exchange.
If a bridge exploit or misappropriation has occurred, the recovery window is measured in hours. Contact OBOLUS immediately at info@oboluslaw.com. If a prior recovery attempt stalled or an account was closed, a second read of the on-chain evidence can surface the structural reason and the route back.
How Do the Major Regulatory Hubs Treat Cross-Chain Bridges Differently?
No single regulatory framework governs cross-chain bridges globally, and the contrasting approaches of the leading hubs create genuine arbitrage risk for operators who fail to map each regime they touch.
Under MiCA, the operative question is whether the bridge constitutes a CASP (crypto-asset service provider) by providing custody, exchange, transfer or portfolio management services. The regulation's service-based categorization is broader than most operators anticipate. A bridge that holds locked assets, even briefly and automatically, may constitute a custody service under the applicable CASP provisions. A bridge that permits users to exchange one asset for another in the locking/minting process may constitute an exchange service. Each of those activities requires CASP authorization from an EU national competent authority, and the passporting mechanism allows – but does not require – a single authorization to cover the whole EEA.
VARA in Dubai takes an activity-based licensing approach across seven defined activities: advisory, broker-dealer, custody, exchange, lending, management, and transfer-and-settlement services. A bridge that operates from Dubai's mainland, or that has a Dubai-nexus operator, must assess which of those seven activities the protocol performs. VARA's rulebooks are granular, and the authority has shown a willingness to engage on novel structures where operators engage proactively before launch rather than after.
The MAS in Singapore applies the Payment Services Act to digital payment token services, which include the exchange and transfer of digital payment tokens. A bridge that routes Singapore-user transactions may require either a standard payment institution or a major payment institution license from MAS, depending on transaction volumes and counterparty characteristics. MAS has historically been receptive to structured engagement from applicants who present a clear compliance architecture upfront.
The SFC in Hong Kong requires VASP licensing for virtual-asset trading platforms. A bridge that permits asset exchange – not merely asset transfer – may fall within the trading platform definition depending on its functionality. The SFC's position is that economic substance governs categorization; a bridge that functions as an exchange is an exchange, regardless of what its documentation says.
The AIFC/AFSA framework in Kazakhstan and the ADGM/FSRA framework in Abu Dhabi both apply common-law-based regulatory regimes that are broadly receptive to crypto-asset business, including novel structures. Both have digital-asset trading facility and custody concepts that may capture bridge operations depending on the activity profile. Operators choosing these hubs for bridge operations benefit from regulators that engage substantively on structuring questions, but the cross-border reach of the bridge's users still requires a mapping of every jurisdiction's obligations.
The FCA in the UK applies its cryptoasset registration under the Money Laundering Regulations and, separately, financial-promotion rules to marketing communications relating to crypto-assets. A bridge accessible to UK users that promotes its services without FCA registration or authorization is potentially in breach of both regimes simultaneously. The UK's financial-promotion restrictions are among the most operationally demanding in any major jurisdiction.
Which Legal Profile Fits Your Bridge Structure?
Not every bridge carries the same legal weight. The profile of the operator, the architecture of the bridge, and the geographic distribution of users together determine which regimes apply and at what intensity. The following decision matrix works through the most common configurations.
Profile A – Custodial bridge with an identified operator entity, issuing a governance token, serving EU and UK users. This profile carries the highest regulatory burden. The operator is likely a CASP under MiCA, requiring CASP authorization in at least one EU member state. The governance token requires a classification opinion and potentially a whitepaper under MiCA. The UK financial-promotion rules apply independently. AML/KYC and Travel Rule obligations attach under both regimes. The operator needs a licensing strategy, a token classification opinion, and a compliance program before launch. Indicative lead time from engagement to operational launch is a matter of months rather than weeks, depending on the chosen NCA and the completeness of the application package.
Profile B – Semi-custodial bridge, no token issuance, users primarily in Singapore and Hong Kong. This profile is more contained but not unregulated. MAS Payment Services Act analysis is required to determine whether the bridge's activity constitutes a digital payment token service. The SFC's VASP licensing framework requires analysis of whether the bridge's routing constitutes a trading platform function. AML obligations attach in both jurisdictions under FATF-aligned frameworks. Travel Rule compliance must be mapped against both MAS and SFC expectations. The compliance architecture is narrower than Profile A but the consequences of misreading either regime are equally severe.
Profile C – Non-custodial bridge, no identified operator, no token, open access. This is the profile most operators assume is outside the regulatory perimeter. The reality is that this profile has the most unpredictable regulatory exposure. FATF's virtual asset guidance specifically addresses DeFi protocols where software is controlled by an identifiable party. Any admin key, fee-capture mechanism, or upgrade authority creates a potential VASP nexus. The sanctions risk is present regardless of architecture. And civil liability for loss follows the chain of causation, not the architecture diagram. A non-custodial bridge whose deployer retains meaningful control may be assessed as a VASP across multiple jurisdictions simultaneously, with no single licensing path that resolves the exposure globally.
Profile D – Bridge integrated into a regulated exchange's product suite. This profile benefits from the exchange's existing regulatory relationship but creates new questions about the scope of that authorization. Does the exchange's CASP authorization extend to the bridge service? Does the bridge's AML program satisfy the exchange's own regulator's expectations? Does the bridge create a new entity-level risk that the exchange's license does not cover? In our cross-border practice, we have seen exchanges assume that their existing authorization covers new DeFi-adjacent product lines, only to find that the addition of a bridge required a separate regulatory engagement or a material expansion of the authorization's scope.
A Common Assumption: Decentralization Removes the Legal Risk
The most persistent misconception in the bridge space is that sufficient decentralization removes the bridge from the regulatory perimeter entirely. The argument runs: if no one controls the protocol, no one can be regulated. Regulators in every major hub have engaged with this argument – and have largely rejected it, at least at the margins where real bridge operations sit.
FATF's guidance on virtual assets explicitly addresses "decentralized applications" and states that where a natural or legal person maintains control or sufficient influence – including through the ability to set parameters, collect fees, or effect upgrades – the VASP definition may apply regardless of the degree of automation. The SEC has adopted a similar functional analysis, focusing on whether the issuance or trading of a token depends materially on the efforts of an identifiable group. The VARA rulebooks in Dubai and the FSRA framework in Abu Dhabi both follow a substance-over-form approach.
In practice, very few cross-chain bridges that operate at commercial scale are fully decentralized in the sense that no identifiable party retains meaningful control. Most have a founding team, a development company, a grants-issuing foundation, or a multisig holder who can affect protocol behavior. That party bears the legal risk even if its role is described in technical rather than legal terms.
The practical implication is that operators who rely on the decentralization defense as their primary legal strategy are making a bet that regulators will not look behind the architecture. In our view, that bet has become considerably riskier as regulators across the major hubs have developed the technical and legal capacity to analyze on-chain governance structures. The more durable strategy is to identify the actual control structure, map the legal obligations that follow from it, and build a compliance architecture that matches those obligations – rather than assuming the obligations do not exist.
To pressure-test your bridge's legal structure before you commit to a jurisdiction or an architecture, message OBOLUS at t.me/oboluslaw.
Related Practices at OBOLUS
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – full-scope legal practice for DeFi protocols, token issuers and on-chain businesses
- Oracle and Data-Feed Liability for Regulated Entities – legal exposure when a protocol depends on third-party price or data feeds
- AML Audit Defence – The Compliance Burden in Practice – managing regulator inquiries and AML audits across digital-asset businesses
FAQ
Can a DeFi protocol be regulated?
Yes. Whether a DeFi protocol falls within the regulated perimeter depends on whether an identifiable natural or legal person retains sufficient control or influence over it – through admin keys, upgrade authority, fee-capture mechanisms or governance rights. FATF's Recommendation 15, the MiCA CASP framework, and the MAS Payment Services Act all apply a substance-over-form test. Architectural labels such as "permissionless" or "decentralized" do not determine the outcome. The control analysis does.
What legal wrapper suits a DAO?
A DAO (decentralized autonomous organization) operating without a legal wrapper exposes its members to unlimited joint liability in most jurisdictions, because an unincorporated association is the default. Common wrappers include a Cayman Islands foundation company, a BVI company, a Marshall Islands DAO LLC, or a Swiss association or foundation. The right choice depends on the DAO's activity, its user base, its tax profile, and the regulatory regimes it touches. There is no universal answer; the decision is a structuring exercise, not a formation preference.
Who is liable when a smart contract fails?
Liability follows the chain of causation and the nature of the relationship between the protocol and the affected party. A deployer who retained admin-key authority, published audited documentation and collected fees may face negligence claims in common-law jurisdictions. A bridge operator that conducted regulated custody without authorization may face both regulatory enforcement and civil claims. Where contractual terms of service exist, those terms govern the scope of liability – subject to applicable consumer-protection and reasonableness tests. The absence of a formal operator does not eliminate liability; it makes identifying the defendant harder, not impossible.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, DeFi protocol teams and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label, and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specializing in cross-jurisdictional regulatory analysis for DeFi protocols, bridge operators and token issuers navigating multi-hub compliance obligations.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.