Staking services sit at one of the most contested boundaries in digital-asset regulation today. A business offering yield on delegated tokens may simultaneously be providing a financial service, operating a collective investment scheme, acting as a custodian, and triggering anti-money-laundering obligations – all before a single user has withdrawn a reward. The compliance burden is not theoretical. Regulators across the United States, the European Union, the United Arab Emirates and Singapore have each signalled that staking services (arrangements through which a third party holds and deploys tokens to generate protocol rewards) will be assessed on their economic substance, not their technical architecture. This analysis maps that burden across the regimes that matter, identifies where the legal positions diverge, and sets out a practical framework for operators managing exposure today.
The central compliance question for a staking service is classification: does the arrangement constitute a regulated financial product? That determination flows from the rights the service confers on the user – the expectation of yield, the degree of operator control, the commingling of assets, and the allocation of risk. A utility label on a whitepaper does not settle that question. The substance of the arrangement does. Regulators and courts in every leading forum have confirmed this principle, and operators who rely on labels rather than legal analysis routinely discover the error at the worst possible moment.
The following sections work through the regulated perimeter, the cross-border classification conflicts, the AML and custody obligations that attach once a service crosses a threshold, and the structural choices available to operators trying to build a compliant staking product. A decision matrix and an anonymized micro-matter ground the analysis in practice.
The Regulated Perimeter: What Triggers a Licensing Obligation?
Most staking services cross the regulated perimeter the moment they promise, imply, or structurally generate yield for a user who has no independent control over the staking process. The operative tests differ by regime, but the analytical core is consistent: discretion plus pooling plus return equals a regulated product in most major jurisdictions.
Under MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), a staking service that holds tokens, exercises discretionary validation strategy, and distributes rewards may fall within the CASP (Crypto-Asset Service Provider) authorisation perimeter – specifically under the custody and portfolio-management activity definitions. Where the staked token itself qualifies as an ART (asset-referenced token) or EMT (e-money token), separate issuer obligations arise before the staking layer is even considered. MiCA does not contain a carve-out for staking as a standalone category; operators are advised to map each element of the service against the activity definitions in the regime, which the relevant national competent authority will apply on a substance-over-form basis.
In the United States, the SEC and CFTC have each asserted jurisdiction over staking arrangements, applying different analytical frameworks. The SEC's position, articulated in enforcement actions rather than rulemaking, treats pooled staking services as potential investment contracts under the applicable federal securities laws: users contribute value, the promoter's efforts generate the return, and the expectation of profit drives participation. The CFTC has asserted parallel commodity-derivatives jurisdiction where the token itself is a commodity and the staking structure resembles a swap or leveraged product. State-level money-transmitter licensing under individual state regimes – and the BitLicense framework administered by the NYDFS – adds a further layer. Operators building for US users cannot resolve this conflict by choosing one regulator; both must be considered simultaneously.
Singapore's MAS, under the Payment Services Act, focuses on the token's classification and the nature of the service. A staking service handling Digital Payment Tokens (DPTs) may trigger licensing obligations as a DPT service provider. Hong Kong's SFC, under the VASP licensing regime, takes a similar substance-over-form approach for staking offered on or through a VATP (virtual-asset trading platform). VARA in Dubai has published activity-based rules covering management and investment services for virtual assets; a staking service with discretionary elements will likely engage those rules.
How Does Classification Conflict Work Across Borders?
Classification conflict arises when the same staking product is legal – or exempt – in one jurisdiction but regulated in another, and the operator serves users across both simultaneously. This is the defining practical problem for most staking businesses. It is not resolved by choosing a single jurisdiction of incorporation; it is resolved by mapping where the service is offered, where the user base is located, and where the economic activity genuinely occurs.
Consider a common build: a staking protocol incorporated in a BVI entity, operated from a team based in the EU, serving users globally. The BVI FSC's VASP Act 2022 addresses registration obligations within the BVI, but it does not insulate the operator from MiCA passporting requirements if the service is accessible to EU users. MiCA's jurisdictional reach extends to services accessible to EU-resident users regardless of where the provider is incorporated. The CASP authorisation requirement follows the user, not the entity's domicile. At the same time, if the team's management decisions are made from an EU member state, that state's NCA may assert that the entity has a permanent establishment or a qualifying nexus requiring local authorisation.
The US nexus problem is more acute. US-person exclusions built into terms of service have, in practice, been given limited weight by the SEC and FinCEN where the platform remains technically accessible and where marketing – including social media activity – reaches US audiences. Operators who have relied on a "not for US persons" disclaimer without technical access controls have consistently found that disclaimer insufficient in enforcement contexts.
For a business sitting between the EU and the UAE, the legal question turns on a structural choice: which regime will anchor the authorised entity, and can that entity's CASP authorisation or VARA licence be demonstrated to the banking and payment partners who require regulatory clarity before onboarding? In our cross-border practice, we regularly see operators discover this problem after choosing a domicile for tax efficiency rather than regulatory coverage – the two considerations are not always aligned.
CTA #1 – The classification analysis above describes the standard path. Your facts – the entity's domicile, the user's residence, the token's economic rights, the operator's degree of control – change the outcome materially. Map your options with an OBOLUS analysis before committing to a structure.
What AML and Travel Rule Obligations Attach to a Staking Service?
A staking service that crosses the VASP or CASP threshold inherits a full AML/CFT compliance programme as a matter of regulatory baseline, including customer due diligence, transaction monitoring, suspicious activity reporting, and – critically – the Travel Rule (the obligation, derived from FATF Recommendation 15, to pass originator and beneficiary identifying information with qualifying virtual-asset transfers).
The Travel Rule creates a specific operational challenge for staking: the transfer of tokens from a user's self-custodied wallet to a staking operator's smart contract may constitute a covered transfer in jurisdictions that have implemented the rule. Whether the de-minimis threshold applies to that transfer, and whether the operator must collect and transmit originator data before accepting the delegation, depends on the specific implementation in the relevant jurisdiction – and those implementations differ. The EU's TFR (Transfer of Funds Regulation, extended to crypto-assets under the MiCA package) takes a broad approach; Singapore's MAS rules apply thresholds that vary by transfer type; the UK FCA has its own schedule. Operators who assume the Travel Rule does not apply to on-chain staking delegations because "no fiat moves" have consistently been corrected by compliance reviews.
Custody is a related pressure point. Most staking services require the operator to hold, or at least exercise control over, the user's tokens for the duration of the staking period. In most flagship regimes, custody is a regulated activity. The segregation of client assets, safeguarding requirements, and – in the event of operator insolvency – the treatment of commingled staked tokens as client assets rather than estate assets are each significant legal questions. The MFSA in Malta, FSRA in Abu Dhabi, and SFC in Hong Kong each impose specific safeguarding expectations on custodians of virtual assets, and a staking service that exercises temporary control over tokens should analyse whether those rules apply to its operational model.
Security, Utility, or Neither: How Does the Classification Test Apply to Staking Tokens?
The security-versus-utility classification test is the single most consequential legal question for most staking operators, and the most frequently misapplied. A utility label on a whitepaper does not settle the legal classification: the test is applied by regulators and courts against the economic reality of the rights the token confers, not the marketing language used to describe them.
The principle is consistent across regimes, though the mechanics differ. In the United States, the applicable federal securities-law analysis focuses on whether token holders invest in a common enterprise with an expectation of profit derived from the managerial efforts of others. A staking token that grants the holder a proportional share of protocol rewards generated by the operator's infrastructure, without any governance right or utility function, is analytically closer to a security than to a utility token – regardless of what the whitepaper says. FINMA in Switzerland applies its own token taxonomy (payment / utility / asset), with hybrid tokens assessed on the dominant economic function. ESMA and national competent authorities under MiCA analyse whether the token is an ART, an EMT, or "other" crypto-asset, with the whitepaper obligations and CASP authorisation requirements following from that classification.
The staking reward structure itself can shift the classification. A protocol that locks tokens, pools them, exercises discretion over validator selection, and distributes rewards proportionally has materially more securities-law exposure than a protocol that allows users to self-delegate directly to a validator of their choice with no intermediate pooling. Operators designing a new staking product should build that distinction into the architecture from the outset, not as an afterthought after the economic model is fixed.
In our practice, we assess classification against the substance of rights – the actual economic entitlements the token confers – not the marketing label. Misclassification at the design stage can convert a product launch into an unregistered securities offering, with enforcement consequences that attach personally to founders and directors in multiple jurisdictions simultaneously.
Does the DeFi Label Reduce the Compliance Burden for Staking Protocols?
The DeFi label does not, in itself, reduce the compliance burden for a staking protocol. Regulators have uniformly rejected the argument that "decentralisation" – however described in a whitepaper or DAO governance document – dissolves regulatory obligations where a human team controls the protocol's economics, upgrades, or treasury.
The FATF guidance on virtual assets expressly addresses DeFi (decentralised finance) protocols: where a developer or team retains control or sufficient influence over a DeFi arrangement, that team may meet the definition of a VASP under Recommendation 15 and its associated guidance. The question is not whether a smart contract (self-executing code deployed on a blockchain) runs automatically; it is whether identifiable persons exercise control over the parameters, revenues, or governance of the arrangement in a way that makes them the functional operator.
A staking protocol governed nominally by a DAO (Decentralised Autonomous Organisation) but in which a founding team holds a majority of governance tokens, controls the upgrade key, or retains economic benefits from the protocol's fee revenue will not satisfy the decentralisation argument in most regulatory contexts. The FSRA in Abu Dhabi, VARA in Dubai, and the SEC in the United States have each signalled this position through guidance or enforcement action.
This does not mean that structuring a staking protocol for genuine decentralisation is impossible; it means the architecture must be designed with legal analysis informing the technical build, not retrofitted after launch. The tokenization (conversion of economic rights into blockchain tokens) and governance-token design decisions made at the outset are the ones that determine the compliance profile for the protocol's life. Roman Levitt, our Technology & DeFi Counsel, frequently advises founding teams on precisely this sequencing: legal analysis before the smart contract is deployed, not after the first regulatory enquiry arrives.
What Legal Wrapper Best Suits a DAO Running a Staking Service?
There is no single legal wrapper that universally resolves the compliance exposure of a DAO operating a staking service, but the choice of wrapper materially affects the risk allocation, the enforceability of governance decisions, and the founders' personal liability exposure. Doing nothing – operating as an unincorporated association – is itself a structural decision, and generally the most dangerous one.
The principal options considered by operators we advise are: a BVI company (with VASP Act registration where required), a Cayman Islands foundation company (which can hold protocol assets without shareholders), a Wyoming DAO LLC (which provides limited liability but subjects the DAO to US law), a Marshall Islands DAO entity, or an AIFC-based structure in Kazakhstan for operators with a Central Asia / CIS user base. Each structure has a different AML obligation profile, a different governance-enforceability outcome, and a different relationship to the jurisdictions in which the staking service will be offered.
The Cayman foundation company model has become one of the more commonly used structures for protocols with significant user bases across multiple continents, because it separates the protocol treasury from its operators, allows governance-token holders to have enforceable rights without being equity shareholders, and gives the protocol a legal personality capable of contracting with service providers and exchanges. The AIFC structure is increasingly used where the operator has meaningful regulatory engagement in the AIFC environment and where the AFSA's common-law framework provides a familiar dispute-resolution mechanism.
Whatever the wrapper, it must be accompanied by a governance document that accurately describes the token holder's rights – and does not promise economic returns that would push the governance token into securities territory in the jurisdictions where it is distributed. The legal analysis of the wrapper is inseparable from the token classification analysis discussed above.
CTA #2 – If a prior structuring attempt has stalled because a banking partner or regulator has raised classification concerns, a second structural read can identify the specific issue and the route to resolution. Map your options with our team at OBOLUS.
How Do Tax and Banking Interact with the Staking Compliance Burden?
Tax and banking are the two pressure points that most often convert a structurally sound staking business into an operationally paralysed one. Neither is purely a legal question, but both have significant legal components that the compliance analysis must address.
On the tax side, the treatment of staking rewards as income versus capital, and the VAT or GST treatment of the staking service fee, varies by jurisdiction and has not been uniformly settled even in the most advanced digital-asset regimes. MiCA is a regulatory instrument; it does not harmonise tax. An operator with a MiCA CASP authorisation from a Lithuanian NCA will have a Lithuanian tax profile on the authorised entity's revenues, but the users receiving staking rewards may have income characterisation questions in their own jurisdictions. Where the operator's infrastructure is distributed – nodes in Switzerland, corporate treasury in Cayman, staff in the UAE – the permanent-establishment and transfer-pricing analysis can be as complex as the regulatory licensing analysis.
On the banking side, staking businesses face a structurally difficult onboarding environment. Most correspondent banks and payment service providers have compliance programmes that treat crypto businesses as high-risk by default. A staking service that can produce a VARA licence, a MiCA CASP authorisation, or an MAS Payment Services Act licence materially improves its banking prospects compared with an unregulated operator – but the licence alone is not sufficient. Banks will also ask about the token classification, the staking mechanism, the source of yield, the user due-diligence programme, and the Travel Rule compliance infrastructure. Operators who arrive at a banking conversation without documented answers to each of these questions consistently fail the onboarding review.
We have seen staking businesses that were structurally well-designed – right jurisdiction, right wrapper, right token classification – lose their primary banking relationship because a compliance officer at the bank concluded that the staking yield mechanism resembled a collective investment scheme under the bank's internal policy. That determination was not made by a regulator; it was made by a compliance professional working from a policy that had not been updated for the specifics of the staking product. Preparing and presenting the legal analysis proactively, before the account application is submitted, is the operationally critical step.
Decision Matrix: Which Profile Should Adopt Which Approach?
The right compliance posture for a staking service depends on the operator's profile, the nature of the staking product, and the user base. The following matrix sets out four common profiles in the operators we advise and the primary strategic considerations each faces.
Profile A – Institutional staking provider, EU user base, pooled service. This operator is most directly in MiCA scope. The primary instrument is a CASP authorisation from a national competent authority, with passporting across the EEA. The authorisation process for a custody and portfolio-management CASP typically involves a detailed application, capital adequacy documentation, an AML programme, and governance disclosures. The indicative timeline varies by NCA, but operators should plan for a process measured in months, not weeks. The key risk is that the NCA reviewing the application concludes the pooled staking product constitutes a collective investment scheme under national law rather than a CASP activity – a classification that would require a different authorisation path and materially higher capital requirements.
Profile B – DeFi protocol, global user base, genuine decentralisation architecture. This operator's primary instrument is a carefully designed legal wrapper (Cayman foundation or equivalent) combined with a robust governance architecture that minimises the concentration of control. The staking reward mechanism must be structured to avoid the economic hallmarks of a managed investment. The key risk is that the decentralisation architecture is challenged by a regulator in a jurisdiction where users are concentrated – typically the US or the EU – and found to be insufficient. The indicative compliance timeline for getting the architecture right is driven by legal analysis, not regulatory process; it can be completed in weeks if the legal work is prioritised from the outset of the build.
Profile C – Exchange adding a staking product to an existing VATP licence (Hong Kong) or VARA licence (Dubai). This operator has the advantage of an existing regulatory relationship. The primary instrument is a licence variation or product approval under the existing authorisation. The key risk is that the staking product's economic structure does not fit within the activity categories already authorised, requiring a new application rather than a variation. Exchanges in this profile sometimes underestimate the additional custody and safeguarding obligations that attach to staked assets held on behalf of users, particularly during a slashing event (a protocol-level penalty reducing the staked balance).
Profile D – Staking-as-a-service platform targeting institutional clients (funds, family offices, treasury managers). This operator's primary compliance driver is the institutional client's own regulatory posture. A fund that delegates to a staking service may have custody, conflict-of-interest, and best-execution obligations of its own that constrain which staking providers it can use. The staking platform must be able to produce documentation – legal opinions, AML certifications, audited smart-contract reports – that satisfies institutional due diligence. The indicative timeline for building that documentation stack is several months. The key risk is that the operator underestimates the documentation burden and loses institutional mandates to better-prepared competitors.
A Staking Classification Crisis Averted: A Practice Illustration
In a recent matter, a mid-size protocol team approached us after their primary banking partner flagged the staking reward distribution mechanism as a potential collective investment scheme. The platform had been operating for several months with a utility-token framing and no regulatory authorisation. The banking review had been triggered by the protocol's growing AUM, not by a regulatory enquiry. We conducted a classification analysis against MiCA, the applicable US securities-law framework, and the VARA activity definitions. The analysis identified that the pooled architecture – in which the operator selected validators, managed the stake allocation, and distributed rewards net of a management fee – had three of the four hallmarks of a managed investment under the applicable test. We restructured the delegation mechanism so that token holders could self-direct to individual validators, eliminating the pooling and discretion elements. The revised architecture was presented to the banking partner alongside a legal opinion. The account was retained, and the team subsequently applied for a CASP authorisation with the revised product design. The matter resolved without regulatory enforcement, but the window available for restructuring was narrow – the banking flag had arrived before a regulator had acted, which gave us the time to respond.
A Common Assumption Operators Get Wrong About Staking Compliance
A common assumption among staking operators is that compliance complexity scales with the size of the business – that a small protocol with modest AUM is below the regulatory radar and can defer the legal analysis until growth justifies the cost. This assumption is structurally incorrect for two reasons.
First, regulatory perimeters are activity-based, not size-based. A staking service that meets the functional definition of a regulated activity is within scope regardless of whether it manages a thousand tokens or a billion. FATF Recommendation 15 and every major implementation of it – under MiCA, the Payment Services Act in Singapore, the SFC's VATP regime in Hong Kong – apply to qualifying activities without a materiality threshold that exempts small operators.
Second, the cost of deferred compliance is not linear. A protocol that has operated without authorisation for a year or two has built up a remediation problem that is operationally and reputationally more complex than the authorisation problem it deferred. Retroactive restructuring of token economics, rewriting of smart-contract parameters post-deployment, and explanations to existing users about changes to the reward mechanism are each materially harder than designing the right architecture at the outset. The compliance investment at the design stage is the cheapest version of this exercise.
A related misconception is that the choice of a permissive jurisdiction – one with light-touch or no VASP regulation – insulates the operator globally. It does not. MiCA, the SEC, and MAS each extend their jurisdictional reach to services accessible to their users, regardless of where the operator is incorporated. Allied counsel in the relevant jurisdiction can advise on the local law position, but the global compliance analysis must be conducted on the basis of where users are, not where the entity is registered.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – our practice area for protocol-level legal analysis and smart-contract structuring
- NFT Project Legal Structuring: What Recent Enforcement Tells Operators – token-classification and enforcement lessons relevant to any issuance strategy
- Sanctions Exposure for Crypto Businesses: A Cross-Border View – the AML and sanctions overlay that interacts with every VASP compliance programme
FAQ
Can a DeFi protocol be regulated?
Yes. Regulatory perimeters attach to economic function and control, not to technical architecture. A DeFi protocol whose founders retain control of governance, upgrade keys, or fee revenue may meet the definition of a VASP or CASP under applicable law, including FATF Recommendation 15, MiCA, and the Payment Services Act in Singapore. Genuine decentralisation – with no identifiable controlling party – may place a protocol outside the regulated perimeter, but that threshold is harder to meet than most whitepapers acknowledge, and regulators in the US, EU and UAE have each challenged decentralisation claims in practice.
What legal wrapper suits a DAO?
There is no universal answer, but the most commonly used structures are Cayman Islands foundation companies (for protocols with a global user base and no single dominant jurisdiction), BVI companies with VASP Act registration, Wyoming DAO LLCs (where a US legal presence is acceptable), and AIFC-based entities in Kazakhstan. The right choice depends on the protocol's governance architecture, token holder rights, the jurisdictions in which the staking service will be offered, and the banking environment the operator needs to access. Legal analysis of the wrapper is inseparable from the token classification exercise.
Who is liable when a smart contract fails?
Liability for a smart-contract failure turns on the facts: who designed the contract, whether it was audited, what the terms of service state about protocol risk, and whether the failure constitutes a regulatory breach, a contractual failure, or both. Where a smart-contract failure causes user losses on a regulated staking service, the authorised entity may face regulatory action alongside civil claims. Developers who retained control after launch, or who made upgrade decisions proximate to the failure, face greater personal exposure. The analysis is jurisdiction-specific and turns on the degree of control exercised by identifiable parties.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is needed. To discuss your staking compliance situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border VASP classification, MiCA CASP authorisation strategy, and the AML/Travel Rule obligations attaching to DeFi and staking structures.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.