Staking services sit at one of the most contested boundaries in digital-asset regulation. Whether a provider offers institutional delegation pools, retail liquid-staking derivatives, or validator-as-a-service infrastructure, regulators across the United States, the European Union, and Asia-Pacific have each reached different conclusions about whether the activity constitutes a securities offering, a collective investment scheme, an e-money service, or something that requires no licence at all. For a business operator, that ambiguity is not academic. Mis-classifying a staking product can convert a product launch into an unregistered securities offering – with the enforcement record to prove it.
The staking service legal framework is not a single regime. It is an overlay of token-classification rules, investment-contract doctrine, collective-scheme definitions, and, under MiCA (the EU's Markets in Crypto-Assets Regulation), the emerging CASP authorisation regime and the ART/EMT stablecoin architecture that increasingly surrounds liquid-staking tokens. The cross-border dimension compounds the difficulty: a protocol headquartered outside the United States still reaches US users; a Malta-registered CASP passporting under MiCA may simultaneously serve users in Singapore, where the Monetary Authority of Singapore applies its own Payment Services Act analysis to digital-payment-token services. This analysis maps the enforcement signals to date, sets out the legal theories in play, and provides a decision framework operators can use before they build or expand.
What Enforcement Has Actually Decided About Staking Services
Enforcement actions against staking providers have consistently turned on two questions: whether the service involves an investment of money in a common enterprise with an expectation of profit from others' efforts, and whether the operator retains sufficient control over the protocol to be the relevant "issuer." Both questions track older securities-law doctrine applied to new infrastructure – the specific statutory label varies by jurisdiction, but the underlying analysis is strikingly consistent. In our cross-border practice, we have seen operators learn this lesson only after a regulator filed.
The most significant signal from US enforcement is the application of the Howey investment-contract test to pooled staking arrangements. Where a provider aggregates user assets, deploys them as a validator, and distributes rewards according to a formula it controls, regulators have argued that users are passive investors depending on the operator's efforts. The operator's marketing materials – promises of "guaranteed APY", "passive income" or "institutional-grade returns" – have repeatedly featured in enforcement records as evidence of the profit expectation prong. The lesson is structural: the closer the protocol comes to a managed fund, the more squarely it lands within securities perimeters.
In the EU, the MiCA regime does not contain a single, express staking-service licence category. However, ESMA guidance and national competent authority statements have made clear that liquid-staking tokens – tokens representing a claim on staked assets and accruing yield – can constitute asset-referenced tokens or, where the yield is denominated in a fiat reference, e-money tokens. Either classification triggers whitepaper obligations, reserve requirements, and CASP authorisation obligations before any marketing to EU users. Operators who assumed that the "utility" framing of a liquid-staking receipt token would avoid these obligations have, in our observation, consistently found that the substance-over-label principle governs the analysis.
Token Classification: Why It Is the Threshold Question
Token classification is the gateway determination: every other legal obligation flows from it. A utility label on a whitepaper does not settle the legal classification – this is the most consequential myth in the staking market, and enforcement has repeatedly corrected it. Regulators assess what rights the token actually confers, not what the issuer calls it.
The analysis branches at three points. First, does the token confer a right to a proportionate share of revenues or profits? If yes, most securities frameworks – US federal law, the UK Financial Services and Markets Act perimeter, Singapore's Securities and Futures Act – will treat it as a security, an investment, or a capital markets product. Staking-reward tokens that pay out a fixed percentage of validator fees are particularly exposed here. Second, does the token represent a claim on a reserve of fiat or other assets? Under MiCA, that makes it an ART or EMT. Third, does the token do nothing except grant access to a non-financial service? Only then does a pure-utility reading become defensible.
For staking derivatives specifically, the analysis almost always lands in the first or second branch. A receipt token for staked ETH, for instance, represents a pro-rata claim on the underlying pool plus accrued yield. That is economically indistinguishable from a unit in a collective investment scheme in most common-law jurisdictions. The Hong Kong SFC has been explicit: pooled staking arrangements where the operator manages the validator process and distributes rewards are subject to its licensing regime for collective investment schemes. The Swiss FINMA token taxonomy similarly classifies yield-bearing digital assets as "asset tokens" requiring regulatory treatment aligned to the underlying exposure.
In our practice, we assess classification against the substance of rights, not the marketing label. That assessment requires a legal opinion that maps the token's economic rights, governance rights, and transferability against each target jurisdiction's classification criteria. Building that opinion before the whitepaper is published is materially cheaper than defending a post-launch enforcement action.
The process above describes the standard classification path. Your facts – the token architecture, the user base, the staking mechanism – change the analysis materially. For a scoped classification assessment ahead of your product launch, contact OBOLUS at info@oboluslaw.com.
How Does MiCA's CASP Regime Apply to Staking Services?
Under MiCA, the CASP (Crypto-Asset Service Provider) authorisation framework covers a defined list of crypto-asset services, and staking-as-a-service falls within its scope where the provider operates the validator infrastructure or pools user assets on a discretionary basis. The key regulatory question is whether the operator exercises discretion over the user's assets – if it does, the service begins to look like portfolio management under an existing financial-services regime rather than a pure infrastructure play.
The MiCA whitepaper regime also catches liquid-staking token issuers. An issuer of an ART must obtain authorisation from its home-state national competent authority before offering tokens to the public in the EU. That authorisation requires a whitepaper that meets the content standards set by ESMA's regulatory technical standards, a governance structure, reserve management rules, and ongoing disclosure obligations. The passporting mechanic then lets the authorised issuer offer across the EEA – a significant commercial advantage for operators prepared to do the upfront compliance work.
The cross-border interaction is critical. A non-EU staking provider actively marketing into EU member states is subject to MiCA's third-country provisions. Those provisions do not allow indefinite reverse-solicitation reliance where the operator has made targeted marketing efforts. Operators who relied on pre-MiCA "no active marketing" arguments to avoid EU authorisation are now in a progressively narrower position as the transition period closes. In our cross-border practice, we regularly advise businesses on the point at which passive availability crosses into active marketing – a distinction that turns on specific facts, including geo-targeted advertising, EU-language documentation, and EU-specific payment rails.
What Does the US Howey Analysis Mean for Staking Operators in Practice?
The US Howey test, drawn from the investment-contract doctrine, remains the operative framework for assessing whether a staking service constitutes an unregistered securities offering under US federal law. Enforcement positions taken by the SEC have applied Howey to pooled staking programs on the basis that users invest money, join a common enterprise, and derive profit from the operational efforts of the operator. The operator's role in selecting validators, managing slashing risk, and calculating and distributing rewards has been central to each enforcement analysis.
The practical implications are significant. A US-registered entity operating a staking pool for retail users is likely offering a security unless it has registered the offering or obtained a valid exemption. A non-US operator with US users is in a materially identical position. The registration requirements that follow are substantial: disclosure obligations, periodic reporting, broker-dealer or investment-adviser registration depending on the service model, and state-level money-transmitter licensing under the parallel FinCEN AML framework.
Validator-as-a-service providers who offer infrastructure only – where the user retains control of the private keys and the provider simply runs the software – occupy a more defensible position. The passivity of the user's profit dependency is reduced when the user selects the validator, sets parameters, and retains the ability to undelegate. That structural argument has been presented in several non-public correspondence exchanges with the SEC, though it has not been definitively validated through a no-action letter for staking specifically. Operators who rely on it should document the user-control architecture carefully.
Separately, FinCEN's money-services-business framework applies to operators who custody user assets or facilitate transfers in connection with staking. This triggers AML programme requirements, suspicious activity reporting, and the Travel Rule – the obligation to pass originator and beneficiary data with transfers above the applicable de minimis threshold.
Smart Contracts and DAO Structures in Staking Protocols: Do They Change the Legal Analysis?
Wrapping a staking protocol in a DAO (decentralized autonomous organization) structure or replacing the operator's discretion with smart contracts (self-executing code deployed on a blockchain) does not automatically defeat the regulatory analysis. Regulators have increasingly looked through automated execution to the humans and entities who wrote, deployed, and maintained the underlying code.
The smart-contract argument has three variants. The first is full decentralization: if no identifiable party controls the protocol and governance is genuinely distributed across a large token-holder base, some regulatory frameworks do apply a reduced-scrutiny standard. FINMA's guidance on DeFi and the FATF's updated guidance on virtual assets both acknowledge the decentralization spectrum, though neither exempts a genuinely decentralized protocol entirely. The second variant is partial decentralization: a DAO that is majority-controlled by a founding team or a venture-capital treasury has governance that is decentralized in form but not in substance, and regulators have not accepted the structural argument in that context. The third is pseudo-decentralization: a smart contract with an admin key, a pause function, or an upgrade mechanism controlled by a company is simply a managed service with extra steps. Enforcement has treated it accordingly.
The DAO legal-wrapper question is equally live. A DAO that operates a staking protocol without a legal entity creates a general-partnership default in most common-law systems – every governance token holder potentially bears joint and several liability for the protocol's acts. The conventional responses include a Marshall Islands DAO LLC, a Wyoming DAO LLC, a Cayman Foundation Company, or a BVI company structure under the BVI FSC VASP Act 2022. Each carries different attributes on limited liability, governance formalization, and regulatory perimeter. The choice turns on the protocol's user base, the revenue model, and the jurisdictions in which it operates or markets.
In a recent matter, a DeFi protocol operating a liquid-staking service approached us after receiving a regulatory inquiry in a leading European jurisdiction. The protocol had deployed under a DAO governance model with no formal legal wrapper. We advised on a Cayman Foundation structure that ring-fenced governance liability, worked with allied counsel in the relevant jurisdiction to prepare the regulatory response, and assessed the CASP authorisation pathway for the liquid-staking token under MiCA. The outcome was a defensible legal posture and a clear roadmap to authorisation. The absence of a legal wrapper at launch had been the single largest structural vulnerability.
Cross-Border Staking: Which Jurisdiction Actually Governs?
For a staking service, the governing jurisdiction is not simply where the operator is incorporated. Regulators apply territorial reach based on where users are located, where marketing is directed, and where assets are custodied. A Cayman-incorporated entity with a Singapore operations team, EU retail users, and US institutional clients faces a four-jurisdiction compliance stack from day one. This is the cross-border reality that operators frequently underestimate at the product-design stage.
The EU's MiCA regime is explicit: it applies to any offer of crypto-asset services to persons located in the EU, regardless of the provider's location. The US federal perimeter applies to US persons and, in many respects, to offshore transactions that have a substantial nexus with US markets. The MAS in Singapore applies its Payment Services Act to digital-payment-token services provided to Singapore users or to users accessing the service through Singapore payment infrastructure. The SFC in Hong Kong applies its VATP regime to exchanges and potentially to pooled staking arrangements operating from or into Hong Kong.
The practical cross-border approach involves a three-layer analysis. First, map every jurisdiction in which users are located or to which marketing is directed. Second, apply each jurisdiction's classification criteria to the token and the service model. Third, identify which licences, registrations, or exemptions are required, and sequence the applications in order of commercial priority. The licensing and banking stack should be designed together – a CASP authorisation in Lithuania or Malta that passports across the EU will need a banking relationship that recognises the authorised status, and the selection of banking jurisdiction is itself a compliance decision.
If a prior application stalled or an account was closed in connection with a staking product, a second structural read can identify the reason and the route forward. Write to OBOLUS at info@oboluslaw.com.
Decision Matrix: Which Operator Profile Requires Which Legal Response?
Different staking service models present materially different risk profiles, and the appropriate legal response varies accordingly. The matrix below describes the principal profiles in prose rather than a table – because the classification turns on facts, not on a checkbox.
Profile A – Institutional validator-as-a-service. An operator that provides validator infrastructure to institutional stakers who retain control of keys and set their own delegation parameters. This profile presents the lowest securities-law risk under most regimes: the user is active, the operator's role is infrastructure, and the profit dependency on the operator's "efforts" is weakest. The primary regulatory exposure is AML / Travel Rule compliance and, in the EU, an assessment of whether the service constitutes a regulated CASP activity. Timeline to a defensible compliance posture: typically a matter of weeks for a legal opinion and policy build-out. Key risk: a contractual architecture that inadvertently gives the operator discretion over the user's staking parameters.
Profile B – Retail liquid-staking protocol with a yield-bearing token. An operator that issues a receipt token to retail users representing their share of a pooled validator position, with the token accruing yield and being freely transferable. This profile presents the highest multi-jurisdictional risk. Under US law, the Howey analysis is strongly engaged. Under MiCA, the receipt token is likely an ART or, if yield is denominated in fiat, an EMT, triggering full authorisation obligations. Under the SFC regime in Hong Kong and the MAS regime in Singapore, a collective-scheme or regulated-product analysis applies. Timeline to a compliant product launch: a multi-jurisdictional legal opinion followed by a CASP authorisation application, which typically takes several months from the date of a complete filing. Key risk: launching before authorisation on the assumption that the token is utility only.
Profile C – Protocol-governed staking via a DAO. An operator that deploys a smart-contract staking pool governed by a DAO with no legal wrapper. This profile presents significant liability risk at the governance level, as well as the full securities/collective-scheme analysis that applies to the underlying token. Immediate priority is the legal wrapper decision, followed by the token classification opinion and jurisdiction selection. Key risk: the "decentralized" argument failing because a founding team or protocol treasury holds majority governance power.
Profile D – Cross-border service with EU and US retail reach. Any of the above profiles with a user base spanning the EU and the US faces a concurrent MiCA authorisation obligation (or a credible geo-restriction mechanism) and a US securities analysis. These obligations do not conflict in structure, but the sequencing, the entity architecture, and the banking decisions must be coordinated. In our practice, we structure licensing, banking, and tax as one mandate rather than three disconnected workstreams – the interdependencies are too significant to manage piecemeal.
What Are the Most Common Structural Mistakes Operators Make Before Enforcement Arrives?
The most common mistake is building the product before commissioning a legal opinion. The second is commissioning a legal opinion from counsel unfamiliar with the cross-border dimension of digital-asset classification. Together, these two errors account for the majority of preventable enforcement exposures we have seen operators face.
A recurring structural error is the assumption that a yield-bearing token can be classified as utility because it is "used" within the protocol. The test under every relevant framework is not whether the token has a use; it is whether the token also confers an economic return. A token that does both – grants access and pays yield – satisfies both the utility criteria and the investment criteria. The investment criteria will govern in most enforcement contexts.
A second recurring mistake is geographic complacency. Operators frequently conclude that because their entity is offshore, they are outside the reach of the EU or US regulatory perimeter. As the enforcement record demonstrates, the relevant question is not where the entity sits – it is where the users are. A protocol with a Cayman entity, an EU user interface, and EU-language marketing materials is, for MiCA purposes, offering crypto-asset services in the EU. The third-country provisions do not provide a free pass; they provide a defined path to compliant operation, which the operator must actually follow.
A third mistake is the failure to maintain a contemporaneous record of the legal analysis underlying key product decisions. When a regulator sends an inquiry letter, the operator's ability to demonstrate that it took the classification question seriously – that it obtained legal advice, that it tested its conclusions against the applicable framework, that it made good-faith design decisions – is a material factor in how the inquiry resolves. Operators who cannot produce that record are in a materially weaker position than those who can.
Related Practices at OBOLUS
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – legal strategy for protocols, DAOs and token issuers across jurisdictions
- Cross-Chain Bridge Legal Risk in the Czech Republic – jurisdiction-specific analysis of bridge liability and the MiCA transition
- EMI Licence for Crypto Firms: A Cross-Border Perspective – structuring payment institution authorisation alongside CASP licensing
FAQ
Can a DeFi protocol be regulated?
Yes. Most major regulatory frameworks apply to the economic substance of an activity, not its technical delivery mechanism. A DeFi protocol that pools user assets, generates yield, and distributes returns to passive holders is regulated under investment-scheme, securities, or CASP frameworks in most leading jurisdictions, regardless of whether execution is automated by smart contract. The degree of decentralization affects the analysis but does not automatically remove the protocol from the regulatory perimeter. Legal structuring decisions made at the protocol-design stage materially affect the risk profile.
What legal wrapper suits a DAO?
The most widely used structures are the Cayman Foundation Company, the Marshall Islands DAO LLC, the Wyoming DAO LLC, and a BVI company under the VASP Act 2022. Each offers different attributes on limited liability, governance formalization, and regulatory perimeter recognition. The right choice depends on the DAO's user base, revenue model, and the jurisdictions in which it operates or markets. Without a legal wrapper, governance token holders risk joint and several liability under the general-partnership default that most common-law systems apply to unincorporated associations.
Who is liable when a smart contract fails?
Liability for a smart-contract failure can attach to the deploying entity, the developers, and, in some frameworks, the governance token holders who approved the relevant code or upgrade. The analysis turns on whether the failure was foreseeable, whether the code was audited, and whether users were adequately disclosed to. In jurisdictions with established consumer-protection or financial-services liability regimes, operators who held out a smart contract as a financial product bear heightened exposure. Legal opinion on liability allocation should be obtained before deployment, not after an incident.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in cross-jurisdictional token classification, CASP authorisation, and staking-service regulatory strategy.
To pressure-test your staking structure before you commit, message us via t.me/oboluslaw or write to info@oboluslaw.com.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.