On paper, drafting a token sale agreement looks like a standard commercial exercise: define the asset, set the price, allocate the tokens, govern the relationship. In practice, the document sits at the intersection of securities law, consumer-protection rules, AML obligations and, increasingly, the specific whitepaper and disclosure regimes now in force across the major licensing hubs. A board that treats the agreement as a boilerplate exercise risks converting a product launch into an unregistered securities offering before the first tranche is sold.
The core question is not how to draft a purchase agreement. It is how to build a document that is simultaneously enforceable across the jurisdictions where buyers sit, defensible against the classification risk that regulators in each of those jurisdictions will apply, and coherent with the issuer's licensing and banking position. Token sale agreement drafting that fails on any one of those three axes can expose the board to personal liability, freeze the issuer's banking relationships and, in the most serious cases, attract regulatory enforcement under the MiCA regime in the EU, VARA (Virtual Assets Regulatory Authority) rules in Dubai, or securities-law frameworks in common-law markets.
This analysis walks through the practical lessons we have distilled from structuring token offerings across multiple jurisdictions. Each section opens with the operative answer, then builds out the analysis and the cross-border complexity behind it.
Classification Must Come Before the Agreement Is Drafted
The most consequential decision in any token offering is the classification of the token itself, and that decision must be made before a single clause of the sale agreement is written. Classification is not a label the issuer chooses; it is a legal conclusion that regulators reach by examining the substance of the rights the token confers. Calling a token a "utility token" on a whitepaper does not protect the issuer if the token grants profit expectations derived from the managerial efforts of others – a formulation that tracks the analysis applied by securities regulators in the United States, the EU and common-law markets alike.
In our practice, boards often arrive having already circulated a draft agreement built around a utility framing. The substantive question – does this token look more like a security, an e-money token, an asset-referenced token or an "other" crypto-asset under MiCA – has not been answered. The agreement then becomes a liability document rather than a protective one.
Classification drives every downstream choice. A token that qualifies as a security under the applicable regime requires a prospectus or an exemption, and the sale agreement must reference the exemption basis explicitly. A token that falls within MiCA's EMT (e-money token) or ART (asset-referenced token) categories requires issuer authorisation under MiCA before any public offer in the EU or EEA. An "other" crypto-asset offered publicly in the EU requires a whitepaper notified to the relevant national competent authority. The classification conclusion should be documented in a board resolution before the agreement is executed – because that document will be the first thing a regulator or a court asks for.
How Does the Cross-Border Buyer Base Change the Analysis?
A token sale that accepts buyers from multiple jurisdictions simultaneously activates the securities and consumer-protection regimes of every jurisdiction where a buyer is located, not just where the issuer is incorporated. This is one of the most frequently misunderstood aspects of token offering structuring, and it is the area where a misdrafted agreement creates the most systemic risk.
Consider a token issuer incorporated in a VARA-licensed entity in Dubai. VARA governs what the issuer does within its regulatory perimeter. But if the offering is accessible to buyers in EU member states, MiCA applies to the offer directed at those buyers. If US persons can access the sale, the SEC's reach and FinCEN's Travel Rule obligations (the requirement to pass originator and beneficiary data with a transfer) become live issues. If buyers in Singapore participate, MAS licensing analysis under the Payment Services Act is relevant.
The practical answer is a jurisdictional restriction and representation matrix built into the agreement itself. The sale agreement should:
- identify each restricted jurisdiction by name, with a representation and warranty from the buyer that they do not reside or hold assets in those jurisdictions;
- require buyers to represent their status under the applicable local securities-law exemption (accredited investor, professional investor, elective professional, and similar);
- include a governing-law and dispute-resolution clause calibrated to the issuer's corporate domicile and the likely enforcement forum, not just the most convenient seat;
- address what happens to tokens if a buyer is later found to have made a false representation.
In our cross-border practice, we regularly advise issuers who have run a single-form agreement with no buyer-representation matrix and then faced enforcement inquiries in two or three jurisdictions simultaneously. The cost of retrofitting those documents is substantially higher than building the matrix at the outset.
For a scoped assessment of your token offering structure and the jurisdictions your buyer base triggers, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the buyer base, the banking – change the analysis. Map your options.
What Are the MiCA Whitepaper Obligations and How Do They Interact With the Agreement?
Under the MiCA regime, a public offer of crypto-assets in the EU or EEA requires the publication of a whitepaper that meets specific content, liability and notification requirements – and the sale agreement must be drafted to align with the whitepaper, not run parallel to it. This interaction is poorly understood by issuers who treat the whitepaper as a marketing document and the agreement as the legal document.
The MiCA whitepaper is a regulated instrument. It creates civil liability for the issuer where the whitepaper contains materially misleading, inaccurate or incomplete information that causes a buyer loss. The sale agreement cannot limit or exclude that liability in a way that contradicts the MiCA regime. Boards that draft broad no-reliance and limitation-of-liability clauses into their sale agreements, without first mapping them against MiCA's whitepaper-liability provisions, may find those clauses unenforceable precisely where the risk is greatest.
The practical interaction points are:
- Consistency: every material representation in the sale agreement about the token's characteristics, rights and use of proceeds must be consistent with the whitepaper. Inconsistency creates an ambiguity that a buyer (or regulator) can exploit.
- Withdrawal rights: MiCA provides buyers with a withdrawal right during a defined window after the whitepaper is published. The sale agreement must identify that window and the mechanics of exercising it.
- No-advertising contradiction: marketing communications referencing the offer must be consistent with the whitepaper; the agreement should cross-reference this obligation on the issuer.
- Notification timing: the whitepaper must be notified to the relevant national competent authority before the offer opens. The sale agreement's effective date must be sequenced after that notification.
ESMA guidance on MiCA whitepaper content requirements is a live reference for any issuer offering into EU markets. Boards should ensure their legal team is working from current regulatory technical standards, not a prior version of the MiCA text.
How Do Regulators Actually Classify Tokens – and Why Does the Agreement Language Matter?
Regulators apply a substance-over-form analysis. The language of the sale agreement is direct evidence of the economic rights conferred, which means that poorly drafted agreement clauses can inadvertently reclassify a token that was intended to fall into one category into a more heavily regulated one.
The most common reclassification triggers we have observed in practice are:
Profit-sharing language. Any clause that entitles token holders to a share of the issuer's revenue, profits or surplus in a way that is derived from managerial effort creates a profit expectation. That expectation is the hallmark of a security in most frameworks. Even a clause that provides for a "buyback" at a price tied to issuer performance can trigger this analysis.
Governance rights with economic consequence. Governance rights that allow holders to vote on matters that directly affect the economic value of the token – fee structures, treasury deployment, protocol upgrades affecting revenue – are read differently from pure product-governance rights. The line is fact-specific, but it is a line the agreement drafting can draw more clearly or more ambiguously.
Resale expectations. Language that references secondary-market listing timelines, anticipated liquidity, or lock-up periods structured around a listing event signals investment expectation. Regulators in multiple jurisdictions treat such language as evidence of a collective investment scheme or securities offering.
In our practice, we assess classification against the substance of the rights conferred – not the marketing label. That assessment feeds directly into what the agreement can and cannot say. A utility label on a whitepaper does not settle the legal classification; the agreement clauses either support or undermine it.
How Do VARA, ADGM and Common-Law Enforcement Forums Interact for a Dubai-Based Issuer?
Dubai is one of the most active token-offering domiciles, and a VARA-licensed issuer faces a specific cross-border challenge: VARA governs the licensing and conduct requirements within the Dubai regulatory perimeter, but common-law enforcement forums – England and Wales, the DIFC Courts, Singapore – will be the venues where a buyer dispute or regulatory referral lands in practice.
A VARA licence does not insulate the issuer from claims brought by buyers in other jurisdictions. Conversely, a VARA-compliant agreement structure is strong evidence of regulated conduct if the issuer is challenged in a foreign court. The practical lesson is that the governing-law clause and the dispute-resolution clause in the sale agreement must be chosen with enforcement in mind, not just legal familiarity.
The DIFC Courts are an increasingly viable forum for digital-asset disputes. They apply English common-law principles, have jurisdiction over entities within the DIFC, and have demonstrated willingness to engage with crypto-specific issues. For an issuer structured in the broader Dubai mainland under VARA, the choice between DIFC arbitration, LCIA arbitration and English courts involves a real analysis of where buyers are, where assets are held, and where enforcement will need to bite.
We have seen ADGM-based issuers face the mirror problem: the FSRA regime within ADGM is a strong regulatory anchor, but the agreement's dispute-resolution clause pointed to a forum with limited experience in digital-asset matters. When a dispute arose, the enforcement process took longer and cost more than necessary. Selecting the right forum is not an administrative choice – it is a risk-management one.
If a prior application stalled or a dispute in an existing offering has created structural uncertainty, a second read of the agreement can surface the issue and the route forward. Contact OBOLUS at info@oboluslaw.com or message via t.me/oboluslaw. Map your options.
AML, KYC and Travel Rule Provisions in the Agreement
The token sale agreement is not just a commercial document – it is a compliance instrument. AML and KYC obligations apply to most token sales under the FATF Recommendations, in particular Recommendation 15 on virtual assets, and the agreement must operationalize those obligations in a way that is enforceable against the buyer and auditable by the regulator.
The minimum provisions are:
- A representation that the buyer has completed the issuer's KYC process and that the funds used for the purchase are of legitimate origin;
- A warranty that the buyer is not a sanctioned person, does not hold assets on behalf of a sanctioned person, and is not located in a jurisdiction subject to applicable sanctions regimes;
- A right for the issuer to withhold token delivery pending AML verification, with no breach consequence for a commercially reasonable delay;
- A provision addressing what happens to tokens if the issuer receives a law-enforcement request or regulatory direction – including the issuer's right to cooperate with such a request without buyer consent.
The Travel Rule – the FATF obligation requiring VASPs to pass originator and beneficiary data along with a virtual asset transfer – interacts with token sale mechanics where the issuer is itself a VASP or where the delivery of tokens to the buyer involves a VASP intermediary. The agreement must address data-transfer obligations in a way that does not conflict with the issuer's VASP compliance program.
In practice, we regularly advise issuers who have drafted a sale agreement without engaging with their compliance team. The AML provisions are either absent or are boilerplate that does not map to the issuer's actual KYC workflow. That mismatch is the first thing an AML auditor flags, and it can delay a token launch by weeks while the documentation is rebuilt.
A Practical Illustration – and the Mistakes That Recur
In a recent structuring matter, a technology company sought to launch a tokenised access product into EU and Gulf markets simultaneously. The initial agreement had been drafted by generalist commercial counsel and contained two provisions that, taken together, created a significant classification risk: a revenue-sharing mechanism tied to platform performance and a governance clause that allowed token holders to vote on fee structures. Under MiCA's ART analysis and under the securities-law analysis of the relevant member states, those provisions pointed toward a regulated instrument requiring issuer authorisation before any public offer. We restructured the rights profile, rewrote the agreement to reflect pure access rights with no economic entitlement, and aligned the whitepaper with the revised agreement before the notification was filed. The offering proceeded on the revised schedule.
The mistakes that recur across token sale agreements are not complex. They are structural oversights:
- No board resolution documenting the classification basis – leaving the issuer without a contemporaneous record of the legal analysis if the classification is challenged;
- Governing-law and dispute-resolution clauses chosen for convenience rather than enforceability in the buyer's jurisdiction;
- No-reliance clauses that are broader than MiCA liability permits, making the clause unenforceable at the point it would be most valuable;
- AML provisions that reference a KYC process not yet built, creating a circular obligation the issuer cannot satisfy at launch;
- Whitepaper and agreement that were drafted by different teams and never cross-referenced, with material inconsistencies between the two.
Which Offering Structure Fits Which Issuer Profile?
Not every token sale requires the same structure. The regulatory regime, the buyer profile and the token's economic substance together determine the appropriate instrument and approach.
Profile A – Early-stage protocol with a genuine utility use case, selling to non-US accredited or professional investors in EU markets. The starting point is an MiCA "other crypto-asset" analysis. If the rights are purely functional, a notified whitepaper and a sale agreement that clearly limits rights to platform access, with no economic entitlement, is the appropriate structure. The timeline from classification analysis to a filed whitepaper is typically a matter of weeks, not months. The key risk is that governance provisions drift into economic entitlement territory during the drafting process.
Profile B – Tokenised real-world asset, accessible to institutional buyers across multiple jurisdictions. This is the most complex profile. Depending on the asset class and the rights conferred, the token may qualify as a security in some jurisdictions and as an ART under MiCA in the EU. A parallel-tracks approach – a securities-exempt private placement structure for securities-law jurisdictions, an ART-compliant structure for EU buyers – requires two agreement variants and careful buyer segmentation. The timeline is longer, and the capital and compliance requirements under MiCA's ART provisions are material. Allied counsel in the relevant jurisdiction is required for the securities-law analysis in each market.
Profile C – Exchange issuing a native token primarily to existing users, structured as an airdrop with a follow-on sale. The airdrop mechanics must be assessed separately from the sale mechanics. An airdrop with no consideration does not trigger a "public offer" under MiCA in the way a sale does – but if the airdrop tokens are identical to tokens later sold, the sale agreement must address the rights of both categories of holder. The AML and sanctions-screening obligations apply to both.
A Common Assumption to Test Before Launch
A common assumption is that a favourable legal opinion from a single-jurisdiction counsel resolves the classification question globally. It does not. A legal opinion from counsel in the issuer's domicile jurisdiction addresses the classification under that jurisdiction's law. It says nothing about how a regulator in the buyer's jurisdiction will analyse the same instrument. In our cross-border practice, we structure the classification analysis to cover the issuer's domicile, the primary target markets and any jurisdiction where a significant portion of the buyer base is likely to be located. That is not three separate opinions – it is a coordinated analysis that produces a single, cross-border classification position.
The second common assumption is that a simple token purchase agreement – a one-page SAFT or SAFE-equivalent – is sufficient for all offering types. The SAFT (Simple Agreement for Future Tokens) structure was developed in a specific regulatory moment and for a specific buyer profile: sophisticated accredited investors purchasing a right to future tokens on the assumption that the tokens, once delivered, would be utility assets. That assumption has been eroded by regulatory developments in the US, the EU and multiple other markets. A SAFT that does not address MiCA obligations, Travel Rule compliance or the specific classification logic of the target markets is not a protective instrument – it is a historic template applied to a different regulatory environment.
Related at OBOLUS
- Token Offerings and Securities Practice – full-scope advice on token classification, offering structure and cross-border securities compliance for digital-asset businesses.
- Security Token Offering Structuring in the Czech Republic – jurisdiction-specific guidance on structuring security token offerings under EU and Czech regulatory requirements.
- Payment Institution Licensing for Institutional Clients – licensing and banking structure advice for institutional digital-asset operators requiring payment access.
FAQ
Is my token a security?
Whether a token is a security depends on the substance of the rights it confers, not on its label. Regulators in the EU, the US and most common-law markets apply a substantive analysis: if the token grants profit expectations derived from the efforts of others, or provides economic rights analogous to equity or debt, it is likely a security. Classification must be assessed against each jurisdiction where buyers are located, not only where the issuer is incorporated. A qualified legal assessment, documented in a board resolution before the offering opens, is the appropriate starting point.
Do I need a MiCA whitepaper?
A public offer of crypto-assets directed at buyers in the EU or EEA generally requires a whitepaper that meets MiCA's content, liability and notification requirements. EMTs and ARTs require issuer authorisation before any public offer, beyond the whitepaper alone. Exemptions exist for certain offer types, including small-scale offers and offers to qualified investors. Whether an exemption applies depends on the token category, the offer size and the buyer profile. The whitepaper must be consistent with the sale agreement and must be notified to the relevant national competent authority before the offer opens.
How should an airdrop be structured legally?
An airdrop that delivers tokens for no consideration is generally not a "public offer" under MiCA in the way a sale is, but it remains subject to AML and sanctions-screening obligations, and the tokens delivered may themselves constitute regulated instruments. The key legal issues are: whether the airdrop creates a regulated instrument requiring prior authorisation; how the airdrop interacts with any follow-on sale of the same token class; and whether the delivery mechanism involves a VASP that triggers Travel Rule obligations. Structuring the airdrop as a distinct, documented event with its own compliance record is the appropriate approach.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label, and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in token classification, cross-border offering structure and regulatory compliance for digital-asset issuers and exchanges.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.