Cross-chain bridges – infrastructure that locks assets on one blockchain and mints corresponding representations on another – have moved from a technical curiosity to a systemic component of decentralized finance. Enforcement agencies in the United States and Europe have now made clear that the legal question is not whether bridges are regulated, but which rules apply, to whom, and when. DeFi legal counsel who advised operators three years ago on a permissionless model are revisiting every assumption. This analysis maps the enforcement signals, the cross-border exposure, and the structural choices available to teams building or operating bridge infrastructure today.
The central legal risk for a cross-chain bridge operator is classification: regulators increasingly treat the bridge's custodial or quasi-custodial function as a money-transmission or virtual-asset-service-provider activity, regardless of how the smart contract is labeled. A bridge that settles billions in token flows without a compliance program is a priority target. The sections below explain why – and what the structural alternatives look like.
What Is a Cross-chain Bridge, Legally Speaking?
A cross-chain bridge is, in legal substance, a mechanism that takes custody of one asset and issues a synthetic claim against it on a different network. That custody moment is where regulatory exposure crystallizes. Under the FATF Recommendations – specifically Recommendation 15 governing virtual assets – any entity that transfers virtual assets on behalf of a customer is a virtual asset service provider (VASP), subject to AML/CFT obligations. Whether a bridge operator qualifies turns on whether a natural or legal person controls the lock-and-mint function, or whether it is genuinely autonomous smart-contract code with no administrative key.
Most production bridges do not meet the autonomy threshold. Multisig validators, relayer sets, and administrative upgrade proxies all introduce human control. Once human control exists, the regulator's classification machinery activates. We have seen this analysis applied not just to the operating entity but to the individuals holding signing authority.
The practical consequence is this: a team that deploys a bridge and retains any upgrade authority, fee sweep, or validator role has, in most leading regimes, created a VASP or money-service business. The tokenization of the bridged asset is a secondary question – the transmission function itself is the primary hook.
What Does Recent Enforcement Actually Reveal?
Enforcement actions against bridge-adjacent infrastructure have established three consistent themes, regardless of which agency brought the action. First, regulators disregard the autonomy narrative when any human actor retains meaningful control. Second, the failure to register as a money-service business or VASP is treated as an independent violation – separate from any underlying fraud or market-manipulation allegation. Third, founders and developers, not just the operating entity, have faced personal exposure where they controlled administrative functions.
In our cross-border practice, the pattern we observe is a regulator leading with the AML/registration failure because it requires no proof of investor harm. The SEC, CFTC, and FinCEN in the United States have each articulated a theory under which a bridge can constitute a money-transmitter, a commodity pool, or an unregistered securities exchange depending on the specific product design and fee mechanism. FinCEN's published guidance on convertible virtual currencies makes explicit that mixing, anonymizing, and bridging services require registration as money-service businesses where a responsible person is identifiable. No enforcement action to date has been built purely on a novel bridge theory; instead, regulators attach bridge liability to existing categories.
In Europe, the MiCA regime administered by ESMA and national competent authorities brings CASP (crypto-asset service provider) authorisation requirements to entities transferring crypto-assets on behalf of third parties. A bridge operator serving EU users – regardless of where the operating entity is domiciled – must assess whether the transfer-service definition applies. The passporting benefit under MiCA is available only to entities that actually obtain authorisation in one member state.
The cross-border read matters enormously here. A bridge domiciled offshore with validators in multiple countries and EU retail users accessing it without geo-restriction is exposed simultaneously to FinCEN's money-transmission rules, MiCA's CASP framework, and potentially the FCA's financial-promotion regime if UK users participate. No single jurisdictional fix closes all three windows.
How Does the VASP Classification Analysis Work for Bridge Operators?
VASP classification follows a substance-over-form analysis in every major regime, and that analysis has three legs for bridge operators: control, custody, and counterparty. Where a bridge operator holds administrative keys – even temporarily during a migration or upgrade – it has custody of the locked assets for purposes of the VASP definition under the applicable VARA, MiCA, MAS, or FCA regime.
Control is the first leg. An upgradeable proxy contract, a governance multisig that can pause the bridge, or a fee-recipient address all indicate human control. Regulators in the leading hubs increasingly expect operators to document who holds each key and what authority it confers.
Custody is the second leg. The lock-and-mint model places bridged assets into a contract. If an identified entity or person deployed that contract and retains the ability to drain or redirect it, that entity holds constructive custody. The MAS Payment Services Act in Singapore and the FSRA framework in ADGM both define custody broadly enough to capture this structure.
Counterparty is the third leg. If the bridge charges a fee, it is providing a service to a counterparty. Fee-bearing bridges are harder to defend as purely autonomous infrastructure. The fee creates a service relationship, and a service relationship creates a provider. A provider in the digital-asset space is, in most regimes, a VASP by definition.
In our practice, classification opinions for bridge operators work through all three legs systematically. A bridge that scores low on all three – no administrative key, no fee, genuinely decentralized governance – sits closest to the safe harbor in each regime. A bridge that scores high on even one leg needs a registration or licensing strategy.
To map your bridge's classification exposure across the relevant regimes, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your specific design – the entity structure, the validator model, the fee flow – changes the answer materially. Map your options.
Do AML and the Travel Rule Apply to Cross-chain Bridges?
AML and Travel Rule obligations apply to a cross-chain bridge wherever a VASP is identified as operating it, and the enforcement posture in every major financial center now treats the Travel Rule as non-negotiable. The Travel Rule – the obligation to pass originator and beneficiary data alongside a virtual-asset transfer – was extended to VASPs under the FATF framework and has been implemented domestically in the US (FinCEN), EU (TFR under MiCA), Singapore (MAS), UK (FCA), and across the Gulf hubs under VARA and FSRA rules.
The structural challenge for bridges is that the transfer is inherently cross-chain: the originator deposits an asset on chain A, and a synthetic representation arrives on chain B, often with no on-chain data linkage between the two legs. FATF guidance acknowledges this gap but does not create an exemption for it. The obligation rests with the VASP operating the bridge to collect, hold, and transmit the required data – regardless of whether the protocol makes it technically convenient.
We regularly advise bridge teams on Travel Rule architecture. The practical approach is to integrate a Travel Rule solution at the point of user deposit (the on-ramp to the bridge), before the cross-chain transfer completes. Several compliant messaging protocols exist for this purpose, though the specific choice is a technical and compliance decision that varies by jurisdiction. What the law requires is clear: the data must travel with the transfer.
Where a bridge operates between two jurisdictions with different Travel Rule thresholds, the more conservative threshold governs. The EU's Transfer of Funds Regulation implements a zero-threshold rule for crypto-asset transfers under MiCA, meaning Travel Rule data is required for every transfer regardless of amount. A bridge operator serving EU users cannot rely on a higher domestic threshold to avoid the obligation. This cross-border asymmetry is a consistent source of compliance gaps in the teams we review.
Does a DAO Structure Shield Bridge Operators from Liability?
A DAO (decentralized autonomous organization) governance structure does not, by itself, insulate bridge operators from regulatory liability – and several enforcement actions have used the DAO structure to reach individual token holders who exercised voting control. The legal theory is straightforward: if governance token holders vote on protocol upgrades, fee changes, or emergency pauses, they are exercising control. Control is the first leg of the VASP analysis. Control creates liability exposure.
The question regulators ask is not "is this a DAO?" but "who made the decision that caused the harm or constituted the regulated activity?" In practice, that question resolves to a small set of actors: the founding team that deployed the initial contracts, the multisig holders who can execute governance decisions, and the delegates who hold concentrated voting power.
A properly structured DAO legal wrapper – a recognized legal entity (a foundation, a Cayman LLC, a Marshall Islands DAO LLC, or a Mauritius structure) placed around the DAO – does not eliminate the regulatory question but it does provide a clear counterparty for regulators and a structured accountability mechanism. Without a legal wrapper, enforcement agencies default to treating the founding team as the responsible persons, which is precisely the outcome the DAO structure was intended to avoid.
In our cross-border practice, we assess DAO governance structures against the substance of control, not the label. A DAO with a four-of-seven multisig controlled by the founding team is, in substance, a partnership with blockchain-based documentation. A DAO with genuinely distributed governance, a legal wrapper, and a separation between protocol development and protocol governance is a meaningfully different risk profile.
The decision of where to establish the legal wrapper matters as much as the wrapper type. Mauritius, the Cayman Islands, and the BVI each offer structures with different tax treatment, regulatory perimeter, and enforceability. The AIFC in Kazakhstan and the ADGM in Abu Dhabi offer common-law environments with their own digital-asset specific frameworks. The right jurisdiction depends on where the core team is located, where the users are concentrated, and what banking relationships the structure needs to support.
Who Bears Legal Liability When a Bridge Smart Contract Fails?
When a bridge smart contract fails – whether through an exploit, a validator collusion event, or a governance attack – the liability question turns on who controlled the contract and what representations were made to users. A smart contract is not a legal person; liability attaches to the humans or entities that deployed, administered, or promoted it.
The legal theories available to claimants vary by jurisdiction and by the specific failure mode. In common-law systems (England and Wales, Singapore, Hong Kong, the DIFC Courts), misrepresentation, negligence, and breach of fiduciary duty are the most frequently invoked bases. A bridge that was marketed with specific security guarantees – audit reports cited in marketing materials, statements about multisig thresholds – creates a misrepresentation risk if those representations were false or misleading.
Regulatory enforcement is a separate track. An unregistered VASP that loses user funds through a bridge exploit faces not only civil claims from users but also regulatory action for the underlying registration failure. The enforcement risk compounds when a hack reveals the absence of the AML/Travel Rule program that registration would have required.
In a recent matter we handled, a protocol team sought advice after a validator compromise drained a significant portion of bridge liquidity. The team had retained upgrade authority but had not registered as a VASP in any jurisdiction. We structured their engagement with the relevant regulator, coordinated on-chain tracing through forensic partners, and advised on the disclosure obligations that applied across multiple jurisdictions simultaneously. The regulatory engagement, managed proactively, was resolved more favorably than an enforcement-initiated process would have been.
For bridge teams that have already experienced an incident, the response window is short. Disclosure obligations in most regimes require prompt notification to the regulator. Forensic chain analysis – using tools capable of tracing assets across chains – should begin immediately. A coordinated legal strategy that addresses the regulatory, civil, and reputational dimensions simultaneously produces materially better outcomes than sequential engagement.
If you are managing the aftermath of a bridge exploit or a regulatory inquiry, contact OBOLUS now at info@oboluslaw.com. A second read of the regulatory posture, the disclosure timeline, and the recovery options can surface paths that a single-jurisdiction view misses. Map your options.
Decision Matrix: Which Legal Structure Fits Which Bridge Profile?
No single structure fits every bridge operator. The relevant variables are the degree of human control, the user base geography, the fee model, and the team's appetite for regulatory engagement. The following profiles illustrate the main decision branches.
Profile A – Permissioned bridge, institutional users, fee-bearing. This profile scores high on all three VASP legs. The appropriate structure is full VASP or CASP registration in the jurisdiction of primary operation, with Travel Rule compliance built into the deposit flow. A VARA licence in Dubai or a CASP authorisation in an EU member state (with MiCA passporting) are the most frequently chosen paths for teams targeting institutional capital. The registration timeline varies by regime and is a matter of months in the faster hubs. The key risk is under-capitalized compliance infrastructure at launch.
Profile B – Semi-permissioned bridge, retail and institutional mixed, governance token. This is the most common and legally complex profile. The DAO wrapper question is live, the Travel Rule applies to the retail leg, and the governance token likely requires a securities analysis in both the US and EU. The appropriate approach is a layered structure: a legal entity (foundation or LLC) holds the administrative keys and interfaces with regulators; genuine governance decentralization is pursued over an articulated roadmap; securities counsel and AML counsel work in parallel. Indicative timeline to a defensible structure is several months. The key risk is a gap between the decentralization narrative and the actual control map.
Profile C – Fully non-custodial, no fee, no administrative key, open-source. This profile is the hardest to achieve and the easiest to defend. If genuinely autonomous, the entity that deployed the contract has the strongest argument that it is not a VASP. The key risk is that "no administrative key" must be objectively verifiable – immutable contracts, no governance token with upgrade authority, published and audited code. Any future monetization or governance mechanism reopens the analysis. Regulatory safe harbors for this profile exist in concept but are narrow in practice.
Profile D – Bridge as product feature inside a licensed exchange or custodian. Where a licensed VASP integrates bridge functionality into its existing product suite, the bridge activity falls within the existing licence perimeter, subject to the regulator approving the new activity. This is often the fastest path to compliance for teams that already hold a MAS, SFC, or VARA licence. The key risk is regulatory surprise – notifying the regulator of the new feature before launch, not after, is essential.
Is Regulatory Arbitrage Still Available to Bridge Operators?
The window for pure regulatory arbitrage – domiciling in a permissive jurisdiction to serve users globally without a compliance program – is effectively closed for any bridge with meaningful scale. FATF's Recommendation 15 and the global adoption of the virtual-asset VASP framework mean that a bridge operator's regulatory exposure follows its users, not its registered office.
A bridge incorporated in a jurisdiction with no VASP registration requirement that serves EU users is subject to MiCA's CASP framework. One serving US users is within FinCEN's reach. One whose validators operate from Singapore must assess the MAS Payment Services Act. The entity location is relevant – it determines which regulator has primary enforcement jurisdiction – but it does not eliminate the exposure to regulators in the user jurisdictions.
This is the multi-jurisdiction reality that distinguishes digital-asset regulatory work from domestic compliance. We regularly advise operators who assumed that an offshore holding company resolved their regulatory position. In practice, the analysis requires a user-base map, a validator-location map, a banking-relationship map, and a regulatory-posture map across all of those dimensions simultaneously.
The jurisdictions that offer the most defensible positions for bridge operators today are those with active VASP frameworks, clear classification guidance, and banking infrastructure that supports the business model: VARA in Dubai, ADGM/FSRA in Abu Dhabi, MAS in Singapore, SFC in Hong Kong, and CASP authorisation in an EU member state under MiCA. Each has a different risk profile, timeline, and cost. None eliminates regulatory risk entirely; all reduce it materially compared to operating without a structure.
A Common Assumption: the Utility Label Settles the Legal Classification
A persistent belief among bridge teams is that labeling their governance token as a "utility token" in the whitepaper resolves the securities classification question. It does not. Token classification under MiCA, the Howey test applied by the SEC, the FSRA's recognised virtual assets concept, and every other leading regime turns on the substance of the rights conferred – not the marketing label.
A governance token that entitles holders to a share of protocol fees, that was sold in a pre-launch round to investors expecting price appreciation, and that is traded on secondary markets is likely to be analyzed as a security or an asset-referenced token regardless of what the whitepaper calls it. The enforcement record on this point is consistent. Regulators treat the label as one data point among many, and courts in common-law jurisdictions look through labels entirely.
In our practice, we assess token classification against the substance of rights conferred, the mechanics of the sale, the investor expectations that the marketing materials created, and the secondary-market behavior of the token. Where a token sits at the boundary of two categories, a conservative structure – offering the token only to qualified investors, restricting secondary market access, or redesigning the fee mechanism – is preferable to relying on a label defense that enforcement history suggests will not hold.
The AUDIENCE_MYTH that a utility label is a legal shield has cost bridge teams regulatory enforcement actions that a structural review at the design stage would have avoided. The cost of a classification opinion before launch is a fraction of the cost of a FinCEN, SEC, or MiCA enforcement action afterward. That calculus is not a guarantee of any outcome – it is a description of the risk differential.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – Our practice for protocol teams, DAO builders and token issuers across jurisdictions.
- DAO Legal Wrapper in Mauritius – Structuring decentralized organizations under the Mauritius framework.
- Economic Substance for Licensed VASPs in Hong Kong – Meeting the SFC's substance expectations for VASP-licensed operations.
FAQ
Can a DeFi protocol be regulated?
Yes. A DeFi protocol can be regulated wherever a natural or legal person exercises control over it. Regulators in the US (FinCEN, CFTC, SEC), the EU (under MiCA), Singapore (MAS) and the UAE (VARA) apply their VASP or equivalent frameworks based on who controls the protocol – not on whether it is labeled decentralized. Genuine, verifiable autonomy with no administrative key and no fee flow is the narrowest available defense; most production protocols do not meet that threshold.
What legal wrapper suits a DAO?
The right wrapper depends on where the core team operates, where users are concentrated, and what banking the DAO needs. Commonly used structures include Cayman Islands foundations, BVI limited liability companies, Marshall Islands DAO LLCs, and Mauritius-based entities. Each carries different tax treatment, regulatory perimeter and enforceability. The wrapper does not eliminate regulatory exposure – it provides a legal counterparty and a structured accountability mechanism that reduces the risk of personal founder liability.
Who is liable when a smart contract fails?
Liability attaches to the humans or entities that deployed, administered, or promoted the contract – not to the code itself. In common-law systems including England and Wales, the DIFC Courts, Singapore and Hong Kong, the available theories include misrepresentation, negligence and breach of fiduciary duty. Regulatory enforcement for AML or registration failures runs in parallel to civil claims. The founding team and multisig keyholders are the most exposed parties; a legal wrapper and a proper compliance program are the primary risk-reduction tools available before an incident.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance architecture that surrounds them. We assess token and protocol classification against the substance of rights and control, not the marketing label – and we advise bridge and protocol teams from the design stage through regulatory engagement and, where necessary, incident response. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Lydia Brennan, Tax & Structuring Analyst – specialising in cross-border token classification, DAO structuring and the tax and regulatory treatment of DeFi protocol revenue.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.