Token classification is the first legal question every issuer must answer – and the one most frequently answered wrong. A token whose rights, economics and distribution pattern resemble a security will be treated as one, regardless of how the whitepaper labels it. That outcome can convert a product launch into an unregistered securities offering, triggering enforcement across every jurisdiction where the token was offered or traded. The analysis below maps how regulators across the major regimes approach classification, where the lines shift under MiCA (the EU's Markets in Crypto-Assets Regulation) and under US securities law, and what a properly structured compliance program looks like in practice.
Why Token Classification Is the Foundational Compliance Question
Classification determines every downstream obligation: prospectus or whitepaper requirements, the licence the issuer must hold, the marketing restrictions that apply, the tax treatment, and the remedies available to token holders if things go wrong. Get it wrong at the design stage and you inherit obligations retroactively. Regulators in virtually every major hub have now confirmed that substance governs over label. A token carrying profit-participation rights, a secondary-market trading expectation, or dependence on a promoter's ongoing effort will be analyzed against the applicable securities test – not against the name the issuer gave it.
In our cross-border practice, misclassification at the whitepaper stage is the single most common structural error we encounter. The cost of correction escalates sharply once a token is live and widely distributed. Early-stage classification analysis is not a compliance formality; it is the architecture decision that shapes everything that follows.
Operators we advise routinely face classification questions simultaneously in three or more jurisdictions – the entity's home regime, the jurisdiction where institutional buyers are located, and the exchange listing venue. Each may apply a different test. A token that escapes securities classification under MiCA may still be a security in Hong Kong, Singapore or the United States, and each of those conclusions carries independent consequences.
CTA #1 – If you are designing a token structure and the classification picture is unclear, an early legal read can close the gap before distribution begins. Map your options with the OBOLUS team at info@oboluslaw.com. The architecture decision is made once; the compliance obligation runs indefinitely.
What Are the Four Main Token Categories and Where Do They Sit?
Most regulatory regimes resolve to four functional categories: payment tokens, utility tokens, asset-referenced tokens, and security tokens – though the precise labels and the tests used to assign them vary. Under MiCA, the regime distinguishes between asset-referenced tokens (ARTs), e-money tokens (EMTs), and "other crypto-assets"; a separate whitepaper obligation attaches to each category, with the most onerous requirements falling on ARTs and EMTs. Tokens that qualify as financial instruments under existing EU financial law fall outside MiCA entirely and into the MiFID II regime, which imposes prospectus and authorisation requirements at a higher threshold.
The United States applies its own distinct test. The Howey analysis – whether there is an investment of money in a common enterprise with an expectation of profit from the efforts of others – remains the operative framework applied by the Securities and Exchange Commission (SEC) and, in the context of derivatives, the Commodity Futures Trading Commission (CFTC). A token that fails the Howey test for security status may nonetheless be subject to FinCEN's money-services business rules if it functions as a payment instrument. The two federal frameworks can apply simultaneously.
Singapore's Monetary Authority of Singapore (MAS) applies its own capital-markets framework to tokens that constitute capital-markets products. Hong Kong's Securities and Futures Commission (SFC) has published detailed guidance on when a digital asset constitutes a security under Hong Kong law, with the analysis turning heavily on whether the token confers economic rights analogous to shares or debt instruments. Neither regime maps precisely onto MiCA or the US Howey test, which is why a multi-jurisdictional classification memo is structurally different from a single-jurisdiction legal opinion.
Does Calling a Token a Utility Token Settle the Classification?
A utility label on a whitepaper does not determine how a regulator will classify the token. This is the most persistent misconception in the token-issuance space, and it has contributed to enforcement actions in multiple jurisdictions. Regulators assess the economic substance of what the token does: what rights it confers, on whom, in what circumstances, and whether those rights carry an expectation of value appreciation linked to the issuer's efforts.
A common assumption in the industry is that including a "use case" – access to a platform feature, a discount on fees, a governance vote – insulates the token from securities characterization. It does not. Where the use case is incidental, the token is liquid before the platform is functional, or the marketing emphasizes return potential, the substance of the arrangement will override the label. The SFC in Hong Kong and ESMA in the EU have each published guidance to this effect, confirming that token classification is a facts-and-circumstances analysis, not a drafting exercise.
FINMA in Switzerland was among the first regulators globally to articulate the substance-over-form principle explicitly in its token guidance. FINMA identifies hybrid tokens – instruments that carry both utility and investment characteristics – as a distinct category requiring closer analysis. A pure utility token that grants platform access and nothing more is the cleaner case. Most real-world tokens are not pure utility tokens. They carry vesting schedules, founder allocations, secondary-market trading rights, and governance powers that together can tip the balance toward security characterization in at least one of the jurisdictions relevant to the offering.
How Does MiCA Reframe the EU Classification Question?
MiCA introduced a tiered classification system that resolves the prior fragmentation across EU member states, replacing the patchwork of national VASP registrations with a harmonized authorization regime for crypto-asset service providers (CASPs) and distinct issuance regimes for ARTs and EMTs. The practical effect is that an issuer distributing tokens into EU markets must now identify, at the outset, whether the token is an ART, an EMT, or an "other crypto-asset" under the regulation – and then apply the corresponding whitepaper and authorization requirements.
The ART regime is the most structurally demanding. A token referencing a basket of assets, currencies or commodities will be scrutinized for ART status; if it qualifies, the issuer must be authorized by the national competent authority of its home member state and must comply with reserve, redemption and disclosure obligations. The EMT regime applies to tokens referencing a single fiat currency and imposes obligations analogous to e-money issuance. Tokens that fall outside both categories – the "other crypto-assets" bucket – still require a whitepaper, but the authorization requirements are lighter.
The wrinkle that most issuers underestimate is the "financial instrument" carve-out. If a token constitutes a transferable security or other financial instrument under MiFID II, it falls outside MiCA and into the prospectus regime. That outcome triggers a prospectus requirement, underwriter obligations, and national supervisory approval at a materially higher threshold. The classification question therefore has a binary fork at the EU level: MiCA or MiFID II. Choosing the wrong branch – or failing to analyze it at all – is an error with no cheap correction.
Lithuania, one of the historically faster EU entry points for crypto businesses under the prior VASP regime, is now transitioning under the Bank of Lithuania's supervision toward full MiCA-aligned CASP authorisation. Malta's MFSA is similarly transitioning its Virtual Financial Assets framework. The practical consequence is that structures built around national fast-track registration now require a MiCA readiness assessment before the next token issuance cycle.
How Does Cross-Border Distribution Multiply the Classification Burden?
A token offered or sold in multiple jurisdictions simultaneously carries the classification risk of each. There is no global harmonization of token classification law. The highest-common-denominator jurisdiction governs enforcement exposure. For most token issuers, that jurisdiction is the United States – not because the issuer is US-domiciled, but because the SEC has asserted broad extraterritorial jurisdiction over offerings that reach US investors, regardless of where the issuer is incorporated or the token is technically issued.
The standard mitigation is a restricted-distribution structure: contractual and technical barriers preventing US-person participation in the initial distribution. FINMA's guidance, MiCA's provisions, and the SEC's Regulation S framework all contemplate this approach in some form. But a restriction that is contractually clean may still fail technically. If a token is freely transferable on a public blockchain and listed on accessible exchanges within days of issuance, the practical effect of the restriction will be tested against the facts of secondary-market distribution. Regulators have treated technically permeable restrictions as ineffective.
In our practice, we regularly advise on multi-jurisdictional classification stacks where the issuer's home jurisdiction is one framework, the primary exchange venue is another, and the institutional-investor base spans a third. The compliance obligation is cumulative. Each jurisdiction's test must be applied independently, and the most restrictive outcome governs the structural choices available to the issuer. There is no shortcut across that analysis.
A second cross-border dimension that often surprises issuers is the interaction with anti-money-laundering rules. The Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with a virtual-asset transfer) applies at the VASP level regardless of whether the token being transferred is a security. A token that escapes securities law obligations in its home jurisdiction may still generate Travel Rule obligations at the exchange or custodian layer – obligations that create their own compliance infrastructure requirements.
CTA #2 – If your token has already been distributed and the classification picture has not been formally resolved, a structured review can identify the outstanding risk and map a remediation path. Reach out to OBOLUS at info@oboluslaw.com. A second read on the classification analysis is a measurably lower cost than enforcement correspondence.
What Does the MiCA Whitepaper Obligation Require in Practice?
A MiCA whitepaper is a mandatory disclosure document, not a marketing brochure, and the issuer bears civil liability for material inaccuracies or omissions it contains. For tokens in the "other crypto-assets" category, the whitepaper must include prescribed information about the issuer, the token's characteristics, the rights it confers, the technology underpinning it, and the risks associated with holding it. The whitepaper must be filed with the national competent authority before issuance – though, for "other crypto-assets," it does not require pre-approval in the same way an ART or EMT issuer's application does.
The disclosure standard is material. The whitepaper must not contain misleading statements; it must be clear, fair and not deceptive; and it must be kept up to date as circumstances change. An issuer that publishes a whitepaper attributing token utility to a platform feature that is not yet built, or that omits known risks to the token's value, faces both regulatory sanction and private civil claims from token holders who relied on the document.
From a drafting perspective, the whitepaper interacts directly with the classification analysis. An overly broad description of token utility may undercut a securities-law argument that the token is not a financial instrument. An overly narrow description may trigger ART or EMT classification concerns. The two analyses must be run in parallel, with the classification memo and the whitepaper drafting proceeding together rather than sequentially.
Which Classification Path Applies to Your Issuer Profile?
Classification analysis produces materially different outcomes depending on the issuer's profile. A protocol issuer distributing governance tokens to early adopters in a decentralized network presents a different fact pattern from a centralized exchange issuing a loyalty token with fee-rebate rights. The compliance burden tracks the substance of the rights, not the issuer's size or sector.
Profile A – Protocol governance token, no profit participation, broadly distributed. This profile has the strongest case for "other crypto-asset" treatment under MiCA and a credible argument against Howey-security characterization in the US, provided the network is genuinely decentralized at the time of distribution. The obligation is a MiCA whitepaper, Travel Rule compliance at the exchange layer, and ongoing monitoring of secondary-market behavior that could shift the classification over time. The timeline from classification memo to whitepaper filing is typically a matter of weeks, assuming the underlying documentation is in order.
Profile B – Exchange or platform token with explicit fee-rebate or buyback mechanics. The buyback mechanic – where the issuer uses a portion of revenue to repurchase tokens from the open market – is the element most likely to attract securities characterization. It creates an economic relationship between the issuer's revenues and the token's secondary-market price that resembles the profit-sharing element of the Howey test. This profile requires a more nuanced securities-law analysis and, in the EU, a more careful whitepaper that addresses the fee-rebate mechanism without characterizing it in terms that trigger ART analysis. Distribution must be restricted from jurisdictions where the token would clearly be characterized as a security.
Profile C – Asset-backed or yield-bearing token. This is the highest-risk profile from a classification standpoint. A token that pays a yield, references an underlying asset portfolio, or promises redemption at a stated value will face ART or EMT scrutiny under MiCA and near-certain securities characterization in the US. The compliance burden includes ART authorization, reserve obligations, and – depending on the underlying assets – potential fund-regulation implications. Issuers in this category typically require a multi-jurisdictional legal structure with counsel across the key relevant regimes.
Classification in Practice: A Recent Engagement
In a recent matter, a token issuer based in a common-law offshore jurisdiction had completed a private distribution of governance tokens under a whitepaper drafted without formal legal classification analysis. The whitepaper described the tokens as "utility tokens" but included a buyback mechanism and a vesting schedule for founding team allocations. When the issuer sought to list the token on a regulated exchange in Hong Kong, the exchange's legal team flagged the buyback mechanic as a potential security characteristic under SFC guidance. We were engaged to conduct a retroactive multi-jurisdictional classification review – covering the SFC's framework, the applicable MiCA analysis given European buyers in the private round, and a Howey analysis for US-person exposure. The review identified the buyback mechanic as the primary structural risk and proposed a contractual modification that removed the profit-participation element while preserving the fee-utility function. The amended structure satisfied the exchange's legal team and allowed the listing to proceed. The engagement was completed in the quarter before the listing window closed.
Do Airdrops Change the Classification Analysis?
An airdrop – a distribution of tokens at no monetary cost, typically to early adopters or community members – does not automatically escape securities-law classification. The absence of monetary consideration removes one element of some securities tests, but regulators have examined the substance of what recipients receive and how the distribution functions in practice. Where an airdrop creates an expectation of secondary-market value appreciation tied to the issuer's ongoing development efforts, the distributional mechanics alone may not insulate the token from classification as a security.
Under MiCA, an airdrop that is truly free and without any tied obligation may benefit from a whitepaper exemption for tokens offered without charge. But the exemption is narrow. A "free" airdrop that conditions receipt on completing tasks, referral activity or social-media engagement may fall outside the exemption because the recipient has provided something of value – a form of consideration – for the tokens. The whitepaper obligation can attach even to distributions that feel operationally like marketing campaigns rather than offerings.
Tax classification of airdropped tokens is a related question. Some jurisdictions treat receipt of tokens as income at market value at the moment of receipt; others defer recognition until disposal. The interaction between the securities-law classification and the tax classification creates a compliance layer that must be planned before the airdrop is structured, not after the tokens have been distributed. See our related analysis on airdrop legal structuring for a detailed treatment of that dimension.
Related at OBOLUS
- Token Offerings & Securities Practice – how OBOLUS advises issuers on the full token-offering cycle, from classification through distribution
- Airdrop Legal Structuring: The Disputes Angle – the securities and tax risks that arise when airdrop mechanics are not structured in advance
- Economic Substance for Licensed VASPs in Hong Kong – the SFC's substance requirements and how they interact with token-issuer structures in Hong Kong
FAQ
Is my token a security?
That depends on the rights the token confers and the jurisdiction where it is offered or traded. The analysis turns on substance, not on the label attached in the whitepaper. In the United States, the Howey test asks whether there is an investment of money in a common enterprise with an expectation of profit from the efforts of others. Under MiCA, the threshold question is whether the token qualifies as a financial instrument under MiFID II – if so, it falls outside MiCA entirely. In Hong Kong and Singapore, the SFC and MAS apply their own capital-markets frameworks. A multi-jurisdictional classification memo is the standard starting point.
Do I need a MiCA whitepaper?
If you are issuing or offering a crypto-asset to the public in the EU – and it does not qualify as a financial instrument under existing EU financial law – a MiCA whitepaper is required before the issuance. The whitepaper must contain prescribed disclosures about the issuer, the token and its risks, and the issuer bears civil liability for inaccuracies. Tokens issued as ARTs or EMTs carry additional authorization requirements beyond the whitepaper. Narrow exemptions exist for truly free distributions and private placements, but the thresholds are specific and must be assessed against the facts of each offering.
How should an airdrop be structured legally?
An airdrop should be structured after completing a classification analysis, not before. The key questions are: does the distribution constitute an "offer to the public" triggering whitepaper requirements; does the absence of monetary consideration remove the token from securities law, or do task-completion mechanics supply a form of consideration; and what is the tax treatment of receipt in the jurisdictions where recipients are located. A well-structured airdrop addresses each of these questions in advance. Post-distribution corrections are substantially more costly and, in some jurisdictions, structurally unavailable.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – a discipline we apply across every major regulatory regime simultaneously. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com.
Ready to resolve the classification question before your next distribution? Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw. We scope the analysis, identify the highest-risk jurisdictions, and deliver a memo you can take to your board. Map your options.
By Lydia Brennan, Tax & Structuring Analyst – specialist in cross-border token structuring, whitepaper compliance and the interaction between securities-law classification and tax treatment across the major digital-asset hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.