Cross-chain bridges occupy a structurally ambiguous position in every major regulatory regime: they move value across blockchain networks, yet no jurisdiction has issued a definitive classification that settles whether the operator is a money transmitter, a custodian, a securities intermediary or something the existing categories do not fully reach. As supervisors from the EU's ESMA, the UK's FCA and the US federal agencies intensify their scrutiny of decentralized finance (DeFi) infrastructure, bridge operators and the legal teams advising them face a classification problem that compounds across every jurisdiction the protocol touches. This page maps that problem, jurisdiction by jurisdiction, and sets out the structural questions any operator must answer before exposure crystallizes.
The short answer is that cross-chain bridge legal risk is primarily a classification and liability risk, not a single licensing gap. The applicable regime – whether MiCA in the EU, the VARA rulebooks in Dubai or the Payment Services Act in Singapore – turns on what the bridge actually does: does it hold assets, does it issue wrapped tokens, does it operate an order book, or does it merely relay messages between chains? Each function attracts a different regulatory consequence, and a bridge that bundles several functions may attract several consequences simultaneously. The cross-border dimension amplifies this: a bridge whose smart contracts are deployed on a server in one jurisdiction, whose liquidity providers sit in a second and whose users access it from a third faces overlapping and sometimes conflicting regulatory claims.
The sections below work through the technical functions that drive legal classification, compare how the leading jurisdictions have approached them, and identify the decision points that separate a defensible structure from an unregistered offering or unlicensed transmission.
What a Cross-chain Bridge Actually Does – and Why It Matters Legally
A cross-chain bridge, in functional legal terms, is a system that accepts an asset on one blockchain, holds or locks it, and issues a corresponding representation – typically a wrapped token – on a second blockchain. That description alone implicates three distinct regulatory categories: custody (the locking function), token issuance (the wrapped representation) and value transfer (the cross-chain movement). The legal exposure follows the function, not the label.
In our cross-border practice, the single most important structural question we ask a bridge operator is whether the protocol holds user assets at any point in the flow. A lock-and-mint bridge retains the original asset in a smart contract or multisig arrangement while the wrapped equivalent circulates elsewhere. That retention – even if algorithmic and non-discretionary – looks like custody to most supervisors. A burn-and-mint design destroys the original and creates a new token; custody risk is reduced, but the token issuance function becomes prominent, and under MiCA's asset-referenced token (ART) provisions, issuing a token whose value references another crypto-asset may require CASP authorisation or, for significant ARTs, direct ESMA oversight.
The distinction between a trust-minimized bridge governed entirely by code and one that relies on a validator set or multisig committee introduces a further layer: operator control. Regulators in the leading hubs increasingly expect that where a defined group of persons controls the key function – whether through a multisig threshold, a guardian committee or an upgradeable proxy – that group is assessable as a regulated entity. The technical architecture, in other words, does not erase the question of who is in control.
Wrapped-token issuance under MiCA is the clearest point of crystallization in the EU. A wrapped BTC or ETH issued by a bridge is a crypto-asset within scope; if the token references the value of another asset and is used as a means of exchange, the ART classification becomes a live question. ESMA guidance on token classification turns on the rights conferred and the economic substance, not the marketing description – a principle our team applies as the starting point of every bridge analysis we conduct.
How Does the EU's MiCA Regime Treat Cross-chain Bridge Risk?
Under MiCA, a bridge operator faces potential CASP authorisation obligations if the protocol's functions map onto any of the regulated crypto-asset services – custody, exchange, transfer or operation of a trading platform. The EU regime does not currently contain a bridge-specific provision, which means classification is conducted by analogy to the services enumerated in MiCA and to the token categories it establishes.
The custody question is the most pressing. Where a bridge smart contract holds user assets – even for a few blocks – the operator may be conducting custody of crypto-assets on behalf of clients, a regulated service under MiCA. The EU passporting mechanism allows a CASP authorised in one member state to operate across the EEA, which is a structural advantage for operators who elect to engage. The alternative – operating without authorisation on the basis that the protocol is fully decentralized – carries the risk that an NCA will reach the developer team, the DAO governance token holders or the multisig signers as the responsible party.
Token classification under MiCA adds a second exposure layer. A wrapped token that references the value of another crypto-asset and circulates as a means of exchange sits close to the ART definition. ART issuers above specified transaction volume and holder thresholds come under direct ESMA supervision – a consequence that was not foreseeable from a pure product-design perspective when many bridges were built. Operators we advise are routinely surprised to discover that their wrapped-token economics, not their transfer mechanics, are the primary MiCA trigger.
The DeFi carve-out that some operators anticipated has not materialized in the form they hoped. MiCA's provisions for "fully decentralized" protocols provide a narrow exemption, but ESMA has signalled that it will apply substance-over-form analysis: if identifiable persons profit from the protocol, control upgrades or set the validator set, the fully-decentralized argument is difficult to sustain.
For a structured review of your bridge's MiCA exposure and whether a CASP authorisation strategy makes sense for your entity, contact OBOLUS at Map your options. The applicable analysis turns on your specific architecture, token design and user geography – factors that change the classification materially.
What Is the US Legal Risk for Cross-chain Bridge Operators?
In the United States, cross-chain bridge risk arises from at least three concurrent regulatory regimes: the SEC's securities analysis, the CFTC's commodity and derivatives jurisdiction and FinCEN's money-services business framework, with state-level money-transmitter licensing layered across all three.
The SEC's position – developed through enforcement actions and guidance rather than bridge-specific rulemaking – is that a wrapped token may be a security if the issuance involves an investment of money in a common enterprise with an expectation of profit from the efforts of others. A bridge that charges a fee, issues governance tokens to liquidity providers or funds development from protocol revenue faces a fact-specific securities analysis that cannot be dismissed on the basis of a "utility" label. We have seen operators who attached a utility description to their bridge token and proceeded without counsel discover, some months later, that the economic substance of the arrangement pointed in a different direction.
FinCEN's money-services business framework applies to persons who accept and transmit value – a description that fits most lock-and-mint bridges. Registration as a money-services business with FinCEN, and compliance with Bank Secrecy Act AML obligations, may be required even where the operator claims full decentralization. The NYDFS BitLicense requirement adds a further state-level obligation for operators with New York users or nexus. Obtaining a BitLicense is a significant undertaking; operating without one where it is required is a material enforcement risk.
The CFTC's reach extends to bridges that facilitate the exchange of commodity derivatives or that operate as a trading facility for commodity interests. For bridges supporting perpetual or leveraged instruments, this adds a third concurrent exposure. In our cross-border practice, US exposure is almost always the most complex leg of a multi-jurisdiction bridge analysis, in part because the three federal regulators do not always agree on where jurisdiction falls, and in part because state-level MTL requirements vary materially across the states.
How Do VARA, Singapore's MAS and Hong Kong's SFC Approach Bridge Risk?
Across the major APAC and Gulf hubs, cross-chain bridge legal risk is assessed through the lens of the activity-based licence regimes rather than bridge-specific rules, and the classification exercise tracks similar functional questions to those applied under MiCA and in the US.
VARA – the Virtual Assets Regulatory Authority in Dubai – operates a set of activity-specific rulebooks covering custody, exchange, transfer and settlement, among others. A bridge that performs any of these functions for users with a Dubai nexus may require a VARA licence. VARA's rulebooks apply to the mainland Dubai perimeter; activity within the DIFC falls under the DIFC's own financial-services regime. Operators structuring a Gulf presence routinely face the question of which perimeter applies to their user base and where the entity should sit – a question that turns on user location, not server location.
Singapore's Monetary Authority of Singapore (MAS) regulates digital-payment-token services under the Payment Services Act. A bridge that facilitates the transfer of digital-payment tokens, or that accepts and transmits them on behalf of users, may require a DPT service licence. The tier of licence – standard or major payment institution – depends on volume thresholds. MAS has been consistent in applying substance-over-form analysis to DeFi structures: where an operator directs or controls the protocol, the exemption for purely decentralized software does not shield the persons involved.
The Hong Kong SFC requires virtual-asset trading platforms to obtain a VASP licence. A bridge that aggregates liquidity or provides access to trading functions on a VATP may require licensing. The SFC has also indicated that persons who operate or materially control a DeFi protocol serving Hong Kong users should consider their licensing position. The "tokenised" injunction obtained in Hong Kong (the first of its kind in that jurisdiction) demonstrates that courts there are prepared to treat on-chain assets with the same urgency as traditional assets in disputes – a development that matters for bridge operators facing smart-contract exploit claims.
Who Bears Liability When a Cross-chain Bridge Fails or Is Exploited?
When a bridge exploit occurs – and bridge exploits remain among the most frequent and high-value incidents in on-chain finance – the liability question turns on three variables: whether the operator was regulated (and therefore under a supervisor's jurisdiction), the legal character of the smart contract governing the bridge, and the jurisdiction whose courts are likely to be asked to adjudicate.
In the leading common-law forums – England and Wales, Singapore and Hong Kong – courts have consistently treated crypto-assets as property capable of being owned and traced. The worldwide freezing order (an injunction freezing a defendant's assets globally) is available in England and Wales and has been granted in crypto-asset disputes. In our recovery practice, we have seen situations where the identifiable persons behind a bridge – developers, multisig keyholders or DAO committee members – became defendants in tracing actions, with claimants arguing that the existence of an identified group exerting control was sufficient to found liability.
The smart contract as a legal instrument is the second axis. In most jurisdictions, a smart contract is not a recognized legal form; it is code that may or may not evidence a contractual relationship between identifiable parties. Where a bridge's terms-of-service disclaim liability for smart-contract failures, those disclaimers are only as effective as the jurisdiction's consumer and commercial law allows. Where no terms-of-service exist – as is common in DeFi bridges with a "pure protocol" posture – the absence of a contractual framework does not eliminate claims in tort or unjust enrichment in many jurisdictions.
In a recent matter, an operator of a cross-chain bridge experienced a liquidity drain following a governance exploit in which a small committee of validators approved a parameter change that exposed user funds. We assisted in mapping the governance trail on-chain, identifying the key signers, and preserving evidence across two blockchain networks in preparation for proceedings. The matter resolved without litigation, but the exercise illustrated how quickly operator control – even where operationally minimal – becomes the focal point of a liability analysis once funds are lost.
A DAO governance structure adds further complexity. Where a bridge is governed by a DAO (decentralized autonomous organization) and DAO governance token holders vote on protocol upgrades, the question of whether token holders are jointly and severally liable for the bridge's operations has not been definitively resolved in any major jurisdiction. US courts have addressed this question in the context of DAO general partnerships; other jurisdictions are watching those developments closely.
If a bridge exploit or governance dispute is live, the recovery clock is short. Contact OBOLUS at Map your options for an assessment of available tracing and freezing remedies. The window for effective action narrows significantly once funds move through secondary exchanges.
What Legal Wrapper Best Suits a Bridge-operating DAO?
No single legal wrapper is correct for all bridge-operating DAOs, but the choice of wrapper determines the extent to which the DAO's members, governance-token holders and developers are exposed to personal liability when the protocol causes loss.
The leading structural options in our cross-border practice are the Cayman Islands foundation company, the BVI business company, the ADGM or DIFC foundation, and – for DAOs with a strong regulatory engagement posture – a licensed entity in a jurisdiction that recognizes DAO-adjacent structures, such as the AIFC in Kazakhstan. Each option reflects a different balance between legal personality, member liability, regulatory visibility and operational flexibility.
A Cayman Islands foundation company provides legal personality separate from its members, can hold assets and enter contracts, and does not require shareholders – a structure that maps reasonably well onto a DAO where no individual "owns" the protocol. Under the Cayman VASP Act, the foundation may nonetheless need to register if it provides virtual-asset services to users. The BVI equivalent offers similar attributes under the VASP Act 2022 framework.
The AIFC, operating under the Astana Financial Services Authority (AFSA), offers a common-law environment within Kazakhstan, with digital-asset-specific licensing categories. For a bridge with a Central Asian or regional APAC user base, the AIFC can serve as the legal and regulatory anchor, with allied counsel in the relevant jurisdictions covering local-law requirements where the bridge is accessed.
What none of these wrappers achieves is complete insulation from the regulators of the jurisdictions where users are located. A Cayman foundation operating a bridge that serves EU users is still within MiCA's territorial reach. The wrapper choice therefore addresses the structure of liability and governance; it does not, by itself, resolve the licensing question for each user geography.
How Does Token Classification Affect a Bridge's Legal Risk Profile?
A bridge token's legal classification – whether as a security, an e-money instrument, an ART or a utility token – is the single variable most likely to convert a product-design decision into a regulatory enforcement. AUDIENCE_MYTH is directly on point: a utility label on a whitepaper does not settle the legal classification. Substance governs.
Under MiCA, the classification matrix works outward from the token's economic design. A governance token that entitles the holder to a share of protocol fees looks different from a pure governance right, and regulators will assess the economic substance. A wrapped token that tracks the price of another asset may qualify as an ART, triggering issuance authorisation and, if volume thresholds are crossed, ESMA oversight. A token used solely as a medium of exchange within the protocol – no fee rights, no redemption right, no value peg – has the strongest argument for treatment as a utility token with lighter obligations.
In the US, the Howey analysis applied by the SEC asks whether there is an investment of money, a common enterprise, and an expectation of profit from the efforts of others. Bridge governance tokens issued to liquidity providers in exchange for capital – especially where those providers expect appreciation based on protocol growth – sit close to the security boundary. We assess classification against the substance of rights and economic design, not the marketing label – a principle the SEC has applied consistently in enforcement contexts.
The cross-border dimension creates a compounding problem: a token classified as a utility in one jurisdiction may be a security in a second and an e-money instrument in a third. Operators deploying a bridge token across multiple markets need jurisdiction-specific classification opinions, not a single global legal memo that applies one regime's test to all geographies. In our practice, we structure these as parallel-track analyses, each anchored to the specific regime, and produce a consolidated risk map that identifies the jurisdictions where regulatory engagement is required before launch.
Decision Matrix: Which Profile Faces Which Risk and Where
Bridge operators present along a spectrum of architectures and user profiles, and the risk constellation differs materially across that spectrum. The following profiles illustrate the principal decision branches.
Profile A – Trust-minimized, permissionless bridge with no identified operator: governance entirely on-chain, no multisig committee, no protocol fee accruing to an identifiable party. This profile has the strongest argument for falling outside the regulated perimeter in most jurisdictions, but the argument is not conclusive. Any jurisdiction that adopts a substance-over-form test will ask whether the original developer team or a foundation retains de facto control through token concentration, upgrade keys or treasury governance. The risk is lower than for Profile C, but it is not zero, and it is extinguished entirely only by the most rigorous decentralization in practice, not just in design documents.
Profile B – Bridge governed by a multisig committee of named validators: the committee is the identified responsible party in most regulators' analysis. This profile requires a careful mapping of each committee member's jurisdiction and the licensing obligations triggered in each. The VARA regime in Dubai, the MAS DPT framework in Singapore and MiCA in the EU each apply to the activity, not the claimed governance model. Timeline to licence readiness varies by jurisdiction – from a matter of weeks for initial registration in some regimes to a process measured in months for full CASP authorisation under MiCA. Key risk: if one committee member is in a restricted jurisdiction (including the US, for a protocol serving US persons), the entire bridge architecture faces that jurisdiction's enforcement reach.
Profile C – Bridge with a foundation entity, a protocol fee, and a governance token distributed to liquidity providers: this is the highest-risk profile. The foundation is a legal person; the fee creates an economic interest; the token distribution to investors triggers securities analysis in multiple jurisdictions simultaneously. This profile requires a full cross-border licensing and compliance strategy, entity domiciliation in a jurisdiction that provides clear regulatory treatment, and, in all likelihood, a securities law analysis for every jurisdiction where the token was offered. The decision matrix here is not "which licence" but "in which sequence do we engage which regulator first to avoid enforcement pre-empting the application."
AML, the Travel Rule and Cross-chain Bridge Compliance
Anti-money-laundering obligations present a specific structural challenge for cross-chain bridges: the Travel Rule (the obligation to pass originator and beneficiary data with a value transfer) was designed for intermediated transfers, but bridges – particularly permissionless ones – do not capture counterparty identity at the protocol level.
FATF Recommendation 15 on virtual assets requires that virtual asset service providers (VASPs) collect and transmit originator and beneficiary information on transfers above applicable thresholds. The threshold varies by jurisdiction. Where a bridge is classified as a VASP – and in many jurisdictions the classification follows from the transfer or custody function – Travel Rule compliance is mandatory. The technical challenge is that a smart contract does not inherently pass customer data alongside a transaction. Bridge operators in the VASP perimeter have addressed this through protocol-level Travel Rule messaging solutions, through identity-layer integrations and through restricting bridge access to KYC-verified wallets.
The FATF guidance on DeFi makes clear that the VASP label attaches to the persons who control or profit from a protocol, not to the protocol itself. Operators we advise who assumed that a smart-contract deployment immunized them from Travel Rule obligations have uniformly found, on analysis, that the control question brings them inside the VASP perimeter. The practical consequence is that AML program design for a bridge must be built into the architecture before deployment, not retrofitted after a regulator inquiry.
Regulators in the leading hubs increasingly expect bridge operators to demonstrate that they have assessed their Travel Rule position, documented their reasoning and, where they conclude they are outside the VASP perimeter, maintained that analysis as a live compliance document. The absence of that analysis is itself a compliance failure in several jurisdictions that have adopted the FATF standards.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – the full practice overview for on-chain legal structuring and compliance
- Staking Service Legal Framework in Bermuda – jurisdiction-specific analysis for staking-adjacent infrastructure operators
- Security Token Offering Structuring for Established Operators – structuring guidance for token issuances at the securities boundary
FAQ
Can a DeFi protocol be regulated?
Yes. Most regulators apply a substance-over-form test: if identifiable persons control the protocol, profit from it or direct its development, those persons may be regulated regardless of whether the underlying code is permissionless. The FATF's guidance on virtual assets, the EU's MiCA regime and the enforcement posture of the US SEC and CFTC all reflect this approach. A fully autonomous, profit-free, upgrade-locked protocol presents the strongest argument against regulated-entity status, but that architecture is rare in practice.
What legal wrapper suits a DAO?
The leading options are a Cayman Islands foundation company, a BVI entity under the VASP Act 2022, an ADGM or DIFC foundation, or a licensed entity within the AIFC. Each provides legal personality separate from token holders and maps reasonably onto a DAO's governance model. The right choice depends on where the DAO's users are, what regulatory engagement the DAO expects and whether the foundation will itself require a virtual-asset service licence. No single wrapper eliminates multi-jurisdiction regulatory exposure; it manages the structure of liability and governance.
Who is liable when a smart contract fails?
Liability follows control. Where identifiable persons – developers, multisig keyholders, DAO committee members – exercised material control over the smart contract or its parameters, those persons may face claims in tort, unjust enrichment or, in regulated contexts, regulatory enforcement. Courts in England and Wales, Singapore and Hong Kong have consistently treated crypto-assets as property subject to tracing and freezing orders. Terms-of-service disclaimers reduce but do not eliminate liability. The absence of any terms-of-service creates a different set of risks under the commercial and consumer law of each jurisdiction in which the protocol operates.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – a distinction that consistently proves decisive in regulatory engagement. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams, which is particularly important for bridge operators managing exposure across multiple regimes simultaneously. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specializing in smart-contract legal analysis, DeFi protocol structuring and cross-border regulatory classification for on-chain infrastructure operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.