EST · MMXXVI
Home/Insights/Tech/Cross-chain bridge legal risk: The Compliance Burden in Practice
DeFi, Tokenization & Smart-Contract Law

Cross-chain bridge legal risk: The Compliance Burden in Practice

Cross-chain bridge legal risk: The Compliance Burden in Practice. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. T

Cross-chain bridges sit at the intersection of the most demanding questions in DeFi legal analysis: which regime applies, who bears the compliance obligation, and what happens when locked assets move across sovereign boundaries without a licensed intermediary in sight. As supervisors across the major hubs increasingly scrutinize infrastructure rather than just end-user applications, operators who treat a bridge as a neutral technical relay are building on a structural assumption that regulators are actively dismantling. This page maps the compliance burden as it stands, jurisdiction by jurisdiction, and identifies the decision points that determine whether a bridge operator faces a licensing gap, an AML exposure, or a securities-classification problem – often all three simultaneously.

What Is a Cross-chain Bridge, and Why Does the Legal Classification Matter?

A cross-chain bridge is not a neutral conduit: depending on how it holds, wraps, mints, or releases assets, it may simultaneously constitute a custodial service, a transfer facility, and – where the bridged token confers rights – an instrument whose distribution triggers securities or e-money rules. The technical architecture is the starting point for any classification analysis, not the marketing label attached to it.

Three dominant models circulate in live deployments. A lock-and-mint bridge immobilizes the origin-chain asset in a smart contract and issues a synthetic representation on the destination chain. A burn-and-release bridge destroys the wrapped token on redemption and unlocks the native asset. A liquidity pool bridge uses pre-funded reserves on both chains to settle near-simultaneously without locking the underlying. Each model produces a distinct legal profile. Lock-and-mint creates a custodial relationship over the locked asset. Burn-and-release resembles an e-money redemption cycle. Liquidity pool bridges look, to a regulator applying substance-over-form analysis, like a payment institution managing pooled client funds.

In our cross-border practice, we have seen operators deploy all three models under the assumption that the smart contract is the operator and therefore no entity is licensed. That assumption does not survive contact with any of the major regimes. Under MiCA, VARA, the MAS Payment Services Act, or the FCA's money-laundering registration framework, the regulated question is whether a person – legal or natural – is providing a regulated activity. The existence of autonomous code does not eliminate the person who deploys, controls, upgrades, or profits from it.

Mis-classifying a token bridged through a lock-and-mint mechanism can convert an otherwise compliant product into an unregistered securities offering – the bridged synthetic may inherit the classification of the underlying asset, or it may acquire a distinct classification based on the rights it confers on its holder. Neither outcome is predictable from the whitepaper alone.

Which Regulators Are Watching Bridges – and Under What Theory?

Regulators across the major hubs are applying three distinct theories to assert jurisdiction over bridge operators, and a cross-border deployment is likely to attract more than one simultaneously. Understanding the theory is the precondition for structuring a defensible position.

The first theory is the transfer-facility theory. Under the applicable VASP provisions in jurisdictions following FATF Recommendation 15 guidance, a bridge that moves virtual assets from one address to another on behalf of a user is providing a virtual-asset transfer service. ESMA and the national competent authorities implementing MiCA have confirmed that transfer and execution services are regulated CASP activities. The FCA applies an analogous analysis under its money-laundering registration regime. VARA in Dubai reaches the same result under its transfer and settlement activity category.

The second theory is the custody theory. Any period during which the bridge contract – or the multisig committee controlling it – holds the user's locked asset constitutes safeguarding of a virtual asset. Under MiCA, custody is a standalone CASP activity requiring authorisation. Under the FSRA regime within ADGM, regulated custody extends to arrangements where a third party controls the private key even temporarily. Lock-and-mint bridges almost universally trigger this analysis.

The third theory is the issuance theory. Where the minted synthetic token on the destination chain confers economic or governance rights on its holder, regulators applying a substance-over-label analysis – which is the approach mandated under MiCA for asset-referenced tokens (ARTs) and e-money tokens (EMTs), and under the FINMA token taxonomy for payment and asset tokens – may classify the synthetic as a regulated instrument in its own right. That classification triggers whitepaper obligations, reserve requirements, and issuer authorisation requirements that are entirely separate from the transfer-service analysis.

The cross-border dimension compounds all three theories. A bridge deployed from a Cayman entity, routing assets between Ethereum and a Layer-2 network, with a front-end accessible to EU users, faces a credible argument under MiCA that it is passporting regulated CASP activities into the EU without authorisation. VARA's territorial scope covers activity directed at UAE residents regardless of where the operator is incorporated. The MAS Payment Services Act applies to operators serving Singaporean users whether or not the entity is domiciled in Singapore. No single licensing solution addresses all three simultaneously; the structure must be built to match the user geography.

How Does the AML and Travel Rule Obligation Attach to a Bridge?

The Travel Rule (the FATF obligation requiring originator and beneficiary information to accompany a virtual-asset transfer) applies to bridges in the same way it applies to any other VASP-to-VASP transfer – but the technical reality of cross-chain transfers makes compliance significantly harder in practice. Operators we advise routinely underestimate the structural changes required to embed Travel Rule compliance into a bridge architecture without degrading the user experience or breaking the bridge's liquidity assumptions.

The core difficulty is that the Travel Rule obligation attaches at the point of transmission: the originating VASP must pass structured data to the beneficiary VASP before or simultaneously with the transfer. In a bridge context, the "beneficiary VASP" is, depending on the architecture, either another bridge operator on the destination chain, a liquidity provider, or the user's own self-hosted wallet. Where the beneficiary is a self-hosted wallet, the applicable provisions in most jurisdictions require the originating VASP to collect and retain the relevant data and, in some cases, to apply enhanced due diligence before releasing the transfer.

Under the Travel Rule as implemented across the MiCA regime and under FATF Recommendation 15, the data-passing obligation does not disappear simply because the destination address is a smart contract rather than a custodial account. The analysis turns on whether the ultimate beneficiary is an identified person. Pseudonymous destination addresses do not satisfy the obligation; they shift the risk to the operator.

In practice, bridge operators face three structural choices: build a compliant data-passing layer into the bridge protocol itself (technically demanding and potentially privacy-limiting); restrict bridge access to identified counterparties who have completed KYC at a gateway custodian; or accept that the bridge is operating outside the Travel Rule perimeter and structure accordingly – which typically means limiting access to professional counterparties in jurisdictions where that is a defensible position. None of these choices is frictionless. Each has a distinct regulatory risk profile, and the right answer depends on the operator's user base, the asset types bridged, and the jurisdictions in which users are located.

In a recent cross-border compliance review, a DeFi infrastructure company running a high-volume lock-and-mint bridge between two EVM-compatible networks engaged us to map its Travel Rule exposure. We identified that a significant proportion of bridge transactions were originating from addresses associated with regulated custodians in EU member states – addresses that, under MiCA's applicable CASP provisions, imposed a co-compliance obligation on those custodians and, by extension, a data-passing expectation on the bridge operator. The company restructured its gateway architecture to route institutional flows through a separately licensed transfer-service entity, isolating the retail exposure to a jurisdiction where a defensible exemption threshold applied.

Does the Bridged Token Create a Securities Classification Problem?

A bridged token can independently acquire a securities or regulated-instrument classification that the underlying asset does not carry, and operators who assume that the classification of the wrapped token tracks the classification of the original asset will be wrong in a meaningful number of cases. The analysis turns on what rights the bridged token confers, not on what the underlying asset is.

Under MiCA, a wrapped token that references a basket of assets or whose value is maintained by reference to a fiat currency is an ART or EMT regardless of whether the underlying is classified differently in its native chain environment. The issuer of that token – which, in a lock-and-mint structure, is identifiably the entity that deploys the minting contract – bears the full ART or EMT issuer authorisation obligation. That obligation includes a whitepaper review by the relevant national competent authority, minimum own-funds requirements (which vary by category and are subject to [VERIFY] before use in any client-specific context), and ongoing reserve and redemption obligations.

Outside the EU, the analysis differs but the risk does not diminish. Under the FINMA token taxonomy, a synthetic that tracks a fiat-denominated value is likely a payment token subject to AML affiliation requirements. Under the SFC's VATP regime in Hong Kong, a synthetic that confers economic exposure to an underlying security is a security token, and its distribution requires a licensed operator regardless of the bridge mechanism through which it was issued. In Singapore, the MAS has been explicit that wrapping a securities token does not alter its regulatory classification.

The issuance theory is where we most frequently see the gap between a whitepaper's utility label and the substance of the rights conferred. We assess classification against the substance of those rights – governance entitlements, economic participation, redemption mechanics, and stabilization mechanisms – not against the marketing description. A token labeled "bridged ETH" that accrues protocol fees, participates in governance votes, and is redeemable against a treasury is not a simple derivative of ETH in any regulatory sense.

CTA #1 — For operators who are uncertain whether their bridged token creates a new classification obligation, the starting point is a structured classification analysis, not a whitepaper disclaimer. The process above describes the standard analytical path, but the specific facts – the rights conferred, the redemption mechanism, the user geography – change the output materially. To map your classification exposure before a product launch, contact OBOLUS at info@oboluslaw.com.

DAO Governance of a Bridge – Does It Distribute or Eliminate Liability?

Governance by a DAO (decentralized autonomous organization) does not eliminate legal liability for a bridge's operators; in most jurisdictions it distributes it in a way that is worse for token holders than conventional corporate governance would be. This is the central myth that informed operators must confront before deploying a DAO-governed bridge.

The assumption that governance token holders are insulated from regulatory liability because they vote on proposals rather than operate infrastructure does not reflect how regulators in the major hubs are approaching DAO structures. The FCA has indicated that meaningful economic participation in a DeFi protocol – including governance participation that materially influences operational decisions – is a factor in determining whether a person is carrying on a regulated activity. ESMA's preliminary positions under MiCA suggest that fully decentralized protocols may fall outside the regime, but the decentralization threshold is demanding: a DAO that retains an upgrade multisig, a treasury controlled by a foundation, or a founding-team veto on governance proposals is not fully decentralized in the regulatory sense.

The BVI has introduced a specific legal wrapper for DAOs under its existing company law, and the AIFC within Kazakhstan has published a DAO framework that provides limited liability to participants meeting specific governance criteria. The Marshall Islands DAO LLC structure has attracted attention. None of these wrappers is universally recognized; a DAO registered under BVI law that provides services to EU users is still subject to MiCA's CASP authorisation requirements for those services. The wrapper mitigates the liability of individual token holders under the DAO's home jurisdiction; it does not resolve the operator's licensing obligation in the users' jurisdictions.

In our cross-border practice, the most defensible DAO-governance structures for bridge operators combine a regulated entity that holds the licence and operates the transfer service, a separately incorporated foundation that manages protocol development and treasury, and a governance token structure that is carefully scoped to advisory rather than operational control. This structure preserves the economic and community attributes of DAO governance without routing regulatory liability through the entire token-holder base.

Which Licensing Path Suits Which Bridge Operator?

There is no universal licensing solution for a cross-chain bridge operator; the right structure turns on the operator's asset types, user base, and operational model. The decision matrix below is a starting point for structuring conversations, not a substitute for jurisdiction-specific advice.

Profile A – Institutional-only bridge, bridging ETH and major stablecoins, users are regulated entities. This profile is the most structurally manageable. A MiCA CASP authorisation in an EU member state, passported across the EEA, addresses the EU user base. A VARA transfer-and-settlement licence addresses UAE institutional counterparties. A MAS major payment institution licence (or a gateway arrangement with a licensed MPI) addresses Singapore. The Travel Rule obligation is manageable because institutional counterparties are identified. The principal risk is the stablecoin-issuer analysis: if the bridge mints a synthetic stablecoin rather than routing the underlying USDC or USDT, the ART/EMT issuer question reopens. Timeline to full multi-jurisdiction stack: measured in months rather than weeks; the precise duration depends on each regulator's current processing capacity and the completeness of the application at submission.

Profile B – Permissionless bridge, mixed retail and institutional users, bridging a proprietary governance token alongside major assets. This is the most legally complex profile. The proprietary governance token requires a standalone classification analysis in every target jurisdiction before the bridge goes live. A utility label on a whitepaper does not settle the classification; the SFC, ESMA, and MAS will each apply a substance test. The permissionless character makes Travel Rule compliance structurally difficult – a gateway model with KYC at the point of entry is the most defensible architecture. This profile almost certainly requires a phased rollout: begin with a restricted jurisdiction set where the regulatory position is clearest, obtain licences in those jurisdictions, and expand geo-by-geo as the compliance stack is built out. Operating globally from day one without that stack creates an enforcement surface that is disproportionate to any first-mover advantage.

Profile C – Bridge operated by a foundation, DAO-governed, with a token whose classification is unresolved. This profile requires the classification question to be resolved before any licensing decision is made. If the token is a security in one or more major jurisdictions, the bridge operator is potentially distributing securities to retail users without registration. That is the most serious regulatory risk in the matrix. The foundation structure does not provide cover. We have seen operators in this profile enter a period of "soft launch" with restricted access and a legal opinion obtained only in the home jurisdiction – a position that typically satisfies neither the home regulator nor the jurisdictions where users actually reside.

CTA #2 — If a prior classification analysis stalled or a banking relationship was terminated because of unresolved bridge compliance questions, a second-look review can identify the structural gap and the route forward. Write to OBOLUS at info@oboluslaw.com or message us at t.me/oboluslaw.

What Are the Most Frequent Compliance Mistakes Bridge Operators Make?

Operators most commonly fail at the bridge compliance analysis in four structurally predictable ways. Each failure is avoidable with early legal input; each becomes significantly more expensive to remediate after a product has gone live.

The first mistake is treating the smart contract as the operator. No major regulatory regime accepts that an autonomous contract is the regulated entity. The developer, the foundation, the multisig committee, or the DAO governance token holders will be the person to whom regulatory obligations attach. Identifying that person – and ensuring it is a legal entity capable of holding a licence and fulfilling compliance obligations – is a threshold step, not a refinement.

The second mistake is assuming territorial limitation through offshore incorporation. A bridge incorporated in the BVI or Cayman Islands with no staff in the EU or UAE is not immune from MiCA or VARA if its services are directed at users in those jurisdictions. Regulators assess the direction of services, not the place of incorporation. The VASP Act 2022 in the BVI and CIMA's Virtual Asset regime in Cayman create registration obligations in the home jurisdiction; they do not create a regulatory shield for activity directed elsewhere.

The third mistake is resolving the AML question without resolving the securities question. These are separate analyses. An operator can obtain an AML registration under the FCA's money-laundering regulations and still be running an unregistered securities offering if the bridged token is a security. We regularly see operators who have addressed one workstream in isolation and are surprised when the other creates an enforcement exposure.

The fourth mistake is deferring the tokenization legal analysis until after token generation. By the time a token has been issued on a destination chain, the classification analysis is retrospective rather than prospective. A retrospective classification that identifies a securities problem does not produce a clean path to compliance; it produces a remediation exercise that typically requires the operator to restrict access, offer rescission to token holders, or redesign the token mechanics – all of which have commercial and reputational costs that a pre-launch analysis would have avoided.

A Common Assumption: Does a Utility Label Settle the Legal Classification?

A common assumption among bridge operators is that attaching a utility description to a token in a whitepaper determines its regulatory classification. It does not. Every major regime – MiCA, the SFC's VATP framework, the MAS Payment Services Act, FINMA's token taxonomy, and the SEC's application of the Howey analysis – applies a substance-over-label test. The label is not irrelevant; it is one data point among many. The decisive factors are the rights conferred on the token holder, the economic arrangement underlying those rights, and the reasonable expectation of the holder at the time of acquisition.

A bridged token that entitles the holder to a share of protocol fees is an economic-participation instrument regardless of the label. A token whose value is maintained by reference to a basket of fiat currencies is an asset-referenced token under MiCA regardless of whether the whitepaper calls it a "utility access token." A governance token in a bridge protocol that controls material economic parameters – fee rates, liquidity allocation, treasury disbursements – is unlikely to satisfy the non-security test in the major common-law jurisdictions.

We assess classification against the substance of rights, not the marketing description. That analysis is not academic: a misjudgment at the classification stage converts a product launch into an unregistered-offering problem retroactively, and retroactive compliance is structurally more difficult and commercially more damaging than pre-launch classification work.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes – and the degree to which it is depends on how decentralized the protocol actually is in practice, not in marketing. Where an identifiable person or legal entity deploys, upgrades, controls a multisig, or receives economic benefit from the protocol, regulators in the major hubs – including ESMA under MiCA, the MAS, and the FCA – treat that person as the subject of regulatory obligations. Full decentralization, with no controlling party and no fee flow to an identifiable person, is the threshold for a credible out-of-scope argument, and most live protocols do not meet it.

What legal wrapper suits a DAO?

The right wrapper depends on the DAO's activities, user base, and home jurisdiction. Options include a BVI company under the VASP Act framework, a Cayman Islands foundation, a Marshall Islands DAO LLC, or an AIFC-registered entity under Kazakhstan's DAO framework. None of these is universally recognized; the wrapper addresses home-jurisdiction liability and governance clarity, but does not substitute for licensing in jurisdictions where the DAO's services are directed. Combining a regulated operating entity with a separately incorporated foundation remains the most defensible multi-jurisdiction structure for active bridge or protocol operators.

Who is liable when a smart contract fails?

Liability for a smart-contract failure – whether through a bug, an exploit, or an oracle manipulation – attaches to the person who deployed or controlled the contract, not to the contract itself. In most common-law jurisdictions, that means the developer or the entity that published the contract. Governance token holders who exercised material operational control may also face exposure. Operators who disclaim liability through a terms-of-service document face the additional risk that those terms are unenforceable in jurisdictions where the service is regulated, because a regulated entity cannot contractually disclaim obligations imposed by statute.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and bridge operators on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label – and we structure licensing, banking, and tax as one mandate rather than three disconnected workstreams. To discuss your bridge compliance position, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specializing in smart-contract legal design, protocol classification, and cross-border compliance for DeFi infrastructure operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours