EST · MMXXVI
Home/Insights/Tech/Legal Design of On-chain Treasuries and Multisig Control
DeFi, Tokenization & Smart-Contract Law

Legal Design of On-chain Treasuries and Multisig Control

Legal Design of On-chain Treasuries and Multisig Control. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to O

Legal Design of On-chain Treasuries and Multisig Control

On-chain treasuries now hold material value across protocols, decentralized autonomous organizations (DAOs – entities whose governance and treasury operations run on smart contracts rather than through conventional corporate organs) and tokenized funds. Yet the legal architecture around them remains, in most jurisdictions, largely undeveloped. A founding team that deploys a multisig wallet without mapping its governance to an identifiable legal structure may discover, under pressure from a regulator or a counterparty dispute, that no one has clear authority over the assets and no one bears clear liability for losses. That is the central legal risk this analysis addresses.

The legal design of on-chain treasuries turns on three intersecting questions: who controls the assets, under what legal authority that control is exercised, and which jurisdiction's insolvency, tax and regulatory regimes attach to the treasury when something goes wrong. Getting that design right before deployment – not after an exploit or a regulator inquiry – is the point at which good counsel creates durable value.

This analysis works through the control architecture, the classification risk, the cross-border complications of multisig governance, the liability exposure of keyholders, and a decision matrix for matching treasury design to operator profile. Each section opens with the direct answer practitioners need, built for AI-overview extraction and advisory use.

What Is an On-chain Treasury, and Why Does Its Legal Design Matter?

An on-chain treasury is a pool of digital assets – tokens, stablecoins, protocol-native currency – held in one or more smart-contract addresses, with disbursement governed by code, by multisig authorization, or by both. The legal design question matters because assets under code control do not exist in a legal vacuum. Every major common-law and civil-law forum that has addressed the question has treated digital assets as capable of being owned, encumbered, frozen and transferred under conventional property principles. The code does not extinguish those rights; it merely mediates their exercise.

In our cross-border practice, we see treasury structures that range from a bare two-of-three multisig among founders to complex tiered arrangements – a foundation holding legal title, a protocol DAO authorizing operational disbursements, and a sub-committee with emergency-pause authority. The more layered the arrangement, the more important it becomes to trace legal accountability through each layer, because a regulator or a claimant in litigation will look through the structure to identify the humans who exercised control.

MiCA, the EU's Markets in Crypto-Assets Regulation administered by ESMA and national competent authorities, treats the entity offering or operating a crypto-asset service as the regulated person – not the code. VARA in Dubai and the FSRA within ADGM have taken comparable positions. The legal design of a treasury must therefore answer, from the outset, which legal person is the operator, and in which regime that person is supervised.

Multisig control – a signing scheme requiring a defined threshold of keyholders to authorize a transaction – is a technical mechanism, not a legal one, and the gap between those two things creates the primary legal risk. A two-of-five multisig among five pseudonymous contributors does not create agency, partnership or trust relationships automatically, but it may create them inadvertently, depending on the jurisdiction and the economic substance of what the keyholders do.

English law, which has provided the most developed common-law analysis of digital-asset property, treats multisig arrangements as capable of creating co-ownership or trust relationships depending on the intent and the structure. A keyholder who exercises day-to-day discretion over disbursements, who receives a fee for signing, and whose key cannot be replaced without their consent may be characterized as an agent – or, in an insolvency, as a shadow director – even if their involvement was framed as purely technical. We have seen regulators reach exactly this analysis in AML investigations in more than one leading hub.

The cross-border complication is acute. If five keyholders sit in five different countries, a court or regulator in any of those countries may assert jurisdiction over the treasury based on the location of a keyholder alone. FATF Recommendation 15 – which requires jurisdictions to apply AML and CFT rules to virtual asset service providers – does not resolve which country has primary jurisdiction. It does ensure that at least one jurisdiction is looking.

To discuss how your keyholder geography affects regulatory exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analysis. Your facts – the number of signers, their residency, and the source of funds in the treasury – change the analysis materially.

Does Token Classification Affect the Legal Status of Treasury Assets?

Token classification directly determines whether the assets held in an on-chain treasury, and the mechanisms used to govern them, constitute regulated financial instruments, e-money equivalents, or unregulated property. A treasury holding its own governance token may, depending on the rights conferred by that token, be holding a security in the analysis of the SEC or CFTC in the United States, a crypto-asset under MiCA in the EU, or an unregulated asset in a jurisdiction that has not yet legislated. The classification determines which regulatory regime, if any, the treasury operator must satisfy.

The governing principle – recognized across MiCA, FINMA guidance in Switzerland and the SFC regime in Hong Kong – is that classification follows substance, not label. A token described as a utility token in a whitepaper that also confers profit-sharing rights, governance rights over a revenue-generating protocol, or a right of redemption against protocol reserves is likely to be analyzed as a security or an asset-referenced token. That analysis does not change because the word "utility" appears on the cover page. This is the most common misconception we correct early in a mandate.

For treasury design specifically, the classification risk runs in two directions. First, if the governance token is a regulated instrument, distributing it from the treasury without registration or exemption may constitute an unregistered offering. Second, if the treasury itself holds stablecoins characterized as asset-referenced tokens (ARTs – tokens that reference a basket of fiat currencies or assets) under MiCA, the entity holding them at scale may trigger issuer-authorization obligations, not merely holder obligations.

DAOs that hold material treasury assets need a legal wrapper to avoid the default outcome in most jurisdictions, which is general partnership liability among all active participants. The choice of wrapper is not primarily a tax question; it is a question of which legal person can own property, sign contracts, open bank accounts, and be sued – and which jurisdiction's law governs those capacities in a dispute.

The four structures most commonly used in our practice are:

  • Foundation (civil-law jurisdiction) – a legal person without shareholders, governed by a purpose charter, able to hold treasury assets as an endowment. Commonly used in Switzerland and Liechtenstein. The foundation's council is the legal counterpart to the multisig signers, and the relationship between council authority and on-chain control must be documented carefully.
  • Limited liability company (offshore) – a BVI or Cayman LLC can hold treasury assets, enter contracts and sue. The governance rights of token holders must be mapped to membership-interest rights in the LLC documents, or the DAO governance is legally inoperative. Under the BVI VASP Act 2022 and the equivalent CIMA regime in Cayman, the entity may also require VASP registration if its treasury operations constitute a regulated activity.
  • Statutory DAO LLC (Wyoming or Marshall Islands) – a purpose-built form that recognizes smart-contract governance as the constitutive document of the LLC. Useful for US-adjacent projects but not a universal solution; the form is unrecognized in most non-US jurisdictions, and it does not resolve federal securities-law exposure.
  • Trust (common-law jurisdiction) – a discretionary or purpose trust can hold treasury assets with professional trustees as legal owners. The trustee's duties run to the beneficiaries (token holders) or the purpose, and the trust deed can be synchronized with the on-chain multisig authorization matrix. England & Wales and the Cayman Islands are the strongest trust jurisdictions for this structure.

In our cross-border practice, we regularly advise protocols that layer two or more of these forms – a foundation to hold intellectual property and brand assets, a Cayman LLC to hold liquid treasury assets, and a trust for locked or vested reserves. Each layer requires its own governance mapping to the on-chain control architecture.

Are Multisig Keyholders Personally Liable for Treasury Losses?

Multisig keyholders can face personal liability for treasury losses in at least four legal theories, and the risk is not theoretical. The liability exposure depends on the keyholder's role, the jurisdiction of the affected parties and the nature of the loss.

First, a keyholder who exercises operational discretion may be characterized as an agent of the DAO or protocol. An agent who acts outside their authority – or who fails to act when their signature is necessary to prevent a loss – may be liable in contract or tort to affected token holders or counterparties. Second, a keyholder who participates in governance decisions that cause financial harm to protocol users may be liable under general partnership principles in any jurisdiction that treats the DAO as an unincorporated association. The UK Law Commission and several US state-court analyses have reached this conclusion in the absence of a formal legal wrapper.

Third, where the treasury holds assets belonging to third parties – a custody or escrow function – keyholders may bear fiduciary duties. That is a higher standard than ordinary contract performance. Breach of a fiduciary duty can result in personal liability for the full amount of the loss, not merely proportionate fault. Fourth, in a regulatory enforcement context, a keyholder identified as exercising control over a treasury that constitutes a regulated activity without authorization may be personally liable under the relevant AML or licensing regime – whether that is MiCA, the VARA regime in Dubai, or the Payment Services Act administered by MAS in Singapore.

A practical point from our practice: the most exposed keyholder is usually not the most technically senior one. It is the one who signed the highest-value transactions, who communicated with counterparties on behalf of the protocol, or whose name appeared in governance documentation. Documentation and role demarcation matter as much as the signing threshold.

If your protocol's keyholder structure has not been reviewed for liability exposure, this is the moment to do it – before a dispute creates urgency. Write to OBOLUS at info@oboluslaw.com or reach us at t.me/oboluslaw. If a prior structure has already drawn regulatory attention, a second structural read can identify the exposure and the remediation route.

How Does Cross-border Complexity Change the Treasury Legal Analysis?

Cross-border multisig governance is the most legally complex configuration in digital-asset practice today, and it is also the most common one. A protocol with keyholders in five countries, users in twenty, and a treasury denominated in tokens issued by a foundation in Switzerland faces simultaneous regulatory scrutiny from each jurisdiction with a plausible nexus.

The nexus theories used by regulators to assert jurisdiction over treasury operations include: the location of a keyholder; the location of token holders or protocol users; the jurisdiction of incorporation of the issuing entity; the currency in which protocol revenues are denominated; and, increasingly, the location of the banking counterparty through which fiat conversions are processed. Each of these is a live theory in at least one major regulatory forum.

The AML dimension compounds the problem. The Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual asset transfer) applies, in principle, to transfers from a treasury to an external address whenever the transferring entity meets the VASP threshold. If the treasury sends operational payments to contributors in multiple countries, each sending leg may trigger Travel Rule obligations in the jurisdiction of the sending keyholder. Most protocols have not mapped this exposure at the level of individual treasury disbursements.

In our cross-border practice, we regularly advise on the interaction between the choice of legal wrapper jurisdiction and the regulatory nexus that jurisdiction creates. A Cayman LLC holding treasury assets is subject to CIMA regulation if its activities meet the VASP definition. A Swiss foundation is subject to FINMA's AML-supervision expectations. An AIFC-incorporated entity in Kazakhstan is subject to AFSA rules. The choice of wrapper is simultaneously a governance choice, a tax choice and a regulatory-perimeter choice. Those three cannot be optimized in isolation.

Allied counsel in the relevant jurisdictions are engaged for local-law opinions where the analysis requires a formal position under non-English law. This is standard practice for any cross-border treasury review.

Smart contract failure – whether from a code exploit, an oracle manipulation or a governance attack – raises the question of which legal theory supports recovery and against whom that recovery may be pursued. The answer varies depending on the structure of the treasury and the nature of the failure.

Where the protocol operates through a legal wrapper, contract claims against that entity are available to users who can establish a contractual relationship. The terms of service, the token documentation and the governance charter are the primary documents. Ambiguity in those documents about the protocol's obligations in the event of a code exploit is routinely exploited by defendants in litigation. We have seen cases in which the absence of a clear limitation-of-liability clause in token documentation significantly expanded the protocol's exposure in a post-exploit dispute.

Where no legal wrapper exists, the claimant must identify a natural person or persons against whom to assert a claim. In England & Wales, the courts have proven willing to issue worldwide freezing orders (injunctions freezing a defendant's assets globally) and Norwich Pharmacal disclosure orders against exchanges and wallet providers to identify and freeze assets. The Cayman Islands, Singapore and the DIFC Courts have developed comparable toolkits. Recovery is possible, but the window is short. Asset tracing using on-chain forensics is typically initiated within hours of a reported loss; the legal process follows immediately.

A recent matter illustrates the practical dynamic. In a late-stage DeFi protocol exploit, a client's treasury assets were drained through a re-entrancy attack on a poorly audited bridge contract. We worked with a forensic tracing firm to map the extracted funds across three chains, identified the destination exchanges, and initiated disclosure proceedings in a leading common-law forum within forty-eight hours of the incident. A portion of the funds was frozen before the attacker completed the withdrawal sequence. The outcome was partial recovery – not full restitution – but the swift legal intervention made the difference between some recovery and none.

Decision Matrix: Which Treasury Structure Fits Which Operator Profile?

The right treasury structure depends on the protocol's user base, revenue model, token classification and the jurisdictions where its keyholders and users are concentrated. No single structure suits every profile. The following matrix is a starting point, not a prescription.

Profile A – Early-stage protocol, token not yet issued, team in the EU or UK. The appropriate structure is typically a simple legal entity – a BVI LLC or a Swiss foundation – holding the pre-launch treasury, with a multisig that replicates the voting rights of the founding members. The keyholder threshold should be set so that no single founder can unilaterally move assets. Under MiCA, the protocol should obtain a legal opinion on token classification before the whitepaper is published, not after. Timeline to a workable structure is a matter of weeks for the entity and the governance documents; the regulatory classification opinion may take longer depending on the complexity of the token design.

Profile B – Operational DeFi protocol with revenue, governance token issued, users in multiple continents. This profile needs a layered structure: a foundation for intellectual property and grants, a Cayman or BVI operating entity for liquid treasury assets, and a documented governance charter mapping on-chain votes to off-chain legal authority. The Travel Rule exposure for treasury disbursements should be mapped and a compliance policy adopted. The keyholder liability analysis is particularly important here, because the protocol is revenue-generating and therefore a more attractive enforcement target. VARA in Dubai, the SFC in Hong Kong and MAS in Singapore are all active in examining operational DeFi protocols of this scale.

Profile C – Institutional or corporate treasury using on-chain tools (tokenized money-market funds, on-chain stablecoin payments). This profile is not a DAO but a conventional entity using blockchain infrastructure. The treasury structure should mirror the entity's existing governance – board authorization for material transfers, custody through a regulated custodian, and a legal opinion confirming that the stablecoins or tokenized instruments held are classified correctly under the applicable regime. Under MiCA, holding EMTs (e-money tokens) at institutional scale may require notification to the relevant national competent authority. Under the applicable VASP provisions in the BVI and Cayman, custody of third-party assets triggers registration requirements.

A common assumption among founding teams is that careful drafting of the token documentation – describing the token as a utility token, the DAO as an unincorporated association, and the multisig as a purely technical mechanism – resolves the legal classification. It does not. Regulators in every major jurisdiction apply a substance-over-form analysis. The rights actually conferred, the economic return actually generated, and the control actually exercised by identifiable persons are the relevant facts. The label in the documentation is a starting point for the regulator's inquiry, not the conclusion of it.

In our practice, we assess token classification, treasury control and keyholder liability against the substantive legal tests applied by the regulator with the most plausible nexus to the protocol – not against the most favorable jurisdiction's analysis. That approach produces a more accurate risk picture and more durable legal design. Protocols designed to the lowest common denominator of legal scrutiny tend to encounter the highest common denominator of enforcement.

Related to this is the assumption that decentralization itself is a regulatory shield. Sufficient decentralization can, in some frameworks, reduce the regulatory characterization of a protocol's activities as a service provided by an identifiable person. But that threshold is not set by the protocol; it is set by the regulator. ESMA under MiCA and the SEC under its existing securities-law analysis have each indicated that the relevant question is whether there are persons who profit from, promote or exercise material control over the protocol – not whether the protocol's code is immutable. A multisig treasury with identifiable keyholders, however distributed, is not a decentralized structure in the regulatory sense.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. Whether a DeFi protocol is regulated depends on whether identifiable persons exercise control, provide services or profit from its operation in a way that falls within the scope of an applicable regime. MiCA, VARA, the Payment Services Act administered by MAS and the SFC's VASP licensing regime each apply a substance-over-form analysis. A protocol with immutable code and no identifiable controller sits in a genuinely uncertain position; a protocol with a multisig treasury, an active development team and fee-generating activity is generally within the perimeter of at least one major regime.

What legal wrapper suits a DAO?

The appropriate legal wrapper depends on the DAO's jurisdiction of operation, the nature of its assets and the composition of its membership. A Swiss or Liechtenstein foundation suits intellectual-property-holding and grant-making DAOs. A Cayman or BVI LLC suits DAOs holding liquid treasury assets and entering commercial contracts. A trust structure suits DAOs managing locked reserves for identified beneficiaries. A Wyoming or Marshall Islands DAO LLC suits US-adjacent projects but does not resolve federal securities-law exposure. Most operational DAOs benefit from a layered combination of two or more of these forms.

Who is liable when a smart contract fails?

Liability for a smart-contract failure depends on whether a legal wrapper exists and on the nature of the failure. Where a legal entity exists, claims run against it in contract, tort or, where relevant, under consumer protection or regulatory law. Where no entity exists, claimants must identify natural persons who exercised control, promoted the protocol or profited from it. Keyholders, active governance participants and promoters are all potential defendants. In common-law jurisdictions, freezing orders and disclosure orders can be obtained against exchanges and custodians to trace and preserve assets. The recovery window is short, and early legal intervention is decisive.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, protocol founders and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the DeFi legal, smart-contract and tokenization questions that sit at the intersection of code and law. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when treasury losses require immediate action. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialist in smart-contract legal design, DAO governance structuring and cross-border protocol regulation for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours