EST · MMXXVI
Home/Insights/Tech/Real-world Asset Tokenization: The Legal Stack
DeFi, Tokenization & Smart-Contract Law

Real-world Asset Tokenization: The Legal Stack

Real-world Asset Tokenization: The Legal Stack. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Token projects increasingly ask the same question before their launch: how does the law treat what we are building? Real-world asset tokenization – the process of representing ownership of a physical or financial asset as a blockchain-based token – sits at the intersection of securities law, property law, AML compliance, and smart-contract enforceability. The answer is never one regime. For any operator building or investing in a tokenized-asset structure, the legal stack must be assembled deliberately, jurisdiction by jurisdiction, before the first token is minted.

This analysis maps that stack: the classification question, the applicable regulatory regimes across the leading hubs, the structural choices that determine liability, and the cross-border pressure points that routinely catch projects off-guard. Each section opens with a direct answer – designed to stand alone as a reference point.

What Is Real-World Asset Tokenization, Legally?

Real-world asset tokenization is, in legal terms, the creation of a digital instrument whose holder claims rights – whether ownership, economic participation, or both – in an underlying asset that exists off-chain. The token is not the asset; it is evidence of a claim. That distinction drives the entire legal analysis.

The off-chain asset might be real estate, a receivable, a commodity, a bond, a fund unit, or a revenue stream. The token may be structured as a security, as a unit in a collective investment scheme, as a hybrid instrument, or – less commonly and with more risk – as a utility token. Regulators in every significant hub assess the instrument against its substance, not its label. A token named "utility coin" that confers profit-sharing rights and governance power over a revenue-generating protocol is, in most analytical frameworks, a security or an interest in a collective investment scheme.

The classification decision is the first and most consequential step in building the legal stack. Mis-classification does not just expose the issuer to enforcement – it can render the token itself invalid as a property interest in the jurisdictions where holders try to enforce their claims.

In our cross-border practice, we encounter projects that have spent significant capital on smart-contract audits and marketing while deferring the classification analysis entirely. That sequencing is backwards. The structure of the token – what rights it confers, how it is transferred, who receives economic benefit, and how it is governed – must be resolved before the technical build, because the legal structure determines which licenses are required, which disclosures are mandatory, and which forums are available if something goes wrong.

How Do Leading Regulators Classify Tokenized Assets?

Classification turns on the rights conferred by the token, not the technology used to record those rights. Across the jurisdictions where we advise, a consistent analytical pattern has emerged, even though the precise rules differ.

Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities – tokenized assets fall into one of three categories: asset-referenced tokens (ARTs), which reference a basket of assets or currencies; e-money tokens (EMTs), which reference a single fiat currency; or "other crypto-assets," a residual category that includes most utility tokens. Instruments that qualify as financial instruments under existing EU financial-law directives fall outside MiCA and into the full securities regulatory regime. A tokenized bond or a tokenized fund unit is not a MiCA product – it is a financial instrument subject to the applicable prospectus, investment-services, and fund-management regimes.

In Singapore, the Monetary Authority of Singapore applies a similar bifurcation under the Payment Services Act and the Securities and Futures Act. A token that constitutes a capital markets product – a security, a unit in a collective investment scheme, or a derivative – requires the applicable authorization. The DPT (digital payment token) service category under the Payment Services Act captures only tokens that function as a means of payment, not tokens conferring investment rights.

In Hong Kong, the Securities and Futures Commission has confirmed that tokenized securities are treated as securities; the VASP licensing regime under the SFC covers trading platforms for virtual assets that are not securities, while traditional regulatory regimes cover tokenized securities trading. VARA in Dubai applies an activity-based licensing model: the issuer's specific activity – advisory, custody, exchange, transfer – determines which VARA rulebook applies, regardless of whether the underlying asset is tokenized or not.

The pattern is consistent: substance over label, with the investment-return test and the collective-pooling test doing most of the analytical work.

For a cross-border token launch, the operator must run the classification analysis in every jurisdiction where tokens will be offered or traded – not just the jurisdiction of the issuing entity. A token structured to avoid securities classification in one hub may squarely fall within the securities perimeter in another.

What Licences Does a Tokenized Asset Project Typically Require?

The licence map for a real-world asset tokenization project depends on the asset class, the token structure, the identity of the issuer, and the jurisdictions where investors and users are located. There is no single licence that covers the stack.

A typical mid-scale tokenization project touches at least four regulatory perimeters. First, the issuance perimeter: if the token is a security or a collective investment scheme interest, the issuer needs either an exemption or a full authorization – a prospectus approval, an offering memorandum, or an exempted offering registration. Second, the trading perimeter: secondary market trading of the token on a platform triggers platform-level licensing under the applicable regime, whether that is a CASP authorization under MiCA, a VASP licence under the SFC regime, or an MTL (money transmitter license) and potentially a broker-dealer registration in the US. Third, the custody perimeter: regulated activity in most flagship jurisdictions; the custodian must be authorized under the applicable asset-safeguarding regime. Fourth, the AML/CFT perimeter: all FATF-aligned jurisdictions require the project to implement a know-your-customer and transaction-monitoring program from day one, and the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary data with each transfer above the applicable threshold – applies to any qualifying transfer.

Projects with a cross-border investor base face the compounded licensing question: a token available to EU, Singapore, and UAE investors simultaneously may trigger obligations under MiCA, MAS requirements, and the VARA rulebooks in parallel. Regulatory arbitrage – selecting the most permissive jurisdiction and relying solely on that regime – carries material risk if the token is substantively offered into a stricter hub.

In our practice, we regularly advise on mapping the licence stack before the offering document is drafted. Retrofitting a licence structure after the token is live is materially more expensive and, in some cases, requires unwinding transactions.

For a scoped licensing assessment of your tokenization project, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your specific asset class, investor base, and platform design will change the analysis.

How Does Property Law Treat a Tokenized Asset?

Property law – specifically, whether a token constitutes or represents a recognizable property right – is the foundation of every downstream legal question: can a token be pledged as collateral? Can a court freeze it? Can a trustee in bankruptcy claim it? Can a defrauded investor trace and recover it?

Courts in the most active common-law forums have progressively confirmed that digital assets can constitute property. In England and Wales, AA v Persons Unknown [2019] established that cryptoassets are property capable of being the subject of a proprietary injunction. Subsequent decisions have built on that foundation. In Hong Kong, Re Gatecoin [2023] HKCFI 914 confirmed that cryptocurrency held by an exchange constitutes property of the exchange's estate for insolvency purposes. Singapore's High Court, in CLM v CLN [2022] SGHC 46, granted a proprietary injunction over misappropriated cryptocurrency.

For a tokenized real-world asset, the property analysis has an additional layer: what is the legal relationship between the token and the underlying asset? Three structures are commonly used, and each produces a different property analysis.

The first is a direct-claim structure, in which the token constitutes or evidences a direct legal or beneficial ownership interest in the underlying asset, typically held through a special-purpose vehicle. The holder's rights against the SPV are the asset. The token is the register of that claim. This structure gives the strongest property basis but requires the most regulatory infrastructure – the SPV must be properly constituted, the chain of title must be clean, and the register must be legally recognized in the jurisdiction of the underlying asset.

The second is a contractual-claim structure, in which the token holder has a contractual right against the issuer – typically a right to receive economic return linked to the underlying asset's performance. The token is not property in the underlying asset; it is a contract right. This structure is simpler to implement but creates credit exposure to the issuer and does not survive the issuer's insolvency in the same way a direct claim might.

The third is a hybrid structure – a contractual claim combined with security interest over the underlying asset or over the SPV that holds it. This is common in tokenized debt instruments, where the token represents a debt obligation and the holder holds a charge over the underlying collateral.

The choice of structure determines not just the investor's rights but the applicable regulatory regime, the insolvency treatment, and the enforceability of the instrument in the courts of the relevant jurisdictions. We have seen projects select a structure primarily for its marketing simplicity, only to discover that the chosen structure is unenforceable in the jurisdiction where the underlying asset is located.

A smart contract is a program that executes automatically when defined conditions are met; it is not, by that fact alone, a legally enforceable contract. The legal risk in relying on smart-contract execution for a real-world asset tokenization project is material and multi-layered.

The first question is whether the smart contract constitutes a binding legal agreement. In most common-law and civil-law systems, a contract requires offer, acceptance, consideration, and the intention to create legal relations. A smart contract deployed on a public blockchain satisfies some of these elements but not necessarily all of them. The more significant the off-chain performance obligation – for example, delivery of title to real property, payment of a rental income stream, or redemption of a tokenized bond – the more important it is that the smart contract is supported by a signed, off-chain legal agreement that a court can enforce.

The second question is liability when the smart contract executes incorrectly. A bug in the contract code may cause it to execute in a way the parties did not intend. A market manipulation may cause a price oracle to feed incorrect data, triggering a liquidation that should not have occurred. In neither case does the smart contract's immutability protect the issuer from legal liability. The issuer and the platform operator remain liable in tort and contract for losses caused by negligent deployment or inadequate disclosure of risks.

The third question is governance. Many tokenized asset projects vest amendment authority over the smart contract in a DAO (decentralized autonomous organization) – a structure in which token holders vote on protocol changes. A DAO is not a legal person in most jurisdictions. Its decisions are not legally binding in the way that board resolutions are. When a DAO votes to change the parameters of a tokenized-asset contract in a way that harms certain holders, the legal question of who bears liability for that decision is unsettled in most forums.

In our technology and DeFi practice, we regularly advise issuers to pair every material smart-contract mechanism with a corresponding off-chain legal document: a terms-of-service agreement, a subscription agreement, an investor-rights deed, or a loan note instrument. The smart contract executes the economics; the legal document governs the relationship. Both are necessary.

The cross-border structure of most real-world asset tokenization projects creates legal pressure points that do not arise in single-jurisdiction deals. The issuer may be incorporated in one jurisdiction, the underlying asset may be located in another, the trading platform may be licensed in a third, the investors may be distributed across many more, and the smart contract may be deployed on a globally distributed blockchain that belongs to none of them.

The first pressure point is conflict of laws: which jurisdiction's law governs the token, the claim it represents, and the dispute that arises when the project fails? Without a clear governing-law clause in the off-chain legal documents, different forums may apply different laws, producing inconsistent results. A token holder in France may assert rights under French law that the issuer in the BVI thought were governed by BVI law.

The second pressure point is regulatory reach. A token offered globally may be offered to residents of jurisdictions where the issuer has no presence and no licence. The offer itself – the publication of a whitepaper, the distribution of marketing material, the listing on an exchange – may constitute a regulated activity in the investor's jurisdiction, even if the issuer did not intend to reach that market. MiCA's territorial scope, for instance, extends to offers directed at EU investors regardless of where the issuer is established.

The third pressure point is tax. The tokenization of an asset does not eliminate the asset's tax character. A tokenized real-estate interest may trigger stamp duty or transfer tax on each transfer of the token, depending on the jurisdiction. A tokenized fund unit may give rise to withholding tax obligations. These obligations often fall on the platform or the custodian as well as the issuer, and they must be mapped before the project launches.

The fourth pressure point is AML/CFT. The Travel Rule applies to transfers of tokenized assets in most FATF-aligned jurisdictions above the applicable threshold. If the platform does not have the technical infrastructure to collect and transmit originator and beneficiary data, it is operating outside the AML regime even if it holds a valid VASP licence. We have seen projects with impeccable licence stacks that remain materially non-compliant because the Travel Rule infrastructure was not built into the platform from the outset.

Decision Matrix: Which Structure for Which Profile?

Different operator profiles require different approaches to the legal stack. The matrix below maps the most common profiles to the indicated structure, the indicative timeline to operational readiness, and the primary legal risk. All timelines are qualitative; specific jurisdiction timelines depend on regulatory backlog and the completeness of the application.

Profile A – Tokenized real estate (direct claim, single jurisdiction): the indicated structure is a licensed SPV holding the property, with tokens constituting beneficial ownership units issued under the applicable securities or collective investment scheme regime. The primary legal risk is title-chain fragility – any defect in the property's title propagates directly to the token. Operational readiness is typically measured in months, driven by property due diligence and regulatory approval timelines.

Profile B – Tokenized debt instrument (contractual claim, cross-border investor base): the indicated structure is a loan note or bond issued by a licensed special-purpose entity, with tokens as the register of noteholder positions. The primary legal risk is governing-law uncertainty and the issuer insolvency question. Operational readiness depends on the prospectus or offering-memorandum approval in the primary listing jurisdiction and on the assessment of exemptions in each investor jurisdiction.

Profile C – Tokenized fund unit (collective investment scheme, institutional investors): the indicated structure is a regulated fund vehicle – Cayman limited partnership, BVI segregated portfolio company, or equivalent – with tokens representing limited-partner or share interests. The primary legal risk is fund-law characterization; many jurisdictions require fund-manager authorization in addition to any VASP or CASP licence. Operational readiness is typically among the longer paths, given the dual regulatory track.

Profile D – Tokenized commodity or revenue stream (hybrid, DeFi-integrated): the indicated structure is a hybrid legal instrument combining a contractual right in the revenue stream with a security interest over the underlying commodity or cash flows, governed by an explicit off-chain agreement and tracked on-chain. The primary legal risk is oracle reliance – the smart contract's performance is only as accurate as the price feed it uses. DAO governance adds further complexity around liability allocation.

No structure suits all profiles. The matrix above is a starting point. A business-specific analysis requires mapping the asset, the investor base, the platform design, and the jurisdictions of the underlying asset and the issuer's entity before settling on a structure.

If your project sits between two of these profiles or involves an asset class not listed here, a structural memo is the most efficient first step. Write to OBOLUS at info@oboluslaw.com. If a prior structuring attempt has stalled or a regulator has raised concerns, a second read can often surface the specific issue.

Objection Handler: The Utility-Label Myth

A common assumption in the tokenization market is that labeling a token "utility" in the whitepaper settles its legal classification. It does not. Regulators and courts assess the economic substance of the instrument, not the marketing terminology applied to it.

The functional tests vary by jurisdiction, but the core questions are consistent: does the token give its holder a right to economic return derived from the efforts of a third party? Is there a reasonable expectation of profit from holding or transferring the token? Are the holders pooling capital in a common enterprise? If the answers are affirmative, the token is likely a security or a collective investment scheme interest regardless of what the whitepaper calls it.

ESMA and national competent authorities under MiCA have been clear that the "other crypto-assets" category – which most utility tokens occupy – does not exempt the issuer from the whitepaper obligation and the applicable conduct requirements. Tokens that cross the line into financial instruments fall into the full securities regime, with or without a utility label.

The NYDFS BitLicense regime, the FCA's financial-promotion rules, and Singapore's MAS framework all apply the same substance-over-label approach. A utility label that is incorrect exposes the issuer to enforcement for operating an unregistered securities offering, for conducting unauthorized financial-promotion activity, and – if AML obligations were thereby circumvented – for AML violations as well.

We assess classification against the substance of the rights the token confers. That analysis is the document that goes in front of the regulator, not the marketing deck.

Micro-Matter: Tokenized Receivables, Cross-Border Recovery

In a recent matter, a fintech operator had tokenized a portfolio of trade receivables through an offshore SPV, with token holders holding contractual rights against the SPV. When the originator of the receivables defaulted, the SPV's assets were effectively frozen in a dispute between the originator's insolvency administrator and the token holders. We were retained to advise on the cross-border enforcement position.

The central legal question was whether the token holders held a proprietary claim in the receivables or merely a contractual claim against the SPV. The off-chain documentation – prepared before our involvement – was ambiguous on this point. We structured a position that the token holders held a beneficial interest in the receivables through the SPV's trust-like obligations under the governing law of the SPV's jurisdiction, and we engaged allied counsel in the relevant common-law forum to seek a disclosure order against the insolvency administrator.

The matter resolved, in the second quarter following our engagement, with the token holders recognized as secured creditors holding enforceable claims ahead of unsecured creditors. The resolution turned entirely on the off-chain legal documentation and the choice of governing law – not on the smart contract. The token was the register; the legal instrument was the source of the right.

The lesson for issuers is direct: the off-chain legal documentation is not a formality. It is the asset.

Self-Assessment Checklist for RWA Tokenization

Before committing to a technical build, operators should be able to answer each of the following questions clearly. A "no" or "uncertain" response on any item is a signal to engage legal counsel before proceeding.

  • Has the token been classified against the securities, collective investment scheme, and payment-instrument tests in each jurisdiction where it will be offered or traded?
  • Is the off-chain legal instrument (subscription agreement, loan note, trust deed, or equivalent) drafted and jurisdiction-tested before the smart contract is deployed?
  • Has the chain of title from the underlying asset to the SPV to the token been verified by counsel in the jurisdiction where the asset is located?
  • Does the project hold, or have a clear path to, the required licences in each operating jurisdiction – including the issuance, trading, custody, and AML perimeters?
  • Is the Travel Rule infrastructure in place, or is the project relying on a platform that has confirmed its own Travel Rule compliance?
  • Has the governing-law and dispute-resolution mechanism been specified in the off-chain documents, and does the chosen forum have a developed body of law on digital-asset property rights?
  • Has the tax treatment of token transfers been assessed in the issuer's jurisdiction and in the primary investor jurisdictions?
  • Is the DAO governance mechanism – if any – accompanied by a legal wrapper that allocates liability for governance decisions?

Projects that can answer all eight questions affirmatively are in a substantially better position at the regulatory review and investor due-diligence stages than those that cannot.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. A DeFi protocol can be subject to regulation wherever it constitutes a regulated activity – operating an exchange, providing custody, facilitating payments, or issuing a financial instrument. Regulators including ESMA, MAS, and the SFC assess the economic function of the protocol, not its technical architecture. Decentralization reduces but does not eliminate the risk: if identifiable persons deploy, control, or profit from the protocol, those persons may be subject to the applicable regime.

What legal wrapper suits a DAO?

No single wrapper suits every DAO. The most commonly used structures are the Wyoming DAO LLC (a US statutory form), a Marshall Islands DAO LLC, a Cayman Islands foundation company, and a BVI company with token-holder governance provisions. The choice depends on the DAO's function, the jurisdictions of its members, its tax obligations, and whether it needs to hold assets or enter contracts. Each wrapper has trade-offs in member liability, regulatory treatment, and legal recognition across forums.

Who is liable when a smart contract fails?

Liability when a smart contract executes incorrectly depends on the facts. Developers may face tort liability for negligent code. Issuers and platform operators may face contractual liability if the contract failed to perform as disclosed. DAO governance bodies – or identifiable participants who voted on a flawed upgrade – may bear liability under negligence or other applicable theories. Smart-contract immutability is a technical fact, not a legal defense. Off-chain legal agreements and adequate risk disclosure significantly affect the liability analysis.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, DeFi protocols and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice. We assess classification against the substance of rights, not the marketing label – because the label a whitepaper applies to a token has never settled a regulatory inquiry. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology and DeFi Counsel – specializing in smart-contract legal architecture, token classification, and cross-border structuring for real-world asset tokenization projects.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours