Staking-as-a-service – the practice of a third party operating validator infrastructure on behalf of token holders – sits at one of the most contested intersections in digital-asset regulation. As proof-of-stake networks mature and institutional demand for yield grows, operators are discovering that the legal question is not simply "do we need a licence?" but rather "which of the four or five overlapping regimes applies, and in which of the jurisdictions where our users sit?" The answer turns on technical architecture, contractual structure and the specific rights a participant receives – not on a product label.
This analysis maps the regulatory positions that leading hubs are converging on, identifies the liability fault lines that smart-contract architecture creates, and provides a decision framework for operators assessing their exposure before a regulator does it for them.
What Is Staking-as-a-Service, and Why Does the Architecture Matter?
Staking-as-a-service describes a business model in which an operator – the service provider – accepts tokens from a customer, delegates or directly stakes those tokens to a validator node, and returns staking rewards net of a fee. The legal characterisation of that arrangement depends almost entirely on what the operator controls, what rights the customer retains and how rewards are generated and distributed.
Three architectural variants produce materially different regulatory profiles. In non-custodial delegation, the customer retains ownership of the private key; the operator controls only the validator signing key. In custodial staking, the operator holds the private key and the customer holds a contractual claim. In liquid staking, the customer receives a derivative token – a receipt instrument representing the staked position – that may itself be tradeable. Each variant raises a distinct set of classification questions: is this custody? Is the derivative token a security, an asset-referenced token or an e-money token? Does the yield component constitute a collective investment scheme?
In our practice, we regularly advise infrastructure operators who underestimate how sharply these distinctions move the regulatory dial. A business that structures its service as non-custodial delegation in one jurisdiction may find that a second jurisdiction's regulator reads the economic substance differently – particularly where the operator exercises discretion over validator selection, slashing risk mitigation or reward compounding.
The liquid staking derivative – a receipt token representing a staked position – is the single architectural choice that most frequently triggers securities analysis across the major hubs. Regulators examine whether the token confers a right to participate in a pool of assets managed by a third party for profit.
How Does MiCA Classify Staking Services, and What Does That Mean for EU Operators?
Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised at the pan-European level by ESMA and implemented by national competent authorities – staking-as-a-service does not fall cleanly into a single licence category, and that ambiguity is itself the problem. The regulation's primary licensing track, the CASP (crypto-asset service provider) authorisation, covers a defined list of activities: exchange, brokerage, custody, transfer and portfolio management of crypto-assets. Pure proof-of-stake validation is not listed as a regulated activity. But the characterisation changes the moment the service provider exercises custody, manages a discretionary pool or issues a receipt token.
Custodial staking – where the operator holds the private key – falls within the custody-of-crypto-assets activity under MiCA, requiring CASP authorisation with the attendant capital and safeguarding obligations. ESMA has signalled, in its published guidance on staking, that activities involving discretionary management of customer assets in a pooled structure may additionally engage the portfolio-management activity category. A CASP authorisation in one EU member state carries passporting rights across the full EU/EEA, which is significant for operators seeking continental reach from a single licence.
The liquid staking derivative is the harder question. If the receipt token qualifies as an asset-referenced token (ART) or e-money token (EMT) under MiCA, the issuer faces a separate, more demanding authorisation track. If it is classified as a security under member-state law – which remains possible where MiCA does not displace national securities regimes for instruments that qualify as financial instruments – the operator faces an entirely different regulatory regime. The interplay between MiCA and national transpositions of the EU Markets in Financial Instruments framework creates a classification gap that operators should map before launch.
A CASP authorisation is required where an EU-facing staking operator exercises custody of customer tokens, regardless of how the service is branded or whether the primary business is marketed as infrastructure rather than financial services.
VARA and ADGM: How Do the UAE Hubs Approach Staking?
The UAE presents two distinct regulatory perimeters. In Dubai, the Virtual Assets Regulatory Authority (VARA) operates an activity-based licence regime that covers, among others, custody, exchange and the management and investment of virtual assets. VARA's rulebooks treat the holding of customer virtual assets – including for staking purposes – as a custody activity requiring a licence. An operator running custodial staking from mainland Dubai requires VARA authorisation; operating without it exposes the business to enforcement action under the applicable VARA regime.
In Abu Dhabi, the Financial Services Regulatory Authority (FSRA) within the Abu Dhabi Global Market (ADGM) regulates virtual-asset activity under its own framework. The FSRA's recognised virtual assets concept and its regulated-activity definitions create a similar result: operating a staking service that involves holding or managing customer assets is a regulated activity requiring FSRA authorisation. ADGM's common-law foundation means that contractual and liability analysis runs on familiar principles – a point that matters when structuring the service agreement governing slashing risk.
The cross-border angle for Gulf-based operators is acute. A Dubai or Abu Dhabi entity whose validator nodes are operated by allied infrastructure in a third country – a common deployment pattern – must trace whether that third-country operation independently triggers regulatory obligations. Operators we advise routinely underestimate how quickly a global validator deployment creates multi-jurisdictional exposure.
Is a Staking Service a Securities Offering? The US and Hong Kong Positions
The United States presents the sharpest enforcement risk for staking operators. The SEC has taken the position – in public statements and in enforcement proceedings against centralised exchanges offering staking programs – that pooled staking arrangements can constitute the offer and sale of investment contracts under US federal securities law. The analytical framework applied is the substance-over-form test: whether customers invest money in a common enterprise and expect profits primarily from the efforts of others. A custodial, pooled staking service with discretionary management by the operator will frequently satisfy this test.
The SEC and CFTC maintain overlapping jurisdictional claims over different aspects of digital-asset activity. The FinCEN money-services-business framework and state money-transmitter licensing regimes add further layers. An operator with US-connected users – even without a US entity – must assess whether its service falls within the reach of federal securities law, and whether the NYDFS BitLicense regime applies to New York users. The analysis is jurisdiction-specific and fact-intensive. We have seen operators assume that a non-US domicile insulates them; it does not, where the economic exposure is US-facing.
In Hong Kong, the Securities and Futures Commission (SFC) has extended its VASP licensing regime to virtual-asset trading platforms, and its published guidance makes clear that staking offered as a service on a licensed platform requires careful treatment. Where the staking arrangement involves the pooling of customer assets managed by a third party for profit, the SFC's analysis of whether the arrangement constitutes a collective investment scheme is directly relevant.
A pooled, custodial staking service in which the operator exercises material discretion over how staked assets are managed is the profile most likely to attract securities or collective-investment-scheme analysis across the major enforcement hubs.
The process above describes the standard classification paths. Your facts – the entity structure, the user base, the degree of operator discretion – change the analysis substantially. For a scoped classification assessment of your staking architecture, contact OBOLUS at info@oboluslaw.com.
Smart-Contract Liability: Where Does the Risk Sit When Something Goes Wrong?
Staking-as-a-service typically runs on or interacts with smart contracts – self-executing code deployed on a blockchain that governs delegation, reward distribution and, in the liquid staking context, the minting and redemption of derivative tokens. When a smart contract fails, the liability question is: who bears the loss, and under what legal theory?
The answer depends on how the service is structured contractually and how the smart contract is presented to users. Where the operator publishes a smart contract as the mechanism of service delivery, courts applying a common-law analysis will examine whether the operator made a representation – express or implied – about the contract's behaviour, and whether a duty of care was owed to users who relied on it. The applicable law will turn on which jurisdiction's rules govern the service agreement, a question that the operator's terms of service can address but cannot resolve unilaterally if those terms are not enforceable in the user's home jurisdiction.
Slashing risk is the concrete form of smart-contract-adjacent liability in staking. A validator that behaves incorrectly – double-signing, for instance – can have a portion of the staked assets destroyed by the protocol. Whether the service provider bears that loss, passes it to the customer or shares it through an insurance mechanism is a matter of contract. Most bespoke staking agreements in institutional contexts allocate slashing risk explicitly. Consumer-facing services often do not, or do so in fine print that may not satisfy regulatory disclosure requirements.
In a recent matter, an institutional staking operator experienced a slashing event affecting a client pool following an infrastructure failure at a third-party validator. The client's contract was silent on the allocation of slashing losses beyond a general disclaimer. We advised on the operator's exposure under the applicable service agreement, the regulatory disclosure obligations that attached, and the contractual amendment required to prevent recurrence. The matter resolved without litigation, but the lesson is that slashing is not a hypothetical: it is a scheduled risk that the service documentation must address before the validator goes live.
AML, the Travel Rule, and KYC: Do Staking Operators Have Compliance Obligations?
Whether a staking-as-a-service operator has anti-money-laundering and know-your-customer obligations depends on whether the operator qualifies as a regulated entity under the applicable national AML/CFT regime – which, in most major hubs, traces back to the FATF Recommendations (the Financial Action Task Force's global standards), including Recommendation 15 on virtual assets.
Under the FATF framework, a business that provides virtual-asset services – including the transfer or safekeeping of virtual assets – is a VASP (virtual asset service provider) and is subject to AML/CFT obligations. A custodial staking operator that accepts tokens, holds private keys and distributes rewards will generally qualify as a VASP in FATF-aligned jurisdictions, including the EU under MiCA, the UK under the Money Laundering Regulations supervised by the FCA, Singapore under the Payment Services Act supervised by MAS, and the UAE under the VARA and FSRA regimes.
The Travel Rule – the obligation to pass originator and beneficiary information alongside a virtual-asset transfer – applies to VASPs in most major jurisdictions above a prescribed threshold. The threshold varies by jurisdiction and is a [VERIFY] figure in each case; operators should confirm the current local de-minimis level before assuming the obligation does not apply to their transfer volumes. In practice, a staking operator that moves customer tokens between wallets as part of the delegation or reward-distribution process may trigger Travel Rule obligations on those transfers.
Non-custodial staking – where the customer retains the private key throughout – presents a lighter AML profile, though not a clean one. The operator may still be providing a service that qualifies as a virtual-asset service under the applicable definition, depending on the jurisdiction and the degree of ongoing operational involvement.
Decision Matrix: Which Operator Profile Carries Which Regulatory Risk?
Staking operators do not face a single regulatory risk profile. The exposure is a function of five variables: custody model, pooling structure, derivative issuance, geographic reach and the degree of discretionary management. The following matrix maps three representative profiles to the primary regulatory exposure they carry.
Profile A – Infrastructure-only, non-custodial. The operator provides validator node infrastructure. The customer retains the private key and delegates the signing key only. No pooling, no derivative token. This profile carries the lowest regulatory exposure in most jurisdictions: the operator is unlikely to qualify as a VASP solely on the basis of running a validator, though specific jurisdictions may have broader definitions. The primary risk is in the service agreement: slashing liability and uptime obligations must be addressed contractually. The indicative timeline for a legal assessment of this profile is a matter of weeks. The key residual risk is that users in certain jurisdictions – particularly the US – may still argue an investment contract analysis applies if the operator is marketing yield to retail participants.
Profile B – Custodial pooled staking, no derivative token. The operator holds customer private keys and pools assets across multiple validators. Rewards are distributed net of fees. This profile triggers VASP and custody-activity obligations in the EU (MiCA CASP authorisation), UAE (VARA or FSRA licence), Singapore (MAS Payment Services Act licence) and UK (FCA MLR registration at minimum). The US analysis is hostile without careful structuring. The indicative path to regulatory compliance in a primary hub is several months of application preparation, followed by a formal review period that varies by regulator. The key risk is operating during the gap between launch and authorisation.
Profile C – Liquid staking with derivative token issuance. The operator runs a custodial pool and issues a receipt token redeemable for staked assets plus accrued rewards. This profile carries the most complex regulatory exposure. The derivative token may be classified as an ART or EMT under MiCA (requiring a separate issuer authorisation), as a security under US federal law or Hong Kong securities regulation, or as a collective investment scheme instrument in multiple jurisdictions. The application process is longer, the capital requirements are higher, and the ongoing compliance burden is substantially greater. Operators in this profile require pre-launch legal assessment, not post-launch remediation.
If a prior regulatory filing stalled or an account relationship was closed because of an unresolved classification question, a second read frequently surfaces the structural cause and the route to resolution. Contact OBOLUS at info@oboluslaw.com to map your current position.
A Common Assumption: "Our Tokens Are Utility Tokens, So We Are Not Regulated"
The most persistent misconception we encounter is that a utility label on a whitepaper or a terms of service resolves the legal classification of a token or a staking arrangement. It does not. Regulators across every major hub apply a substance-over-form analysis: the legal classification turns on the rights the token actually confers and the economic reality of the arrangement, not the label the issuer has chosen.
A staking receipt token that entitles the holder to a proportionate share of pooled rewards, generated through the operator's ongoing management of validator infrastructure, will be examined against the investment-contract test (in the US), the financial-instrument test (in the EU and UK), and the collective-investment-scheme test (in Singapore, Hong Kong and the UAE) regardless of whether the whitepaper calls it a utility token, a governance token or a protocol token. The label may be relevant to the inquiry – it is one piece of evidence – but it is not determinative.
We assess classification against the substance of rights conferred, not the marketing description. That assessment must happen before product launch, not in response to a regulatory inquiry. The cost of a pre-launch classification analysis is a fraction of the cost of an enforcement response or a product restructure after launch.
A related misconception is that operating from an offshore jurisdiction – a BVI holding company, a Cayman Islands fund vehicle – insulates the staking operator from the regulatory reach of the US, the EU or the UAE. It does not, where the service is marketed to users in those jurisdictions. Most major regulatory regimes extend to conduct directed at their markets regardless of where the operator entity is domiciled. The BVI FSC and CIMA each operate VASP registration frameworks that apply within their own perimeters, but registration in the BVI does not satisfy MiCA, VARA or SEC requirements for services directed at those markets.
Cross-Border Stacking: Managing the Multi-Jurisdiction Reality
A staking operator headquartered in one jurisdiction, with validators in a second, serving users in a third, and banking through a fourth, faces a regulatory stack that no single jurisdiction's law resolves. This is the structural reality of staking-as-a-service at any scale, and it is the primary reason why legal analysis must begin with the full entity map rather than with the domicile of the operating company.
The cross-border interactions that we see most frequently in our practice involve three patterns. First, an EU-facing operator domiciled outside the EU – typically in an offshore or Commonwealth jurisdiction – that discovers MiCA applies to its activities by reason of its user base, not its incorporation. Second, a VARA-licensed Dubai entity whose validator infrastructure is operated by a third-party provider in Eastern Europe or Southeast Asia, creating a chain-of-responsibility question under VARA's outsourcing rules. Third, a US-connected operator that has structured its holding company offshore to avoid US securities analysis but has not adequately restricted access by US persons, leaving the economic exposure intact.
In each pattern, the solution requires a combination of entity structuring, jurisdictional licence sequencing and contractual allocation of regulatory responsibility between the operator and its infrastructure partners. Where the operator cannot independently cover all relevant jurisdictions, allied counsel in the relevant jurisdiction provides the on-the-ground regulatory relationship and the local-law analysis. The sequencing of licences – which hub to authorise first, which to passport from – is itself a strategic decision with cost, timing and operational implications.
Banking is a parallel constraint. Staking operators regularly report difficulty maintaining fiat banking relationships, particularly for reward payouts and fee collections. The banking analysis is inseparable from the licensing analysis: a bank will typically require evidence of regulatory status in the jurisdiction from which the account is operated. An operator that has not obtained the appropriate licence in its banking jurisdiction will face account closures regardless of its compliance posture elsewhere.
Related at OBOLUS
- DeFi, Tokenization and Smart-Contract Law – the full practice overview for technology-forward digital-asset businesses
- Oracle and Data-Feed Liability – cross-border liability analysis for smart-contract data dependencies
- Digital-Asset Custody Authorisation in ADGM – FSRA licensing for custody and related virtual-asset activities
FAQ
Can a DeFi protocol be regulated?
A DeFi protocol can be subject to regulatory obligations where the entity or persons who deploy, operate or control it qualify as a VASP or regulated service provider under the applicable regime. Regulators in the EU, US, Singapore and UAE focus on the degree of centralised control or profit extraction. A fully autonomous protocol with no identifiable operator presents a harder regulatory target, but most commercial DeFi deployments involve an operator with sufficient control to attract regulatory scrutiny. The analysis is fact-specific and jurisdiction-by-jurisdiction.
What legal wrapper suits a DAO?
A decentralized autonomous organization (DAO) can be structured through several legal vehicles: a Marshall Islands DAO LLC, a Wyoming DAO LLC, a Cayman Islands foundation company, a BVI company or a Swiss association are the most commonly used forms. The appropriate wrapper depends on the DAO's activities, the jurisdictions in which it operates, the nature of its token governance and its regulatory risk profile. A wrapper that limits member liability and supports contractual capacity is typically the starting point; the tax and compliance overlay shapes the final selection.
Who is liable when a smart contract fails?
Liability for a smart-contract failure turns on the contractual relationship between the deployer or operator and the user, the applicable law governing that relationship, and whether a duty of care exists in tort. Where the operator presented the smart contract as a service – not merely open-source code – courts applying common-law principles will examine representations made about its behaviour and the foreseeability of the loss. In practice, slashing events, oracle failures and code exploits are the most frequent sources of dispute; a well-drafted service agreement allocates these risks explicitly rather than leaving them to general law.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that surround them. Digital assets are the whole of our practice. We assess classification against the substance of rights conferred, not the marketing label – because a mis-classification can convert a product launch into an unregistered securities offering. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology and DeFi Counsel – specialising in smart-contract liability, token classification and the regulatory treatment of DeFi and staking infrastructure across multiple jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.