EST · MMXXVI
Home/Jurisdictions/Compare/Security Token vs Utility Token: Legal Lines
Token Offerings & Securities

Security Token vs Utility Token: Legal Lines

Security Token vs Utility Token: Legal Lines. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Mis-classifying a token can convert a product launch into an unregistered securities offering — exposing the issuer to enforcement action, civil liability, and the prospect of rescission demands from every token purchaser. The legal boundary between a security token (a digital asset conferring rights analogous to equity, debt, or a collective investment scheme) and a utility token (a digital asset granting access to a product or service) is not settled by what an issuer calls the instrument. It is settled by the substance of the rights the instrument confers, assessed under the applicable regulatory regime. Across the leading digital-asset hubs — the EU under MiCA, Dubai under VARA, Singapore under the Payment Services Act, and the US under SEC and CFTC supervision — classification turns on the same underlying question, framed differently by each regime. This analysis maps those differences, identifies the decision axes that matter, and explains why the cross-border angle changes everything.

Why Token Classification Matters Before You Launch

Getting the classification wrong at the point of offering is not a correctable clerical error — it is a founding defect that follows the instrument through its entire lifecycle. An offering that should have been registered or prospectus-disclosed, but was not, triggers liability under securities law in most major jurisdictions regardless of how the issuer described the token. Regulators in the US, the UK, Singapore, and the EU have each taken enforcement positions on tokens originally marketed as utility instruments but found on examination to carry investment characteristics. The cost of a mis-classification is not limited to regulatory fines. It extends to rescission rights for purchasers, private litigation, and in some regimes, criminal exposure for officers who authorised the offering.

In our practice, the most common moment of crisis is not launch day. It is the point, often months later, when a secondary market develops, trading volume attracts regulatory attention, and the issuer discovers that the contemporaneous legal opinion was too narrow — it addressed one jurisdiction but the token had been purchased across fifteen. A correct classification exercise must address every jurisdiction in which the token is offered, marketed, or accessible to purchasers. That is the cross-border reality of public token sales.

Operators we advise routinely underestimate the reach of US securities law in particular. The SEC's long-arm approach to tokens distributed to US persons — even where the issuer is incorporated elsewhere and the sale is nominally offshore — means that a classification decision made in Zug or Dubai can still be tested against the Howey test.

If you are approaching a token launch and the classification question is still open, contact OBOLUS at info@oboluslaw.com before the whitepaper is finalised. The process above describes the standard analytical path. Your token design — the rights it confers, the economics it embeds, the jurisdictions it touches — changes the analysis materially.

The Five Decision Axes: How Regulators Draw the Line

Across every major regulatory regime, classification turns on the same five substantive questions — but the weight each regime places on each question, and the legal consequence that follows, differs. Working through these axes in sequence is the practical methodology for any serious classification exercise.

Axis 1: Investment of money or money's worth. Does the purchaser exchange value — fiat, cryptocurrency, or another digital asset — for the token? If so, the first limb of an investment-contract analysis is typically satisfied. A token given freely, with no monetary exchange and no expectation of economic return, is a weaker candidate for security status — but a free distribution (an airdrop, for example) does not automatically resolve the question. The Travel Rule (the obligation to pass originator and beneficiary data with a transfer) and AML obligations may still apply regardless of classification.

Axis 2: Common enterprise. Are the returns of the purchaser tied to the fortunes of a common pool, managed by the issuer or a third party? Token holders who share proportionally in a treasury, a staking yield pool, or issuer revenues are more likely to be participants in a common enterprise. Governance tokens that confer genuine, immediate voting rights over a fully operational protocol present a harder case — but "governance" rights that are nominal, illusory, or contingent on a future launch do not insulate the token.

Axis 3: Expectation of profit derived from others' efforts. This is the axis most frequently mis-assessed. The question is not whether the purchaser hopes the token appreciates. It is whether the expectation of profit is derived primarily from the entrepreneurial or managerial efforts of the issuer or a promoter, rather than from the purchaser's own use of the token. Where the token's primary value proposition at the point of sale is secondary market appreciation — not present utility — this axis typically points toward security classification.

Axis 4: Present consumability. Can the purchaser use the token for its stated function today, on a live, operational network? A token sold before the network is built, or before the product is accessible, is far more likely to be classified as a security in the US, and as a financial instrument under MiCA, than a token that is genuinely redeemable for a service at point of sale. ESMA and the relevant national competent authorities assess this as part of the MiCA whitepaper sufficiency review. Under MiCA, asset-referenced tokens (ARTs) and e-money tokens (EMTs) carry their own issuer-authorisation requirements distinct from the security analysis.

Axis 5: Issuer communications and marketing. Secondary market listings, price-appreciation messaging, and comparisons to investment returns are not legally irrelevant after the fact. Regulators treat contemporaneous communications — social media posts, Telegram announcements, roadshow materials — as evidence of the issuer's own understanding of what the instrument is and who it is being sold to. A utility label in the whitepaper that contradicts six months of "ROI" messaging from the founding team is not persuasive. We assess classification against the substance of rights and the totality of the record, not the marketing label.

How Does the US Howey Test Apply to Digital Tokens?

The Howey test (the four-prong US Supreme Court framework for identifying an investment contract, and therefore a security) remains the primary analytical tool applied by the SEC to digital assets, and understanding it is essential for any issuer with US-person exposure — which, in practice, means almost every issuer offering a publicly tradeable token. The test asks whether there is an investment of money in a common enterprise with an expectation of profit from the efforts of others. All four prongs must be satisfied; an issuer that can credibly demonstrate that the profit expectation does not arise from others' efforts has a stronger case for non-security status.

The SEC's enforcement record makes clear that the agency applies the test to the economic reality of the instrument at the time of the original offering, not to its eventual use. A token sold on the promise of a future network, with value tied to the issuer's development roadmap, is highly likely to satisfy all four prongs — even if, years later, the same token operates as a genuine access credential. The transformation from security to utility is not automatic. It requires a separate, affirmative analysis, and in the US context, formal guidance or a no-action framework.

The CFTC's parallel jurisdiction over commodity instruments adds a further layer. Tokens that are not securities under Howey may still be regulated as commodities, bringing CFTC registration and margin-trading rules into scope. US token issuers and exchanges face a dual-regulator environment that is not replicated in the same form anywhere else in the world.

MiCA's Token Categories: Where Does Your Token Land?

Under MiCA — the EU regulation supervised by ESMA and national competent authorities — the classification question is answered by a distinct taxonomy that runs parallel to, but does not exactly replicate, the securities-law analysis. MiCA establishes three categories: asset-referenced tokens, e-money tokens, and "other crypto-assets." The first two carry specific issuer-authorisation requirements. The third category — which captures most utility and governance tokens — is subject to whitepaper and marketing obligations but does not require authorisation to issue.

Critically, MiCA does not govern tokens that qualify as financial instruments under MiFID II. A token that satisfies the MiFID II definition of a transferable security, a unit in a collective investment undertaking, or a derivative falls outside MiCA entirely and into the existing EU securities regime. The classification step under MiCA is therefore bifurcated: first, ask whether the token is a MiFID II financial instrument; if yes, MiCA does not apply; if no, apply MiCA's own taxonomy to determine which category the token falls into.

For issuers targeting the EU market, the practical consequence is significant. A token wrongly classified as "other crypto-assets" — and therefore governed only by the lighter-touch MiCA whitepaper rules — that is later found to be a MiFID II financial instrument has been offered without a prospectus in a public offering. The liability exposure mirrors a mis-registered securities offering in any other jurisdiction.

Passporting under MiCA means that a CASP (crypto-asset service provider) authorised in one EU or EEA member state may provide services across the bloc. That is a material commercial advantage — but it does not resolve the token-classification question. Classification must be completed before the whitepaper is filed and the passport is invoked.

How Do VARA, ADGM, and Singapore Approach Classification?

Outside the EU and the US, the three most operationally significant digital-asset regimes each take a recognisable but distinct approach to the security-versus-utility question, and each has implications for issuers structuring a multi-jurisdictional offering.

VARA (Dubai). The VARA regime — which governs virtual assets in mainland Dubai, excluding the DIFC financial free zone — is activity-based rather than instrument-based. VARA issues licences by activity (advisory, exchange, custody, lending, and others), and its rulebooks address the conduct of those activities. Classification of a specific token as a security sits primarily with the SCA (Securities and Commodities Authority) rather than VARA; issuers structuring a Dubai-based offering must assess both regulatory perimeters. ADGM's FSRA, operating in the Abu Dhabi free zone, maintains its own "recognised virtual assets" concept and applies a substance-over-form analysis consistent with international standards.

Singapore (MAS). The Monetary Authority of Singapore applies a token taxonomy that mirrors the securities-law analysis under the Securities and Futures Act. A token that constitutes a capital markets product — a share, a debenture, a unit in a collective investment scheme, or a derivative — is subject to full securities regulation and requires a prospectus or an applicable exemption. Tokens that fall outside this definition may be regulated under the Payment Services Act as digital payment tokens, with lighter but still material AML and licensing obligations. MAS has been explicit that substance determines classification and that promotional materials are part of the evidentiary record.

Hong Kong (SFC). The SFC's VASP licensing regime applies to virtual-asset trading platforms. The classification question for individual tokens is informed by the SFC's existing guidance on whether a token constitutes a "security" under Hong Kong law — broadly analogous to the MiFID II/Howey analysis but adapted for the local statutory framework. In our cross-border practice, issuers targeting both Singapore and Hong Kong simultaneously face two separate classification exercises with broadly aligned but not identical outcomes, and the practical work is in mapping the differences at the margin.

Which Instrument for Which Profile? A Decision Matrix

The classification analysis is not purely academic — it feeds a commercial decision about how to structure the instrument, the offering, and the jurisdictional perimeter. The following profiles capture the most common fact-patterns we encounter.

Profile A: Pre-network token sale, issuer-dependent returns, global purchaser base. This profile almost universally points toward security treatment in the US, MiFID II financial instrument treatment in the EU, and capital-markets-product treatment in Singapore. The appropriate instrument is a registered or prospectus-covered offering, or a sale confined to qualified investors under the available exemptions, with a geographic restriction that credibly excludes US persons if US registration is not intended. The timeline for building the legal structure for this profile is measured in months, not weeks.

Profile B: Live-network token with genuine present utility, no profit expectation embedded in the design, no issuer control over secondary-market value. This profile is the strongest candidate for non-security treatment. Under Howey, the issuer's argument rests on the absence of the "efforts of others" prong. Under MiCA, the token likely falls into the "other crypto-assets" category, requiring a whitepaper but not issuer authorisation. The risk here is not classification at issuance — it is the secondary market. If the token trades on exchanges and becomes the subject of price-appreciation messaging by the issuer or affiliated parties, the classification analysis reopens.

Profile C: Governance or DAO token, global distribution, no clear issuer entity. This is currently the hardest profile to manage. Governance tokens issued by a decentralised autonomous organisation sit in a regulatory grey zone in every major jurisdiction. The absence of a formal issuer does not eliminate the investment-contract analysis in the US; the SEC has taken the position that promoters who retained a material interest in the protocol's success may be the relevant "others" for Howey purposes. Under MiCA, the absence of a legal issuer may prevent whitepaper compliance entirely, creating a different category of exposure. The practical answer for this profile is a jurisdiction-by-jurisdiction risk assessment, not a global blanket conclusion.

Profile D: Token issued by a fully licensed CASP or regulated issuer, with full MiCA whitepaper compliance. This profile has the clearest regulatory pathway in the EU but requires the underlying classification to be correct. A whitepaper filed for an "other crypto-assets" token that a national competent authority subsequently determines is an ART or a MiFID II instrument does not cure the mis-classification — it demonstrates it in writing. Pre-filing legal review is not optional; it is the core deliverable.

If a prior classification exercise returned ambiguous results or a second application of the analysis has produced a different answer, contact OBOLUS at info@oboluslaw.com. A second review of the substantive rights structure and the contemporaneous communications record can surface the analytical gap and identify the remediation path.

The Cross-Border Angle: Why One Classification Does Not Travel

A token classified as a utility instrument under one regime may be a security under another. This is not a theoretical observation — it is the operational reality of any token with a global purchaser base. The leading hubs have broadly convergent analytical frameworks, but they diverge at the margins in ways that matter commercially. A token structured to satisfy the MiCA "other crypto-assets" threshold may nonetheless satisfy the Howey test if US persons participate in the offering. A token that clears the SFC's capital-markets-product analysis in Hong Kong may still require MAS licensing in Singapore for the platform distributing it.

The practical consequence is that a classification exercise scoped to a single jurisdiction is a partial answer. Issuers with a global distribution ambition need a classification memo that addresses each jurisdiction in the distribution perimeter — not a single-flag analysis extrapolated outward. In our cross-border practice, we coordinate that exercise across the primary markets, relying on allied counsel in the relevant jurisdiction for local-law sign-off where needed.

A further complexity arises from the interaction of token classification with the banking relationship. Banks with digital-asset clients in multiple jurisdictions apply their own internal risk ratings, and a token that has attracted regulatory scrutiny in one jurisdiction can affect the account relationship in another. Structuring the offering and the classification analysis correctly at the outset reduces the downstream banking risk — a connection that issuers focused on the regulatory filing often miss until a correspondent bank flags the token.

In a recent matter, an issuer based in a Gulf free zone had completed a MiCA-aligned whitepaper review but had not mapped the US-person exposure in its distribution list. We identified a subset of purchasers that created potential Howey exposure and coordinated a remediation exercise — restructuring the purchaser eligibility criteria and supplementing the contemporaneous documentation record — before the secondary market opened. The issuer avoided an enforcement referral and retained its exchange listings.

A Common Assumption: "Our Whitepaper Labels It a Utility Token"

A common assumption among first-time token issuers is that a "utility token" label in the whitepaper, combined with a legal opinion confirming that label, provides durable protection from securities-law liability. It does not. The legal opinion is only as strong as the facts it was asked to assess — and facts change. If the network is not yet live at the point of the opinion, if the token economics subsequently shift, or if the issuer's marketing communications diverge from the assessed design, the opinion's protective value diminishes materially.

Regulators in the US, the EU, Singapore, and Hong Kong have each issued public guidance making clear that they look through marketing labels to the economic substance of the instrument. An opinion letter that relies primarily on the issuer's own characterisation of the token — rather than on an independent analysis of the rights conferred, the offering mechanics, and the distribution record — is not a reliable defence in an enforcement proceeding.

The correct approach is a classification exercise grounded in the actual instrument design, the actual distribution plan, and the actual communications record, repeated at each material change in any of those three inputs. Classification is not a one-time filing — it is an ongoing legal risk management function for the life of the token.

Related at OBOLUS

FAQ

Is my token a security?

The answer depends on the substance of the rights the token confers, assessed under the applicable regime in each jurisdiction where it is offered or accessible to purchasers. In the US, the Howey test governs; in the EU, MiCA applies alongside the MiFID II financial-instrument analysis; in Singapore and Hong Kong, the Securities and Futures Act and the SFC regime respectively. A utility label in the whitepaper does not settle the question. Classification requires a substantive analysis of the instrument design, the offering mechanics, and the contemporaneous communications record.

Do I need a MiCA whitepaper?

Under MiCA, an issuer offering crypto-assets to the public in the EU — unless the token qualifies as a MiFID II financial instrument, in which case MiCA does not apply — must publish a compliant whitepaper before the offering opens. The whitepaper must be notified to the relevant national competent authority. Exemptions exist for small offerings and certain private placements. The first step is confirming that the token falls within MiCA's scope rather than the MiFID II securities regime; only then does the whitepaper obligation attach.

How should an airdrop be structured legally?

An airdrop distributes tokens without a direct monetary exchange, but that does not exempt it from classification analysis or AML obligations. The key legal variables are whether the airdrop creates an expectation of profit derived from the issuer's efforts, whether recipients are required to perform tasks that constitute consideration, and which jurisdictions the recipients are based in. In the US, a free distribution to a broad, anonymous audience that includes US persons may still engage securities-law analysis. A properly structured airdrop addresses eligibility, geographic restrictions, and the token's classification before distribution begins.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label — and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel — specialising in token instrument design, cross-border classification analysis, and the regulatory treatment of decentralised protocols across the major digital-asset hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours