Cross-chain bridges sit at the intersection of the most demanding questions in digital-asset law: who controls the protocol, where does value move, and which regulator has jurisdiction over each leg. Gibraltar's Distributed Ledger Technology (DLT) Provider regulatory regime – administered by the Gibraltar Financial Services Commission (GFSC) – was among the first purpose-built licensing frameworks for blockchain businesses, and its treatment of cross-chain infrastructure is now a benchmark operators examine before deploying bridge contracts in or through the jurisdiction. Mis-classifying the activity a bridge performs, or failing to identify the correct regulated perimeter, can convert a product launch into an enforcement event.
This guide walks through the legal steps a DeFi operator or token issuer must complete before operating or integrating a cross-chain bridge (a protocol that locks, mints, burns or wraps assets across two or more blockchains) in Gibraltar. Each step identifies the applicable regime, the cross-border complications that arise when the bridge also touches EU users under MiCA (the Markets in Crypto-Assets Regulation), and the practical mistake most commonly made at that stage.
What is the regulated perimeter for a bridge in Gibraltar?
A cross-chain bridge in Gibraltar is most likely to engage the DLT Provider licence if the operator stores or transmits value using distributed ledger technology in or from Gibraltar. The GFSC's DLT framework does not define a discrete "bridge" licence category; rather, it asks whether the activity falls within the nine DLT Provider use classes – which include storing, transferring or exchanging value. A bridge that locks native tokens on one chain and mints synthetic equivalents on another is, in substance, performing a custody and transfer function. That substance governs, regardless of how the operator labels the protocol.
Token classification is the first decision node. The rights conferred by the bridged asset – not the marketing label applied in the whitepaper – determine whether the bridge is moving a utility token, a security token, or an e-money equivalent. The AUDIENCE_PAIN point is real: a utility label on a whitepaper does not settle legal classification. Regulators in Gibraltar, and ESMA under MiCA for EU-facing operations, assess substance over label. A bridged token that confers rights to profit share, governance votes weighted to economic exposure, or redemption against a reserve will be examined as a financial instrument.
The Gibraltar Financial Services Commission expects operators to map the full activity chain before applying, identifying every point at which Gibraltar-based infrastructure stores, moves or creates a claim on value.
If you are designing a bridge architecture and need to map which activities trigger the DLT licence perimeter, contact OBOLUS at info@oboluslaw.com before the smart contract is deployed. The analysis changes once code is live. Map your options
How does the DLT Provider regime apply to bridge operators?
The DLT Provider regime requires operators to satisfy the GFSC across a set of Regulatory Principles – covering governance, financial crime prevention, customer protection, financial resilience and technology security – rather than prescribing a single capital figure or a rigid process checklist. For a cross-chain bridge, the principles that generate the most friction in practice are financial crime prevention and technology security.
Financial crime prevention is demanding for bridge operators because bridges are structurally attractive to money-laundering schemes. The bridge moves value across chain boundaries, potentially severing the transaction trail a conventional blockchain analysis tool tracks on a single ledger. The GFSC expects a DLT Provider to have AML/CFT controls calibrated to that specific risk. The Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary information alongside a transfer – applies where Gibraltar-based operators transmit virtual assets above the applicable threshold. A bridge that processes transfers between wallets it does not control raises immediate questions about how counterparty data is collected and transmitted.
Technology security is equally focal. A bridge is a smart-contract system that, by design, holds locked assets – sometimes in very large aggregate balances. The GFSC's Regulatory Principle on security requires operators to have robust protections against unauthorised access, and that means independent code audits, formal verification evidence, and a documented incident-response plan, all of which must be presented as part of a licensing submission or a post-deployment compliance review.
In our practice, operators frequently underestimate the depth of AML program documentation the GFSC expects for non-custodial or pseudo-custodial architectures. The fact that the bridge does not hold a user's private keys does not, by itself, take the activity outside the regulatory perimeter.
What are the key steps in the Gibraltar bridge compliance process?
The compliance process for a cross-chain bridge in Gibraltar follows a logical sequence. Each step is a decision gate; moving to the next without completing the previous one typically generates rework.
Step 1 – Activity and token classification. Before any engagement with the GFSC, the operator must produce a legal memorandum that maps each activity the bridge performs against the DLT use classes and, where relevant, the token classification framework under the applicable Gibraltar legislation and the MiCA regime for EU users. The memo should address both the wrapped token (the synthetic asset minted on the destination chain) and the locked token (the collateral held on the source chain). A bridge that mints a stablecoin-equivalent on the destination chain must also consider whether the instrument qualifies as an e-money token (EMT) under MiCA, which triggers a separate authorisation requirement for EU-facing activity.
Step 2 – Corporate structure and governance mapping. A Gibraltar DLT Provider must be incorporated in Gibraltar or, where the operator uses a branch or technology provider model, must demonstrate local accountability. For a DAO-operated bridge, this raises immediate structuring questions. A DAO (decentralised autonomous organisation) without a legal wrapper has no separate legal personality in Gibraltar and cannot hold a licence. Operators running bridge protocols through DAO governance typically require a Gibraltar private company or a foundation to sit as the licensed entity, with the DAO's governance rights articulated through a constitutional document that the GFSC can review. We regularly advise on the selection and design of that wrapper.
Step 3 – AML/CFT program drafting. The AML program must address the specific risks of cross-chain value movement, including chain-hopping layering typologies, mixers and privacy protocols that may be used in conjunction with the bridge, and the procedure for responding to blockchain forensics requests from law enforcement. The program must name a Money Laundering Reporting Officer (MLRO) who is a fit-and-proper individual subject to GFSC approval.
Step 4 – Technology security documentation. This package includes: a description of the bridge architecture; an independent smart-contract audit from a recognised auditor; a summary of the custody and key-management model; a penetration-testing report; and the incident-response and business-continuity plans.
Step 5 – Application submission and GFSC engagement. Gibraltar operates a pre-application meeting process. Operators are strongly encouraged to engage the GFSC before formal submission to clarify scope and to identify any novel elements of the bridge architecture that may require regulatory guidance. The timeline from formal submission to determination varies; operators should plan on a process measured in months rather than weeks, with interim information requests likely.
Step 6 – Post-authorisation ongoing compliance. A DLT Provider licence is not a one-time event. Ongoing obligations include annual financial reporting, MLRO reporting cycles, mandatory notification of material changes to the bridge's technology or governance, and co-operation with GFSC supervisory reviews. A bridge upgrade that materially changes the custody model or introduces a new token may require a new or amended notification.
How does MiCA interact with a Gibraltar bridge licence?
Gibraltar is a British Overseas Territory and is not a member of the EU; it does not benefit from MiCA passporting. A bridge licensed under the GFSC's DLT regime that actively markets to or serves users in EU member states faces a dual regulatory obligation: it satisfies Gibraltar requirements under the DLT framework, and separately must address whether any activity-based CASP (Crypto-Asset Service Provider) authorisation is required in an EU member state, or whether an entity within the bridge group must obtain authorisation under the MiCA regime administered by ESMA and the relevant national competent authority.
The practical consequence is significant. A Gibraltar bridge operator with EU retail users is operating in two distinct legal environments simultaneously. The MiCA token classification framework – which distinguishes asset-referenced tokens (ARTs), e-money tokens (EMTs) and other crypto-assets – does not map precisely onto the Gibraltar DLT use-class analysis. It is entirely possible for a wrapped token to be classified differently under each regime, with different disclosure, reserve and authorisation consequences applying to the same instrument.
Operators we advise routinely confront a further complication: the banking and payment-processing layer. EU banks increasingly apply MiCA-readiness criteria when onboarding crypto businesses. A Gibraltar-licensed bridge operator may find that a potential EU banking partner requires evidence of MiCA-compatible governance and AML controls before opening an account, even if the operator's formal licensing obligation sits entirely in Gibraltar.
The smart decision for an operator with EU exposure is to structure the entity group from the outset with both the Gibraltar DLT licence and a potential MiCA CASP authorisation in a passportable EU jurisdiction in mind. Trying to retrofit a structure after the bridge is live is materially more expensive and more disruptive to operations.
The process above describes the standard dual-jurisdiction path. Your facts – the entity structure, the user base geography, the token design – will change the analysis materially. For a scoped assessment, contact OBOLUS at info@oboluslaw.com. Map your options
What is smart contract liability, and who bears it in Gibraltar?
Smart-contract liability for a bridge failure – whether caused by an exploit, a logic error, or an oracle manipulation – is one of the least resolved questions in Gibraltar DeFi law, and the answer is not found in a single statutory provision but is constructed from general private-law principles applied to the specific facts of the protocol's architecture and governance.
The threshold question is whether the bridge smart contract constitutes a legally binding contract between identifiable parties. In Gibraltar, as in most common-law systems, a contract requires offer, acceptance, consideration and identifiable parties. A bridge contract deployed to a public blockchain and interacted with by anonymous wallets does not, in every configuration, satisfy those requirements in a form that generates an enforceable claim. However, where the operator is an identified and licensed DLT Provider, the relationship between the operator and a user may give rise to contractual duties, tortious duties, or both.
Where a bridge exploit results in user losses, the operator's liability exposure turns on several factors: whether the operator made representations about security that were not met; whether the operator owed a duty of care to bridge users under Gibraltar or applicable conflict-of-laws principles; whether the bridge's terms of service (if any) effectively limited liability to the extent permitted by applicable consumer-protection or financial-services law; and whether the operator holds insurance that covers smart-contract failure.
For DAO-operated bridges without a legal wrapper, the liability question is more acute. Absent a separate legal entity, governance token holders who actively voted for a deployment decision may, in some jurisdictions, face arguments that they participated in the conduct giving rise to the loss. Gibraltar has not yet produced definitive case law on this point, but the trend in leading common-law forums – including England and Wales – moves toward recognising digital assets as property and examining the governance structure of protocols to identify responsible parties.
The micro-matter below illustrates how liability allocation plays out in practice.
In a recent matter, a token issuer operating a multi-chain tokenization protocol from a common-law jurisdiction suffered a bridge exploit that drained a seven-figure balance of wrapped tokens. The issuer had not obtained a legal opinion on the classification of the wrapped token before deployment, and the bridge's terms of service did not address Gibraltar law or the DLT regime. We were engaged to assess the operator's exposure, map applicable forums, and co-ordinate with forensic partners to trace the extracted assets across three chains. The operator ultimately restructured its legal entity, obtained a DLT Provider licence for the relaunched bridge, and aligned its AML program with the GFSC's revised expectations – a process completed within a single operational quarter.
What common mistakes do bridge operators make in Gibraltar?
Operating under the assumption that a utility label resolves token classification is the most consequential error in our experience. A bridge that wraps a token and mints a synthetic equivalent on a destination chain creates a new instrument. That new instrument must be classified independently. The GFSC and, for EU-facing operations, ESMA under MiCA, will examine the rights conferred by the synthetic token and not the rights of the original. Operators who deploy first and classify later encounter the maximum possible compliance debt.
A second common mistake is treating DeFi infrastructure as outside the regulatory perimeter because it is non-custodial. The DLT framework in Gibraltar does not condition its application solely on custody. The operative question is whether the operator is using DLT to store or transmit value as a business in or from Gibraltar. A bridge relayer or bridge operator that earns fees from value transmission may satisfy that test regardless of whether it holds user keys.
A third mistake is building the DAO governance structure after incorporation rather than before. Once a DAO has distributed governance tokens to a global holder base, restructuring the governance wrapper to satisfy the GFSC's fit-and-proper and accountability requirements becomes a complex and time-consuming exercise involving potential token repurchases, governance votes, and shareholder restructuring at the licensed entity level.
Finally, operators consistently underestimate the AML obligations that attach to cross-chain operations. The Travel Rule's data-transmission obligations apply to the operator as a licensed entity even when the protocol is automated. Building Travel Rule compliance into the bridge architecture as a post-deployment retrofit is significantly harder than designing for it from the start.
Decision point: which operator profile should choose which structure?
The right structure for a cross-chain bridge in Gibraltar depends on the operator's activity profile, user base, and token design. The following analysis addresses the three configurations we see most frequently in practice.
Profile A – Institutional bridge operator, permissioned architecture, no retail users. This operator is moving value between institutional counterparties or between protocol treasuries. The DLT Provider licence is the primary Gibraltar instrument. AML obligations are lighter in practice because counterparties are identified and onboarded through a KYB process. The key legal risk is on the smart-contract liability side: institutional users have deeper pockets and greater appetite for litigation following an exploit. The governance wrapper should be a Gibraltar private company with a documented operational policy the GFSC can review. The indicative compliance program can be assembled and submitted in a measured timeline, though the GFSC's determination timeline is ultimately in the regulator's discretion.
Profile B – DeFi bridge operator, permissionless architecture, global user base including EU retail. This is the highest-complexity profile. The operator must address the Gibraltar DLT licence, the MiCA CASP authorisation question for EU users, Travel Rule compliance for transfers above the relevant threshold, and token classification for each asset the bridge supports. The DAO governance question is acute: this operator almost certainly requires both a Gibraltar licensed entity and a legal opinion on whether governance token holders bear any residual liability. This profile typically benefits from a dual-entity structure with the Gibraltar DLT Provider holding the operational licence and an EU-domiciled CASP holding the MiCA authorisation for EU-facing services.
Profile C – Token issuer deploying bridge functionality as a secondary feature of a tokenization platform. The primary licence may already exist (a DLT Provider authorisation covering the tokenization activity). The bridge adds a new DLT use class. The operator should file a material-change notification with the GFSC, update the AML program to address cross-chain risks, and obtain a supplementary legal opinion on the classification of any new synthetic instruments the bridge creates. The timeline is shorter than a fresh application, but the token classification step cannot be abbreviated.
Related at OBOLUS
- DeFi, tokenization and smart-contract law – legal structuring for protocols, tokens and on-chain business models
- Smart-contract legal review under MiCA – how the EU's MiCA regime applies to on-chain code and automated execution
- Crypto exchange licensing in Kazakhstan's AIFC – AFSA licensing process and timeline for exchange operators seeking a common-law hub outside the EU
FAQ
Can a DeFi protocol be regulated?
Yes – the question is not whether DeFi is regulated in principle, but whether a specific protocol's architecture and the operator's role bring the activity within a jurisdiction's regulatory perimeter. In Gibraltar, the DLT Provider regime is activity-based: if an identifiable operator uses DLT to store or transmit value as a business in or from Gibraltar, the licence requirement applies regardless of how decentralised the protocol's governance is. The existence of a DAO or an automated smart contract does not, by itself, remove the operator from regulatory scope.
What legal wrapper suits a DAO?
The appropriate wrapper depends on the DAO's purpose, its jurisdiction of operation, and the regulatory requirements of the applicable licensing regime. In Gibraltar, a DAO that operates a DLT-regulated business typically requires a Gibraltar private company or a foundation as the licensed entity, with the DAO's governance rights documented in a constitutional instrument. Unincorporated DAOs cannot hold a licence, may face unlimited liability exposure for token holders, and present insuperable difficulties for banking counterparties and regulators who need an identifiable accountable person.
Who is liable when a smart contract fails?
Liability allocation following a smart-contract failure is determined by examining who operated the protocol, what representations were made to users, whether the operator owed a duty of care under applicable law, and what the protocol's terms of service provide. A Gibraltar-licensed DLT Provider faces the clearest exposure. A DAO without a legal wrapper presents a more complex picture: governance token holders who actively participated in deployment decisions may face arguments of joint participation in the relevant conduct, depending on the facts and the forum in which any claim is brought.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract legal architecture, DeFi protocol structuring and cross-chain regulatory analysis for operator clients in Gibraltar and across leading digital-asset hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.