On paper, structuring an NFT project in Lithuania looks straightforward. The country has a well-developed legal infrastructure, a history of accessible digital-asset registration, and a position inside the EU single market that MiCA passporting makes commercially attractive. In practice, the analysis turns quickly on what the NFT actually is – and whether that classification holds under Lithuanian law, EU regulation, and the laws of every jurisdiction where the tokens will be sold or held.
NFT project legal structuring in Lithuania requires working through three distinct legal questions before incorporation: token classification under the MiCA regime (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), AML/VASP registration obligations under the Bank of Lithuania's supervision, and the cross-border interaction between the project's entity seat, its user base, and its banking relationships. Getting these right before launch is materially cheaper than correcting them after the fact.
This guide walks through each structuring step in sequence – from classification and entity selection through to the AML/VASP posture and the cross-border tax and banking stack.
Why Lithuania is a realistic base for an NFT project
Lithuania sits inside the EU, which means a well-constructed entity benefits from the MiCA passporting mechanism across the EU/EEA from a single authorisation. The Bank of Lithuania has developed supervisory experience with digital-asset businesses, and the country's company formation process is efficient relative to other EU member states. For NFT projects in particular, the combination of EU legal recognition and a functioning local legal and banking market is a practical starting point – provided the project structure is built correctly from the outset.
In our cross-border practice, we have seen founders choose Lithuania for the entity and then inadvertently expose the project to regulatory requirements in Germany, France, or the Netherlands because the token's rights structure pulled it into securities or e-money territory under those national laws. The entity seat is one input. The token's substance is another. Both have to be designed together.
Lithuania's transition from its earlier VASP registration regime to the MiCA CASP (Crypto-Asset Service Provider) authorisation model is ongoing. Projects that registered under the prior regime should assess whether existing registrations remain adequate for their current activity scope. The Bank of Lithuania is the national competent authority responsible for that transition.
The MiCA framework draws a line between three categories of regulated token: asset-referenced tokens (ARTs, which reference a basket of currencies or assets), e-money tokens (EMTs, which reference a single fiat currency), and all other crypto-assets, which include most NFTs. The third category carries lighter-touch obligations than ARTs or EMTs, but it is not unregulated – and the classification itself requires analysis.
To discuss your project's EU entity strategy before you commit to a structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis.
Step 1: Classify the NFT before anything else
Token classification is the first structural decision, and it determines every other step in the analysis. A common assumption is that attaching a "utility" label to a whitepaper settles the legal classification. It does not. ESMA and the Bank of Lithuania assess the substance of the rights the token confers – not the marketing term – and a token that grants profit participation, revenue sharing, or a claim against the issuer may be a financial instrument regardless of what the documentation calls it.
For NFT projects specifically, the analysis turns on three questions. First, is the token genuinely unique and non-fungible in a legally meaningful sense, or is it part of a series where economic substance creates effective fungibility? Second, does the token confer rights that look like those of a security – profit, governance over a fund, or a claim on an issuer's assets? Third, is there a secondary market structure that could pull the token into MiCA's "other crypto-assets" category with whitepaper and disclosure obligations?
Under MiCA, unique and non-fungible tokens issued in individual artistic or collectible contexts fall outside the regulated perimeter – but that carve-out is narrower than most founders assume. A project that issues thousands of tokens in a series, or that attaches utility rights redeemable across a broader ecosystem, should not assume the carve-out applies without analysis. We assess classification against the substance of rights, not the marketing label – and the Bank of Lithuania applies the same standard.
The output of Step 1 is a written classification opinion. It becomes the foundation of the whitepaper (if required), the AML assessment, and the approach to regulated activity in each target market.
Step 2: Select the right legal entity and seat
For most NFT projects, a Lithuanian private limited liability company (UAB, uždaroji akcinė bendrovė) is the standard operating entity. It offers limited liability, a straightforward governance structure, and the corporate form required for Bank of Lithuania VASP registration and MiCA CASP authorisation. The UAB can hold intellectual property, enter into smart-contract-related agreements, and serve as the issuing entity for a token offering.
Several factors push some projects toward a layered structure. If the project has a DAO (Decentralised Autonomous Organisation) component – a governance structure managed through on-chain voting rather than a traditional board – a single UAB may not adequately separate the protocol layer from the operational and liability layer. In our practice, we regularly advise on structures that combine a Lithuanian UAB for licensed activities with a Cayman or BVI foundation for protocol governance, keeping the operational entity inside the EU regulatory perimeter while giving the governance layer a legal form appropriate to its nature.
Intellectual property is a separate consideration. NFT projects typically involve significant IP – art, music, code, brand. Where that IP is held, and whether the Lithuanian entity owns or licenses it, affects both tax and the project's exposure to claims from contributors, co-creators, or platforms. The entity structure should address IP ownership explicitly at formation, not as an afterthought.
The entity selection step should also resolve the question of ultimate beneficial ownership disclosure. Lithuania, as an EU member state, applies the EU beneficial ownership register requirements. Founders who wish to maintain any degree of structural privacy need to consider this before finalising the entity design – a layer of holding entities does not remove the disclosure obligation.
Step 3: Navigate the AML and VASP registration requirement
Whether an NFT project must register as a VASP (virtual asset service provider) in Lithuania depends on the activity it conducts, not the asset it trades. If the project operates an exchange, marketplace, or custody function for virtual assets – including NFTs that qualify as virtual assets under the applicable VASP provisions – registration with the Bank of Lithuania is required before those activities commence.
Lithuania's AML framework is built on the FATF Recommendations, including Recommendation 15 (which applies FATF standards to virtual asset service providers). The Bank of Lithuania has been an active supervisor of VASP compliance, and the transition to MiCA CASP authorisation does not pause that supervision in the interim period. Projects relying on the MiCA "other crypto-asset" carve-out for NFTs should still assess whether their marketplace or secondary-trading infrastructure triggers VASP registration independently.
The AML programme itself requires a written policy, a designated compliance officer, customer due diligence (CDD) and enhanced due diligence (EDD) procedures, and transaction monitoring. For NFT projects, the CDD question is practically complex: on-chain pseudonymity is the norm, but the Bank of Lithuania expects identification of customers above applicable thresholds. How that interacts with the technical architecture of the project – wallet-based onboarding versus custodial account models – requires specific design attention.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) also applies to transfers above the applicable threshold. Projects that integrate with custodial wallets, fiat on-ramps, or other licensed VASPs need to build Travel Rule data exchange into the technical stack, not bolt it on post-launch.
Step 4: Conduct a smart-contract legal review before deployment
A smart-contract legal review identifies where the contract's on-chain logic creates legal obligations or liabilities that the off-chain documents either contradict or fail to address. For NFT projects, the audit scope typically covers: the minting function and the legal effect of issuance; the royalty mechanism and whether it is legally enforceable as a contractual right; the transferability logic and any restrictions that need to mirror regulatory requirements; and the upgrade or pause mechanisms and who can trigger them.
The royalty enforcement question is particularly live for NFT projects. On-chain royalty logic is a technical default, not a legally binding right enforceable across all marketplaces. If the project's economic model depends on secondary-sale royalties, the legal structure needs to create an enforceable off-chain contractual right that supplements the on-chain mechanism – and it needs to specify which law governs that right and which forum resolves disputes.
Smart-contract audit firms test code for bugs. A legal review tests the contract for legal risk. Both are necessary, and neither substitutes for the other. In the structuring timeline, the legal review should occur before final code deployment, because changes after deployment are expensive and some cannot be made at all in non-upgradeable contracts.
We recently worked with a digital media company building an NFT-based content rights platform. The on-chain licensing terms in the contract conflicted with the platform's terms of service, creating a situation where token holders held rights the platform's legal structure did not recognise. We restructured the off-chain terms and introduced a dispute-resolution clause under a common-law forum before the contract went live, avoiding what would otherwise have been an immediate post-launch dispute.
Step 5: Map the cross-border tax and banking stack
A Lithuanian UAB is subject to Lithuanian corporate income tax on its profits. NFT revenue – whether from primary sales, royalties, or licensing – is likely business income for a trading entity. How token proceeds are characterised for VAT/GST purposes varies across EU member states; the VAT treatment of NFT transactions is not uniform, and the project's structure needs to address it explicitly in the jurisdictions where it has economic substance or users.
Staking rewards, token grants to team members, and secondary-market royalty flows each raise distinct tax questions. We advise founders to build the tax analysis into the structuring step, not to address it at the first filing deadline. The interaction between Lithuanian tax treatment and the tax residency of founders and investors adds a cross-border layer that is best resolved at formation.
Banking is the practical chokepoint for many NFT projects. Lithuanian banks serve digital-asset businesses, but each bank applies its own risk appetite to onboarding. Projects with anonymous token distributions, high-volume peer-to-peer transfers, or unresolved classification questions face extended onboarding timelines or declines. The structuring work – classification opinion, AML programme, entity governance documents – is also the bank's underwriting file. A well-prepared structure opens the banking conversation significantly faster than a project that arrives with a UAB and a whitepaper and nothing else.
If your project's banking or tax stack needs a second read before you file, write to info@oboluslaw.com. If a prior application stalled or an account was closed, a structural review can surface the reason and the route back.
Step 6: Identify the decision point – Lithuania only, or a layered structure?
The right structure for an NFT project depends on the project's profile, not a universal preference for one jurisdiction or one entity type. The following decision branches are the ones we work through most often in practice.
Profile A – A project issuing genuinely unique digital art NFTs to a predominantly EU audience, with no secondary marketplace and no embedded financial rights. A single Lithuanian UAB with appropriate AML documentation is likely sufficient. The MiCA carve-out for unique, non-fungible tokens applies in substance, the Bank of Lithuania VASP registration question turns on whether the issuer operates a marketplace, and the structure is relatively lean. Timeline from incorporation to operational readiness is typically a matter of weeks, depending on banking.
Profile B – A project issuing a series of utility NFTs with embedded ecosystem rights, a secondary marketplace, and a global user base including US persons. The Lithuanian UAB remains the EU operating entity, but a second entity – likely Cayman or BVI – may be needed for the protocol governance layer or the token treasury. US persons trigger a separate securities law analysis that runs in parallel. Banking is best approached through an EU fintech bank with digital-asset experience rather than a domestic Lithuanian commercial bank. Timeline from initiation to fully operational is typically measured in months, not weeks.
Profile C – A project with a DAO governance structure, a multi-chain deployment, and ambitions to offer DeFi-adjacent functionality (staking, lending, yield). This profile requires the most layered analysis: the DAO legal wrapper question, the DeFi regulatory perimeter under MiCA and potentially under the applicable VASP provisions in non-EU jurisdictions, and the smart-contract liability question across each chain. Allied counsel in the relevant jurisdictions outside the EU is standard for this profile.
No single structure fits every profile. The structuring work is the analysis, not the paperwork.
Self-assessment checklist before engaging counsel
Before a structuring engagement begins, the following questions help identify the complexity level and the right scope of advice.
- Has the project produced a written token classification analysis, or is the classification based on a label in a whitepaper draft?
- Does the project involve a marketplace, secondary trading infrastructure, or custody function – and if so, has the VASP registration question been assessed?
- Does the smart contract include an upgrade mechanism, a pause function, or royalty logic – and have those been reviewed for legal effect?
- Are there US persons in the target user base, and has the US securities law analysis been run?
- Does the project have a DAO component, and if so, does that DAO have a legal wrapper in any jurisdiction?
- Has the cross-border VAT and corporate tax treatment of NFT sale proceeds been mapped?
- Has a bank been approached, and on what basis was any account opened or application declined?
Projects that can answer all seven questions in writing before engaging counsel reduce structuring time and cost materially. Projects that cannot answer two or more are at a higher risk of launch delays or post-launch regulatory exposure.
Related at OBOLUS
- DeFi, tokenization and smart-contract law for digital-asset businesses – Legal foundations for token issuers, protocol operators and on-chain businesses
- Smart-contract legal review in Guernsey – Offshore-jurisdiction review practice for deployed and pre-deployment contracts
- Travel Rule compliance program under heightened scrutiny – Building a defensible Travel Rule posture where regulators are actively reviewing
FAQ
Can a DeFi protocol be regulated?
Yes – depending on the activity it performs, not the technology it uses. Under MiCA and the Bank of Lithuania's supervisory approach, a DeFi protocol that provides exchange, custody, or lending services in a sufficiently decentralised way may still fall within the regulated perimeter if identifiable persons perform those functions. Governance token holders who exercise control may also face regulatory exposure. Classification requires a fact-specific analysis of the protocol's actual structure.
What legal wrapper suits a DAO?
No single wrapper is universal. Common options include a Cayman Islands foundation company, a BVI foundation, a Marshall Islands DAO LLC, or a Swiss association – each suited to different governance and liability profiles. A Lithuanian UAB can serve as the operational subsidiary of a DAO-governed protocol, holding the licence and handling regulated activity, while the DAO layer sits in a jurisdiction with a more permissive legal form. The right choice depends on the protocol's tokenomics, the degree of decentralisation, and the target markets.
Who is liable when a smart contract fails?
Liability follows control. Where an identifiable entity deployed, controls, or profits from a smart contract, that entity is the first candidate for legal liability – whether in contract, tort, or regulatory enforcement. A genuinely decentralised protocol with no controlling person presents a harder target, but courts in England and Wales, Singapore, and Hong Kong have increasingly been willing to pierce pseudonymity to identify defendants. The smart-contract legal review stage exists precisely to identify and address these exposure points before deployment.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – and we have worked through the structuring questions this guide raises across more than seventy licensing jurisdictions. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract legal risk, token classification, and DeFi protocol structuring for EU-based and cross-border digital-asset projects.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.