What cross-chain bridge operators face in Seychelles
A cross-chain bridge (a protocol that locks assets on one blockchain and mints equivalent tokens on another) sits in an uncomfortable legal position in Seychelles: the jurisdiction has no dedicated digital-asset service-provider statute, yet operating a bridge for external users can attract regulatory, liability and AML consequences under the existing legal order. The core question is not whether the technology is sophisticated. It is whether the bridge operator, the smart-contract deployer, the DAO governance token holder, or some combination of all three carries legal exposure that the Seychelles corporate envelope does not insulate against. For teams building in the Indian Ocean hub, getting that classification right before a product goes live is the difference between a defensible structure and an unregistered offering.
The foundational issue is token classification. Mis-classifying a token can convert a product launch into an unregistered securities offering under the laws of the jurisdictions where users actually sit – regardless of where the development company is incorporated. Seychelles' company law is permissive, but it does not override the securities, payment-services and AML rules of the markets a bridge serves. A utility label on a whitepaper does not settle the legal classification. Substance governs.
This guide walks through the six key steps a bridge team must work through: classification, structural design, AML obligations, smart-contract liability, cross-border interaction with banking and tax, and the decision point on when to engage specialized counsel.
Step 1: Classify the bridge token before you deploy
Token classification is the first and most consequential step for any cross-chain bridge team operating under a Seychelles structure. The rights conferred on holders – not the marketing term printed on the whitepaper – determine whether the bridged asset or the bridge's native governance token is a security, an e-money instrument, or a utility token in the jurisdictions your users inhabit.
Seychelles itself has not enacted a dedicated virtual-asset classification regime equivalent to MiCA (the EU's Markets in Crypto-Assets Regulation, which distinguishes asset-referenced tokens, e-money tokens, and "other" crypto-assets). That absence cuts both ways. A Seychelles-incorporated bridge operator has no local securities regulator conducting an ongoing review of token design. But that same operator's token will be classified by every regulator in every jurisdiction where users can access the bridge – and those regulators will apply their own tests.
In our cross-border practice, we assess bridge tokens against four substance-over-label criteria: economic rights (does the token represent a claim on revenues or assets?), governance rights (does holding tokens confer controlling or material influence over the protocol?), secondary-market expectation (is the primary purchase rationale price appreciation?), and passivity of yield (is value derived from the efforts of others?). A bridge governance token that fails more than one of those tests carries material securities-law risk in the EU under MiCA, in Singapore under the Payment Services Act administered by MAS, and in the United States under the SEC's longstanding analytical framework.
The practical consequence: classification must be documented in a formal legal memorandum before the token is offered or the bridge is marketed. That document becomes the first line of defence if a regulator in a user-facing jurisdiction opens a review.
For a scoped token-classification assessment, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analysis. Your token design, your user base geography and your governance structure each change the outcome. Map your options.
Step 2: Choose the right legal wrapper for the protocol
Selecting the legal entity structure for a cross-chain bridge built on a Seychelles entity is a multi-variable decision that turns on liability exposure, governance design, and the tax and banking position the operator needs to maintain. Seychelles offers three common vehicles for crypto operations: the International Business Company (IBC), the Special Licence Company (CSL), and the Foundation. Each carries a different liability and governance profile.
The IBC is the dominant structure for DeFi and bridge projects. It is fast to incorporate, carries minimal local filing obligations, and sits comfortably under Seychelles' Business Tax Act. Its weakness for a bridge operation is that it provides no liability shield against the personal exposure of smart-contract deployers in foreign jurisdictions. An IBC does not mean that a developer who is domiciled in Germany, the UK or Singapore is protected from their home regulator's reach.
The Foundation structure – less commonly used but increasingly considered for protocol governance – separates the asset-holding and the governance function. In our practice, we have seen teams use a Seychelles Foundation as a protocol treasury vehicle alongside a separate IBC that serves as the employing and contracting entity. This bifurcation can insulate the treasury from operational claims, but it adds administrative complexity and requires careful tax analysis before adoption.
A DAO structure without any legal wrapper is the highest-risk configuration for a bridge. Unincorporated DAOs do not enjoy limited liability in any major common-law jurisdiction. In England and Wales, in New York, and in Singapore, an unincorporated DAO whose bridge tokens are treated as partnership interests can expose each governance-token holder to unlimited personal liability for protocol-level losses. Seychelles incorporation of the DAO's software deployment vehicle does not cure that exposure in those forums.
The practical decision matrix runs as follows. A bridge team with a small, decentralized governance token distribution and no token-sale revenue profile can often manage risk through an IBC deployer entity, a carefully documented non-security token opinion, and a geographic access restriction on jurisdictions with prescriptive VASP licensing. A bridge team conducting a public token offering, taking bridge fees into a treasury, or offering yield products must add a licensed entity – either in the Seychelles structure or in a recognized hub – before launch.
Step 3: Work through the AML and Travel Rule position
AML obligations are the most immediately enforced legal risk for a cross-chain bridge operator, and Seychelles is not an AML-free environment. Seychelles has implemented FATF Recommendation 15 on virtual assets into its domestic AML/CFT framework. A business incorporated in Seychelles that provides a service constituting a virtual asset transfer is subject to the AML/CFT obligations applicable to virtual asset service providers under that framework – including customer due diligence, transaction monitoring, and suspicious-activity reporting.
The harder question is whether a non-custodial bridge – one where the protocol's smart contracts hold assets in escrow and no human intermediary takes custody – triggers VASP obligations at all. FATF's guidance on virtual assets acknowledges that truly decentralized protocols without a controlling party may fall outside the VASP definition. In practice, however, most operational bridges retain an identifiable controlling party: a company that deploys and upgrades the contracts, a multi-sig operator that controls the bridge's validator set, or a foundation that holds emergency-pause authority. Any of those control points can attract VASP classification.
The Travel Rule (the obligation, derived from FATF Recommendation 16, to pass originator and beneficiary data alongside a virtual-asset transfer) adds further complexity for bridge operations. When a user sends assets through a bridge from one chain to another, the transfer may constitute a covered transaction under the Travel Rule regimes applicable in the originating or receiving jurisdiction. MiCA imposes Travel Rule obligations on EU-regulated transfers; MAS imposes them under the Payment Services Act; the FCA has implemented them under the UK regime. A Seychelles bridge operator serving EU, UK or Singapore-based users may need a compliance solution for Travel Rule data even if it does not hold a local licence.
In a recent cross-border matter, a bridge development company incorporated in Seychelles was providing services to users across multiple EU member states. We identified that the company's multi-sig control architecture gave it VASP status under the MiCA transition rules and that it faced Travel Rule obligations for transfers above the applicable threshold. The team restructured its governance architecture – removing the single-entity control point – and implemented a third-party Travel Rule compliance solution before the MiCA deadline. The restructure also involved a geographic restriction on EU-resident users until a MiCA-passported entity could be authorised in a member state. The outcome was a defensible compliance posture without a forced halt to operations.
Step 4: Address smart-contract liability before an exploit occurs
Smart-contract liability is the most under-documented risk in cross-chain bridge operations. The question of who bears legal responsibility when a bridge exploit drains user funds – a vulnerability in the bridge logic, a compromised validator key, or a governance attack – is not answered by pointing to the smart contract's immutability. Courts in England and Wales, New York and Singapore have all reached factual situations where they needed to identify a responsible legal person behind a protocol. That analysis looks at who deployed, who controlled upgrades, and who marketed the service.
The tokenization of bridged assets creates an additional liability dimension. When a bridge mints a wrapped token representing an asset on the origin chain, it makes an implicit representation: the wrapped token is redeemable one-for-one for the underlying. If the bridge is exploited and the reserve of underlying assets is depleted, holders of wrapped tokens may have a claim against the operator. In the absence of a liability disclaimer that has been tested against the applicable consumer-protection or financial-services law, that claim may be live in multiple jurisdictions simultaneously.
Operators we advise routinely underestimate the importance of pre-deployment documentation: a technical audit report from a recognized auditing firm, a legal memorandum addressing user-facing liability, terms of service that comply with the consumer-protection rules of the jurisdictions where the interface is accessible, and – where the bridge token has any staking or yield component – a staking-rewards analysis addressing tax classification in the team's home jurisdictions.
Seychelles law does not impose specific smart-contract liability rules. But Seychelles-incorporated companies can be sued in foreign courts, and judgments against a Seychelles IBC can be enforced in jurisdictions where the company holds banking relationships or where its founders are domiciled. The corporate veil in Seychelles, as in most common-law jurisdictions, will not protect a director who personally authorized a deceptive product or who knowingly operated an unregistered offering.
If your smart-contract architecture has not been reviewed against a liability and disclosure framework, contact OBOLUS at info@oboluslaw.com. If a prior review surfaced structural concerns you have not yet addressed, a second read can identify the route to a defensible position. Map your options.
Step 5: Resolve the banking and tax interaction
For a cross-chain bridge team using a Seychelles structure, the banking and tax position is rarely straightforward. Seychelles benefits from a territorial tax system: income sourced outside Seychelles is generally not subject to Seychelles income tax for an IBC. That rule sounds simple. In practice, the determination of where income is sourced – whether bridge fees accruing to a smart contract count as Seychelles-source income, foreign-source income, or income with no defined source – requires a careful analysis under Seychelles' Business Tax Act and any applicable tax treaty.
Banking is the more immediate operational constraint. Seychelles IBCs operating in the digital-asset space face heightened scrutiny from correspondent banks and local financial institutions. In our cross-border practice, we regularly advise bridge teams that their Seychelles company has a clean incorporation record but cannot open a functional corporate account because the bank's AML risk appetite does not extend to cross-chain bridge operations. The solution is typically a combination: a Seychelles IBC as the protocol deployer and IP holder, and a licensed entity in a hub jurisdiction – an EU member state under MiCA, Singapore under the Payment Services Act, or the UAE under VARA – as the operational vehicle that holds the banking relationship.
That dual-entity structure has tax consequences. Where the licensed hub entity earns bridge fee revenue that it then transfers to the Seychelles IP-holder, transfer pricing rules in the hub jurisdiction will govern the arm's-length rate. An underdocumented intercompany arrangement is a significant tax risk in any EU member state and in Singapore. The tax layer must be designed in parallel with the legal structure, not after the fact.
Staking rewards and liquidity-provision income generated by bridge participants add another layer. The treatment of such income as trading income, investment income or capital gain varies materially across jurisdictions. A governance token holder who is tax-resident in Germany or the UK will not escape their home country's tax rules by pointing to a Seychelles company as the issuer.
Step 6: Know the decision point for engaging cross-border counsel
The decision to engage specialized digital-asset counsel is not a question for after a regulator makes contact. By that point, the structural options have narrowed significantly. The optimal time to engage is at one of four trigger points: before a token is designed or a whitepaper is drafted; before the bridge interface is made publicly accessible in any jurisdiction; before the first institutional or retail fundraising round; and before a banking or payment-processing relationship is sought for the protocol's treasury.
A common assumption is that a utility label on a whitepaper settles the legal classification question and that no further legal review is required until a regulator raises the issue. That assumption is incorrect and costly. Regulators in the EU under MiCA, in Singapore under the MAS Payment Services Act, and in the United States under the SEC's analytical regime do not accept a self-applied label as determinative. They assess the substance of rights conferred, the economic structure of the instrument, and the manner in which it was offered and marketed. By the time a review is initiated, the facts are already fixed.
We assess classification against the substance of rights, not the marketing label. That analysis is most valuable – and most cost-effective – when conducted before the architecture is finalized, because structural adjustments at the design stage cost a fraction of the remediation required after a regulatory inquiry begins.
Allied counsel in relevant hub jurisdictions – the EU, the UK, Singapore and the UAE – are engaged where a matter requires local-law opinions or regulatory submissions in those forums. The cross-border coordination is managed through our practice.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – structuring protocols, token offerings and smart-contract liability for digital-asset businesses
- NFT Project Legal Structuring in the UAE (VARA) – VARA licensing and structural analysis for NFT and tokenization projects in Dubai
- Stablecoin Issuance Authorisation in Estonia – MiCA-aligned authorisation path for stablecoin issuers in the EU via Estonia
FAQ
Can a DeFi protocol be regulated?
Yes, in most operational configurations. A DeFi protocol is regulated when an identifiable legal person – a company, a foundation, or a developer group – controls deployment, upgrades or emergency functions. Regulators in the EU under MiCA, in Singapore under the Payment Services Act, and in the UK under FCA rules assess control as a matter of substance. A protocol that retains a controlling party is treated as a VASP, regardless of the degree of automation in its day-to-day operation.
What legal wrapper suits a DAO?
An unincorporated DAO carries unlimited personal liability risk for governance-token holders in most common-law jurisdictions. The leading wrappers are a Foundation (which separates treasury from governance), a Marshall Islands DAO LLC, or a Cayman Islands Foundation Company. Seychelles IBCs are used as deployer or IP-holding vehicles alongside a governance wrapper. The right structure turns on the DAO's governance token distribution, revenue model and the jurisdictions where members are domiciled.
Who is liable when a smart contract fails?
Liability follows control and representation. Courts in England and Wales, Singapore and New York have looked to who deployed the contract, who marketed the service, and who held upgrade or pause authority. A developer or company that publicly promoted a bridge and retained admin keys is the most exposed party. Terms-of-service disclaimers may reduce but will not eliminate liability, particularly where a court finds that the service constituted a regulated financial activity in the applicable jurisdiction.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, bridge operators and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We assess token classification against the substance of rights, not the marketing label – a discipline that has proved critical for clients who came to us after a regulatory inquiry had already begun. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – advises bridge operators, protocol developers and DAO structures on smart-contract liability, token classification and cross-border regulatory exposure.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.