EST · MMXXVI
Home/Jurisdictions/South Africa/Cross-chain bridge legal risk in South Africa
DeFi, Tokenization & Smart-Contract Law

Cross-chain bridge legal risk in South Africa

Cross-chain bridge legal risk in South Africa. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Cross-chain bridges sit at one of the most legally ambiguous points in digital-asset infrastructure. A bridge that moves value across two blockchains can simultaneously be a payment system, a custodian, a securities-transfer facility and a money-transmission service – depending on which regulator is looking and which rulebook they apply. In South Africa, where the Financial Sector Conduct Authority (FSCA) formally classified crypto assets as financial products in 2022, that ambiguity is no longer theoretical. Operators running or integrating bridge protocols now face concrete licensing questions, AML obligations and potential liability exposure under South African law.

The direct answer is this: a cross-chain bridge that handles South African users or rand-denominated value almost certainly triggers FSCA oversight, and may separately engage the South African Reserve Bank's (SARB) payment-system and currency-control frameworks. The analysis turns on what the bridge does, for whom, and where the operator sits. This guide works through each step of that analysis, from initial classification through to the cross-border structuring decisions a business must make before it goes live.

What is a cross-chain bridge and why does it attract legal risk?

A cross-chain bridge is a protocol – or a combination of smart contracts and off-chain infrastructure – that locks or burns an asset on one blockchain and mints or releases a corresponding representation on another. The legal risk is embedded in that mechanism. When a bridge holds assets in a lock-up, it functions operationally like a custodian. When it mints a wrapped token, it creates a new financial instrument whose classification may differ from the underlying asset. When it charges a fee denominated in a native token, it may be providing a financial service. Every one of those functions has a regulatory analogue under South African law.

The FSCA's 2022 declaration – made under the Financial Advisory and Intermediary Services Act (FAIS) – brought crypto assets within the definition of "financial products." That single step changed the analysis for any service provider touching those products. A bridge that was once unregulated infrastructure became, overnight, a potential financial services provider requiring a licence. Bridge operators who built before that shift, and who have not revisited their structure since, are exposed.

There is a second layer of risk that the FSCA declaration did not address: the SARB's oversight of payment systems and South Africa's Exchange Control framework. Moving rand-denominated stablecoins or synthetic rand assets across chains may engage both. The two regulatory threads often run in parallel, and failing to manage either one is independently actionable.

How does the FSCA classify cross-chain bridge activity?

Classification under the FSCA regime starts with function, not label. The authority's declaration covers crypto assets as a category of financial product; any person who gives advice on, or intermediates in, those products must hold a FAIS licence or be exempted from the requirement. A bridge operator who provides user-facing routing decisions – choosing the cheapest or fastest route across chains – may be giving advice. One who executes the transfer on behalf of a user is intermediating.

The harder question is the wrapped-token issue. When a bridge mints a wrapped asset – say, a wrapped version of an ERC-20 token on a Cosmos-based chain – it is creating a new instrument. Under the substance-over-label principle that South African financial law shares with most leading regimes, the wrapped asset's classification depends on the rights it confers, not the name given to it. If the underlying asset is a crypto asset under the FSCA declaration, the wrapped version almost certainly is too. If the underlying asset is a share, bond or collective investment scheme unit, the wrapped version may inherit that classification – and trigger a completely different licensing obligation.

We regularly advise clients on exactly this classification exercise. The analysis is not a one-page whitepaper exercise. It requires mapping every asset type that can flow through the bridge, identifying the rights conferred at each hop, and testing each against the FSCA's criteria. A bridge that handles fifteen token types may produce fifteen different classification conclusions, each with its own compliance consequence.

Practical step: Before any South African launch, prepare a token-type matrix. For each asset the bridge will handle, document its classification, the applicable licence requirement, and the consequence of getting it wrong. This is the foundation of every FSCA licence application and every legal opinion we produce in this area.

CTA #1 bridge: The classification process above describes the standard analytical path. Your facts – the specific token types, the user geography, the fee model – change the conclusion at every step.

For a scoped classification assessment of your bridge protocol's position under South African law, contact OBOLUS at info@oboluslaw.com.

What payment-system and exchange-control obligations does a bridge trigger in South Africa?

The SARB administers two separate bodies of law that can independently apply to a cross-chain bridge: the National Payment System Act (NPS Act) and the Exchange Control Regulations made under the Currency and Exchanges Act. A bridge that processes payments between South African users, or that moves value across the rand/crypto interface, sits in the intersection of both.

Under the NPS Act framework, the SARB's Payment Association of South Africa (PASA) oversees payment-system operators and participants. Whether a bridge is a "payment system" in the NPS sense depends on the degree to which it clears or settles obligations between parties. A bridge that simply moves a token from Chain A to Chain B, with no fiat settlement leg, may not qualify. One that wraps a rand stablecoin, or that forms part of a payment flow ending in rand, almost certainly does.

Exchange control is the sharper risk for international bridge operators. South Africa maintains capital controls administered by the SARB's Financial Surveillance Department. Transactions that move value out of the rand currency area – or that allow South African residents to hold offshore assets without disclosure – can constitute exchange control contraventions. A bridge that enables a South African user to move rand-denominated value to a foreign chain, convert it, and hold it offshore is directly in scope. The penalties for exchange control breaches are significant, and the SARB has shown an increasing appetite for enforcement in the digital-asset space.

In our cross-border practice, we have seen bridge operators dismiss the exchange-control angle because their protocol is "purely on-chain." That is a structural error. The question is not where the transaction happens technically. It is whether the economic effect is the movement of value across the rand currency boundary. If the answer is yes, exchange control applies.

Who is liable when a smart-contract bridge fails or is exploited?

Liability for a bridge failure in South Africa is determined by the same general-law principles that govern any contractual or delictual claim – but applied to a context where the contract is immutable code and the "counterparty" may be a DAO or an anonymous development team. South African contract law does not recognise smart contracts as a distinct category, but courts will give effect to the terms of a smart contract as a valid contract where the required elements are present: offer, acceptance, consideration and lawful object.

The harder question is fault-based delictual liability (the South African equivalent of tort). Where a bridge is exploited because of a coding error – a re-entrancy vulnerability, a price-oracle manipulation, a flawed cross-chain message-verification routine – the development team, the auditors and the protocol's governance body all face potential delictual claims from users who suffered losses. The standard is whether a reasonable person in the position of the developer would have foreseen the harm and taken steps to prevent it.

Under South African delict principles, foreseeability is assessed objectively. A bridge team that published an audit, disclosed known risks and offered users a clear terms-of-use agreement is in a materially better position than one that did not. Documentation is not a complete defence, but it is the starting point of any liability analysis. Bridge operators who cannot produce an independent security audit and a legally reviewed terms-of-service document are exposed in a way that is both avoidable and, in our experience, common.

The DAO question adds a further layer. Where a bridge is governed by a DAO (decentralised autonomous organisation) – a structure in which token holders vote on protocol changes – South African law does not yet recognise the DAO as a legal person. Absent a recognised legal wrapper, DAO participants risk being treated as partners in a general partnership or, in the worst case, as joint wrongdoers in a delictual claim. The appropriate legal wrapper – a foundation, a special-purpose company or a trust – must be chosen before the bridge goes live, not after an exploit.

How do AML and Travel Rule obligations apply to a South African bridge?

South Africa's AML regime is administered primarily through the Financial Intelligence Centre Act (FICA) and its accompanying regulations. The Financial Intelligence Centre (FIC) is the supervisory body; the FSCA acts as the sector-specific supervisor for accountable institutions in the financial sector, including crypto-asset service providers.

A cross-chain bridge that qualifies as a VASP (virtual asset service provider) under the FATF definition – and most bridges that accept user deposits and execute transfers will qualify – must register as an accountable institution under FICA. The obligations that follow include customer due diligence, record-keeping, suspicious-transaction reporting and, critically, compliance with the Travel Rule (the obligation, arising from FATF Recommendation 15, to pass originator and beneficiary data with a transfer).

South Africa's Travel Rule implementation follows the FATF standard. For a bridge, this creates a technical challenge as well as a legal one. Most bridge architectures do not capture the identity of the originating wallet's beneficial owner. Retrofitting a Travel-Rule-compliant data-capture and transmission mechanism onto an existing bridge is architecturally disruptive. Operators who design for Travel Rule compliance from the outset – building identity-verification and data-passing into the protocol's flow – avoid the more costly retrofit problem.

The cross-border dimension of AML is also acute. A bridge connecting a South African user to a Kazakh or Singaporean chain must satisfy not only South African AML standards but also the VASP-registration requirements of the destination jurisdiction's regime. In our practice, we coordinate that multi-jurisdictional AML mapping before the bridge goes live, identifying the registration or licence trigger in each relevant forum and building a compliant data-architecture from the outset.

What cross-border structuring, tax and banking decisions does a South African bridge operator face?

For a business sitting between South Africa and an international hub, the legal question turns on where the operating entity should sit, where it should hold its Treasury assets, and how it should account for the fees and spread income the bridge generates. These three questions are connected, and answering them in the wrong order is one of the most common structuring errors we see.

Entity location: South Africa offers no specific digital-asset licence regime at the protocol level, but the FSCA's FAIS framework requires that any entity giving advice or intermediating in crypto-asset financial products holds a licence in South Africa or appoints a licensed representative. An offshore entity operating a bridge that is used by South African residents is not automatically exempt from this requirement. The FSCA has stated publicly that it looks to the location of the user, not the location of the operator. An operator sitting in, say, a VARA-licensed Dubai entity still needs a FSCA-authorised representative to serve South African users, unless an exemption applies.

Tax: South Africa's South African Revenue Service (SARS) treats crypto assets as assets for income-tax purposes. Revenue derived from bridge fees, spread income or token rewards is taxable in South Africa if the source is South African or the recipient is South African tax-resident. Structuring the Treasury and fee-flow through an offshore entity may defer but does not eliminate South African tax exposure if the effective management of the entity is conducted from South Africa. The permanent-establishment risk – the risk that a South African-resident team effectively manages an offshore entity and thereby creates a South African taxable presence – is frequently underestimated.

Banking: obtaining and retaining a bank account for a bridge-operating entity is consistently one of the most operationally difficult parts of the build. South African banks apply elevated AML scrutiny to crypto-adjacent businesses, and a bridge operator who cannot demonstrate FSCA registration, a clean audit trail and a credible AML programme will struggle to maintain correspondent banking. The banking conversation should start before the licence application, not after it is granted.

To map the licence, banking and tax stack for your South African bridge build, write to OBOLUS at info@oboluslaw.com.

How a recent bridge matter illustrates the cross-border recovery challenge

In a recent matter, a protocol operator discovered that funds had been misappropriated through a vulnerability in its cross-chain message-verification logic. The affected pools spanned two chains; the attacker had converted the proceeds into stablecoins within hours of the exploit. We were engaged within the same business day.

We coordinated a disclosure request to the stablecoin issuer – leveraging the issuer's contractual freeze authority, which applies on receipt of satisfactory evidence of a court order or law-enforcement referral – and simultaneously prepared a without-notice application in a leading common-law forum for a worldwide freezing order over the attacker's identified addresses. The forensic chain-of-custody report, produced by a specialist on-chain analytics partner within 36 hours, was the evidential foundation of both the issuer freeze request and the court application. A partial freeze was achieved before the attacker could move the remaining balance to a mixing protocol.

The matter illustrated two lessons that recur across bridge-exploit recoveries. First, the recovery window is measured in hours. A business that does not have a pre-agreed incident-response protocol – including identified counsel, a forensics partner and a draft application framework – will lose those hours to internal coordination delays. Second, the legal structure of the protocol matters at recovery time. A bridge operated through an identifiable legal entity, with proper terms of service and a documented AML programme, can obtain court orders faster than one operated anonymously through a DAO with no registered legal presence.

Self-assessment: is your bridge legally prepared for South African users?

Before accepting South African users or handling rand-denominated assets, a bridge operator should be able to answer yes to each of the following questions.

  • Has the team completed a token-type classification matrix for all assets the bridge will handle, tested against the FSCA's financial-product definition?
  • Has the operating entity obtained, or engaged to obtain, the applicable FSCA authorisation under the FAIS framework?
  • Has the bridge been assessed against the SARB's NPS Act and Exchange Control framework, with a formal legal opinion where the position is not clear?
  • Is the bridge registered as an accountable institution under FICA, with a functioning AML/CFT programme including a Travel-Rule-compliant data-capture architecture?
  • Does the bridge have a legally reviewed terms-of-service agreement, an independent security audit and a published risk-disclosure document?
  • Has the operating entity adopted a recognised legal wrapper (company, foundation or trust) to house the protocol's governance function, removing the default-partnership risk that attaches to an unwrapped DAO?
  • Has a banking-relationship strategy been prepared in parallel with the licence application, with primary and contingency account options identified?
  • Has a cross-border tax analysis been conducted, including permanent-establishment risk, for any offshore entity that receives bridge fee income with South African-resident management?

A "no" answer to any of these questions is a live legal risk. In our practice, we use this checklist as the opening diagnostic in every bridge-compliance engagement. The answers map directly to the scope of work required before a South African launch can proceed safely.

Addressing the "utility label" assumption

A common assumption among bridge builders is that labelling their native token as a "utility token" in the whitepaper settles the classification question under South African law. It does not. The FSCA applies a substance-over-form analysis: a token is classified by reference to the rights it confers on the holder, the economic exposure it creates and the manner in which it is marketed and sold. A token that entitles holders to a share of bridge-fee revenue, or that is sold to the public with an expectation of profit from the team's efforts, will be analysed as an investment product regardless of the label. We assess classification against the substance of rights, not the marketing label. That distinction has separated compliant launches from enforcement actions in every major jurisdiction where digital assets are now regulated.

If a prior structure was built on a utility-label assumption and you need a second read before your next raise or launch, contact OBOLUS at info@oboluslaw.com.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. Regulation attaches to the activity and the economic effect, not the technology. A DeFi protocol that intermediates in financial products, accepts user deposits or executes transfers on behalf of South African users will engage the FSCA's FAIS framework and potentially the SARB's payment-system oversight. Decentralisation reduces but does not eliminate regulatory exposure, particularly where an identifiable team or entity controls upgrade keys, fee flows or governance.

What legal wrapper suits a DAO?

South African law does not recognise a DAO as a legal person. Without a wrapper, participants risk partnership liability. The most common solutions are a special-purpose company incorporated in South Africa or an offshore foundation in a jurisdiction that has enacted DAO-recognition legislation. The right choice depends on the DAO's governance model, the jurisdictions of its token holders and its tax objectives. We assess each situation individually and recommend the structure that minimises default-liability risk.

Who is liable when a smart contract fails?

Liability turns on whether the failure was caused by a foreseen or foreseeable risk that the responsible party failed to address. Under South African delict principles, the development team, auditors and governance participants can all face claims. An independent security audit, clear risk disclosures and a legally reviewed terms-of-service agreement are the primary mitigation tools. Where a bridge is governed by a DAO, the absence of a legal wrapper can expose individual governance-token holders to joint liability.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, bridge operators and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around those activities. Digital assets are the entirety of our practice. We assess classification against the substance of rights, not the marketing label – and that discipline has been the difference between compliant launches and enforcement exposure for the operators we advise. To discuss your bridge's legal position, contact info@oboluslaw.com.

By Roman Levitt, Technology and DeFi Counsel – specialising in smart-contract liability, cross-chain protocol structuring and DeFi regulatory analysis across common-law and civil-law jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours