Turkey sits at a regulatory inflection point for digital assets. The country operates one of the largest retail crypto markets in the world by volume, yet its legislative framework for token distribution – including airdrops (distributions of tokens to wallets, typically at no direct monetary cost to the recipient) – has evolved rapidly and continues to tighten. A business planning to run an airdrop with Turkish recipients, or a Turkish-incorporated entity distributing tokens abroad, must answer a threshold question before the first token moves: does this distribution trigger securities, capital-markets or payment-services obligations under Turkish law, and how does that interact with the cross-border regimes that govern the issuer's home jurisdiction?
The answer turns on substance, not label. Turkey's capital-markets regulator, the Capital Markets Board (Sermaye Piyasası Kurulu, or CMB), asserts jurisdiction over instruments that confer investment rights – regardless of whether the issuer calls them tokens, coins, or utilities. An airdrop of tokens that carry profit-participation, governance rights linked to economic outcomes, or redemption expectations can be treated as an offering of capital-markets instruments, triggering registration, prospectus and investor-protection obligations. This page sets out how we structure airdrop programmes for clients with Turkish exposure, what the cross-border interaction with MiCA, banking and tax looks like, and where the real decision points sit.
The Turkish regulatory environment for token distribution
Turkey's primary digital-asset legislative instrument – the framework enacted under the Capital Markets Law amendments and the subsequent CMB communiqués – places crypto-asset service providers under mandatory registration and subjects token offerings to regulatory scrutiny. The CMB has explicit authority to assess whether a token constitutes a capital-market instrument and to take enforcement action against unregistered offerings directed at Turkish investors.
The key structural reality is this: the CMB does not defer to the issuer's own characterisation. A whitepaper that labels a token "utility" does not insulate the issuer from a securities analysis. The analysis turns on the rights the token actually confers. Does it give holders a claim on profits, revenues or assets? Does governance participation translate into economic benefit? Is there a reasonable expectation of appreciation based on the issuer's efforts? If yes to any of those questions, the CMB's capital-markets perimeter is engaged.
Airdrops are not categorically exempt. A distribution of tokens at zero monetary cost can still constitute an offering if the tokens themselves are capital-market instruments. The CMB's approach tracks the substance-over-form principle common across G20 regulators. In our cross-border practice, we regularly advise issuers who assume that "free" distribution avoids securities law – it does not, when the token carries investment characteristics.
Additionally, Turkey's anti-money-laundering and payment-services rules apply to entities facilitating token transfers. Turkish-registered exchanges and wallet providers that support an airdrop distribution face their own compliance layer, separate from the issuer's obligations.
How token classification works in Turkey
Token classification under Turkish law follows a functional analysis: the regulator looks at what the token does, not what the issuer says it does. The CMB applies a test broadly analogous to the investment-instrument analysis used in other major markets, asking whether the token represents a transferable right with economic value that derives from a third party's efforts.
Three broad categories emerge in practice:
- Payment tokens – tokens used purely as a medium of exchange, with no embedded investment right. The cleanest structure for an airdrop; still subject to AML and payment-services rules where applicable.
- Utility tokens – tokens granting access to a product or service, where the value is tied to use rather than investment. Classification holds only if the right is genuinely functional and not speculative at the distribution point.
- Security-equivalent tokens – tokens conferring investment rights, profit participation or governance with economic effect. These fall within the CMB's capital-markets perimeter, requiring authorisation before any offering or distribution to Turkish persons.
The boundary between utility and security is fact-specific. A token that grants "access" to a platform but whose value tracks the platform's revenue is unlikely to survive a utility-only analysis. We have seen enforcement postures across the major jurisdictions harden on exactly this point. The CMB's approach reflects a global trend: form does not bind substance.
For airdrop structuring purposes, classification is the foundational step. It determines whether the distribution is a regulated offering, whether a whitepaper is required, whether Turkish-resident recipients can be included at all without triggering registration, and how the token must be described in any marketing or on-chain metadata.
What does an airdrop actually trigger under Turkish law?
An airdrop that distributes a security-equivalent token to Turkish-resident wallets triggers the CMB's offering regime – and doing so without authorisation constitutes an unregistered public offering. The consequence is not administrative only: Turkish enforcement has civil and criminal dimensions, and the CMB can refer matters to prosecutors.
Even for utility or payment tokens, the airdrop mechanic interacts with Turkey's AML framework. An entity that systematically transfers value – including tokens – to Turkish persons may be treated as operating a payment service without authorisation if it lacks the appropriate registration. The relevant threshold is whether the activity constitutes a "payment service" under the Turkish payment-services regulatory perimeter, which is broadly drawn.
There is a further layer specific to the cross-border operator. If a non-Turkish entity structures an airdrop that targets Turkish users – through localised marketing, Turkish-language communications, or Turkish social-media channels – the CMB may assert territorial jurisdiction on the basis of the distribution's effects in Turkey. The "effects doctrine" is not codified in precise terms, but CMB enforcement practice demonstrates a willingness to reach offshore issuers whose tokens are clearly directed at domestic retail participants.
In our practice, we map every airdrop against three trigger points: (1) token classification, (2) geographic scope of distribution, and (3) the marketing and eligibility mechanics. All three must be clean before the structure is viable.
To pressure-test your token structure before the first wallet receives a token, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analysis. Your token's specific rights matrix – the entity, the user base, the distribution mechanic – changes the answer materially.
How should an airdrop be structured to manage Turkish legal risk?
Structuring a legally defensible airdrop with Turkish exposure requires four interconnected decisions: entity positioning, token design, distribution mechanics and jurisdiction of offering.
Entity positioning. The issuing entity should be incorporated in a jurisdiction with a clear token-offering or CASP regime – a CASP (crypto-asset service provider) authorisation under MiCA in the EU, a registered entity under the Singapore Payment Services Act, or a licensed entity in a recognised offshore hub. Turkish law applies to the distribution's effects in Turkey; it does not automatically prohibit a non-Turkish entity from issuing, so long as that entity does not direct its offering at Turkish residents in a way that triggers the CMB's jurisdiction.
Token design. At the design stage, we work through the rights matrix in detail. Governance rights must be genuinely non-economic or structured so that the governance function does not translate into investment return. Access rights must be operationally real and not merely nominal. Any vesting or cliff mechanic that creates an expectation of appreciation based on issuer effort is a red flag under every jurisdiction's securities analysis.
Distribution mechanics. The airdrop eligibility criteria, the wallet-filtering process, and the geo-blocking implementation determine whether Turkish-resident wallets receive tokens. If the issuer intends to include Turkish recipients, it must either (a) obtain CMB authorisation for the offering if the token is security-equivalent, or (b) structure the token to sit cleanly outside the capital-markets perimeter and document that analysis. Geo-blocking that excludes Turkish-resident wallets – based on IP, KYC data, or on-chain wallet screening – is a recognised risk-management tool, but it must be implemented effectively, not nominally.
Jurisdiction of offering. If the issuer is MiCA-authorised in the EU, the whitepaper and offering regime under MiCA apply. MiCA's whitepaper obligations require the issuer to publish a compliant whitepaper before any offer to the public or admission to trading. Turkey is outside the EU; MiCA does not directly apply to Turkish-resident recipients. But an MiCA-compliant structure signals regulatory maturity and reduces the CMB's risk appetite for enforcement action against a well-documented, EU-authorised offering.
Cross-border interaction: tax and banking
The Turkish tax treatment of received tokens is unsettled and evolving. Turkish recipients of airdropped tokens may face personal income-tax obligations on the fair-market value of tokens received, depending on the classification and the recipient's tax status. For the issuer, the cross-border picture turns on the issuer's home jurisdiction and the structure of the distribution.
Banking is the practical chokepoint for many token issuers with Turkish operations. Turkish banks have been cautious in their exposure to crypto-adjacent businesses, and an entity operating a large-scale airdrop with Turkish treasury management may encounter account scrutiny or closure if the banking relationship is not properly documented. In our cross-border practice, we advise issuers to establish their banking relationships in a jurisdiction where the bank's compliance team understands token distributions – typically a major European, Singaporean or UAE banking relationship – and to maintain Turkish banking (if any) for operationally distinct purposes.
VAT treatment of token distributions in Turkey should be assessed on a transaction-by-transaction basis. Where no consideration passes, there may be no supply for VAT purposes; but where the airdrop is linked to a prior or concurrent obligation (a retrospective reward, a staking incentive), Turkish revenue authorities may treat it as consideration for a service. The VAT analysis is jurisdiction-specific and should be confirmed with tax counsel in Turkey for each programme design.
The interaction between Turkey's foreign-exchange control rules and token distributions is a further structural consideration. Turkey maintains foreign-exchange restrictions that, depending on the token's characterisation, may engage reporting or authorisation obligations for Turkish entities involved in the distribution chain.
Does MiCA apply, and what is the whitepaper obligation?
MiCA does not apply directly to Turkish-resident recipients or Turkish-incorporated issuers. Turkey is not an EU member state and has not adopted MiCA. However, MiCA is structurally relevant to any issuer with an EU entity, EU users, or EU banking relationships – and most serious token issuers distributing at scale have at least one of those three connections.
Under MiCA, a CASP authorisation grants passporting rights across all EU/EEA member states. An issuer who has obtained CASP authorisation in one member state – Lithuania, Malta, and other EU jurisdictions are commonly used – can offer tokens across the EU without separate national approvals. The whitepaper required under MiCA must be published before any public offer or admission to trading; the regime distinguishes between asset-referenced tokens (ARTs), e-money tokens (EMTs), and other crypto-assets, each carrying different obligations.
For a Turkish-facing airdrop, the structural question is whether the issuer can design the programme so that the EU-regulated entity handles the MiCA-compliant aspects of the offering while the Turkish-facing component is either excluded or structured separately under a clean utility analysis. This dual-track approach is common in our practice. It requires careful documentation of the boundary between the EU offer and the Turkish distribution.
Where a client has an EU-domiciled entity and a Turkish user base, we regularly advise on the architecture of the offering: which entity issues, which entity distributes, where the whitepaper is filed, and how the geo-restrictions are engineered. The goal is a structure that is clean under MiCA for EU purposes and defensible under Turkish law for the Turkish-facing component.
If your prior airdrop structure stalled at the whitepaper or geo-restriction stage, or your bank flagged the programme, a second look can often identify the structural correction. Reach us at info@oboluslaw.com. We have worked through the MiCA/Turkey interface on programmes at multiple stages of completion.
Decision matrix: which profile should use which structure
Not every airdrop carries the same risk profile. The right structure depends on the token's rights matrix, the issuer's jurisdictional position, and the intended recipient base. Three profiles dominate the instructions we receive.
Profile A – EU-incorporated issuer, MiCA-track, Turkish users excluded. The issuer holds or is pursuing CASP authorisation in a member state. The airdrop is designed for EU and select non-EU markets. Turkish-resident wallets are geo-blocked at the IP and KYC eligibility layers. The applicable regime is MiCA; the whitepaper is prepared and filed before distribution; the Turkish risk is managed by exclusion rather than authorisation. Timeline to a distribution-ready structure: typically a matter of weeks for the Turkish exclusion mechanics once the MiCA whitepaper is in process. Key risk: nominal geo-blocking that fails at implementation.
Profile B – Non-EU issuer, utility-token analysis, selective Turkish inclusion. The issuer is incorporated outside the EU – in Singapore, the BVI, Cayman or a similar hub. The token is designed as a genuine utility token. Turkish recipients are included, but on the basis of a documented legal analysis concluding that the token sits outside the CMB's capital-markets perimeter. The issuer registers with the relevant home-jurisdiction regulator under the applicable VASP provisions (whether under the BVI FSC's VASP Act, CIMA's VASP regime, or MAS's Payment Services Act). The Turkish analysis is documented in a legal opinion. Timeline: varies by issuer complexity and home-jurisdiction registration status. Key risk: a rights-matrix change post-distribution that retrospectively moves the token into security territory.
Profile C – Turkish-incorporated entity, domestic offering. The issuer is Turkish and intends a domestic distribution. The CMB's full suite of capital-markets obligations applies if the token is security-equivalent. The issuer must either obtain CMB authorisation or design the token to sit outside the capital-markets perimeter and document that position. Banking and AML compliance are managed through Turkish-registered intermediaries. Timeline: CMB engagement is a multi-stage process; expect a structuring and documentation phase before any regulatory interaction. Key risk: proceeding on a utility assumption without a documented legal analysis.
In practice: a cross-border airdrop with Turkish overlap
In a recent structuring matter, a DeFi protocol incorporated in a leading offshore hub planned a large-scale token distribution across multiple markets, including Turkey. The protocol had designed its governance token with economic voting rights tied to protocol fee revenue. We assessed the token against both the CMB's investment-instrument analysis and the applicable VASP provisions in the issuer's home jurisdiction. The conclusion was that the token's fee-sharing mechanic placed it squarely within the capital-markets perimeter for Turkish-law purposes. Rather than seek CMB authorisation for a speculative timeline, we restructured the governance rights to remove the economic linkage, added a genuine utility layer, and implemented a KYC-gated eligibility filter that excluded Turkish-resident wallets from the initial distribution. The protocol reserved a separate Turkish-facing tranche for a later date, pending a formal legal opinion. The distribution completed in the subsequent quarter without regulatory challenge. The restructuring required approximately three weeks of intensive drafting and eligibility-system engineering.
Self-assessment checklist before your airdrop
Before instructing counsel or proceeding to distribution, issuers with Turkish exposure should work through the following questions. A "yes" to any of the flagged items signals that legal structuring work is required before tokens move.
- Does the token grant profit-participation, revenue-sharing or any economic return based on the issuer's efforts? (Flag: security analysis required.)
- Does governance participation translate into an economic benefit for token holders? (Flag: security analysis required.)
- Are Turkish-resident wallets included in the eligible recipient set? (Flag: Turkish legal analysis required.)
- Has the issuer published marketing or eligibility communications in Turkish? (Flag: CMB territorial jurisdiction risk.)
- Is the issuer MiCA-authorised, and has a compliant whitepaper been prepared? (Flag: MiCA obligations must be satisfied before EU-facing distribution.)
- Has the banking relationship supporting the airdrop been reviewed for crypto-compliance tolerance? (Flag: account risk without proactive bank communication.)
- Has a VAT and foreign-exchange analysis been obtained for the Turkish-facing component? (Flag: tax and FX risk without jurisdiction-specific advice.)
Related at OBOLUS
- Token Offerings and Securities – Cross-border securities law and token classification for digital-asset businesses
- How to Structure an Airdrop Legally – Step-by-step guide to legally defensible airdrop design across jurisdictions
- VARA Licence Application in the Bahamas – Licensing strategy for token issuers and exchanges in a leading offshore hub
FAQ
Is my token a security?
Whether a token is a security turns on the rights it confers, not its label. Regulators – including Turkey's CMB and counterparts in the EU, Singapore and the US – apply a functional test: does the token carry investment rights, profit participation or an expectation of return based on the issuer's efforts? A token called a "utility token" that grants revenue-linked governance rights will be treated as a security in most major markets. Classification must be documented in a legal opinion before any distribution.
Do I need a MiCA whitepaper?
If your issuer is EU-incorporated or your airdrop is directed at EU-resident recipients, MiCA's whitepaper regime applies before any public offer or admission to trading. Turkey is outside the EU, so MiCA does not directly govern a purely Turkish distribution. However, most cross-border token programmes touch EU users or entities, making MiCA compliance structurally necessary. The whitepaper requirements differ by token type – asset-referenced tokens, e-money tokens and other crypto-assets each carry distinct obligations under MiCA.
How should an airdrop be structured legally?
A legally defensible airdrop requires four decisions made in sequence: token classification, entity positioning, distribution mechanics and geographic eligibility. Classification determines which regulatory perimeters are engaged. Entity positioning determines which home-jurisdiction regime governs the offer. Distribution mechanics – KYC gating, geo-blocking, vesting parameters – implement the legal conclusions operationally. Geographic eligibility defines which recipients are included and on what legal basis. All four layers must be consistent. We assess classification against the substance of rights, not the marketing label.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label – a discipline that matters when a regulator asks the question. To discuss your airdrop structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Roman Levitt, Technology and DeFi Counsel – specialising in token design, smart-contract legal architecture and cross-border digital-asset structuring for protocol issuers and Web3 businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.