EST · MMXXVI
Home/Jurisdictions/United States/Cross-chain bridge legal risk in United States (federal + state MTL)
DeFi, Tokenization & Smart-Contract Law

Cross-chain bridge legal risk in United States (federal + state MTL)

Cross-chain bridge legal risk in United States (federal + state MTL). Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

Cross-chain bridges – infrastructure that locks assets on one blockchain and mints a synthetic equivalent on another – sit at one of the most legally contested positions in United States digital-asset regulation today. A business operating a bridge, or routing material value across one, faces simultaneous exposure under federal money-transmission law, the Bank Secrecy Act, and the money-transmitter licensing (MTL) regimes of every state whose residents use the service. The classification question is not academic: mis-classifying the bridge function can convert a product launch into an unlicensed money-transmission operation or, worse, an unregistered securities offering. This guide maps each exposure layer, describes the compliance path, and identifies the cross-border complications that operators headquartered outside the United States routinely underestimate.

What Is a Cross-Chain Bridge Under US Law?

A cross-chain bridge is a protocol or service that moves economic value between distinct blockchain networks, and under US law the mechanism – not the marketing label – determines whether the operator is transmitting money. FinCEN (the Financial Crimes Enforcement Network), acting under the Bank Secrecy Act, has consistently analysed value-transfer intermediaries by asking whether the operator accepts and transmits value on behalf of another person. A bridge that receives a user's tokens, routes them across networks, and delivers an equivalent amount to a recipient address fits that description even when the underlying code is entirely non-custodial in design.

The distinction between custodial and non-custodial matters less than many developers assume. FinCEN's 2019 guidance on convertible virtual currencies extended money-services business (MSB) treatment to a broad category of value-transfer arrangements, including those mediated by software. A bridge operator that writes, deploys, and operates the bridging mechanism – collecting fees, controlling upgrade keys, or managing validator sets – is not insulated from MSB registration simply because users self-custody their private keys at the start and end of the transaction.

The Travel Rule (the obligation to pass originator and beneficiary data with a transfer) applies to covered financial institutions and MSBs above applicable thresholds. For a bridge operator registered as an MSB, that obligation follows the transfer regardless of chain. The threshold is set qualitatively by the applicable rules; operators should confirm the current de minimis figure with counsel before designing compliance controls.

In our cross-border practice, we see founders treat FinCEN registration as the finish line. It is the starting line. State MTL obligations layer on top, and they apply concurrently.

For a scoped assessment of whether your bridge architecture triggers MSB registration and which states require licensing before you onboard US users, contact OBOLUS at info@oboluslaw.com. The process above describes the standard federal path. Your facts – the entity structure, the user base, the token mechanics – change the state-level analysis materially. Map your options.

The Federal Layer: FinCEN, SEC, and CFTC

Three federal agencies have overlapping jurisdiction over a cross-chain bridge, and each approaches the activity from a different statutory premise. Understanding the three simultaneously is essential; an operator that satisfies FinCEN may still face an enforcement posture from the SEC or the CFTC.

FinCEN / BSA. A bridge operator is almost certainly a money-services business subject to BSA registration, AML program requirements, suspicious activity reporting, and the Travel Rule. Registration with FinCEN is mandatory before the service goes live for US persons. Failure to register is a federal criminal exposure, not merely a civil penalty.

SEC. If either the native token used for bridge incentives or the wrapped asset delivered on the destination chain constitutes a security under the Howey test, the bridge operator may be operating as an unregistered broker, dealer, or exchange. The SEC has signalled that economic substance – the reasonable expectation of profit from the efforts of others – governs, not the label on a whitepaper. A wrapped token that tracks an asset whose value depends on a development team's continued work is a candidate for security classification. This analysis applies independently of the FinCEN question.

CFTC. Where bridge activity facilitates delivery of digital commodities or synthetic derivatives, CFTC jurisdiction is plausible. The CFTC has asserted that Bitcoin and Ether are commodities; a bridge wrapping either into a synthetic derivative instrument could engage the CFTC's anti-fraud and anti-manipulation authority at minimum, and its registration regime in some configurations.

In our practice, we regularly advise bridge teams to map all three federal vectors before launch, not as a sequential checklist but as a concurrent risk matrix. The overlaps are not resolved by picking one agency to satisfy.

State MTL: The Concurrent Licensing Layer

State money-transmitter licensing is the compliance burden that most cross-chain bridge operators underestimate. Forty-nine US states and the District of Columbia maintain independent MTL regimes. Each defines money transmission differently. Each sets its own capital requirements, bonding conditions, net-worth thresholds, and examination cycles. An operator with users in a substantial number of states faces a multi-state licensing programme that is logistically demanding and legally distinct from federal MSB registration.

The NYDFS BitLicense regime in New York deserves separate attention. The BitLicense applies to any business engaged in virtual currency business activity involving New York or New York residents, and its requirements – capital, cybersecurity, AML, consumer protection – are substantially more demanding than most state MTL regimes. A bridge operator that geofences New York users avoids the BitLicense trigger but must document that geofencing rigorously; a single New York user can restart the clock.

Some states have adopted the Money Transmission Modernization Act (MTMA), which creates a degree of harmonisation. Others retain entirely bespoke frameworks. A few states have enacted specific digital-asset or virtual-currency transmission statutes. The practical result is that a nationwide bridge operation requires a licensing programme that is managed as a continuous compliance obligation, not a one-time application. Renewal, examination, reporting and capital-maintenance cycles all run in parallel across multiple jurisdictions.

For an operator domiciled outside the United States, the analysis is territorial, not entity-based. If US persons use the bridge, the MTL exposure follows – irrespective of where the company is incorporated or where the servers are located. We have seen overseas operators assume that an offshore entity structure resolves US state jurisdiction. It does not.

How Does Token Classification Affect Bridge Risk?

Token classification is not a subsidiary question for bridge operators – it is a primary risk multiplier. A bridge that transfers a token classified as a security operates as an unregistered securities-transfer facility unless an exemption applies. The classification analysis runs at each end of the bridge: the origin asset, the wrapped synthetic, and any bridge governance or incentive token may each carry independent legal characterisation.

The applicable test under US federal law is substance over label. A token qualifies as a security if it involves an investment of money in a common enterprise with an expectation of profit from the efforts of others – the formulation established in federal securities jurisprudence and applied by the SEC to digital assets. A utility label on a whitepaper does not settle the question. We assess classification against the actual rights conferred, the economic structure, the degree of reliance on an identified team, and the secondary-market trading patterns that accompany the token.

For bridged assets, the wrapping process can alter the classification analysis. A wrapped version of an asset may carry rights or dependencies that the original does not. Bridge operators should run a fresh classification analysis on every synthetic asset their protocol creates, not merely on the underlying.

Where a bridge token is used for governance or fee distribution, the DAO structure question becomes legally significant. A DAO (decentralised autonomous organisation) that issues governance tokens may itself be characterised as an unincorporated association or general partnership under state law, exposing token holders to joint liability. The legal wrapper chosen for the DAO – a Marshall Islands DAO LLC, a Wyoming DAO LLC, a Cayman foundation, or a Swiss association – affects both securities analysis and enforcement exposure. This question interacts directly with the bridge operator's MTL obligations.

What Does a Bridge Compliance Programme Look Like?

A compliance programme for a US-facing cross-chain bridge is built in phases, and each phase carries a cross-border dimension. The steps below describe the standard path for an operator launching or remediating a bridge that serves US persons.

Step 1 – Architecture review. Before any regulatory filing, counsel and technical advisors map the bridge's custody mechanics, operator controls, upgrade authority, fee flows, and governance structure. The legal analysis cannot precede the technical facts. This review typically takes several weeks and produces a legal memorandum that anchors all subsequent filings.

Step 2 – Federal MSB registration. The operator registers as a money-services business with FinCEN. Registration is self-effecting upon filing; it does not require FinCEN approval. However, registration triggers immediate BSA obligations: an AML program, a compliance officer, SAR/CTR reporting, and Travel Rule controls. These controls must be operational at registration, not months later.

Step 3 – State MTL mapping. Counsel produces a state-by-state nexus analysis based on user geolocation data, the operator's commercial footprint, and each state's jurisdictional triggers. The output is a priority licensing list: states where the operator must be licensed before serving users, states where an exemption may apply, and states where the risk is manageable pending a later application cycle.

Step 4 – Priority state applications. The operator files MTL applications in the highest-priority states. Application timelines vary materially by state – from several weeks in fast-processing states to many months in states with examination-heavy review cycles. Capital posting, bonding, and background investigation requirements run concurrently. The NYDFS BitLicense process is typically the longest and most document-intensive.

Step 5 – Token classification memo. Separately from the MTL programme, counsel prepares a classification analysis for each token in the bridge ecosystem. The memo assesses the Howey factors, the secondary-market conditions, and the governance structure. It informs both the MTL programme and any securities-law disclosure obligations.

Step 6 – Ongoing maintenance. State licences require annual renewal, periodic examination, material-change notifications, and capital-maintenance certificates. The BSA programme requires annual independent testing. The compliance programme is not a project; it is a standing function.

In our practice, we regularly advise bridge operators at Steps 3 and 4 who launched without completing Steps 1 and 2. Remediating that sequence is possible but more complex than building it correctly at the outset.

Cross-Border Complications for Non-US Operators

For a bridge operator incorporated outside the United States, the threshold question is whether US persons are being served. If they are, federal and state US law applies to that activity regardless of the operator's domicile. The IP-geofencing of US persons is a partial mitigation, not a complete answer; it must be technically rigorous, consistently enforced, and documented.

Non-US operators face a secondary complication: their home-jurisdiction licence does not substitute for US authorisation. An operator holding a MiCA CASP authorisation in an EU member state, a MAS DPT service licence in Singapore, or a VARA licence in Dubai has satisfied the requirements of those regimes. None of those licences operates as a passport into the United States. The US MTL and MSB obligations are entirely separate and must be met independently.

Banking access compounds the issue. US correspondent banks that process USD settlements for bridge-related flows will apply Bank Secrecy Act due diligence to the bridge operator. An operator without FinCEN registration and credible AML controls will find those relationships difficult to establish or maintain. The licensing programme and the banking programme must be built in parallel, not sequentially.

Tax obligations intersect as well. A non-US operator with US users may have US federal income tax nexus, depending on the structure of the entity and the nature of its activities. The interaction between the MTL programme and US tax obligations – particularly whether bridge fees constitute US-source income – is a structuring question that should be addressed before the licensing programme is designed, not after.

For operators sitting between the EU and the US, or between Asia-Pacific hubs and the US, we work alongside allied counsel in the relevant jurisdictions to ensure that the US compliance build does not conflict with obligations already in place in the home jurisdiction. We have seen US AML programme requirements and EU data-protection obligations create genuine tension in the Travel Rule data-sharing context; resolving that tension requires input from both sides of the engagement.

If a prior US MTL application stalled, or a banking relationship was closed on regulatory grounds, a second structural read can surface the reason and the route back. Write to OBOLUS at info@oboluslaw.com. Map your options.

A Micro-Matter: Bridge Remediation in Practice

In a recent matter, a cross-chain bridge operator incorporated in a non-US jurisdiction had been serving US users for several months without FinCEN MSB registration or any state MTL. The operator's banking partner initiated an account review after identifying bridge-related flows and requested evidence of US regulatory authorisation. We conducted an architecture review, filed MSB registration on an expedited basis, and produced a state nexus analysis that identified three priority states requiring immediate application. We also prepared a token classification memo for the bridge's governance token, which informed the operator's disclosure posture going forward. The banking relationship was preserved following submission of the compliance documentation. The full remediation programme – from instruction to the first state licence filing – was completed within a matter of weeks.

Decision Matrix: Which Operator Profile Faces Which Risk?

Bridge operators are not a single category. The legal risk profile varies materially by operational structure, and the compliance path differs accordingly.

Profile A – Fully decentralised, no identifiable operator. A bridge governed entirely by on-chain smart contracts, with no controlling team, no fee capture, and no upgrade authority, sits at the outer edge of the FinCEN MSB analysis. The argument that there is no "person" to register is legally available but untested in enforcement. The risk is that regulators identify a founding team or foundation as the de facto operator and apply MSB treatment retrospectively. This profile should seek legal opinion before launch, not after an enforcement inquiry arrives.

Profile B – Protocol with a named development team and governance token. This is the most common profile. The team deployed the bridge, controls the upgrade keys, and receives fees through a treasury. FinCEN MSB registration is the expected baseline. State MTL applications in priority states are required before US users are onboarded. The governance token requires a Howey analysis. Timeline to a compliant launch – including priority state licences – is typically measured in months, not weeks.

Profile C – Institutional bridge operated by a licensed entity. An operator that already holds a state MTL or BitLicense in key states, and that has an existing BSA programme, faces a narrower gap. The compliance work centres on extending the existing programme to cover the bridge activity, updating the token classification analysis, and notifying state regulators of the new activity where required. This profile moves fastest.

Profile D – Non-US operator expanding into the US. This profile combines the compliance build of Profile B with the cross-border structuring questions described above. The US entity structure, tax nexus analysis, and banking programme must be designed before the MTL applications are filed. Allied counsel in the home jurisdiction should be coordinated from the outset. Timeline is longer than Profile B, and the banking programme often determines the critical path.

A common assumption among bridge developers is that a sufficiently decentralised protocol – one governed by a DAO, operated by community validators, and accessible only through open-source front-ends – escapes the US regulatory perimeter entirely. That assumption is not consistent with the current enforcement posture of US regulators.

FinCEN's guidance does not exclude non-custodial or decentralised architectures as a category. The SEC has brought enforcement actions against DeFi protocols on securities and broker-dealer grounds. The CFTC has asserted jurisdiction over decentralised derivative platforms. The Department of Justice has pursued criminal charges against developers of privacy protocols on the basis that the code, knowingly deployed to facilitate money laundering, constituted unlicensed money transmission.

Decentralisation is a spectrum, and regulators assess it on the facts at each point along that spectrum. A founding team that retains admin keys, earns protocol revenue, or guides governance proposals is not legally invisible simply because the smart contracts are publicly deployed. The smart contract is a legal instrument; who wrote it, deployed it, and profited from it remains legally relevant.

Operators we advise are consistently counselled to document the governance structure, the distribution of upgrade authority, and the fee-capture mechanics before making any decentralisation argument to a regulator. An undocumented claim of decentralisation is not a defence; a well-documented governance structure that supports the claim is a different matter entirely.

Related at OBOLUS

FAQ

Can a DeFi protocol be regulated?

Yes. US regulators – FinCEN, the SEC, and the CFTC – apply existing statutory frameworks to DeFi protocols based on the economic function of the activity, not the label attached to it. A protocol that facilitates money transmission, operates as a broker or exchange, or deals in commodity derivatives is subject to the relevant registration and compliance obligations regardless of its on-chain architecture. The degree of decentralisation is a factual question that affects but does not eliminate regulatory exposure.

What legal wrapper suits a DAO?

The right legal wrapper depends on the DAO's activity, its token structure, and the jurisdictions in which it operates. Common options include Wyoming DAO LLCs, Marshall Islands DAO entities, Cayman foundations, and Swiss associations, each with distinct liability, tax, and securities-law implications. There is no universal answer. The wrapper must align with the DAO's governance mechanics and its regulatory posture in each active market. Counsel should assess the interaction between the chosen structure and any US money-transmission or securities exposure.

Who is liable when a smart contract fails?

Liability for a smart-contract failure turns on who deployed the contract, what representations were made to users, and whether the loss resulted from a code defect, an exploit, or an operational decision by an identifiable party. Developers, foundations, and DAOs can all face liability under US tort, contract, and securities law depending on the facts. Governance token holders may carry exposure as members of an unincorporated association. A well-drafted legal wrapper, clear risk disclosures, and documented governance processes are the primary mitigation tools.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – and we work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology and DeFi Counsel – specialising in smart-contract legal risk, bridge and protocol compliance, and DeFi regulatory exposure for US and cross-border operators.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours