Token Offerings & Securities for Digital-Asset Businesses
Mis-classifying a token can convert a product launch into an unregistered securities offering overnight. That risk is not theoretical. Regulators across the EU, the United States, the United Kingdom, Singapore and the UAE have each moved to assert jurisdiction over token sales they characterize as unregistered capital-raising. For any business issuing tokens to investors or users – whether as a fundraising instrument, a network-access mechanism or a synthetic claim on an underlying asset – the legal classification question is the first one to answer, not the last. This page sets out the regulated perimeter, maps the instruments available, addresses the cross-border reality, and explains when and why to engage specialist counsel.
Token classification under the applicable regime determines disclosure obligations, investor-protection rules, licensing requirements and criminal exposure. The analysis turns on the substance of what a token does – the rights it confers, the expectations it creates and the economic reality it produces – not on the label a whitepaper applies to it. A well-structured token offering, designed from the outset around the classification question, reaches investors and secondary markets faster, at lower legal cost, and without the regulatory clean-up that follows a mis-timed launch.
What Is the Regulated Perimeter for Token Offerings?
The regulated perimeter for token offerings spans securities law, e-money regulation, banking rules and, in the EU, the dedicated MiCA regime (the Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities). Most jurisdictions maintain three or more overlapping regulatory triggers that a single token sale can activate simultaneously. Identifying which triggers apply – and in which sequence – is the first task of a structured legal engagement.
At the broadest level, the core question is whether a token constitutes a transferable security, a unit of e-money, a payment instrument or an asset-referenced instrument. Each classification carries a distinct regulatory track. In the United States, the SEC and CFTC apply their respective jurisdictions across the securities/commodity divide. In the EU, MiCA creates three token-specific regimes: asset-referenced tokens (ART), e-money tokens (EMT), and a residual category of other crypto-assets subject to lighter but still mandatory obligations. Tokens that fall outside MiCA's residual category because they qualify as financial instruments remain under existing EU financial-services law.
The FCA in the United Kingdom applies its own classification logic under the existing Regulated Activities Order, with cryptoasset financial-promotion rules layered on top. VARA in Dubai and the FSRA within ADGM each operate activity-based licensing regimes that reach token-related activities. The MAS in Singapore applies its Payment Services Act to digital payment tokens, while the SFC in Hong Kong licenses virtual-asset trading platforms that handle tokens with securities characteristics.
The practical result: a single token sold to users in more than two or three jurisdictions will touch multiple regulators. The regulated perimeter is not the perimeter of any one regime. It is the union of all the regimes that claim reach over your token, your users and your entity.
The first structural decision is therefore jurisdictional: where the issuing entity sits, where the token is offered and where secondary trading occurs each attracts a distinct regulatory claim. In our practice, we map those claims before any whitepaper is drafted.
Contextual note for the reader approaching this issue for the first time: the process above describes the standard classification path. Your specific facts – the entity's home jurisdiction, the nature of the rights attached to the token, the target investor base, the distribution mechanism and the banking structure – change the analysis materially. To scope the classification and disclosure work for your offering, contact OBOLUS at info@oboluslaw.com or map your options with us directly.
How Is a Token Classified? The Substance-Over-Label Test
Token classification is a substance-over-label analysis: every major regulatory system looks through the marketing description to the economic reality and legal rights the token actually confers. A utility label on a whitepaper does not settle the classification question; it is evidence only of the issuer's intent, not of the token's legal character.
The operative questions vary by regime but converge on a small set of core inquiries. Does the token give the holder a right to a share of profits or revenues? Does it represent a debt claim against the issuer? Does its value derive primarily from the efforts of a third party? Does it function as a medium of exchange pegged to a reference asset? Each affirmative answer shifts the classification toward a regulated instrument.
In our cross-border practice, we apply a structured classification matrix across the jurisdictions where the token will be offered. The exercise is not purely academic. An incorrect classification, discovered by a regulator after the token trades on secondary markets, can trigger a requirement to register the offering retroactively, suspend the token's trading on licensed platforms, and expose the issuer and its directors to civil and criminal enforcement. We have seen businesses in the secondary phase of a successful token program face precisely this scenario – remediation at that stage is possible but orders of magnitude more expensive than front-loading the analysis.
Three classification profiles recur in our practice:
Profile A – the governance/utility token. Rights are limited to participation in a protocol or access to a specific service; no revenue or profit entitlement; no exchange-rate peg. Under most regimes this falls in the residual crypto-asset category or outside the regulated perimeter entirely, subject to how the token is marketed and whether investment-expectation language appears in any communications. Timeline to a clean classification opinion: relatively short, measured in weeks. Key risk: secondary-market trading patterns that transform the holder profile toward investors rather than users.
Profile B – the revenue-sharing or profit-participating token. The holder receives a contractual or economic entitlement to a stream of cash flows. Under the SEC's long-standing analytical framework, under MiCA's financial-instrument carve-out and under the SFC's approach in Hong Kong, this instrument is likely to qualify as a security or a regulated financial instrument. Timeline to compliant launch: significantly longer; a registered or exempted offering structure is required. Key risk: marketing the token as a utility instrument to bypass registration, which compounds the enforcement exposure.
Profile C – the stablecoin or asset-referenced token. The token's value is stabilized by reference to a currency, commodity or basket. Under MiCA, an ART (asset-referenced token) or EMT (e-money token) triggers issuer authorization, reserve and redemption obligations, and, where the token is significant, enhanced ESMA oversight. The FSRA in ADGM and VARA in Dubai each impose parallel stablecoin-specific authorization requirements. Key risk: launching under a private-label brand without obtaining the applicable authorization before distribution commences.
The classification result is never permanent. Token functionality evolves. A governance token that adds a fee-sharing mechanism mid-program crosses a classification boundary. We advise clients to build a classification review into any material change to token economics.
When Does MiCA Require a Whitepaper – and What Must It Contain?
Under MiCA, a whitepaper (the mandated disclosure document for a crypto-asset offering to the public in the EU/EEA) is required for most token offerings that target EU residents and fall within the regulation's scope. The obligation attaches to the offeror, whether the issuer is incorporated in the EU or not. A non-EU issuer offering tokens into EU member states triggers MiCA's whitepaper obligation in the same way a European issuer does.
MiCA distinguishes disclosure requirements across its three token categories. For the residual "other crypto-assets" category, the whitepaper must be notified to the relevant national competent authority and published before the public offer begins. The whitepaper is not a prospectus in the traditional securities-law sense: it does not require pre-approval by the NCA for most crypto-asset categories. It does, however, give rise to civil liability for misleading or materially incomplete statements. For ART and EMT issuers, the authorization requirement comes before the whitepaper; the document is part of a more extensive regulatory filing.
Mandatory whitepaper content under MiCA covers the identity of the issuer and any offeror, the nature of the crypto-asset, the rights and obligations attached to it, the underlying technology, the risks and the financial information relevant to the issuer's ability to honor its obligations. The document must be accurate, clear and not misleading. It must not contain a forward-looking statement that is presented as a guarantee.
One design consideration we consistently raise with clients: the whitepaper and the token's technical documentation must be aligned. Inconsistency between the on-chain mechanics of the token and the rights described in the whitepaper is not merely a drafting problem – it is a mis-statement that creates liability. We draft whitepapers in parallel with technical specifications, not after them.
For operators considering EU distribution as part of a multi-jurisdiction rollout, the MiCA whitepaper can serve as a disclosure backbone that other jurisdictions' requirements are layered onto. The UK FCA has its own disclosure expectations for cryptoasset financial promotions; Singapore's MAS applies a different standard for digital payment token advertising. A well-structured MiCA whitepaper, appropriately adapted, provides a strong foundation for those parallel requirements.
How Are Cross-Border Token Offerings Structured?
A cross-border token offering requires a legal structure that matches the entity, the offering mechanics and the investor base across each applicable jurisdiction – and those three things rarely align by default. The structural work begins with the entity question.
The issuing entity's home jurisdiction determines the initial regulatory gate. EU member states offer MiCA passporting for CASP authorizations, meaning a CASP authorized in one state can passport its services across the EU/EEA. That passporting mechanism does not extend automatically to a token offering conducted by the same entity; the whitepaper obligation is assessed offer by offer, not entity by entity. Operators we advise routinely run the following question early: should the token be issued by the operating entity, a dedicated SPV or a foundation? Each answer produces a different liability, tax and regulatory profile.
For offerings that will reach US persons, the securities-law analysis under the applicable federal framework is unavoidable. The core question is whether the offering can qualify for an exemption from registration – and if so, whether restrictions on secondary transfers are commercially acceptable. Many issuers choose to structure a US-restricted tranche alongside an offshore or EU-compliant tranche, with transfer restrictions engineered at the smart-contract level to limit US-person participation. We have seen this dual-tranche approach work well where the issuer's primary market is outside the United States; it requires careful legal coordination between the US counsel and the offshore-counsel team.
The interaction between token offerings and banking is a recurring friction point. Banks in every major jurisdiction apply enhanced due diligence to accounts used to receive proceeds from token sales. Structuring the banking relationship before the sale – including the jurisdiction of the account, the Know-Your-Customer process applied to investors and the segregation of offering proceeds – materially reduces the risk of account closure mid-offering. In our practice, we engage banking counsel at the same time as securities counsel, not as an afterthought.
For operators sitting between a Dubai entity under VARA and an EU-distributed offering under MiCA, the legal question turns on which regulatory system governs the issuer, which governs the offeror and which governs the exchange on which the token will trade. Those three can be in three different jurisdictions. We map the interaction before the term sheet is drafted.
If your offering structure involves multiple jurisdictions and a secondary-market ambition, the structural decisions made now determine the regulatory surface area you will carry for the life of the token. To pressure-test your structure before you commit, message us via t.me/oboluslaw or map your options.
How Does Securities Law Interact With a Token Launch?
Securities law reaches a token launch whenever the token, the offering mechanics or the communications surrounding the sale satisfy the conditions for a security under the applicable regime – and those conditions are assessed by each jurisdiction independently. A token that is not a security under Singapore's Payment Services Act framework may simultaneously be a security under the UK Financial Services and Markets Act and a note or investment contract under US federal law.
The multi-jurisdictional securities-law exposure is not neutralized by a choice-of-law clause in the token purchase agreement. Each regulator applies its own territorial and effects-based tests. The UK FCA's financial-promotion regime applies to communications that reach UK persons regardless of where the communication originates. The SEC's historical position on offers and sales of securities "by any person" to US persons is similarly extraterritorial in practice. ESMA and national competent authorities under MiCA apply the whitepaper obligation to any public offer in the EU/EEA, irrespective of issuer domicile.
The securities-law exposure of a token offering is therefore not defined by a single jurisdiction's test. It is the aggregate of all the tests that apply. In a recent advisory matter involving an early-stage token program designed for institutional investors, we identified four distinct regulatory triggers across three jurisdictions – triggers that the client's initial legal review, conducted within a single jurisdiction, had not surfaced. The structural modification required to address them added two weeks to the timeline but avoided a post-launch enforcement problem.
One objection we frequently hear: "We consulted our corporate lawyer and they said it was fine." Corporate lawyers in non-specialist practices typically apply a single jurisdiction's test. They do not always have visibility into the FCA's financial-promotion perimeter, the MiCA whitepaper obligation as applied to non-EU issuers, or the VARA activity-based framework in Dubai. The securities-law analysis for a token offering is multi-jurisdictional by nature. Single-jurisdiction sign-off is not sufficient where the token will trade on a public market accessible from multiple countries.
How Should Airdrop and Distribution Mechanics Be Structured?
An airdrop (a distribution of tokens to wallet addresses without direct monetary payment) is not legally neutral simply because no purchase price changes hands. The absence of a direct sale price does not remove the distribution from the regulated perimeter. The analysis turns on whether the airdrop constitutes a transfer of value to the recipient, whether it creates investor expectations and whether it is tied to a prior or anticipated investment relationship.
Under MiCA, an airdrop that is truly gratuitous – no purchase, no service, no prior or conditional expectation – may fall outside the whitepaper obligation. However, the line between a gratuitous airdrop and a promotional distribution tied to a broader capital-raise is narrow. Where the airdrop is the means of distributing tokens to early investors, community participants or work contributors who received their allocation in lieu of cash payment, the regulatory analysis shifts materially. Regulators in several leading hubs have begun to scrutinize airdrop mechanics as a vector for distribution to investors without the protections a formal offering would carry.
In terms of practical structuring, the key design variables are: who receives the airdrop, on what terms, whether any eligibility condition creates an investment-expectation nexus, and whether the airdrop is combined with a liquidity event that allows immediate conversion to cash. Each variable changes the regulatory exposure. We structure airdrop programs with a written legal opinion on classification before the distribution occurs, and with transfer-restriction logic where the recipient profile suggests potential securities-law exposure.
The tax treatment of airdrops is a separate and parallel question. In most jurisdictions, receipt of an airdrop triggers a taxable event, even in the absence of a purchase. We address the tax dimension alongside the regulatory analysis, not in a separate engagement that arrives after the distribution mechanics are already set.
What Are the Most Common Legal Mistakes in Token Offerings?
The most consequential mistakes in token offerings are structural, not documentary. They are made before the first draft of a whitepaper and they persist through the life of the token.
The first is the classification assumption. Founders often proceed on the basis that their token is a utility token because it is designed to access a product. That design intent is relevant but not determinative. If the token was sold before the product existed, to investors who expected the token's value to increase, the classification analysis may produce a different result than the design intent suggests. We assess classification against the substance of rights and the economic reality of the distribution – not the marketing label.
The second common error is single-jurisdiction analysis. As noted above, a token that reaches users or secondary markets in more than one jurisdiction activates multiple regulatory regimes. Receiving a clean opinion from a single-jurisdiction lawyer does not satisfy the regulatory exposure in the other jurisdictions that assert reach over the offering.
The third error is decoupling the legal and technical teams. Whitepapers drafted by legal counsel in the absence of the engineers produce documents that describe token mechanics that the smart contract does not actually implement. The resulting inconsistency is a mis-statement that creates liability under MiCA and equivalent regimes. In our practice, we treat the whitepaper and the technical specification as a single document for review purposes.
The fourth error – underestimated even by experienced operators – is the banking risk. Proceeds from token sales deposited into accounts that were not configured with the bank's prior knowledge of the offering frequently trigger suspicious-activity reviews. Account freezes mid-offering are disruptive at best and fatal to the program at worst. We advise clients to complete banking compliance before the offering opens.
A common assumption among token issuers at the growth stage is that the regulatory exposure diminishes once the token is live and widely traded. The opposite is often true. A token with broad secondary-market distribution has a larger regulatory surface area than a freshly launched one. Any material change to token economics after launch – a fee-sharing mechanism, a buyback program, a governance modification that increases economic rights – re-opens the classification question.
If a prior application stalled, an exchange refused to list, or a bank account was closed in connection with a token program, a second review can surface the structural reason and the route forward. Contact OBOLUS at info@oboluslaw.com or map your options.
Which Offering Structure Fits Your Profile?
No single offering structure is optimal across all operator profiles. The right instrument depends on the issuer's regulatory home, the target investor base, the nature of the rights the token confers and the secondary-market ambitions of the program.
Operator A – a protocol-stage startup issuing governance/utility tokens to a global community base. The primary concern is avoiding inadvertent securities characterization. The applicable instrument is a carefully structured utility offering with a MiCA-compliant whitepaper for EU distribution, transfer restrictions for US persons and a classification opinion anchored in the substance of the rights. Indicative timeline from engagement to launch: several weeks to a few months, depending on the complexity of the technical documentation and the number of jurisdictions in scope. Key risk: marketing language that introduces investment-expectation framing.
Operator B – a fintech company issuing a revenue-linked token to accredited or institutional investors. The instrument is closer to a structured product or a security. The applicable structure involves either a registered offering or a private placement exemption in the relevant jurisdiction, with secondary-transfer restrictions at the smart-contract level. The EU treatment under MiCA's financial-instrument carve-out requires engagement with the applicable NCA. Indicative timeline: materially longer, with regulatory filing periods that vary by jurisdiction. Key risk: designing secondary-market liquidity into the token in a way that undermines the placement restrictions.
Operator C – an established exchange or payments business launching a stablecoin for settlement use. The applicable instrument is an ART or EMT under MiCA where the EU is a target market, with parallel authorization requirements under VARA for UAE distribution and similar frameworks in Singapore and Hong Kong. The timeline is driven by the authorization process in each applicable jurisdiction. Key risk: launching before authorization is in place, even in a "soft" or beta form, where the distribution reaches the regulated perimeter.
Operator D – a Web3 fund distributing a liquid token to LPs alongside a traditional fund structure. The interaction between fund-regulation obligations and the token's legal character requires careful analysis in each LP's home jurisdiction. The token may be treated as a fund unit, a security or a separate crypto-asset depending on the applicable regime. Key risk: the tax and fund-reporting treatment of token distributions diverging from the treatment of the underlying fund interest.
In our cross-border practice, we regularly advise operators across all four profiles. The decision matrix above is illustrative; the correct instrument for your situation requires a scoped legal review of the specific facts.
When Should You Engage Specialist Token Counsel?
Specialist counsel should be engaged before the token economics are finalized – not after. The classification analysis, the offering structure and the whitepaper are downstream of the economic design of the token. If the economic design creates securities characteristics, it is far more efficient to address that at the design stage than to attempt to redraft a completed whitepaper or restructure a tokenomics model after the marketing has already shaped investor expectations.
The trigger points we see most frequently in practice are: a fundraising round where tokens are the instrument, a platform launch where a native token will have both utility and economic functions, a secondary exchange listing application that requires confirmation of the token's regulatory status, and any material modification to a live token's economic rights. Each of these is a moment where the classification question is active and where the legal analysis must be current.
Cross-border counsel is also appropriate when a business formed in one jurisdiction plans to distribute tokens in markets governed by different regulatory regimes. The lead counsel for a VARA-licensed entity in Dubai will not automatically carry expertise in MiCA's whitepaper obligations, the FCA's financial-promotion perimeter or MAS's digital payment token licensing framework. Where the distribution is multi-jurisdictional, the legal team must match.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights across all applicable regimes, not within a single jurisdiction. We draft MiCA whitepapers in alignment with technical specifications. We coordinate allied counsel in relevant jurisdictions where the offering extends beyond the jurisdictions we cover directly. Digital assets are the whole of our practice.
For a scoped assessment of your token offering, the classification question and the whitepaper requirements that apply to your distribution, contact OBOLUS at info@oboluslaw.com.
Self-Assessment: Is Your Token Offering Legally Ready?
Before any token offering opens, the following questions should each have a documented answer based on a legal review of the specific facts – not on a general assumption about the token category.
Has the token been classified under the applicable regime in each jurisdiction where it will be offered or traded? Has the classification been tested against the substance of the rights, not just the marketing label? Has a whitepaper or equivalent disclosure document been prepared that accurately reflects the on-chain mechanics of the token? Has that document been reviewed for consistency with the technical specification? Has the offering been structured to comply with the securities law of each jurisdiction where it may reach investors, including applicable exemptions or restrictions? Has the banking structure for the receipt of offering proceeds been configured with the relevant bank's prior knowledge of the offering? Has the airdrop or distribution mechanic, if applicable, been reviewed for regulatory characterization? Has a post-launch review process been established so that material changes to token economics are assessed for classification impact before implementation?
Operators we advise routinely complete this checklist as part of a pre-launch legal review. It is not a guarantee of regulatory approval. It is the documented record that the issuer applied informed legal judgment at each decision point. In an enforcement context, that record matters.
Related at OBOLUS
- Crypto Whitepaper: Legal Function and Drafting Guide – the legal mechanics of a MiCA-compliant whitepaper and its liability implications
- Crypto Exchange Setup in Japan: FSA/JVCEA Licensing Guide – how the FSA and JVCEA framework applies to exchange operators entering Japan
- EMI Licence for Crypto Firms: A Cross-Border Perspective – the interaction between e-money licensing and crypto-asset business models
FAQ
Is my token a security?
Whether a token is a security depends on the applicable regime and the substance of the rights it confers. No single test applies across all jurisdictions. The EU, US, UK, Singapore, Hong Kong and UAE each apply their own criteria. The analysis looks at the economic reality of the token – the rights attached, the investment expectations created and the economic relationship between the issuer and holders – not at the label the issuer uses. A legal classification opinion, conducted across all relevant jurisdictions before the offering opens, is the reliable basis for answering this question.
Do I need a MiCA whitepaper?
Under MiCA, a whitepaper is generally required for any public offer of crypto-assets in the EU/EEA that falls within the regulation's scope. The obligation applies to the offeror regardless of whether the issuer is incorporated in the EU. ART and EMT issuers face an authorization requirement in addition to the whitepaper. Certain limited exemptions apply – for example, for small-scale offerings or fully private placements – but the conditions are specific and must be assessed against the facts of the individual offering. Assuming an exemption applies without a legal review is a common and avoidable risk.
How should an airdrop be structured legally?
An airdrop is not automatically outside the regulated perimeter simply because no purchase price is paid. The legal analysis turns on whether the airdrop creates investment expectations, is tied to a prior capital-raise or constitutes a transfer of value with regulatory significance. A truly gratuitous distribution with no eligibility condition linked to an investment relationship may fall outside MiCA's whitepaper obligation, but that assessment must be made on the specific facts. Transfer restrictions, a written classification opinion and a tax analysis of the recipient-side treatment should each be completed before the distribution mechanics are finalized.
By Marisa Holt, Partner – Licensing & Regulatory — advising digital-asset issuers and exchanges on token classification, MiCA compliance and cross-border securities law across the EU, UAE, Singapore and the UK.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.