EST · MMXXVI
Home/Services/Token Offerings Securities/Security token offering structuring from a Cross-border Perspective
Token Offerings & Securities

Security token offering structuring from a Cross-border Perspective

Security token offering structuring from a Cross-border Perspective. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring

A token issuer expanding across three continents discovers that the rights embedded in its token trigger securities laws in each of them – yet each applies a different test, a different regulator, and a different offering regime. That is the practical reality of a security token offering (an offering of a digital token that confers rights analogous to equity, debt or a collective investment interest). The legal question is not simply whether the token is a security; it is which jurisdictions' securities laws apply simultaneously, and how the structure must adapt to satisfy all of them without collapsing under the weight of conflicting obligations.

Getting classification wrong converts a product launch into an unregistered securities offering. The consequences range from investor rescission rights and regulatory enforcement to reputational damage that forecloses future banking relationships. The sections below map the regulated basis, the structuring process, the cross-border interaction, and the decisions that matter most before a token offering goes live.

What Makes a Token a Security?

Token classification turns on the substance of the rights conferred, not on the label applied in a whitepaper or marketing deck. Across the leading regimes, the analytical framework is consistent in principle and divergent in detail: regulators ask whether the instrument gives holders a financial interest – in the form of profit participation, voting rights over a venture, or a claim on underlying assets – that is sufficiently analogous to an equity, debt or collective investment product.

In the European Union, MiCA (the Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities) carves out instruments that qualify as financial instruments under MiFID II. Those instruments are not regulated by MiCA; they remain inside the securities directive regime. The boundary is therefore drawn by a classification exercise that looks at the economic function of the token, not its technical architecture.

In the United States, the SEC applies a substance-over-form test derived from investment contract doctrine. The CFTC may also assert jurisdiction where commodity characteristics are present. State money-transmitter licensing under FinCEN and NYDFS frameworks adds a further layer. Running a single offering across both the EU and the US without mapping these classification outcomes in parallel is the single most common structural error we observe.

Singapore's MAS applies the Securities and Futures Act, reading token characteristics against the definition of a capital markets product. The SFC in Hong Kong takes a similar functional approach under its VASP licensing regime. FINMA in Switzerland uses a taxonomy – payment, utility, and asset tokens – but recognises hybrid tokens that combine characteristics and applies the most restrictive applicable regime. The consistent thread is this: a utility label settles nothing. The question is always what rights the token actually confers.

A common assumption is that calling a token "utility" in the whitepaper fixes the legal classification. It does not. Regulators across MiCA, SEC doctrine, MAS and FINMA guidance all direct their analysis to the economic substance of what holders receive. A token that grants governance rights over a revenue-generating protocol, or that entitles holders to a share of fees, will attract securities analysis regardless of how it is described. We assess classification against the substance of rights at every stage of a structuring engagement, before the whitepaper is written.

The Regulatory Regime for Security Token Offerings

A security token offering is subject to the securities law of every jurisdiction in which it is made to investors – and, in most regimes, every jurisdiction in which investors are habitually resident. The issuer's place of incorporation is relevant but rarely determinative on its own. This point alone drives most of the complexity in cross-border structuring.

Under MiCA, tokens that qualify as financial instruments are excluded from the MiCA whitepaper regime and instead require a MiFID II-compliant prospectus or a prospectus exemption. The EU Prospectus Regulation provides several exemptions – for small-denomination offers, for offers limited to qualified investors, and for offers below defined monetary thresholds – but the conditions and caps vary, and reliance on one exemption in the EU does not satisfy the equivalent regime in the UK, the US, or Singapore. Each jurisdiction must be addressed separately.

In the UK, the FCA applies the Financial Services and Markets Act framework. Cryptoassets that qualify as specified investments require FCA authorisation to offer; financial promotion rules impose consent requirements even for communications aimed at UK persons from offshore issuers. The FCA's cryptoasset financial promotion regime extended those rules significantly and applies extraterritorially on a targeting basis.

For issuers operating in or targeting the Abu Dhabi market, the FSRA within ADGM applies its regulated activities framework for virtual assets. In Dubai, VARA's activity-based licences include categories relevant to token distribution and transfer. The AIFC's AFSA in Kazakhstan applies a common-law-derived framework for digital-asset activities. Each of these regimes has its own offering documentation and investor-access rules.

The practical consequence is that a well-structured STO typically involves a layered jurisdictional plan: a primary offering jurisdiction that provides regulatory certainty for the headline offering, combined with investor-specific restrictions or reliance on qualified-investor exemptions in secondary jurisdictions. The issuer's entity structure, the placement agent's location, and the secondary trading venue each pull in different directions.

To map the full jurisdictional exposure of your STO structure before launch, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity, the investor base, the rights structure, and the intended trading platform – change the analysis materially.

How Is a Security Token Offering Structured in Practice?

Structuring a compliant STO involves four principal workstreams that run in parallel: classification and regime mapping, entity and instrument design, offering documentation, and distribution controls. Missing any one of them after launch is significantly more expensive than addressing it upfront.

The first workstream is classification. The issuer commissions a written classification opinion that applies the tests of each target jurisdiction to the specific rights the token will confer. This opinion is not a whitepaper; it is a legal memorandum that the board, auditors, and future regulators may rely on. We regularly advise clients on the structure of that analysis before the token design is finalised, because design choices – governance rights, fee-sharing mechanisms, lock-up periods – affect the classification outcome directly.

The second workstream is entity and instrument design. The choice of issuing entity affects which offering exemptions are available, how the token is taxed in the hands of the issuer, and what the AML/KYC onboarding obligations will be. A Cayman or BVI special-purpose vehicle is a common structuring choice for offshore issuances targeting institutional investors, because CIMA and the BVI FSC each provide a VASP Act framework that accommodates structured digital-asset offerings while preserving access to international placement agents. A European issuer passporting under MiFID II may instead use a Malta or Lithuanian authorised entity transitioning to the MiCA CASP regime.

The third workstream is offering documentation. This includes the classification opinion, the investor-facing offering memorandum or prospectus (structured to qualify for the applicable exemption in each target jurisdiction), the token purchase agreement, and – where required under MiCA for non-exempted token categories – the crypto-asset whitepaper. The whitepaper under MiCA is a liability document: the issuer takes on civil liability for its contents, and ESMA and the national competent authorities retain supervisory oversight over it.

The fourth workstream is distribution controls. Geofencing, investor accreditation verification, and contractual jurisdiction restrictions do not, by themselves, eliminate exposure to the securities laws of excluded jurisdictions. They reduce it. The legal analysis must confirm that the residual exposure is within acceptable bounds. Placement agent selection is critical: agents must hold the appropriate licence in each jurisdiction in which they solicit investment.

What Are the Principal Cross-Border Structuring Challenges?

The hardest cross-border structuring problems in an STO arise at the intersection of conflicting classification outcomes, secondary market trading, and AML obligations. Each of these is manageable; none of them is manageable by ignoring them.

Conflicting classification outcomes occur when a token is classified as a security in one jurisdiction and as a utility or payment instrument in another. The issuer cannot in those circumstances use a single legal structure for all markets. The practical answer is a segregated offering structure: a primary-market offering compliant with the strictest applicable regime, combined with specific investor restrictions that limit the reach of the secondary offering into jurisdictions with divergent classification outcomes. Operators we advise routinely maintain jurisdiction-specific schedules to their offering memoranda that set out the applicable restrictions market by market.

Secondary market trading is the second fault line. Even where a primary offering is structured to comply with all applicable securities laws, secondary trading on a venue that is not authorised in the investor's jurisdiction can create ongoing securities-law exposure. The SFC in Hong Kong and the SEC in the United States have each taken the position that operating or facilitating secondary trading of security tokens without the appropriate authorisation constitutes operating an unregistered securities exchange. Under MiCA, trading venues handling MiFID II financial instruments require authorisation as regulated markets or multilateral trading facilities – not CASP authorisation. Structurers must therefore address the secondary market from the outset, not as an afterthought.

The Travel Rule (the FATF obligation to pass originator and beneficiary data with a virtual asset transfer) applies to transfers of security tokens just as it does to other virtual assets in most of the leading regimes. Compliance requires technical integration at the token or platform level. Issuers that build a token architecture incompatible with Travel Rule data transmission face a costly rebuild when their custodian or trading venue demands compliance. We have seen this happen more than once in the later stages of a token launch, when the cost of remediation is at its highest.

In our cross-border practice, the most avoidable structural failures arise not from the primary offering documentation but from the downstream decisions: the choice of trading venue, the identity of the transfer agent, and whether the token standard supports the compliance requirements of the markets the issuer actually wants to serve.

Which Structure Fits Which Issuer Profile?

Different issuer profiles call for materially different STO structures. The matrix below describes the most common profiles we encounter, and the structuring approach each typically requires.

Profile A – Early-stage issuer, institutional investors only, global placement. The issuer is raising growth capital from qualified or professional investors and does not intend to list on a public exchange in the near term. The preferred structure is an offshore SPV – typically Cayman or BVI – issuing tokens under a private placement exemption in each target jurisdiction. Documentation centres on an offering memorandum drafted to satisfy Regulation D (US), Regulation S (US non-US persons), the EU qualified-investor exemption under the Prospectus Regulation, and equivalent exemptions in Singapore and Hong Kong. The MiCA whitepaper obligation may or may not apply depending on the primary EU nexus; that question turns on where the token will be offered or admitted to trading within the EU. Timeline from instruction to first close is a matter of weeks for a well-prepared issuer; a fully documented multi-jurisdiction package typically takes longer depending on the number of target markets.

Profile B – Established business tokenising an existing asset class, EU-primary offering. The issuer is a licensed financial institution or an operating business tokenising equity, real estate income rights, or fund units. The primary offering is into the EU. This structure requires either a MiFID II-compliant prospectus or reliance on a prospectus exemption, combined with CASP authorisation in a passporting jurisdiction for any CASP activities carried on by the issuer. Malta and Lithuania remain common choices for the CASP piece under MiCA transition arrangements. The documentation burden is substantially higher than in Profile A. Secondary market access requires coordination with an authorised multilateral trading facility.

Profile C – MENA-based issuer targeting regional and Asian investors. The issuer seeks to access both the Gulf and Asian investor bases. VARA in Dubai and the FSRA within ADGM each apply their own offering and distribution rules. MAS in Singapore and the SFC in Hong Kong require separate analysis for investor solicitation. This profile often involves a hub-and-spoke entity structure, with a primary VARA or ADGM-licensed entity and jurisdiction-specific distribution agreements with locally licensed placement agents. The AML/KYC burden is high: each jurisdiction applies its own Travel Rule threshold and due diligence standard.

What Are the Most Common Mistakes in STO Structuring?

In our practice, the mistakes that generate the highest remediation cost fall into three categories: classification errors caught late, distribution controls that are contractual rather than technical, and whitepaper liability that is not adequately understood before publication.

Classification errors caught late are the most expensive. An issuer that has already issued tokens, onboarded investors, and potentially facilitated secondary trading before obtaining a classification opinion faces a much narrower set of remediation options than one that engaged counsel at the design stage. The contractual and reputational cost of rescinding an offering, restructuring the token rights, or seeking a no-action position from a regulator is substantially higher than the cost of the initial classification analysis.

Distribution controls that are contractual rather than technical create a false sense of security. A jurisdictional restriction in a token purchase agreement does not prevent a US person from acquiring the token on a secondary market. Smart-contract-level transfer restrictions, issuer whitelist mechanisms, and permissioned secondary trading platforms are the technical answer; the legal documentation sits on top of those controls, not in place of them.

Whitepaper liability under MiCA is a structural liability question, not a disclosure exercise. The issuer is the legally responsible party. That means the board approves the whitepaper as a liability document, the legal opinion addresses every material statement in it, and the issuer has a process for updating or withdrawing the whitepaper if the material information in it changes. Operators we advise who have come to us after receiving a regulatory query about whitepaper content consistently identify the same gap: the whitepaper was treated as a marketing document, not as a regulated disclosure.

A micro-matter from our recent practice illustrates the downstream cost of deferring classification: a technology business approached us after a mid-stage token sale, having received investor demands for rescission on the basis that the tokens were unregistered securities in their home jurisdiction. We re-examined the classification across the relevant jurisdictions, identified a structural path to a retrospective offering exemption in the primary markets, and coordinated with allied counsel in the relevant jurisdiction to implement the remediation. The process required restructuring the token purchase agreements, updating the offering documentation, and engaging directly with the investors' counsel. It was resolved in a matter of months, but the cost – in fees, management time, and investor relations – significantly exceeded what a pre-issuance classification analysis would have required.

Self-Assessment: Is Your STO Structure Ready?

Before a security token offering goes live, a thorough internal review should confirm the following. The list is not exhaustive, but it surfaces the questions that most often go unanswered at launch.

  • Has a written classification opinion been obtained for each target jurisdiction, analysing the specific rights the token confers?
  • Does the offering documentation include jurisdiction-specific schedules addressing each market where investors will be solicited?
  • Is the issuing entity licensed or relying on an applicable exemption in each target jurisdiction for both the primary offer and any facilitation of secondary trading?
  • Are the distribution controls technical – not merely contractual – in jurisdictions where the token must not circulate?
  • Does the whitepaper comply with MiCA requirements if the offering has an EU nexus, and has the board approved it as a liability document?
  • Has the token architecture been reviewed for Travel Rule compatibility in each applicable jurisdiction?
  • Has a placement agent been identified who holds the necessary authorisations in each solicitation market?
  • Is there a post-issuance monitoring process for secondary market trading that could extend the issuer's regulatory exposure?

If any item on this list is unresolved, the offering carries unquantified legal risk. Regulatory enforcement and investor rescission claims are the typical consequence, both of which are materially more expensive than pre-issuance structuring.

If a prior structuring exercise left gaps, or if a regulatory query has arrived, contact OBOLUS now at info@oboluslaw.com. A second read can surface the structural reason and the route forward.

Related at OBOLUS

FAQ

Is my token a security?

Classification turns on the economic substance of the rights the token confers, not its label. Across MiCA, SEC doctrine, MAS, and FINMA guidance, the test asks whether the token grants holders profit participation, a claim on assets, or a governance interest in a revenue-generating venture. A written classification opinion analysing each target jurisdiction's test against the specific token design is the only reliable answer. Calling the token "utility" in the whitepaper does not determine the outcome.

Do I need a MiCA whitepaper?

Under MiCA, tokens that qualify as financial instruments under MiFID II are excluded from the MiCA whitepaper regime and fall instead under EU securities law. If your token is not a financial instrument and is offered within the EU, a MiCA whitepaper is required unless an exemption applies. The whitepaper is a liability document for the issuer. Whether an exemption is available depends on the offer size, the investor category, and the nature of the token. A classification analysis must precede this determination.

How should an airdrop be structured legally?

An airdrop distributes tokens without direct monetary consideration, but that does not make it legally neutral. If the distributed token is a security in any target jurisdiction, an airdrop may constitute a securities offering in that jurisdiction and trigger prospectus, registration, or exemption requirements. AML/KYC obligations may also apply if the airdrop constitutes a virtual asset transfer under the applicable regime. The structure must be assessed against the classification outcome and the applicable rules in each jurisdiction where recipients are located.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – and we have worked through this analysis for issuers spanning EU, MENA, and Asian markets simultaneously. To discuss your situation, contact info@oboluslaw.com.

By Roman Levitt, Technology & DeFi Counsel – specialising in token design, smart-contract legal architecture, and cross-border securities analysis for digital-asset issuers.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours