EST · MMXXVI
Home/Services/Token Offerings Securities/Token legal classification for Early-stage Founders
Token Offerings & Securities

Token legal classification for Early-stage Founders

Token legal classification for Early-stage Founders. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS

Token legal classification is the first legal question every early-stage founder must answer correctly – and the one most frequently answered on the basis of wishful thinking. Across the major regulatory regimes, from MiCA (the EU's Markets in Crypto-Assets Regulation) to VARA (Dubai's Virtual Assets Regulatory Authority) to the SFC (Hong Kong's Securities and Futures Commission), the operative question is the same: what rights does this token confer, and what does that make it under the applicable law? A token legal classification (the process of analysing a proposed token against each relevant regulatory category) is not a marketing exercise. It is a legal analysis, and the consequences of getting it wrong are serious.

Mis-classifying a token can convert a product launch into an unregistered securities offering. That exposure follows the founder personally, travels across borders with the token's distribution, and does not dissolve simply because the project rebrands. This page sets out the classification regime, the analytical process, and the decisions a founder must make before the first token is issued or distributed.

Why Classification Drives Every Other Decision

Token classification is the foundation of every subsequent legal choice a founder makes. The licence category required, the whitepaper obligations, the exchange listing eligibility, the banking access, and the investor protections that apply – all of these depend on what the token is as a matter of law. A founder who classifies incorrectly does not just face a regulatory fine. They may face a requirement to unwind a completed offering, register with one or more securities regulators, or refund investors in a transaction that was never structured for refund.

In our cross-border practice, we regularly advise founders who have already drafted a whitepaper and a token sale agreement before seeking legal input. The documents often reflect a desired classification rather than an assessed one. Regulatory examiners do not read whitepapers in good faith; they read them looking for the substance of what the token does. A regime designed for payment tokens does not apply to a token that looks, economically, like an equity stake in a project's future revenue. The label on the cover matters far less than the rights embedded in the smart contract.

The process above describes the standard path. Your facts – the token structure, the user base, the distribution mechanism, and the jurisdictions your investors sit in – change the analysis materially. For an initial scoped assessment of your token's classification risk, contact OBOLUS at info@oboluslaw.com.

What Are the Recognised Token Categories Across Major Regimes?

Every leading regime has its own taxonomy, but the underlying logic converges on a small number of economic categories. Understanding the map across regimes is the starting point for any multi-jurisdiction distribution.

Under MiCA, the EU has codified three token categories. An asset-referenced token (ART) is a token that purports to maintain a stable value by reference to a basket of assets, currencies or commodities. An e-money token (EMT) is a token that purports to maintain a stable value by reference to a single official currency. All other tokens – including the utility tokens that most early-stage projects issue – fall into a residual category subject to a lighter whitepaper regime administered by ESMA and the relevant national competent authority. MiCA does not, however, cover tokens that qualify as financial instruments under EU financial services law. Those remain governed by existing securities legislation. A token that gives holders a share in future profits, voting rights in a governance structure, or a claim on project revenues may well cross that line.

In the United States, the analysis centres on established securities law principles. The longstanding test asks whether money has been invested in a common enterprise with an expectation of profit derived from the efforts of others. The SEC has applied that analysis to a wide range of tokens. The CFTC separately asserts jurisdiction over tokens it characterises as commodities. A US nexus in distribution – even one investor, one exchange listing, or one US-resident team member accessing a sale portal – can engage federal securities law.

VARA in Dubai distinguishes between virtual assets used as a medium of exchange and virtual tokens that confer rights analogous to securities or investment products. The FSRA in Abu Dhabi's ADGM maintains a list of recognised virtual assets and separately regulates tokens that fall within its investment business perimeter. The SFC in Hong Kong applies its securities ordinance to tokens that constitute a collective investment scheme or otherwise fall within the definition of a security under Hong Kong law.

Switzerland's FINMA, one of the earliest regulators to articulate a formal token taxonomy, distinguishes between payment tokens, utility tokens, and asset tokens, acknowledging that many tokens are hybrids. Hybrids are assessed on their dominant characteristic.

Why the Substance-Over-Label Principle Governs

A utility label on a whitepaper does not settle the legal classification. This is one of the most persistent misconceptions in early-stage token issuance, and regulators across every major jurisdiction have explicitly rejected it.

The controlling principle – recognised by ESMA guidance, the SEC's published communications, FINMA's token guidance, and the SFC's circular practice – is substance over form. What matters is the economic reality of what the token does, not what the issuer calls it. The analytical questions are consistent across regimes: Does the token confer a right to future profits or revenue? Does it entitle holders to vote on governance decisions that affect the project's commercial direction? Was it sold on the promise of appreciation, with the marketing emphasis on the project team's ability to deliver value? Is there a secondary market where the token trades as an investment? Positive answers to any of these questions, in any combination, push a token toward the securities perimeter – regardless of whether the whitepaper calls it a utility token, a governance token, or a network access credential.

We assess every token against the substance of the rights it actually confers. That means reviewing the smart contract, the token sale agreement, the whitepaper, the marketing materials, and the project roadmap together. The classification opinion rests on that full picture.

How Does the Classification Process Work in Practice?

A defensible token classification follows a structured analytical sequence. Each step builds on the last, and the analysis must be documented to survive regulatory scrutiny.

The first step is a rights-mapping exercise. This means producing a complete list of every right the token confers on its holder: economic rights (profit share, revenue share, redemption rights), governance rights (voting on parameters, treasury deployment, protocol upgrades), access rights (use of a protocol feature, reduced fees, access to a platform tier), and transfer rights (whether the token is freely transferable, restricted, or subject to lock-ups). Rights that are described in the whitepaper but not yet encoded in the smart contract still count; regulators look at representations made at the point of sale.

The second step is a jurisdiction mapping exercise. This means identifying every jurisdiction where the token will be offered, where investors are located, where the issuer is incorporated, where the team members are resident, and where the token will be listed. Each of those jurisdictions applies its own classification test. A token that is a utility token in one regime may be a security in another. The classification opinion must address each relevant jurisdiction separately.

The third step is an application of the relevant legal tests in each jurisdiction to the rights mapped in step one. This is the substantive legal analysis. It produces a classification outcome for each jurisdiction – security, payment token, utility token, e-money token, ART, or unclassified – and identifies any jurisdiction where the proposed structure presents elevated risk.

The fourth step is a structuring review. Where a jurisdiction produces a high-risk classification, the founder has a choice: restructure the token rights to move the token outside the regulated perimeter, obtain the relevant registration or authorisation, or exclude investors from that jurisdiction. Each path has costs and trade-offs that vary with the project's stage.

In a recent matter, a DeFi protocol team approached us ahead of a token generation event. The token as initially designed included a revenue-sharing mechanism tied to protocol fees – a feature that several team members believed was standard in the market. Our analysis identified that the mechanism, in the form proposed, would have engaged securities regulation in at least two of the five distribution jurisdictions. We advised on a restructured rights model that preserved the economic logic the team needed while materially reducing the regulatory perimeter. The revised structure was documented before any public communications were issued.

Cross-Border Distribution: How Does Jurisdictional Stacking Work?

For most early-stage founders, the instinct is to focus on a single home jurisdiction and treat cross-border distribution as a later problem. That approach generates avoidable risk from the outset.

Token distributions are inherently cross-border in ways that physical product launches are not. A public sale portal accessible by IP address is accessible globally unless technically restricted. A public announcement on a social platform reaches investors in every jurisdiction simultaneously. Exchange listing – even on a platform incorporated in a single jurisdiction – distributes the token to users in dozens of countries. Each of those touchpoints can create regulatory nexus in the corresponding jurisdiction, and each nexus carries its own classification analysis.

The practical consequence is jurisdictional stacking. A token launch with genuinely global reach must be assessed under the laws of the US (federal and relevant state level), the EU (MiCA and underlying financial instruments law), the UK (FCA cryptoasset registration and financial promotion rules), Singapore (MAS Payment Services Act), Hong Kong (SFC), and any jurisdiction where a significant investor pool is located. Each of those regimes uses a somewhat different classification test, applies a different threshold for when a distribution crosses the regulated perimeter, and provides different safe-harbour or exemption structures where the classification produces a securities outcome.

Where the stacking produces a securities classification in a high-priority jurisdiction, the structuring options typically include: a restricted investor pool with robust geographic restrictions, a private placement or accredited-investor-only structure in the relevant jurisdiction, staged distribution that sequences launches by jurisdiction and timing, or a foundation/protocol bifurcation that separates the entity issuing the token from the entity operating the protocol. Allied counsel in the relevant jurisdiction is engaged where local-law sign-off is required.

What Triggers a MiCA Whitepaper Obligation?

Under MiCA, a crypto-asset whitepaper (the disclosure document required for offers to the public within the EU/EEA) is mandatory for most non-ART, non-EMT public token offers above the applicable threshold. The whitepaper must be notified to the relevant national competent authority and contain prescribed disclosures about the issuer, the project, the token, the rights it confers, and the risks involved. It is not a marketing document. It is a legal instrument that carries liability for material inaccuracy or omission.

The whitepaper obligation is distinct from any authorisation requirement. A token that is not an ART, not an EMT, and does not qualify as a financial instrument can be publicly offered under MiCA on the basis of a notified whitepaper, without a full CASP (Crypto-Asset Service Provider) authorisation by the issuer. But that does not mean the offering is unregulated. The whitepaper liability regime is real, and ESMA's guidelines on content requirements are detailed. A whitepaper that mischaracterises the token's rights, overstates the project's development status, or omits material risk factors creates direct civil liability to purchasers.

Early-stage founders distributing into the EU market – or into a jurisdiction that has adopted MiCA-equivalent rules – must assess the whitepaper trigger at the point of project design. If the trigger is met, the whitepaper drafting process is part of the legal preparation for launch, not an afterthought. We draft and review whitepapers as part of the classification and launch preparation workflow.

If a prior classification or whitepaper process has stalled, or if your structure has changed since the original analysis, a fresh read often identifies the path forward. Write to OBOLUS at info@oboluslaw.com to discuss a review.

Airdrops, Grants, and Distribution Mechanics: What Are the Legal Risks?

Distribution mechanics matter to the classification analysis. The way a token reaches its initial holders affects both the classification outcome and the exemption structures available.

An airdrop (a distribution of tokens to wallet addresses for free, with no direct purchase consideration) is often assumed to fall outside the securities analysis on the basis that there is no investment of money. That assumption is frequently wrong. Where an airdrop is conditional on participation in a community, completion of a task, or holding of another token, regulators in several jurisdictions have analysed the conditional performance as economic consideration. Where an airdrop is announced in advance as part of a broader marketing campaign designed to generate token value, the expectation of appreciation element of the securities test may still be engaged. The analysis is fact-specific.

Retroactive airdrops – distributions to wallets that interacted with a protocol before the token's existence – present a different profile. There is typically no prospective investment decision, no solicitation, and no marketing of appreciation potential at the time of the distribution. This structure has a stronger claim to falling outside the securities perimeter in most jurisdictions, though it is not immune from analysis, particularly in the United States.

Ecosystem grants – tokens distributed to developers, early contributors, or protocol users under a formal grant programme – involve their own classification questions. Where grant recipients are providing services in exchange for tokens, the employment, contractor, and withholding tax implications may be at least as significant as the securities classification.

In our practice, we regularly advise on airdrop structures at the design stage, before the distribution mechanism is built into the smart contract. Retrofitting a compliant structure after a non-compliant distribution has already occurred is significantly more expensive and produces a less clean outcome.

What Are the Most Common Token Classification Mistakes?

The same errors appear repeatedly in early-stage token projects. Knowing them in advance is the most efficient form of risk management.

The first and most common mistake is treating the whitepaper as the primary legal document. The whitepaper is a disclosure document. The legal instruments are the token sale agreement, the smart contract, the terms of use, and – in the case of DAO tokens – any governance documentation. Classification analysis must begin with those instruments, not with the marketing narrative.

The second mistake is designing the token for the most permissive jurisdiction and treating that jurisdiction's analysis as definitive globally. The US nexus question in particular is frequently under-assessed. A single US investor, a single US-accessible exchange listing, or a US-resident founding team member can be sufficient to engage federal securities law, regardless of where the project is incorporated.

The third mistake is sequential analysis – classifying the token, then designing the distribution, then reviewing for AML compliance, and only then considering tax. Each of those workstreams affects the others. A token structure that works for classification purposes may trigger adverse tax treatment in the issuer's residence jurisdiction. An AML-compliant KYC regime for the token sale may produce investor data that creates securities law filing obligations in certain jurisdictions. The analysis must be concurrent.

The fourth mistake is under-documenting the classification decision. A well-reasoned legal opinion that addresses the rights-mapping exercise, the jurisdiction mapping, and the application of the relevant tests is not merely useful for regulatory defence. It is a material input to exchange listings, institutional investor due diligence, and future fundraising. Exchanges in Singapore, Hong Kong, and the EU all carry out their own classification analysis before listing; a pre-existing defensible opinion materially accelerates that process.

Which Classification Path Fits Your Token Profile?

The right approach to classification varies with the founder's specific fact pattern. The following matrix describes four representative profiles and the corresponding legal path.

A DeFi protocol issuing a governance token with no economic rights (no revenue share, no profit claim, no redemption right), distributed via a retroactive airdrop to protocol users, presents a relatively contained classification profile in most jurisdictions outside the United States. The focus should be on ensuring the rights are genuinely limited (not just described as limited), on the US distribution restriction, and on the AML posture for any future exchange listing.

A payments or fintech project issuing a token that functions as a settlement instrument within a closed ecosystem may fall into the payment token or EMT category under MiCA, depending on whether it purports to maintain value against a single fiat currency. The MiCA authorisation path for EMT issuers is more demanding than the whitepaper-only path for utility tokens, and the reserve and redemption requirements are substantive. Timeline for this path is typically a matter of months from completed application.

A token sale with a return expectation baked into the marketing – language in the whitepaper or pitch deck that emphasises token appreciation, project team delivery, or treasury management as a driver of value – faces the highest securities classification risk across all jurisdictions. The remediation path involves either a restructured rights model and marketing strategy or a full securities registration/exemption analysis in each distribution jurisdiction. The latter is resource-intensive; many early-stage projects find that restructuring is the more practical path.

A token issued by an established protocol with a defined utility function – access to a compute layer, a data feed, a storage allocation – and with no secondary-market appreciation narrative in the distribution process has the cleanest classification profile under most regimes. The key risks are residual US nexus and the ongoing obligation to ensure that secondary-market trading does not retroactively change the characterisation as the token's economic function evolves.

Related at OBOLUS

FAQ

Is my token a security?

There is no universal answer. The determination turns on the rights the token confers and the economic substance of the distribution – not the label applied in the whitepaper. Across the EU, the US, Hong Kong, Singapore, and the UAE, the controlling principle is substance over form. A token that confers profit rights, governance rights that affect commercial outcomes, or is marketed on an appreciation thesis will face a securities analysis in most major regimes. The correct answer requires a jurisdiction-by-jurisdiction rights-mapping exercise against the applicable legal tests. We carry out that analysis as the first step in any token launch engagement.

Do I need a MiCA whitepaper?

If you are publicly offering a token within the EU or EEA and the token is not an ART, an EMT, or a financial instrument, a notified crypto-asset whitepaper is required under MiCA above the applicable public offer threshold. The whitepaper must meet ESMA's prescribed content requirements and carries civil liability for material inaccuracy. The obligation is triggered by the offer to the public, not by the issuer's place of incorporation. A founder based outside the EU who offers tokens to EU residents without a compliant whitepaper is within the MiCA perimeter. Whitepaper drafting and notification support is part of our token launch service.

How should an airdrop be structured legally?

The legal treatment of an airdrop depends on whether it involves consideration (conditional tasks, community participation, or the holding of another token), whether it is accompanied by marketing emphasising future appreciation, and which jurisdictions' residents receive the distribution. Purely retroactive airdrops to prior protocol users generally present a lower securities risk profile, though US nexus remains a live issue. Conditional airdrops require a full classification analysis before the mechanism is built into the smart contract. We advise on airdrop structure at the design stage, addressing classification, AML, and tax implications concurrently.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than 70 jurisdictions, on disputes and on-chain asset recovery across more than 25 forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess classification against the substance of rights, not the marketing label – the same discipline we apply across every token engagement. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your token's classification, contact info@oboluslaw.com or reach us at t.me/oboluslaw.

By Roman Levitt, Technology & DeFi Counsel – advises early-stage and growth-stage token projects on classification analysis, whitepaper structuring, and cross-border distribution across the major digital-asset regulatory regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours