On paper, calling a token a "utility" token looks like a clean solution. In practice, regulators in every major jurisdiction assess classification against the substance of rights a token confers – not the label printed on a whitepaper. A token issuer who gets that analysis wrong does not face a paperwork problem. The business faces the consequences of running an unregistered securities offering across every jurisdiction where holders sit.
Token legal classification from a cross-border perspective turns on one question: what rights does the token actually give the holder? The answer determines whether a token offering triggers securities law, MiCA (the EU's Markets in Crypto-Assets Regulation) authorisation requirements, payment-institution obligations, or none of the above. That analysis must be run simultaneously across the issuer's home jurisdiction, the target markets, and wherever the token trades. Getting it right before launch is the single most consequential legal act in a token project.
This page maps the classification regimes, the process for getting a defensible answer, the cross-border pressure points, and the practical decisions that follow.
Why Classification Comes First
Classification is not a formality that follows the product decision – it is the product decision. Every downstream choice, from whitepaper disclosure to listing venue to treasury management, depends on how the token is characterised under applicable law. Regulators in the US, EU, UK, Singapore, Hong Kong and the UAE all apply different tests, but every one of them will look past the marketing label to the substance of what the token does.
In our cross-border practice, the most expensive regulatory problems we encounter trace back to a classification opinion that was given too late, too narrowly, or only for one jurisdiction. A token that passes muster in the EU under MiCA as an "other crypto-asset" may still engage Securities and Futures Commission (SFC) rules in Hong Kong if it carries profit-sharing mechanics, and may simultaneously trigger FinCEN reporting obligations in the United States if it functions as a payment instrument. The analysis is not additive – each layer interacts.
The fundamental principle is substance over label. Token rights – governance votes, revenue shares, redemption claims, access entitlements – each carry distinct legal significance depending on the jurisdiction. A one-jurisdiction utility opinion that ignores where token holders actually reside provides no real protection.
Mis-classifying a token can convert a product launch into an unregistered securities offering. That consequence is not theoretical. Regulators in the US, EU and Asia-Pacific have each brought enforcement actions against issuers on precisely this basis.
What Does Each Major Regime Look For?
The leading classification regimes converge on a common question – does the token resemble a regulated financial instrument? – but they answer it through different legal tests, with meaningfully different consequences for issuers.
Under MiCA, tokens fall into three categories: asset-referenced tokens (ARTs), which maintain stable value by reference to multiple assets; e-money tokens (EMTs), which reference a single fiat currency; and a residual "other crypto-assets" category that covers everything else, including the tokens most projects call utility tokens. ARTs and EMTs require authorisation from a national competent authority and must satisfy reserve, disclosure and redemption obligations. "Other" tokens require only a whitepaper notification for public offerings above a de minimis threshold – but that whitepaper triggers civil liability for its contents, and the MiCA exemptions are narrower than many issuers assume. ESMA and the national competent authorities continue to refine guidance on where the boundaries sit.
In the United States, the classification question runs through a securities-law analysis – examining whether a token involves an investment of money in a common enterprise with an expectation of profit from the efforts of others. The SEC and CFTC each claim authority over different token categories. Many tokens sit in a contested zone between the two agencies. State money-transmitter licensing adds a further layer for tokens that function as payment instruments, and the NYDFS BitLicense regime is relevant for businesses serving New York customers.
The SFC in Hong Kong and the MAS in Singapore both apply a "look-through" approach: if a token confers rights equivalent to a share, debt instrument or collective investment scheme unit, the relevant securities law applies regardless of the token label. The MAS Payment Services Act captures digital payment tokens as a separate category with its own licensing framework.
VARA in Dubai applies an activity-based licensing model. Classification of the token itself informs which VARA licence the issuer or exchange must hold – advisory, exchange, custody or other – but the token is not itself the primary focus of VARA's framework in the way that MiCA's token categories are.
FINMA in Switzerland published landmark token guidance that introduced the payment/utility/asset taxonomy that influenced global practice. Under FINMA, a token is an asset token if it promises a share in earnings, a claim against the issuer, or other investment-return characteristics. Payment tokens are pure exchange instruments. Utility tokens give access to a service. Hybrids are assessed on their dominant characteristic.
The Cross-border Pressure Points
Cross-border token distribution creates a compounding classification problem. An issuer incorporated in the BVI, with a technical team in Lithuania, selling tokens to buyers in the EU, UK, US and Singapore does not face one classification question. It faces at least five, applied simultaneously, with results that may differ and interact.
The most common structural mistake is to obtain a single-jurisdiction opinion and treat it as global clearance. A legal opinion that addresses only EU classification under MiCA says nothing about whether the same token, sold to a US person via the same smart contract, constitutes an unregistered security under federal law. A token that qualifies as an "other crypto-asset" under MiCA and therefore requires only a whitepaper may still engage FCA financial-promotion rules in the UK if UK persons receive the offer. Those rules carry criminal sanctions for breach.
Geographic restrictions in the token purchase documentation – commonly called purchaser restrictions or jurisdictional disclaimers – are a risk-management tool, not a classification argument. A restriction that purports to exclude US persons is of limited value if the smart contract is permissionless and the token is listed on a platform accessible to US customers. Regulators assess the practical reality of distribution, not the contractual aspiration.
In our cross-border practice, we have seen tokens that were structured with detailed EU and Swiss opinions but with no analysis of the jurisdictions where the largest community of holders actually sat. The classification gap was identified only when a secondary-market listing triggered regulatory inquiry. The cost of retroactive restructuring – and the reputational damage to the project – exceeded many times the cost of the original multi-jurisdictional analysis.
The secondary market is a further pressure point that many issuers underestimate. Classification obligations can attach not just to the initial offering but to the ongoing trading of the token. Under MiCA, a token admitted to trading on a regulated venue must comply with the ongoing disclosure and liability framework even if the original whitepaper notification was filed correctly. Under US law, secondary-market trading of a token that has been characterised as a security engages exchange-registration requirements that apply to the trading venue, not just the issuer.
For a first assessment of where your token sits across the regimes relevant to your distribution plan, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your facts – the rights conferred, the holder base, the entity structure, the secondary-market plan – change the outcome in ways that a generic analysis cannot capture. Map your options.
How Should a Classification Analysis Be Structured?
A defensible cross-border classification analysis follows a defined sequence. It is not a document-drafting exercise. It is a substantive legal assessment that precedes drafting – and that drives every document that follows, from the whitepaper to the terms and conditions to the smart-contract architecture.
The first step is a rights inventory: a complete enumeration of what the token does, what rights it confers, and how those rights are created and enforced. This must be done at the level of the smart contract, not the marketing deck. Governance rights, redemption rights, revenue-share mechanics, upgrade triggers and burn conditions are all legally significant. We regularly advise clients who discover, during this step, that a token they believed to be purely a utility instrument carries an implicit profit-sharing feature that was added during a hackathon and never removed.
The second step is a jurisdiction map: identifying every jurisdiction in which the token will be offered, sold, or traded at launch, and every jurisdiction in which material token holder communities are anticipated over the following twelve months. This map drives the scope of the classification analysis. It also drives the purchaser-restriction architecture and the whitepaper disclosure approach.
The third step is the concurrent classification analysis across each jurisdiction in the scope. Each jurisdiction's test is applied to the rights inventory. Where the tests produce conflicting results – a token that is a security in one jurisdiction and not in another – the issuer must decide whether to restructure the token, restrict distribution to the non-security jurisdictions, or accept the compliance obligations that follow from the security characterisation.
The fourth step is the documentation architecture: the whitepaper, the token terms, the purchaser agreements, the smart-contract disclosures, and any required regulatory filings or notifications. Under MiCA, a whitepaper for an "other crypto-asset" must be notified to the relevant national competent authority at least twenty business days before publication. The whitepaper carries statutory civil liability for misleading, inaccurate or incomplete information.
The whitepaper is a legal document, not a marketing document. The MiCA whitepaper regime imposes mandatory content requirements and statutory liability standards that are distinct from and additional to any marketing obligations under consumer protection or financial-promotion rules.
What Are the Most Common Classification Mistakes?
The most pervasive mistake is the one named directly in the premise of this page: the belief that a utility label resolves the classification question. It does not. No regulator – in the EU, UK, US, Singapore, Hong Kong or the UAE – treats the name of a token category as determinative. The label "utility token" in a whitepaper is a self-serving characterisation. The legal test is applied to the substance of the rights, not to the name the issuer chose.
The second common mistake is treating classification as a static determination. Token rights can change – through governance votes, smart-contract upgrades, or changes to the underlying platform. A token that was correctly classified as a utility instrument at launch may, after a protocol upgrade that adds a revenue-share mechanism, cross into the security or ART category. Issuers rarely have legal processes in place to monitor and re-assess classification as the protocol evolves.
The third mistake is using legal opinions as a litigation shield rather than as a genuine analysis. An opinion letter commissioned to reach a predetermined conclusion – to confirm utility status regardless of the rights analysis – provides limited protection and creates litigation risk. The opinion may be produced in discovery; if it does not reflect a genuine assessment, it can become evidence of the issuer's awareness that the token might be a security.
A fourth mistake – particularly relevant for EU issuers – is assuming that MiCA provides a complete regulatory answer. MiCA regulates the offering and trading of crypto-assets. It does not pre-empt national company law, tax law, consumer protection law or AML/CFT obligations. A MiCA-compliant whitepaper notification does not constitute a compliance clearance for the entire token project.
The fifth mistake, one we encounter regularly in transactions involving a BVI or Cayman issuer, is the assumption that an offshore issuer entity insulates the project from EU or US regulation. Regulators in both jurisdictions apply an effects-based analysis: if the token is offered to persons in the jurisdiction, the jurisdiction's rules apply regardless of where the issuer is incorporated. The VARA regime in Dubai and the FSRA regime within ADGM apply similar reasoning to offers made into or from their territories.
Decision Matrix: Which Classification Profile Applies to Your Project?
Token projects do not present a uniform profile. The analysis and the resulting compliance obligations differ significantly depending on the nature of the rights conferred, the distribution model and the issuer's geographic footprint. Three broad profiles illustrate the divergence.
Profile A – Platform access token with no financial return: A token that gives holders access to a specific platform service, with no revenue share, no redemption right against the issuer, and no governance rights over profit allocation, presents the strongest case for classification outside the securities category in most jurisdictions. Under MiCA, it likely falls into the "other crypto-asset" category and requires only a whitepaper notification for a public offering above the de minimis threshold. The US analysis is more nuanced and depends on whether the platform was operational at launch and whether purchasers could reasonably expect profit from secondary-market appreciation. Timeline to documentation: typically a matter of weeks for a single jurisdiction; longer for multi-jurisdictional scope. Key risk: protocol upgrade that adds financial mechanics post-launch.
Profile B – Token with governance and revenue-share mechanics: A token that gives holders a vote on protocol revenue distribution, or a claim on a share of protocol fees, is significantly harder to classify outside the securities category in most major jurisdictions. Under FINMA's taxonomy, this is an asset token. Under US law, the profit-sharing element is a strong indicator of security status. Under MiCA, the token may be characterised as an ART if the revenue is derived from a basket of assets, or it may trigger the ART or EMT regime if the economics approximate those of a managed fund. Compliance cost and timeline are materially higher. Key risk: regulatory challenge in every distribution jurisdiction.
Profile C – Stablecoin or payment token: A token pegged to a single fiat currency is an EMT under MiCA and requires authorisation from an EU national competent authority. An EMT issuer must be authorised as a credit institution or as an electronic money institution. Reserve, redemption and interoperability obligations apply. Outside the EU, the analysis varies: under the MAS Payment Services Act, a stablecoin may be a digital payment token or may engage additional MAS stablecoin-specific requirements. Under the NYDFS regime, a US-facing stablecoin issuer requires a BitLicense or trust-company charter. Timeline and capital requirements vary materially by category and jurisdiction and should be assessed against current regulatory guidance. Key risk: the regulatory burden is substantial and the cross-border compliance requirements are layered.
In a recent engagement, a token project launching a governance and staking instrument reached OBOLUS after receiving a single-jurisdiction EU classification. The rights inventory identified a secondary revenue-distribution mechanic that had not been flagged to the initial classification counsel. Working through the cross-border analysis, we identified the relevant regulatory exposure and advised on a structural adjustment to the revenue mechanic that addressed the primary securities-law concern without altering the protocol's economic logic. The amended whitepaper was filed ahead of the planned launch date.
If your project sits between these profiles, or if an earlier classification opinion has become stale after a protocol upgrade, write to OBOLUS at info@oboluslaw.com for a scoped reassessment. A second read on a prior opinion frequently surfaces structural adjustments that were not considered at the time. Map your options.
The Whitepaper as a Legal Instrument
The MiCA whitepaper is the most widely misunderstood document in a token project. Issuers routinely treat the whitepaper as a marketing and technical disclosure document that is then filed with a regulator as a regulatory formality. That framing is legally incorrect and tactically dangerous.
Under MiCA, the whitepaper carries statutory civil liability for any misleading, inaccurate or incomplete information. An investor who suffers loss from reliance on a whitepaper has a statutory claim against the issuer and, in some categories, against the person who filed the whitepaper. That liability attaches to the issuer regardless of whether the whitepaper contains the standard disclaimers that token projects have used historically. MiCA pre-empts the disclaimer approach for the categories it covers.
The whitepaper must contain prescribed information: a description of the issuer, the token, the underlying technology, the rights and obligations attached to the token, the risks, the AML/CFT framework, and the arrangements for safeguarding token holders' interests. The mandatory content requirements are detailed and specific. A whitepaper drafted to satisfy marketing objectives – emphasising growth potential and minimising risk disclosure – is unlikely to satisfy the MiCA content standard and exposes the issuer to enforcement action from the relevant national competent authority.
For tokens classified outside MiCA – because they are securities, or because the offering is to fewer than 150 persons per member state, or because the total consideration is below the relevant threshold – the whitepaper question does not disappear. It is replaced by the equivalent disclosure obligation in the applicable securities or financial-instruments regime. A security token offering in the EU requires a prospectus or a prospectus exemption. An offering in the US to accredited investors requires compliance with the applicable registration exemption, with its own disclosure and filing requirements.
The whitepaper is also the document that defines, and in many jurisdictions binds, the rights of token holders against the issuer. Courts in England and Wales, Singapore and Hong Kong have characterised tokens as property and have applied contract and trust analysis to determine token holder rights. The whitepaper, the token terms, and the smart contract together form the legal relationship between issuer and holder. Inconsistencies between those three documents are a source of litigation risk that can be avoided at the drafting stage.
Airdrop and Secondary-Market Distribution: Legal Considerations
An airdrop – the distribution of tokens to wallet addresses at no direct monetary cost – is not legally neutral. Airdrops can constitute a public offering of tokens depending on how they are structured, to whom they are distributed, and whether the recipients are located in jurisdictions that require whitepaper or prospectus disclosure for token distributions.
Under MiCA, a public offering of crypto-assets to the public above a threshold requires a whitepaper. Whether a gratuitous distribution constitutes an "offer to the public" for MiCA purposes depends on the circumstances: targeted airdrop campaigns to existing community members raise different issues from broad distributions to anonymous wallet holders. ESMA and national competent authorities are developing guidance on these edge cases, but the conservative approach is to assess each airdrop as a potential public offering until that guidance crystallises.
In the United States, an airdrop of tokens that are securities is a distribution of securities. The "free" nature of the distribution does not eliminate the registration requirement or the need for an applicable exemption. The SEC has examined airdrops in the context of broader enforcement actions and has characterised certain airdrops as promotional distributions designed to increase the value of existing holdings – a framing that supports, rather than undermines, the securities analysis.
From a cross-border perspective, the safest airdrop structure involves a clear jurisdictional scope decision (who is eligible and who is excluded), a classification analysis for each jurisdiction of eligible recipients, and documentation that addresses the applicable disclosure obligations. Smart-contract level restrictions are not a substitute for legal eligibility determinations, but they are a useful operational reinforcement of the legal restrictions.
Secondary-market listing raises classification questions that are distinct from, though related to, the original offering analysis. A token that was distributed via a MiCA-compliant whitepaper notification and then listed on an exchange may, if it is later characterised by a regulator as a security, expose the exchange to unlicensed trading venue liability. Issuers who want to list on regulated venues typically require a current and comprehensive classification opinion as part of the listing due diligence process.
Related at OBOLUS
- Token Offerings & Securities practice overview – the full scope of OBOLUS's work for token issuers and exchanges
- Legal counsel for stablecoin issuers – EMT and ART authorisation, reserve structures and cross-border compliance
- Crypto exchange setup in France under the AMF/PSAN regime – EU market entry and MiCA transition for exchange operators
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers and the jurisdiction of distribution – not the name in the whitepaper. Regulators in the US, EU, UK, Singapore and Hong Kong each apply their own test to the substance of those rights. A token carrying profit-sharing, redemption or investment-return characteristics faces significantly higher classification risk across all major regimes. A rights inventory and a concurrent multi-jurisdictional analysis are the only defensible way to answer this question before launch.
Do I need a MiCA whitepaper?
Under MiCA, a public offering of crypto-assets that are not ARTs or EMTs requires a whitepaper notification to the relevant national competent authority at least twenty business days before publication, unless a specific exemption applies. Exemptions include offers to fewer than 150 persons per member state and offers below the relevant total-consideration threshold. ART and EMT issuers face authorisation requirements that go well beyond a whitepaper. Whether a specific offering qualifies for an exemption turns on the structure of the distribution and the category of the token.
How should an airdrop be structured legally?
An airdrop is not automatically exempt from token-offering regulation. Under MiCA, a gratuitous distribution that constitutes a public offer may require a whitepaper. In the US, an airdrop of tokens characterised as securities requires a registration exemption regardless of the zero-cost structure. A legally defensible airdrop requires a prior classification analysis, a jurisdiction-by-jurisdiction eligibility scope decision, and documentation that addresses applicable disclosure obligations. Smart-contract restrictions support but do not replace the legal eligibility framework.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights conferred, not the marketing label – working through concurrent multi-jurisdictional analysis so that a classification opinion actually addresses the distribution reality. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when mis-structured token projects lead to enforcement or investor claims. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialist in token classification, smart-contract legal architecture and cross-border digital-asset structuring for issuers and trading platforms.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.