Token classification is the legal question that determines whether a digital-asset launch succeeds or triggers enforcement. As regulators across the major hubs move toward substance-based analysis – examining the rights a token actually confers, not the label on its whitepaper – a utility designation that seemed defensible at the drafting stage can collapse under a regulatory examination or a securities-law challenge. The consequences are severe: an unregistered securities offering carries civil liability, potential criminal exposure, and the reputational damage that comes with a public enforcement action. This page sets out the classification analysis, the regimes that matter, and the process OBOLUS applies when a token issuer needs a defensible legal position before launch or under pressure.
Why token legal classification is the highest-stakes question in a launch
Token legal classification under heightened scrutiny is the process of determining, under every applicable legal regime, whether a digital asset constitutes a security, an e-money instrument, a payment token, or something else entirely – and that determination controls every subsequent legal decision in a token offering. The label a project applies to itself is irrelevant. What matters is the bundle of rights the token creates, how it is marketed, and who holds economic expectations in relation to it.
Regulators in the major hubs have made this explicit. Under MiCA – the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities – the regime itself distinguishes among asset-referenced tokens (ARTs), e-money tokens (EMTs), and other crypto-assets, each attracting a distinct authorization and whitepaper obligation. A token that resembles an ART in economic substance but is labeled a utility token does not escape the ART regime; the issuer simply operates outside it without authorization.
The SEC and CFTC in the United States apply a similar logic. The SEC's analysis draws on the investment contract doctrine – the test that asks whether funds are invested in a common enterprise with an expectation of profit derived from the efforts of others. That test turns on substance. In our practice, we have seen issuers launch with whitepaper utility language and then discover – through a subpoena or a secondary-market enforcement action – that the actual token economics placed them squarely in securities territory. The cost of that discovery is orders of magnitude greater than the cost of classification analysis before launch.
The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis. For a scoped initial assessment of your token's classification risk, contact OBOLUS at Map your options or write to info@oboluslaw.com.
Which legal regimes govern token classification – and which apply to your offering?
No single global regime determines token classification; the applicable analysis depends on where the issuer is established, where tokens are offered, and where buyers are located – and all three can differ. A token issued by a Singapore entity, sold through a Swiss exchange to EU residents, may face concurrent analysis under the Payment Services Act, FINMA guidance, and MiCA.
The major frameworks apply the following structural logic:
- EU – MiCA / ESMA: tokens are classified as ARTs, EMTs, or other crypto-assets. Those that fall under existing EU financial-instruments law (such as MiFID II) are excluded from MiCA and regulated under that prior framework instead. The question of whether a token is a transferable security under the financial-instruments regime is therefore a threshold question before MiCA even applies.
- United States – SEC / CFTC / FinCEN: the securities analysis uses an investment-contract test applied by the SEC; the CFTC has asserted commodity jurisdiction over assets that do not qualify as securities; FinCEN's money-services-business and Travel Rule (the obligation to pass originator and beneficiary data with a transfer) requirements apply separately to exchanges and custodians. State money-transmitter licensing adds a further layer.
- United Kingdom – FCA: under the Money Laundering Regulations, the FCA's cryptoasset registration regime applies to specified activities. The FCA's financial-promotion rules, which restrict the marketing of qualifying cryptoassets to UK consumers, operate independently of whether a token is a security.
- Singapore – MAS: tokens that constitute capital markets products under the Securities and Futures Act are regulated as such. Tokens that are digital payment tokens (DPTs) but not capital markets products fall under the Payment Services Act and attract DPT service licensing obligations.
- Switzerland – FINMA: FINMA's token taxonomy – payment, utility, and asset tokens – provides a structural baseline, though hybrid tokens require a combined analysis. FINMA guidance on this taxonomy has been influential across other regimes.
- UAE – VARA / ADGM-FSRA: VARA governs virtual-asset activity in mainland Dubai through activity-based licences; the FSRA within ADGM operates a parallel regime with a "recognised virtual assets" concept that bears on what may be offered. Both frameworks require classification before any marketing or sale.
The cross-border reality is that classification in one jurisdiction does not resolve the question in another. Operators we advise routinely face a matrix of concurrent analyses. The practical approach is to identify the three or four regimes most likely to assert jurisdiction – based on issuer domicile, offering venue, and buyer location – and to work through each in sequence, identifying the governing test and the available arguments.
Why a utility label does not resolve the legal classification
The assumption that a "utility" label on a whitepaper settles the legal classification is the most persistently damaging misconception in token issuance practice. Every regime of significance assesses substance, not labels. The relevant questions are economic and structural, not editorial.
Under the investment-contract analysis applied by the SEC, the key axes are: (i) is there an investment of money or value; (ii) in a common enterprise; (iii) with a reasonable expectation of profit; and (iv) derived predominantly from the efforts of others? A token that grants access to a platform but is sold before the platform exists, at a price that rises and falls with project development, with active promotion of secondary-market returns, will satisfy all four. The utility label is not a defense.
Under MiCA, the classification question is similarly structural. A token that references the value of a basket of assets, regardless of how the issuer describes it, attracts the ART framework and the authorization and reserve obligations that follow. An issuer that calls such a token a "reward point" or a "governance instrument" without examining whether it falls within the ART perimeter is exposed.
We assess classification against the substance of rights, not the marketing label. That means reviewing the token's technical architecture, the rights encoded in the smart contract, the economic incentives for holders, the marketing materials, and the secondary-market context – and then mapping those facts to the applicable tests across the relevant jurisdictions. The output is a structured memorandum that either confirms the intended classification or identifies the revisions required to reach a defensible position.
How OBOLUS conducts a token classification analysis
A token classification engagement follows a defined process: we examine the facts, apply the applicable legal tests, identify risk zones, and produce a written position that the issuer can use operationally and, where necessary, present to a regulator.
The process typically proceeds as follows:
- Fact gathering. We review the token's technical design, the rights it confers on holders, the economic model (including any staking, yield, or buyback mechanisms), the marketing materials, and the intended offering structure. We also identify the relevant issuing entities and the jurisdictions in which tokens will be offered or accessible.
- Jurisdiction mapping. We identify the regimes most likely to apply and the applicable classification tests in each. Where a jurisdiction's test is ambiguous on the specific facts, we identify the range of available positions and the factors that would move the analysis in each direction.
- Classification opinion. We produce a written classification analysis that states our conclusion, the reasoning, the applicable regime, and the assumptions on which the analysis rests. Where the structure requires adjustment to reach a defensible classification, we set out what those adjustments are.
- Whitepaper alignment. Where a whitepaper is required – either under MiCA's mandatory disclosure regime or as a matter of market practice – we review it for consistency with the classification. A whitepaper that contradicts the legal analysis creates its own risk: it is the document regulators read first.
- Ongoing monitoring. Classification is not a one-time exercise. Secondary-market behavior, changes to the token's economic model, and regulatory developments can alter the analysis. We advise on trigger points for re-examination.
In our cross-border practice, we have seen classification analyses that addressed one jurisdiction competently but failed to consider concurrent exposure in others – producing a defensible position in the issuer's home market while leaving serious unaddressed risk in the markets where actual sales occurred. That gap is where enforcement actions are made.
What are the most common token classification mistakes?
The most common mistake is treating classification as a drafting exercise rather than a legal analysis. An issuer that instructs a drafter to produce a whitepaper that says "this is a utility token" without conducting the underlying legal analysis has not obtained a classification – it has obtained a document that will be read critically by any regulator who opens an inquiry.
Several other mistakes recur in our practice:
- Ignoring secondary-market context. The classification analysis cannot be conducted in isolation from how the token will behave after issuance. If a token is designed to appreciate in value and is promoted to investors on that basis, the secondary-market framing is part of the classification facts, not a separate matter.
- Conflating registration exemptions with classification. In the US context, a Regulation D or Regulation S exemption from registration is not a classification. It is a method of offering an asset that is already classified as a security. Issuers that rely on an exemption without establishing the underlying classification have assumed the conclusion.
- Assuming a single-jurisdiction analysis is sufficient. A token issued by a Cayman SPV but promoted to EU residents triggers MiCA's whitepaper and, potentially, authorization requirements, regardless of where the issuer is domiciled. The regime follows the offer, not the entity.
- Treating the airdrop as classification-neutral. An airdrop – a distribution of tokens to wallet addresses, typically without payment – is not inherently outside securities law. If the airdrop is used to build a community of economic participants who then have an expectation of value appreciation, the economic substance may place the distributed token within a securities regime.
- Failing to document the analysis. A classification conclusion that exists only in an email thread or a verbal conversation provides no protection. A written legal opinion, produced before the launch, is the evidentiary record of a good-faith classification analysis.
In a recent engagement, a token issuer approaching its public sale discovered that its planned airdrop to early contributors, combined with active secondary-market promotion, had created the very economic profile the issuer believed it had avoided. We restructured the airdrop mechanics and the marketing approach prior to launch, removing the features that created securities-law exposure while preserving the commercial objective. The revised structure was documented in a classification memorandum before any token was distributed.
If a prior analysis has been challenged or your structure has changed since your last classification review, a second examination can identify where the exposure lies. Write to OBOLUS at info@oboluslaw.com or message us at Map your options.
Which classification path fits your token profile?
Token issuers do not all face the same classification question. The applicable analysis – and the depth of effort required – varies significantly by token type, offering structure, and the markets targeted. The following profiles capture the most common situations we encounter.
Profile A – Infrastructure utility token, single jurisdiction, no yield mechanism. A token that grants access to a defined software function, carries no financial return, is not promoted as an investment, and is sold only in a single jurisdiction with a clear utility-token carve-out presents the most straightforward classification analysis. The work focuses on confirming that the token's actual design matches the claimed profile and that no secondary-market behavior contradicts it. Timeline: typically a matter of weeks for a well-documented issuer. Key risk: secondary-market appreciation that post-launch creates an investment expectation the issuer did not intend.
Profile B – Hybrid governance / yield token, multi-jurisdiction offering. A token that confers governance rights and also distributes a share of protocol revenue to holders is a hybrid. The yield component introduces securities-law analysis in virtually every major regime. The multi-jurisdiction offering requires parallel analysis under MiCA, the applicable securities law of each target market, and potentially the Travel Rule where the token is transferred between wallets. Timeline: a matter of weeks to two or three months depending on jurisdictional complexity. Key risk: an ART characterization under MiCA if the revenue distribution creates a reference to an asset basket.
Profile C – Stablecoin or ART-adjacent instrument, EU offer. A token that references a fiat currency, a commodity, or a basket of assets triggers MiCA's ART or EMT framework if offered to EU residents, regardless of the issuer's domicile. Authorization under MiCA is required before the token may be offered; a whitepaper complying with MiCA's disclosure standards is a prerequisite to authorization. Timeline: the authorization process under MiCA varies by national competent authority and the completeness of the application; it is not a matter of weeks. Key risk: operating without authorization while tokens circulate on secondary markets accessible to EU residents.
Profile D – Token offered to US persons, securities-law question unresolved. Any offer to US persons triggers the SEC's analysis. Where the securities-law question is unresolved, the issuer's options are: restructure the token to remove the investment-contract characteristics; conduct the offering under a registered exemption (accepting that the token is a security); or exclude US persons and build the exclusion mechanism into the technical architecture. Each path has a different timeline and compliance burden. Key risk: a post-launch enforcement action that treats a prior offer to US persons as an unregistered securities offering.
What does heightened scrutiny mean for whitepaper and disclosure obligations?
A whitepaper produced under heightened scrutiny is not a marketing document with a legal disclaimer appended. It is a disclosure instrument that must accurately describe the token's nature, rights, risks, and the issuer's legal classification – and it must be consistent with the legal analysis underlying that classification.
Under MiCA, a whitepaper for crypto-assets other than ARTs and EMTs must be filed with the relevant national competent authority and must contain specified disclosures about the offeror, the project, the token, and the rights attaching to it. The content requirements are prescribed. A whitepaper that mischaracterizes the token's nature – even inadvertently – creates civil liability for the issuer and for any persons who signed it.
For token offerings outside the MiCA perimeter – in Singapore, the UAE, or the United States – the applicable disclosure standards differ, but the principle is consistent: the document must be accurate, and the accuracy of the legal characterization within it is the classification analysis. A whitepaper that says a token is not a security, where the underlying analysis does not support that conclusion, is not simply wrong – it is a false statement in a public offering document.
We review whitepapers for legal consistency with the classification analysis. That is a distinct exercise from drafting the whitepaper for commercial appeal. Both are necessary. A whitepaper that is compelling but legally inconsistent creates the same exposure as no whitepaper analysis at all. Regulators in the leading hubs read whitepapers before they read anything else about an issuer; the document is the first point of scrutiny, and its legal accuracy is the first risk vector.
How does cross-border token distribution change the classification analysis?
A token distributed globally does not have a single legal classification. It has a classification in each jurisdiction where it is offered, held, or traded – and those classifications may differ. A token that is a utility instrument in one regime may be a capital-markets product in another, and the issuer bears the compliance obligation in both.
The cross-border angle is most acute in three situations. First, where the issuer is domiciled in a jurisdiction with a permissive regime but actively markets to residents of jurisdictions with stricter classification rules: the offer follows the buyer, not the seller. Second, where the token is listed on an exchange that is accessible globally without geo-blocking: listing on an unregulated exchange does not resolve the securities-law analysis in the jurisdictions where that exchange's users are located. Third, where the token's economic model changes after launch – for example, through the addition of a staking reward or a protocol revenue share – and the change creates a new classification question in a jurisdiction where the original token was compliant.
Operators we advise with global distribution build geo-blocking, purchaser verification, and periodic classification review into their operating model from the outset. That is not a purely defensive position. Regulators in the major hubs increasingly expect to see evidence that an issuer thought carefully about cross-border exposure before launch – and a documented, multi-jurisdiction classification analysis is that evidence.
For issuers with allied counsel in specific national jurisdictions, we coordinate the classification analysis to produce a coherent global position, rather than a set of independent national opinions that may contradict each other on the overlapping questions. That coordination is often the most valuable element of a cross-border classification engagement.
Related at OBOLUS
- Token Offerings & Securities for Digital-Asset Businesses – practice overview covering the full lifecycle of a token offering
- Token Sale Agreement Drafting – legal counsel for digital-asset firms structuring the contractual framework for a token sale
- Fiat On/Off-Ramp Banking in the Czech Republic – banking access and fiat infrastructure for digital-asset operations in the EU
FAQ
Is my token a security?
Whether a token is a security depends on the rights it confers, how it is marketed, and the economic expectations it creates – not the label applied in the whitepaper. Every major regime applies a substance-based test. Under the investment-contract analysis used in the United States, the key factors are an investment in a common enterprise with an expectation of profit derived from others' efforts. Under MiCA, classification turns on the token's structural characteristics. Legal analysis across the relevant jurisdictions is required before a defensible answer can be given.
Do I need a MiCA whitepaper?
If your token is an asset-referenced token or an e-money token offered within the EU, MiCA requires both issuer authorization and a compliant whitepaper before any public offer. For other crypto-assets offered to the public in the EU, a whitepaper must be produced, notified to the relevant national competent authority, and published. Tokens that qualify as financial instruments under existing EU law are excluded from MiCA but subject to that prior framework instead. The threshold question is whether your token falls within MiCA's perimeter at all.
How should an airdrop be structured legally?
An airdrop is not inherently outside securities law. If distributed tokens create an economic interest in a project's success – particularly where recipients are early contributors with an expectation of value appreciation – the distribution may trigger securities-law analysis in the jurisdictions where recipients are located. A legally structured airdrop defines the recipient class carefully, limits promotion of secondary-market value, documents the classification rationale before distribution, and excludes recipients in jurisdictions where the distribution would constitute an unregistered offering.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance obligations that sit around them. Digital assets are the entirety of our practice. We assess token classification against the substance of rights, not the marketing label – and we act only for business clients who need a defensible legal position, not a rubber stamp. To discuss your token structure, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – advising token issuers and protocol operators on classification analysis, whitepaper consistency, and cross-border securities-law exposure across the major hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.