Token misclassification is the most consequential early mistake in a digital-asset product launch. A founder who labels a token "utility" and proceeds without rigorous legal analysis risks converting a product release into an unregistered securities offering – with enforcement, rescission liability and reputational damage that can follow the entity, and its directors, across jurisdictions. Regulated entities face a sharper version of this risk: a mis-classified token sale can imperil an existing licence, trigger supervisory review and expose senior management to personal liability. The legal question is not whether the label fits; it is whether the substance of the rights conferred, the manner of sale and the regulatory regime governing the issuer collectively require a regulated instrument and a compliant form of agreement.
This page sets out how OBOLUS approaches token sale agreement drafting for regulated entities: the classification step that must precede drafting, the agreement architecture, the cross-border complications that reshape standard terms, and the common structural mistakes we see in late-stage review. The analysis covers the principal regimes – MiCA (the EU's Markets in Crypto-Assets Regulation, supervised by ESMA and national competent authorities), VARA in Dubai, the MAS Payment Services Act framework in Singapore and the SFC VASP licensing regime in Hong Kong – as well as the securities analysis that governs whether a token offering must be treated as an investment product rather than a simple transfer of digital rights.
Why Token Classification Must Precede Every Drafting Decision
The form of a token sale agreement is determined entirely by how the token is classified under the relevant regulatory regime. Classification is not a labelling exercise; it is a legal analysis of the rights the token confers, the economic relationship between issuer and holder and the manner in which the token is sold or offered. Under MiCA, the primary categories are asset-referenced tokens (ARTs), e-money tokens (EMTs) and "other" crypto-assets – each carrying a distinct authorisation track, whitepaper obligation and agreement structure. Outside the EU, a parallel securities analysis applies: does the token constitute an investment contract, a transferable security or a regulated financial instrument under the law of the issuer's jurisdiction and, critically, under the laws of the jurisdictions into which the token is sold or distributed?
The substance-over-label principle governs in every major regime. ESMA has been explicit that classification turns on the rights and obligations attached to the token, not the marketing term. The SFC in Hong Kong and MAS in Singapore apply equivalent functional tests. A token that offers profit-sharing, governance rights with economic consequences or a redemption mechanism can attract securities regulation regardless of what the whitepaper calls it. For a regulated entity – a licensed exchange, a VASP holding a VARA licence, a MiFID firm expanding into token issuance – this analysis is not optional. It determines whether the token sale sits inside or outside the regulatory perimeter the entity already operates within, and whether a second authorisation is required.
In our cross-border practice, we run classification in parallel across the issuer's home jurisdiction and the primary distribution jurisdictions before a single clause of the sale agreement is drafted. That sequence prevents the agreement from locking in assumptions that later legal analysis contradicts.
A common assumption is that a utility label on a whitepaper settles the legal classification. It does not. Regulators assess substance. An agreement drafted on a utility assumption that later fails a securities analysis will need to be rescinded or restructured at considerable cost – and, for a regulated entity, under regulatory scrutiny. We assess classification against the rights the token actually confers, not the name the issuer assigns it.
For a scoped classification and agreement review, contact OBOLUS at info@oboluslaw.com. The analysis above describes the standard path. Your facts – the entity, the token economics, the distribution list and the licensing position – change the analysis materially. Map your options
What Does a Compliant Token Sale Agreement Look Like for a Regulated Entity?
A token sale agreement for a regulated entity is a multi-layer instrument that integrates the commercial terms of the sale with the regulatory obligations imposed on the issuer by its licence, the token's classification and the applicable AML/KYC regime. It is not a simple terms-and-conditions document, and it is not a standard share purchase agreement with "token" substituted for "share." The architecture must address at least six discrete legal layers simultaneously.
The first layer is the description and delivery mechanics: what the purchaser acquires, when and how, with technically accurate language referencing the smart contract address, the applicable blockchain, the vesting or lock-up schedule and the conditions to delivery. Vague delivery terms are one of the most common sources of post-sale dispute, particularly where tokens are subject to vesting or are issued on a future-date basis (a SAFT – Simple Agreement for Future Tokens – or a token warrant structure).
The second layer is the regulatory representations and warranties. A regulated entity selling tokens must represent its authorisation status, confirm that the sale complies with applicable licence conditions and warrant that the token is classified in the manner described in the whitepaper. Purchasers in institutional rounds will require these representations; regulators may also expect them as a matter of internal governance.
The third layer is the jurisdiction, eligibility and transfer restrictions. Under both MiCA and the US securities regime (supervised by the SEC and CFTC at the federal level, with state money-transmitter licensing also relevant), the agreement must restrict participation by persons in jurisdictions where the offer would constitute an unlicensed offering, and must impose transfer restrictions that prevent resale into prohibited markets. For a VARA-licensed entity in Dubai, the VARA rulebooks impose specific disclosure and conduct obligations that must be reflected in the contractual terms.
The fourth layer is the AML/KYC and sanctions compliance framework. The agreement must specify the purchaser's obligation to complete verification, the issuer's right to refuse or reverse a sale on AML/KYC grounds and the consequence of a sanctions match. Under FATF Recommendation 15 and the applicable Travel Rule (the obligation to pass originator and beneficiary data with a transfer), a regulated entity may also be required to collect and transmit data at the point of sale that a non-regulated issuer would not consider.
The fifth layer is the whitepaper relationship. Under MiCA, the crypto-asset whitepaper is a legally significant document and the sale agreement must cross-reference it, incorporate its risk disclosures and specify the consequences of a material change to the whitepaper after the agreement is signed.
The sixth layer is dispute resolution and governing law. Cross-border token sales require careful selection: English law and the courts of England and Wales, or the DIFC Courts, are frequently preferred for institutional sales given their well-developed approach to digital-asset disputes; Singapore is favoured for Asia-Pacific distributions. The choice of governing law also affects which rights the agreement confers – and therefore feeds back into the classification analysis.
How Does a Multi-Jurisdiction Distribution Reshape the Agreement?
A token sale to purchasers in multiple jurisdictions is not a single transaction governed by a single set of rules – it is a series of bilateral or multilateral sales, each of which may trigger different regulatory obligations in the purchaser's jurisdiction. For a regulated entity, this cross-border reality creates material drafting risk.
The primary complication is the securities perimeter. A token that is not a security in the EU under MiCA may nonetheless be characterised as a security in the United States under the federal securities laws supervised by the SEC, or in a Canadian province, or in the United Kingdom under FCA rules. The agreement must therefore include a robust eligibility schedule that maps distribution restrictions by jurisdiction, with representations by the purchaser as to their location and regulatory status. For US persons specifically, the standard market practice involves Regulation S and/or Regulation D safe-harbour reliance, with corresponding contractual mechanics.
The second complication is banking and payment rail selection. Regulated entities often use fiat on-ramps or licensed payment service providers to receive sale proceeds. The choice of payment rails, the currency in which proceeds are denominated and the jurisdiction in which they are held all affect the tax treatment of the transaction, the entity's AML obligations and the practical ability to return proceeds if a sale is rescinded.
In our practice, we have seen issuers structure a token sale correctly under the issuer's home regime, only to find that the distribution list includes purchasers in jurisdictions where the token constitutes a regulated financial product requiring a prospectus or registration. Retrofitting eligibility restrictions after the sale has launched is operationally difficult and, in some cases, requires regulatory notification. The cross-border analysis should be part of the pre-launch agreement review, not a post-incident fix.
The MAS Payment Services Act regime in Singapore and the SFC VASP framework in Hong Kong both impose requirements on entities conducting token offerings in or from those jurisdictions, and each has extraterritorial reach to offerings directed at local residents. A VARA-licensed Dubai entity offering tokens to Singapore residents needs to assess MAS requirements independently of its VARA position.
SAFT, Token Warrant or Direct Sale: A Decision Matrix
The choice of instrument is not stylistic. It determines the regulatory treatment, the accounting consequences and the enforceability of the issuer's obligations. Three instruments predominate in institutional token sales by regulated entities, and each suits a different operator profile.
A regulated entity that is issuing a token which has cleared a non-securities classification, whose token generation event (TGE) is imminent and whose purchasers are institutional or professional investors in jurisdictions where the token can be freely sold is best served by a direct token sale agreement. The agreement is executed, the token is delivered at TGE or according to a vesting schedule and the regulatory representations are made at closing. This is the cleanest structure; it is also the one most exposed to classification error if the pre-drafting analysis was inadequate.
A regulated entity whose token is ready in concept but whose TGE is several months out, and where the entity needs to raise capital in advance of launch, typically reaches for a SAFT (Simple Agreement for Future Tokens). The SAFT defers token delivery to a future date and ties delivery to specified conditions. The critical drafting question is whether the SAFT itself constitutes a security – a question that turns on the law of the jurisdiction in which it is entered into and the identity of the counterparty. In many jurisdictions, a SAFT sold to an accredited or professional investor under a private placement exemption avoids securities regulation; in others, no such exemption applies.
A token warrant is a contractual right to acquire tokens at a future date at a specified price or exchange rate. It is the instrument most likely to attract securities characterisation, because it most closely resembles a financial option. For a regulated entity holding a securities or derivatives licence, a token warrant may sit comfortably within the entity's existing regulatory perimeter. For an entity whose licence does not cover securities or derivatives, issuing a token warrant may require a second authorisation or may be impermissible altogether.
The risk profile across all three instruments is asymmetric for a regulated entity: the downside of getting the instrument wrong is not merely a civil dispute with a purchaser; it is a supervisory finding that the entity conducted an unregulated activity within its licensed perimeter. We regularly advise on the pre-launch instrument selection as part of the overall token sale mandate.
What Are the Most Common Drafting Mistakes in Token Sale Agreements?
In late-stage agreement review – where a client brings an existing draft to us before launch – we encounter a consistent pattern of structural errors. Each carries a different risk profile for a regulated entity.
The first is an absent or inadequate classification analysis. The agreement references the token type without recording the legal analysis that supports the classification. If the classification is later challenged, the entity cannot demonstrate that it applied a reasoned process. For a supervised entity, this gap is a governance failure, not merely a legal risk.
The second is jurisdiction-blind eligibility provisions. Generic "no offer in regulated jurisdictions" language does not discharge the issuer's obligation to assess each distribution jurisdiction. The UK, the US, Canada and Australia each have specific requirements that cannot be addressed by a blanket exclusion. We have reviewed agreements that nominally excluded US persons but whose mechanics – public website, no geo-blocking, no IP check – made that exclusion unenforceable.
The third is whitepaper decoupling. The agreement does not properly incorporate the whitepaper, does not address the consequences of a post-signing whitepaper change and does not specify which version of the whitepaper governs. Under MiCA, a material change to a whitepaper triggers specific notification and, in some cases, revision obligations; an agreement that is silent on this creates a conflict between the contractual and regulatory frameworks.
The fourth is inadequate AML/KYC mechanics. The agreement states that purchasers must complete KYC but does not specify the standard, the timing, the consequence of failure or the entity's rights on a sanctions match. This is a compliance gap that VASP supervisors – including VARA and the Bank of Lithuania under the MiCA transition – will identify in a routine audit.
The fifth is governing-law mismatch. The agreement selects a governing law that is inconsistent with the entity's licence jurisdiction, the token's classification jurisdiction or the primary distribution market. For example, an agreement governed by the law of an offshore jurisdiction, for a token that is classified as an ART under MiCA and sold primarily into the EU, creates a regulatory and conflicts-of-law problem that is difficult to resolve after the fact.
A Cross-Border Token Sale Restructured Before Launch
Earlier this year, a licensed virtual-asset exchange approached us for review of a SAFT it had prepared for a strategic round ahead of its token launch. The entity held an activity-based licence in a Gulf Cooperation Council jurisdiction and intended to distribute the SAFT to institutional purchasers across Europe, Asia-Pacific and the Middle East. The draft SAFT had been prepared internally and described the token as a utility token without a prior formal classification analysis. The eligibility schedule excluded US persons but contained no jurisdiction-specific analysis for EU or Singapore distribution.
We conducted a classification assessment against MiCA, the MAS Payment Services Act framework and the applicable GCC regime. The classification analysis concluded that the token, as then designed, carried profit-participation mechanics that risked ART or securities characterisation in the EU and MAS-regulated territory. We worked with the entity to amend the token economics before drafting was completed, removing the profit-participation feature and replacing it with governance rights that, properly structured, fell outside the securities and ART perimeters in the relevant jurisdictions. The SAFT was then redrafted with jurisdiction-specific eligibility schedules, a whitepaper incorporation clause and a restructured AML/KYC framework. The round launched within the entity's existing licence conditions without a second authorisation being required.
Self-Assessment Checklist for Regulated Entities Before Launch
The following checklist is not a substitute for legal advice; it is a structuring guide for the internal review a regulated entity should complete before engaging external counsel for the drafting phase.
First, has a formal written classification analysis been completed, assessing the token against the regimes in the issuer's jurisdiction and all primary distribution jurisdictions? If the analysis was oral or is embedded only in internal marketing materials, it needs to be formalized before drafting begins.
Second, does the entity's existing licence cover the proposed token-sale activity, or does the sale require a variation, a second authorisation or a notification to the regulator? For a VARA-licensed entity, the activity-based licence scope is determinative. For a MiCA-authorised CASP, the authorisation conditions and the applicable CASP category matter.
Third, is there a current, legally reviewed whitepaper, and does it reflect the token rights as they will be described in the agreement? The whitepaper and the agreement must be consistent. Divergence is a regulatory red flag.
Fourth, has the entity assessed the AML/KYC and Travel Rule obligations that apply to the token sale in the issuer's jurisdiction and in the distribution jurisdictions? FATF Recommendation 15 applies to virtual-asset transfers, and the Travel Rule imposes data-transfer obligations that must be reflected in the agreement mechanics.
Fifth, has the dispute-resolution and governing-law clause been assessed for consistency with the entity's licence jurisdiction, the classification analysis and the distribution markets? A clause that sends disputes to an arbitral seat that has no enforcement track record for digital-asset claims may be commercially inadequate for an institutional round.
If a prior token sale agreement stalled in regulatory review or a supervisory question has been raised about an existing token structure, a second read can surface the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or write to us at t.me/oboluslaw. Map your options
Related at OBOLUS
Related at OBOLUS
- Token Offerings & Securities practice overview – the full regulatory scope for token issuers and digital-asset businesses
- Stablecoin issuance authorisation in Mauritius – the VAITOS Act regime for regulated stablecoin and ART-adjacent structures
- Licence renewal and variation for digital-asset firms – managing scope changes and supervisory notifications when a token programme alters the licensed perimeter
FAQ
Is my token a security?
Token classification turns on substance, not label. The key questions are: does the token confer rights that resemble a security (profit participation, investment return, ownership interest)? In what jurisdictions is it offered and traded? Different regimes apply different tests – the EU applies the MiCA and MiFID II frameworks; the US applies a functional economic substance analysis; Singapore and Hong Kong each apply regulatory guidance specific to their VASP licensing regimes. A written classification analysis across the issuer's jurisdiction and all distribution markets is the necessary first step. A utility label alone does not resolve the question.
Do I need a MiCA whitepaper?
Under MiCA, a crypto-asset whitepaper is required for most public offers of crypto-assets within the EU, with limited exemptions (for example, offers to fewer than 150 natural or legal persons per member state, or offers exclusively to qualified investors). A MiCA-authorised CASP or an entity offering ARTs or EMTs faces additional whitepaper content and notification requirements specific to those token categories. If your token is offered into the EU – including through secondary trading platforms accessible to EU residents – the whitepaper obligation and its timing relative to the offer are material. The specific thresholds and timelines should be confirmed against current MiCA implementing measures.
How should an airdrop be structured legally?
An airdrop – a distribution of tokens without direct monetary consideration – can still constitute an "offer to the public" under MiCA or a distribution of securities under applicable law if the tokens have economic value and are distributed in connection with a commercial purpose. The legal structure depends on the token's classification, the jurisdiction of recipients, whether the airdrop is truly gratuitous or contingent on an action (staking, referral, community participation) and whether the distributing entity is licensed. A regulated entity conducting an airdrop should treat it as a mini-offering: classification confirmed, eligibility assessed, AML/KYC obligations mapped and the distribution mechanics documented.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We assess token classification against the substance of rights, not the marketing label – a distinction that consistently matters when regulators review a token programme after launch. To discuss your token sale, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialises in token structure, smart-contract legal analysis and the regulatory interface between DeFi protocols and licensed digital-asset entities.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.