Token sale agreements are the contractual spine of any token offering. Get the classification wrong, mis-draft the investor rights provisions, or fail to align the agreement with the applicable regulatory regime, and a product launch can become an unregistered securities offering overnight. As regulators across the EU, the UAE, the UK and Asia-Pacific converge on stricter disclosure and classification standards, the margin for error in token sale documentation has narrowed to near zero.
Drafting a token sale agreement (the binding contract between an issuer and a purchaser in a token offering) under heightened regulatory scrutiny requires more than boilerplate terms. It requires a prior classification analysis, a jurisdiction-specific disclosure architecture, and contractual provisions that reflect – not contradict – the regulatory posture the issuer is taking. This page sets out how that process works in practice, where it goes wrong, and how OBOLUS structures the work for business clients operating across multiple jurisdictions.
Why token classification must precede every drafting decision
The single most consequential decision in any token offering is classification: is the token a security, an e-money token, an asset-referenced token, a utility token, or a payment token? Every subsequent drafting choice – the investor rights provisions, the transfer restrictions, the disclosure obligations, the governing law – follows from that determination.
Under MiCA (the EU Markets in Crypto-Assets Regulation), a token that qualifies as a security falls outside MiCA entirely and into the existing securities regime; only utility tokens and, with specific treatment, asset-referenced tokens and e-money tokens fall within MiCA's scope. Under the VARA rulebooks in Dubai, classification determines which activity-based licence an issuer must hold before offering tokens to the public. In the United States, the SEC applies a functional test focused on the economic substance of the instrument, not its label.
A common assumption is that placing a "utility" label in the whitepaper settles the legal classification. It does not. Regulators and courts assess classification against the substance of the rights conferred – economic participation, profit expectation, a common enterprise, secondary market pricing driven by issuer efforts. The label is one data point; the rights are the determinant. In our practice, we assess classification against that substance before a single operative clause is drafted.
The classification analysis must also be run jurisdiction by jurisdiction. A token that qualifies as a utility instrument under MiCA may nonetheless engage securities law in Singapore under the Payment Services Act framework administered by MAS (Monetary Authority of Singapore), or trigger the VASP licensing regime under the SFC in Hong Kong. A single-jurisdiction sign-off is not enough for any offering that distributes tokens to purchasers in multiple markets.
For a scoped classification analysis and drafting brief before your token launch, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the purchaser base, the token economics – change the analysis substantially.
What a token sale agreement must contain under heightened scrutiny
A well-drafted token sale agreement under heightened scrutiny is structured around five functional layers: the parties and capacity representations; the purchase mechanics and payment terms; the token description and associated rights; the regulatory disclosure package; and the transfer restriction and secondary-market regime.
The parties and capacity layer is where many early-stage issuers create the first enforcement risk. The agreement must accurately identify the issuing entity and confirm that entity holds – or has applied for – any licence or registration required by the applicable regime. An issuer entity incorporated in the BVI but offering tokens to EU purchasers without a MiCA-compliant structure creates a direct regulatory exposure that appears on the face of the agreement if the drafting is careless about capacity representations.
The token description provisions are the most scrutinized section in any enforcement review. They must describe what the token confers: access rights, governance rights, revenue-sharing, redemption mechanics, or simply a claim to a future network utility. They must not overstate any right that is not yet operative. An agreement that describes token holders as "participating in the protocol's revenue" when the revenue-sharing mechanism has not yet been deployed is both a misrepresentation and a securities-classification red flag.
The regulatory disclosure package is increasingly expected to be incorporated by reference rather than appended in full. Under MiCA, a whitepaper for a qualifying crypto-asset must be notified to the relevant national competent authority before publication; the sale agreement should reference the version of the whitepaper that is current at the date of the agreement and confirm the purchaser has reviewed it. Under the FCA's financial-promotion rules in the UK, the agreement must be consistent with the approved promotion; discrepancies between the promotion and the agreement create a compliance gap.
Transfer restrictions deserve particular attention for institutional purchasers. Lock-up periods, resale restrictions tied to the issuer's listing timeline, and jurisdiction-specific restrictions on secondary trading all need to be drafted with precision. A restriction that is too broad can create a practical liquidity problem; one that is too narrow can undermine the issuer's ability to control the secondary market in the early period and expose the issuer to additional regulatory scrutiny if unrestricted secondary trading begins before the project is operationally live.
How does cross-border distribution complicate the drafting?
Cross-border token distribution is the standard operating environment for most issuers, and it is where agreement drafting becomes genuinely complex. A single agreement structure that works for EU purchasers under MiCA may not satisfy the disclosure requirements applicable to purchasers subject to MAS supervision in Singapore, or to purchasers in the United States where the SEC's analysis of the offering would proceed on different functional grounds.
In our cross-border practice, we typically see three structural approaches to this problem. The first is a jurisdictional carve-out structure: one master agreement with jurisdiction-specific schedules that layer in the additional disclosure and restriction provisions required in each market. The second is a multi-agreement architecture: separate agreements for each major purchaser jurisdiction, with consistent economic terms but jurisdiction-specific legal provisions. The third is a restricted-purchaser approach: a single agreement that excludes purchasers from jurisdictions where compliance is not operationally feasible, with robust representation and warranty mechanics from each purchaser confirming their eligibility.
Each approach carries a different compliance cost and a different enforcement risk profile. The jurisdictional carve-out structure is the most operationally efficient for large distributions but requires the most careful drafting to ensure the schedules are internally consistent. The restricted-purchaser approach is the most defensible from a regulatory standpoint but limits the offering's reach. The multi-agreement architecture is the most resource-intensive but provides the cleanest regulatory record for each jurisdiction.
The governing law and dispute resolution provisions also deserve attention in the cross-border context. An agreement governed by English law and providing for arbitration in a recognized seat gives institutional purchasers a familiar enforcement framework. However, the governing law choice does not determine the regulatory classification in each purchaser's jurisdiction; an English-law agreement does not exempt the issuer from MiCA disclosure requirements for EU purchasers, or from MAS licensing requirements for Singapore purchasers.
Aligning the token sale agreement with the whitepaper and disclosure regime
The whitepaper and the token sale agreement must form a coherent disclosure package; inconsistencies between the two are one of the most common mistakes we see in practice, and they carry material enforcement risk. Under MiCA, the whitepaper is a public-facing disclosure document with regulatory content requirements; it is not a marketing brochure that can be revised freely after the agreement is executed.
Under MiCA's applicable provisions, an issuer of certain crypto-assets (other than ARTs and EMTs, which carry their own stricter obligations) must publish a compliant whitepaper before making the tokens available to the public. The whitepaper must describe the project, the token's functionality, the rights attached to it, and the material risks. Any material change to the project after publication requires an updated whitepaper. If the token sale agreement contains representations about the project that are inconsistent with the whitepaper – or more expansive than the whitepaper – the issuer faces liability under both the regulatory regime and the contractual misrepresentation provisions.
In the ADGM (Abu Dhabi Global Market) environment, where the FSRA (Financial Services Regulatory Authority) has its own disclosure and marketing requirements for virtual asset activities, the alignment obligation extends further. The FSRA expects that all investor-facing documentation is consistent, accurate, and not misleading. An agreement that references features of the token or the project that are not disclosed in the regulated offering document creates both a regulatory compliance failure and a private law claim.
The practical protocol we follow is to draft the agreement and the whitepaper in parallel, with a cross-reference audit before finalisation. Every operative right described in the agreement should be traceable to a disclosure in the whitepaper. Every risk factor in the whitepaper should be reflected in the agreement's limitation of liability and force majeure provisions. This alignment discipline takes time but it is the difference between a defensible offering document package and one that collapses under regulatory review.
If your whitepaper and sale agreement were drafted separately or at different times, a consistency audit is worth running before distribution begins. Write to info@oboluslaw.com to scope that work. If a prior process stalled or produced inconsistent documents, a second read can identify the structural gap and the route to resolution.
What are the most common drafting mistakes in token sale agreements?
The most damaging drafting errors in token sale agreements share a common cause: they are made by counsel who understand general commercial law but have not worked through the regulatory classification analysis before drafting begins. The result is agreements that are commercially coherent but legally exposed.
The first category of error is over-specification of future functionality. Agreements that describe in contractual terms the future features of a protocol – the governance rights that will vest on mainnet launch, the staking rewards that will accrue from a specific date, the revenue that will be distributed to token holders – create contractual obligations that the issuer may not be able to fulfil. When the protocol launches on a different timeline or with different features, the issuer faces breach of contract claims from purchasers who relied on those specifications.
The second category is inadequate jurisdiction-specific restriction mechanics. A purchaser representation that says only "I am not a US person" is insufficient for a cross-border offering. Effective restriction mechanics require layered representations covering the purchaser's residence, the jurisdiction in which they received the marketing, the jurisdiction in which they will hold the tokens, and confirmation that the purchase does not violate any law applicable to them. These representations need to be backed by a right of the issuer to void the agreement and return the consideration if a representation proves false.
The third category – frequently overlooked – is the treatment of airdrops and bonus token allocations within the main agreement framework. Operators we advise regularly structure airdrops as separate arrangements from the primary sale, without recognising that where an airdrop is directed at identified individuals in exchange for services (community promotion, social media amplification, testnet participation), it may constitute a regulated offering in certain jurisdictions. The better approach is to include airdrop mechanics in the primary agreement with a clear statement of the basis on which additional tokens are distributed, and to ring-fence jurisdictions where airdrop distribution is not permissible.
A fourth common error is the governing law / regulatory mismatch noted above: selecting a governing law for reasons of familiarity without considering whether that choice affects the regulatory treatment in the purchaser's jurisdiction. Governing law governs the private rights between the parties; it does not determine the regulatory classification or compliance obligations applicable to the offering in each market.
Which agreement structure fits your offering profile?
The right agreement architecture depends on four variables: the token's classification, the geographic distribution of purchasers, the issuer's regulatory posture, and the stage of the project at the time of the offering.
Profile A: An issuer with a MiCA-compliant utility token offering to EU purchasers from an authorised CASP entity, with no US or Singapore distribution, at a project stage where the core functionality is already live. This profile supports a single-agreement structure with a MiCA-compliant disclosure schedule and a relatively straightforward transfer restriction regime. The timeline from classification sign-off to finalised documentation is typically a matter of weeks at this stage.
Profile B: An issuer offering tokens to a mixed EU and Asia-Pacific purchaser base from a Dubai entity licenced under VARA, with the protocol at pre-launch stage. This profile requires a master agreement with separate jurisdiction schedules for EU (MiCA-compliant) and Singapore (MAS-compliant), robust future-functionality disclaimers, and enhanced transfer restrictions for the pre-launch period. The classification analysis is more complex – VARA's activity-based framework, MiCA's category analysis, and MAS's functional test all apply in different contexts. The drafting timeline is longer and the whitepaper alignment audit is critical before any document is finalised.
Profile C: An institutional token offering to qualified investors in the Cayman Islands and the AIFC (Astana International Financial Centre), with the AFSA (Astana Financial Services Authority) as one relevant regulator. This profile may support a restricted private placement structure with qualified investor representations, a negotiated form of agreement rather than a public-form standard contract, and a disclosure package calibrated to institutional rather than retail expectations. The regulatory analysis here focuses on whether the offering triggers CIMA registration in Cayman and whether the AIFC's digital-asset trading facility regime applies.
In each profile, the key risk is the same: committing to a contractual structure before the classification analysis is complete. Operators we advise who have made that error typically discover it when a regulator reviews the offering documentation or when a secondary market develops and purchasers begin characterising their token holdings as investments.
How the process works in practice: an illustrative matter
In a recent instruction, a technology company had drafted and circulated a token sale agreement without prior legal sign-off. The agreement described the token as a "utility token" conferring access rights, but included provisions on governance voting, a secondary-market resale right at a formula price tied to the issuer's performance, and a commitment to distribute a share of protocol revenues to holders after mainnet launch. We were engaged after the draft had been reviewed by a prospective institutional purchaser's counsel who flagged the securities-classification risk. We conducted a reclassification analysis across three relevant regimes, rewrote the rights provisions to remove the investment-contract characteristics while preserving the functionality the issuer required, and rebuilt the whitepaper alignment audit from scratch. The revised documentation package was accepted by the institutional purchaser and supported the issuer's VARA licensing application. The matter completed within a business quarter.
Related at OBOLUS
- Token Offerings & Securities practice – the full scope of our advisory work across token classification, offering structures and regulatory compliance.
- Security token offering structuring for institutional clients – end-to-end advisory for issuers targeting institutional markets under securities law frameworks.
- Founder relocation and tax counsel for digital-asset firms – tax and structuring advice for issuers optimising the entity stack around a token launch.
FAQ
Is my token a security?
Token classification as a security turns on the substance of the rights the token confers, not the label placed on it. The applicable test differs by jurisdiction – the SEC applies a functional economic-substance analysis; MiCA assesses whether the token qualifies as a transferable security under the existing securities regime; MAS applies its own classification framework under the Payment Services Act. A classification opinion requires a fact-specific analysis of the token's rights, economics and distribution mechanics against the relevant regime. OBOLUS conducts that analysis before any drafting begins.
Do I need a MiCA whitepaper?
Under MiCA's applicable provisions, issuers of crypto-assets (other than ARTs and EMTs, which have their own authorisation requirements) that are offered to the public in the EU must publish a compliant whitepaper before the offering commences. There are limited exemptions, including for offerings to fewer than a specified number of persons and for offerings to qualified investors only. Whether your offering triggers the whitepaper obligation depends on the token category, the size and structure of the offering, and the jurisdiction of the purchasers. We advise on both the obligation and the content requirements.
How should an airdrop be structured legally?
An airdrop's legal treatment depends on whether it constitutes a regulated offering in the recipient's jurisdiction and whether it involves consideration – including non-monetary consideration such as services or community activity. A gratuitous airdrop to an unrestricted public may avoid offering-regime obligations in many markets, but a targeted distribution in exchange for services is more likely to engage both the securities and AML regimes. The agreement or terms governing an airdrop should be drafted with the same classification rigour applied to a paid token sale. OBOLUS structures airdrop mechanics as part of the broader token documentation package.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We assess token classification against the substance of rights, not the marketing label – because that is the standard regulators apply. Digital assets are the entirety of our practice, and we act only for businesses. To discuss your token documentation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Roman Levitt, Technology & DeFi Counsel – specialising in token classification, smart-contract governance and regulatory documentation for protocol-stage and institutional token issuers.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.