Whether a token is utility or security is not determined by the whitepaper
Introduction
In recent years, "token issuance" has become one of the most sensitive terms in the Web3 world. Some have achieved overnight fame through it, while others have faced investigations, token refunds, and account bans. The issue lies not in the act of "issuing," but in "how it is issued." While some tokens are listed on major exchanges, supported by communities, and governed by DAOs, others are deemed illegal securities offerings. The distinction lies in whether the issuance occurs within a legal framework.
The reality in 2025 is that utility tokens are no longer in a gray area. Regulators are scrutinizing every Token Generation Event (TGE), every Simple Agreement for Future Tokens (SAFT), and every "airdrop" with a magnifying glass.
This article is written for every Web3 project founder: On the journey from Testnet to DAO, the legal structure is the skeleton of your project. Before issuing tokens, learn how to build this skeleton.
Note: This article is based on an international jurisdiction perspective and does not target or apply to the legal environment of mainland China.
A token's "identity" is not determined by what you write in the whitepaper
Many teams claim, "Our token is purely utility-based, with no profit distribution, so it should be fine, right?"
However, reality is not so simple. In the eyes of regulators, a token's "identity" depends on market behavior, not on how you describe it.
A typical case is Telegram's TON project.

Telegram raised $1.7 billion from investors in a private placement, claiming the tokens were merely "fuel" for a future communications network;
However, the U.S. Securities and Exchange Commission (SEC) determined that this fundraising constituted an unregistered securities offering—because the investors' purpose in purchasing was clearly "future appreciation" rather than "immediate use."
As a result, Telegram refunded the investment funds and paid fines, and the TON network was forced to operate independently from Telegram.
Lesson learned: Regulators look at "investment expectations," not "technical visions." As long as you use investors' money to build an ecosystem, it carries securities attributes.
Therefore, do not fantasize about eliminating risk by using the "utility" label. The nature of a token evolves dynamically—in the early stages of a project, it may constitute an investment contract, only potentially becoming a genuine proof of usage after the mainnet launch.
First, identify what type of project you are
What determines your compliance path is not the token's name or total supply, but the type of project.
- Infrastructure Projects (Infra):
Examples include Layer 1, Layer 2, public chains, ZK protocols, and storage protocols.
These typically adopt a "Fair Launch" model, with no pre-mining and no SAFTs; tokens are generated through node consensus.
Bitcoin, Celestia, and EigenLayer belong to this category.
The advantages are natural decentralization and low regulatory risk; the disadvantages are difficulty in fundraising and long development cycles.
- Application Layer Projects (App Layer):
Examples include DeFi, GameFi, and SocialFi projects.
Tokens are pre-minted by the team (TGE) and the ecosystem treasury is led by the team, with typical representatives such as Uniswap, Axie Infinity, and Friend.tech.
While the business model is clear, compliance risks are high: sales, airdrops, and circulation all require handling regulatory disclosure and Know Your Customer (KYC) issues.
Conclusion: Infrastructure survives on consensus, while application projects survive on structure. Without a well-designed structure, all "Tokenomics" are empty talk.
Testnet Phase: Do not rush to issue tokens; first establish the "legal skeleton"
Many teams begin seeking investors, signing SAFTs, and pre-mining tokens during the Testnet phase.
However, the most common mistake at this stage is:
Taking investors' money while still claiming "this is just a utility token."
Filecoin in the United States serves as a cautionary tale. It raised approximately $200 million through SAFTs before its mainnet launch. Although it obtained an exemption from the SEC, delays in launching and the temporary unusability of tokens led investors to question their "securities attributes," ultimately forcing the project to incur huge compliance costs to rectify the situation.
The correct approach is:
- Distinguish between two entities:
- DevCo (Development Company) is responsible for technical research and development and intellectual property;
- Foundation / TokenCo (Foundation or Token Company) is responsible for ecosystem building and future governance.
- Fundraising method: Use an Equity + Token Warrant structure, rather than selling tokens directly.
Investors receive the right to future tokens, not existing token assets.
This approach was first adopted by projects such as Solana and Avalanche, allowing early investors to participate in ecosystem construction while avoiding directly triggering securities sales.
Principle: The legal structure at the early stage of a project is like the genesis block. If the logic is wrong once, compliance costs may increase tenfold.
Mainnet Issuance (TGE): The moment most likely to attract regulatory scrutiny
Once a token can be traded and has a price, it enters the regulatory radar. This is especially true when involving public distributions such as airdrops, Liquidity Bootstrapping Pools (LBPs), and Launchpads.
- Public Chain Projects:
For example, Celestia, Aptos, and Sui typically have tokens automatically generated by the validator network at the time of TGE,
The team does not directly participate in sales, the distribution process is decentralized, and regulatory risk is minimized.
- Application Layer Projects:
Such as the airdrops by Arbitrum and Optimism, or the community distributions by Blur and Friend.tech,
Regulators in certain jurisdictions have focused on whether their "distribution and voting incentives constitute securities sales."
The safety line during the TGE phase lies in disclosure and usability:
1. Clarify the token's use cases and functions;
2. Publish token allocation ratios, lock-up periods, and unlocking mechanisms;
3. Implement KYC/Anti-Money Laundering (AML) procedures for investors and users;
4. Avoid promotional materials suggesting "expected returns."
For instance, the Arbitrum Foundation explicitly stated at TGE that its airdrop was solely for governance purposes and did not represent investment or profit rights; it also gradually reduced the foundation's dominant proportion in community governance—this is precisely the key path to "de-securitizing" the token.

DAO Phase: Learn to "let go" and allow the project to truly decentralize
For many projects, "issuing tokens" marks the end, but the real challenge is—how to exit control and return the token to being a public good.
Take the Uniswap DAO as an example:
- Initially, development and governance were led by Uniswap Labs;
- Later, the Uniswap Foundation managed the treasury and funded ecosystem projects;
- The community decided on protocol upgrades and parameter adjustments through UNI voting.
This structure makes it more difficult for regulators to deem it a "centralized issuer" and enhances community trust.
Conversely, some projects that failed to manage the DAO transition properly, such as certain GameFi or NFT ecosystems, were ultimately viewed as "pseudo-decentralized" because the team still controlled the majority of tokens and held voting power, thus retaining securities risks.
Decentralization is not "laissez-faire," but "verifiable exit." Establishing a triangular balance among code, the foundation, and the community is the secure DAO architecture.
What regulators are looking for: Can you prove "this is not a security"?
Regulators are not afraid of you issuing tokens; they are afraid of you saying "it is not a security" while acting like one.
In 2023, in its lawsuits against Coinbase and Kraken,http://Binance.USthe SEC listed dozens of "utility tokens," determining that they exhibited characteristics of "investment contracts" during the sales and marketing phases. This means that as long as a project conveys "expected returns" in token sales, even if the token itself has functionality, it will be deemed a security.
Therefore, the key to compliance is dynamic response:
- Testnet → Focus on technology and development compliance;
- TGE → Emphasize use cases and functional attributes;
- DAO → Reduce team control and strengthen governance mechanisms.
Risks differ at each stage, and token positioning must be re-evaluated with each upgrade. Compliance is not a one-time stamp of approval, but continuous iteration.
Conclusion: Projects that survive cycles never rely on "speed," but on "stability"
Many projects fail not because of inadequate technology, but because of poor structure. While others are still talking about "price fluctuations," "airdrops," and "exchange listings," truly smart founders are already building legal frameworks, writing compliance logic, and planning DAO transitions.
The issuance of utility tokens is not about bypassing regulation, but using law to prove that you do not need regulatory intervention. When code takes over the rules, law becomes your firewall.

