Some time ago, an entrepreneur intending to launch adigital collectiblesbusiness consulted Mankun Law Firm:

"We plan to start a digital collectibles business, primarily focusing on membership benefits and brand co-branding. Are there any legal matters we should pay special attention to?"

This question warrants separate discussion because many digital collectibles projects today no longer operate through "speculative trading of collectibles," but are instead packaged as membership benefits, brand co-branding initiatives, AI assets, offline consumption opportunities, points systems, and RWA rights certificates. While they appear more like consumer products on the surface, the underlying flows of funds, transferability, and user expectations have not disappeared.

In the previous wave of digital collectibles, many platforms employed relatively straightforward mechanisms: issuance, flash sales, gifting, and consignment. Users were primarily concerned with whether they could purchase items, resell them, and whether prices would appreciate. Previously, Mankun lawyers discussed such scenarios in the "Legal Pitfall Avoidance Guide for Web3 Practitioners" and several articles on digital collectibles, addressing why rights-protection claims by digital collectibles users are frequent, why secondary markets—although largely operating through consignment and resale models—may still be subject to manipulation, and why platform insiders may face criminal risks such as embezzlement due to their control over rare items, inventory, and backend administrative privileges.

Over the past two years, the industry has adopted new packaging. Digital collectibles are no longer merely "small images"; they are increasingly structured as membership cards,blockchain gameequipment, AI avatars, event tickets, points airdrops, physical item redemptions, and brand co-branding initiatives, and are even discussed in conjunction with wineries, concerts, offline stores, overseas platforms, and community nodes.

These models are not inherently illegal. For entrepreneurs, the critical issues to clarify in advance are: what exactly the project is selling, why users are willing to pay, how the platform collects payments, how benefits are fulfilled, whether transferability is permitted, and how backend administrative privileges are managed.

If users are purchasing content, memberships, and consumption-related benefits, the project has a clear performance pathway, and the platform does not encourage speculation, it more closely resembles a digitalized rights-and-benefits product. However, if users are purchasing based on expectations of price appreciation, the platform relies on multi-level referral rebates to recruit participants, the consignment market is price-controlled by internal accounts, or refunds and wind-down processes lack clarity regarding both funds and data, the risks may gradually shift from commercial disputes to criminal liability.

This article does not seek to address the broad question of whether digital collectibles can still be issued, but rather focuses on more specific operational issues: if a project is preparing for launch, which rules must be clarified in advance, which actions must be avoided, and which materials must be retained. The following ten high-frequency risks primarily concern funds, rights and interests, circulation, backend operations, and personnel liability.

I. Do Not Market Digital Collectibles as Investment Products

The initial step most likely to cause issues for digital collectibles is typically not technical, but rather sales rhetoric.

A digital collectible may originally serve as an avatar, ticket, membership card, brand credential, or offline benefit. However, within community groups, the sales rhetoric can easily become distorted: limited-edition releases; earlier purchases yield higher profits; secondary markets will be opened later; the platform will repurchase holdings; longer holding periods confer greater benefits; genesis collectibles will provide future dividends; node-based collectibles will generate continuous returns.

Once users pay not for content and benefits but because they believe “the platform will drive up the price after purchase,” the project begins to resemble a financing scheme.

In criminal cases, investigating authorities will not merely examine whether the platform explicitly uses the term “investment.” They will further assess: whether sales are directed at the unspecified public; whether returns are promised or implied; whether user funds are allocated to genuine business operations; whether redemptions depend on the continued entry of new users; and whether the project operators have transferred major sales proceeds to personal accounts or affiliated entities.

If the platform lacks genuine performance capacity and the collectibles serve merely as a pretext for collecting funds, and if—when users request refunds or withdrawals—the operators shut down backend systems, delete data, transfer funds, or change the operating entity, this constitutes more than mere business failure. In less serious circumstances, it may be characterized as illegal absorption of public deposits; in more serious circumstances, it may raise questions regarding intent to illegally possess, leading to considerations of fundraising fraud or fraud.

Entrepreneurs must draw a clear line: digital collectibles may offer collection, display, membership, consumption, and community benefits, but they must not be structured as “platform-backed investment products.” Terms such as guaranteed principal, repurchase, dividends, annualized returns, holding rebates, guaranteed profits, node-based yields, and official price support should preferably not appear in product rules, community sales rhetoric, or agent training materials.

II. When Does Community User Acquisition Become a Pyramid-Selling Risk?

There is no issue with digital collectible projects building communities. The problem arises when some teams structure community growth as multi-level rebate schemes.

Common practices include: requiring the purchase of genesis collectibles to become a team leader; offering first-tier, second-tier, or even multi-tier commissions for recruiting purchasers; increasing fee-sharing ratios based on higher team performance; determining eligibility for airdrops, whitelists, priority purchases, or synthesis features by the number of downstream recruits; and daily posting of team rankings and capital-recovery progress within community groups.

Project operators may claim that this constitutes private-domain growth, channel incentives, or community co-building. Criminal proceedings will not rely solely on these labels. They will examine the actual source of the returns.

If users earn profits primarily by recruiting downlines rather than through genuine goods, genuine rights and interests, or genuine services; if the hierarchical structure of teams and rebate rules constitute the core appeal of the project; if users purchase collectibles primarily to obtain eligibility, recruit teams, and earn commissions, then the risks will approach those associated with the crimes of organizing and leading pyramid schemes.

The greatest danger here is not the mere existence of commissions, but that commissions overshadow the product itself. A healthy promotional commission should correspond to genuine promotional services, with its ratio, recipients, and hierarchy being justifiable. A dangerous rebate system, by contrast, leads users to believe that they can recoup their prior investments simply by continuing to recruit new participants.

From a compliance perspective, platforms should emphasize genuine equity interests rather than "team returns," prioritize one-time reasonable channel fees over multi-level rebates, and avoid deeply tying membership tiers, airdrop eligibility, and priority purchase rights to the number of referrals. While community engagement is encouraged, it must not be built upon hierarchical recruitment structures.

III. Consignment and Resale: Why Platform Market Manipulation Remains a Concern

The most sensitive aspect of China’s digital collectibles industry has always been secondary market circulation.

Many platforms avoid the term “trading,” opting instead for consignment, gifting, circulation, player markets, or transfer of rights. While names may change, functions cannot. If a platform provides continuous listings, centralized matching, price displays, buy-sell depth, and transaction fee deductions, coupled with narratives of scarcity and expectations of price appreciation, it closely resembles a trading venue.

Even more hazardous is when the platform itself engages in market manipulation.

For example, platforms may use internal accounts to artificially inflate floor prices; project teams, employees, and agents may obtain rare items in advance and list them for sale; backend systems may be configured to prioritize transactions from whitelisted accounts; bots may be employed to fabricate trading volumes and manipulate rankings; and screenshots of high-price transactions executed by affiliated accounts within community groups may be used to entice new users to enter the market. While users perceive this as genuine market enthusiasm, the prices they observe are, in reality, orchestrated by the platform.

Such conduct may not directly constitute the crime of market manipulation under securities laws, as digital collectibles are typically not securities or futures issued in accordance with law. However, if project sponsors induce users to buy at inflated prices through fake transactions, fabricated popularity, and artificial scarcity, and then abscond with the funds, the risk of fraud is significantly amplified. If a platform long-term organizes trading in virtual assets or financial-like products, it may also face discussions regardingillegal business operationsrisks.

In our previous Pitfall Avoidance Guide, we discussed a criterion for judgment: the secondary market for digital collectibles in China mostly operates on consignment and resale models, which differ from traditional securities and futuresMarket makersare not the same thing. However, this does not mean that platforms may operate with no boundaries whatsoever regarding price control. Consignment markets may also be structured in a manner where the platform claims not to manipulate prices while in fact exercising such control.

For entrepreneurs, the most damning evidence is often not found on promotional pages but in backend records: repeated transactions conducted from the same device, the same IP address, or the same payment account; employee accounts participating in buying and selling; concentrated holdings in affiliated wallets or linked mobile phone numbers; and transaction prices changing in sync with community promotions. Once these materials are produced pursuant to a data request, the explanation of “user-initiated spontaneous trading” becomes significantly weakened.

Platforms may design mechanisms for limited gifting and the circulation of rights and interests, but they must implement real-name verification, cooling-off periods, anti-speculation measures, anti-money laundering controls, trading restrictions, and procedures for handling abnormal transactions. The more a platform resembles a continuous listed trading market, the less it can rely solely on user agreements to mitigate criminal liability risks.

IV. Blind Boxes, Lucky Draws, and Synthesis: Where Do They Resemble Gambling Operations?

Blind boxes, lucky draws, synthesis, and upgrades are common operational tools in digital collectibles projects. They are not inherently illegal, but they are easily misused.

A common scenario is as follows: users pay to purchase blind boxes; common items drawn have little to no value, while rare items can be resold at high prices; the platform repeatedly publicizes the transaction prices of rare items; online communities frequently post messages such as “someone hit the jackpot on the first try” or “someone achieved a tenfold return through synthesis”; users repeatedly top up their accounts in hopes of drawing rare items; and agents continue to recruit new participants by circulating screenshots of blockbuster successes.

At this point, what users are purchasing no longer resembles cultural and creative merchandise, but rather resembles a wager on a random outcome.

Criminal liability risks depend on several factual elements: whether users invest real funds; whether the outcome is primarily determined by random mechanisms; whether the prizes can be converted into cash; whether the platform continuously takes a cut from draws, synthesis, or upgrades; and whether the backend allows manual adjustment of probabilities, inventory, and rarity levels. If these elements converge, the project may be construed as gambling-like mechanics cloaked in the guise of digital collectibles.

The core of risk prevention is not merely deleting the term “blind box,” but rather realigning the mechanics with consumer attributes. Probabilities must be disclosed; participation frequency must be limited; rare items must not be packaged as investment returns; and prizes must not be strongly tied to cash, virtual currencies, or freely tradable secondary markets. If backend probabilities, inventory, and synthesis rules are subject to manual adjustment, there must be approval processes and audit logs; otherwise, it will be difficult to provide a credible explanation in the event of an incident.

V. So-Called “Empowerment”: Do Not Sell Rights and Interests That Do Not Exist

“Empowerment” is a commonly used term in the digital collectibles industry.

The issue is that the risks of many projects are also embedded in this term.

Some platforms promote that holding collectibles can be redeemed for concert tickets, winery benefits, offline store consumption, gaming equipment, brand dividends, and eligibility for commercial events. At the time of purchase, users see these as definite rights and interests. After the sale is completed, the platform claims delays in cooperation, ecosystem upgrades, adjustments to rights and interests, or technical maintenance, ultimately resulting in the dissolution of community groups and unanswered customer service calls.

If it is merely a failure of commercial cooperation, it may not directly escalate to criminal cases. Startup projects may encounter performance difficulties, and offline collaborations may also undergo temporary changes. The real danger lies in the project party lacking relevant resources from the outset of sales: no authorization, no cooperation agreements, no budget, and no path to performance, yet packaging these rights and interests as definite promises to sell to users.

Criminal investigations will scrutinize: how the sales pages were written, what was stated in community groups, how agents were trained, whether the cooperating parties truly exist, where the funds went after collection, and whether the project party continued sales despite knowing they could not perform.

Therefore, entrepreneurs should not describe "future plans" as "definite rights and interests." If matters are still under negotiation, in the planning stage, or being prepared for integration, they should not be used as reasons for sales. Rights and interests already included in whitepapers, official websites, posters, live streams, and community scripts must be traceable back to contracts, authorizations, budgets, inventory, and personnel responsible for performance.

What most easily triggers criminal risk is not failing to deliver rights and interests to 100% perfection, but collecting money for rights and interests that do not exist.

VI. Risks Associated with Accepting USDT, Points Redemption, and Personal Bank Card Collections

Some teams believe that as long as the project is called "digital collectibles" and not "virtual currency," it will not encounter criminal risks related to virtual currencies. In practice, risks are often introduced through payment and settlement methods.

For example, the platform supports the purchase of collectibles using cryptocurrencies such as USDT; users first top up with RMB, which is then converted into platform points, energy values, or platform tokens; points can be used for purchasing, synthesizing, gifting, reselling, and even cashing out; agents or USDT dealers assist users with off-platform deposits and withdrawals; the platform collects payments using personal bank cards, employee cards, or third-party channels.

While users see "purchasing collectibles," the fund flows may already involve agency collection and payment, illegal payment-settlement schemes, underground banks, online gambling, or proceeds from fraud. Once issues arise with upstream funds, the platform, finance personnel, channels, and personnel handling deposits and withdrawals may all become implicated in risks such as aiding information network criminal activities, concealing or disguising criminal proceeds, money laundering, and illegal business operations.

Here, three lines of inquiry must be examined.

First, the collection line. Whether user funds were transferred to the platform's corporate account, or to employees, agents, personal bank cards, or unidentified third parties.

Second, the convertibility threshold. Whether points, energy values, or platform tokens can be exchanged for RMB, USDT, or other virtual currencies; whether they can be transferred among users; and whether they may constitute de facto tokens.

Third, the risk control threshold. Whether the platform implements real-name verification, transaction limits, identification of anomalous transactions, interception of third-party payments, refund pathways, and disclosures regarding the source of funds.

Do not interpret “do not accept USDT” as ensuring full compliance. Even if only RMB is accepted, pooling funds through personal bank accounts, or allowing agents to make advance payments, top-ups, or buybacks for users in over-the-counter transactions, may draw the project into chains of financial crimes.

VII. Unclear IP licensing may entail more than copyright disputes

Digital collectibles are inseparable from content. The more popular the content, the higher the likelihood of legal issues.

To boost volume, many projects use anime characters, game avatars, film and television imagery, celebrity likenesses, sports event materials, brand logos, or mint online images, AI-generated images, and derivative works as collectibles. Platforms may assume these are merely copyright defects entailing at most monetary compensation. However, if sales are large-scale, profits are significant, and replication and distribution continue despite knowledge of the lack of authorization, the risk may escalate from civil infringement to criminal liability.

Particular attention should be paid to “fake authorizations.”

Users sometimes purchase collectibles not for the image itself, but because the platform claims official co-branding, licensed authenticity, limited issuance, and on-chain title confirmation. If authorization documents do not exist, or the scope of authorization does not cover the issuance of digital collectibles, secondary sales, or revenue sharing, yet the project promoters still market them as “officially authorized,” this may compound fraud risks.

AI-generated images are not inherently safe. While AI can reduce creation costs, it cannot replace authorization reviews. Using AI to generate an image resembling a well-known IP and packaging it as a brand collaboration; using celebrity likenesses, voices, or deepfaked content for digital collectible marketing; or directly commercializing unauthorized training data or image materials may trigger intellectual property, personality rights, advertising compliance, and even criminal risks.

Entrepreneurs should at least properly document the authorization chain, creation process, and sales pages. Issues such as who granted the authorization, the scope of authorization, whether NFTs may be minted, whether gifting or secondary sales are permitted, how revenues are distributed, and whether trademarks and likenesses may be used should not be addressed only after complaints arise.

VIII. Loss of control over backend permissions may implicate both employees and the platform

Many domestic digital collectible platforms do not operate on a fully on-chain wallet model; instead, they rely more on consortium chains, custodial accounts, platform accounts, backend title confirmation, and limited gifting. Users do not necessarily hold private keys, and the circulation of collectibles may not occur entirely on public blockchains. The most frequent risks often stem from internal platform permissions and operational rules.

For example, how are rare editions actually allocated? Who controls the reserved inventory? Are whitelist spots resold by insiders? Can airdrop eligibility be added via the backend? Can user transfer records be rolled back? Can consignment prices be manually intervened? Can withdrawal reviews be unilaterally approved by a single operations or finance staff member?

These matters may appear to be mere “operational details” in ordinary course. However, once the platform encounters legal issues, they become critical evidence for determining whether there has been embezzlement by employees, theft, illegal acquisition of computer information system data, complicity in fraud, or a loss of corporate management control.

The Avoiding Pitfalls Guide has previously specifically addressed the risk of embezzlement by employees of NFT digital collectible companies. This risk is not abstract within the platform. For many digital collectible platforms, “assets” are not held in an employee’s personal wallet but are reflected in backend accounts, inventory, whitelists, holder records, consignment status, and withdrawal reviews. Whoever can modify this data has access to the platform’s most core asset entry points.

Consider a scenario. The platform originally promised that only 100 units of a rare edition would be issued. However, insiders preemptively appropriated a batch and sold them through affiliated accounts in the consignment section. After users complained about abnormal pricing, the platform explained it as “random system allocation.” Later, backend logs revealed that an administrator had manually adjusted the inventory and holder records. This issue thus extends beyond a mere consumer complaint.

Another example arises when a project prepares for delisting or refunds. Backend personnel export certain user information, wallet addresses, and refund lists to external channels; or finance staff use personal accounts to collectively receive refund deposits, handling fees, or unfreezing fees. Users believe they are cooperating with the platform’s remediation efforts, but in reality, the funds flow into personal accounts. Such scenarios are highly sensitive from a criminal law perspective.

Therefore, internal controls for digital collectible platforms cannot stop at “preventing hackers.” A more practical approach is to granularly segregate backend permissions: who can issue collectibles, who can modify inventory, who can adjust rarity, who can review transfers, who can handle consignment, who can export user data, and who can access funds. Every operation must require approval, generate logs, and leave an audit trail.

For entrepreneurs, platform rules may be simple, but backend permissions must not be chaotic. When issues arise, the ability to clearly explain “who performed what operation at what time” is often more important than how elegantly the platform’s white paper is written.

9. Overseas Entities and Overseas Chains Are Not Shields for Onshore Teams

Currently, some projects pursuing native NFTs choose overseas entities, overseas chains, and overseas platforms for issuance, while onshore teams handle product, technology, community, marketing, and customer service. This structure itself is not unusual; cross-border operations are common in Web3 projects.

However, an overseas entity can only resolve certain corporate structure issues; it cannot eliminate the evidence left by substantive onshore operations.

If the project’s users are primarily from mainland China, promotion is mainly conducted in Chinese-language communities, KOLs and agents primarily target onshore users, customer service handles complaints from onshore players, and the onshore team participates in drafting the white paper, managing payment channels, facilitating secondary market trading, designing commission rules, and formulating delisting or refund plans, then it will be difficult to sever liability merely by claiming that “the company is overseas” after an incident occurs.

Law enforcement authorities focus more on substantive participation: Did the onshore team know who the project targeted? Did they participate in fund inflow channels? Were they responsible for user acquisition? Did they design commission and trading rules? Did they handle withdrawal difficulties and rights-protection complaints? Did they continue to appease users, induce reinvestment, or transfer data after the project encountered problems?

For employees, outsourcing technical development, visual design, translation, and basic operations and maintenance is not at the same risk level as being responsible for Chinese-language community management, agency systems, fiat on-ramps and off-ramps, consignment rules, and backend market manipulation. For founders, establishing overseas entities, using overseas servers, and entering into overseas contracts cannot shield the domestic team from liability for its actual decision-making and execution.

If a cross-border project is indeed to be undertaken, it is advisable to clearly define the boundaries from the outset: what services the domestic company actually provides; whether it has access to user funds; whether it promotes to users in mainland China; whether it participates in token issuance and secondary trading; whether there are measures prohibiting domestic sales or restricting domestic access; and whether records of relevant decisions and risk control measures are retained.

Adding the statement “we are merely a technology service provider” after an incident occurs is usually too late.

X. The Liability of Employees and Founders Ultimately Depends on Their Specific Conduct

Once a digital collectibles project becomes involved in legal cases, the most common statement made by family members and employees is: “He was just working at the company.”

This statement is not meaningless, but it is far from sufficient.

Criminal liability is not determined solely by the job title stated in the employment contract. A person’s actual role must be assessed based on the business functions they accessed, the income they received, the meetings they attended, whether they had backend administrative privileges, whether they handled user funds, and whether they processed complaints and managed refunds or withdrawals.

Founders and senior executives must primarily explain their decision-making. This includes how the issuance volume was determined, how pricing was set, who approved the representations regarding returns, who designed the agency commission structure, who controlled user funds, who decided on withdrawal restrictions, and who arranged for data transfer, community cleanup, or entity replacement after problems arose with the project.

Operations and marketing personnel must primarily explain their sales representations and user acquisition practices. This includes whether they continued sales while knowing that promised benefits could not be delivered; whether they used screenshots of price increases, transaction records, or stories about rare items to stimulate purchases; whether they managed agency teams; and whether their income was linked to sales volume, recharge amounts, or team performance.

Technical and product personnel must primarily explain their system privileges. This includes whether they developed or maintained core modules such as lottery probability algorithms, inventory allocation, consignment matching, withdrawal restrictions, price displays, and data deletion; and whether they knew that these functions were being used for false advertising, market manipulation, or delaying refunds.

Finance and customer service personnel must primarily explain their handling of funds and their knowledge of irregularities. This includes whether they processed payments received into personal bank accounts, third-party disbursements, USDT conversions, or abnormal refunds; whether they repeatedly received user complaints regarding inability to withdraw, failure to deliver promised benefits, or inducement to purchase; and whether they followed unified scripts to delay responses, placate users, or guide them to continue recharging.

Ordinary employees are not automatically guilty, and when a platform encounters legal issues, responsibility should not be imposed on every individual. However, if a person has long-term proximity to funds, transactions, promotion, and core backend administrative privileges, they cannot simply rely on the defense “I was just an employee.”

For entrepreneurs, the most effective risk prevention is not to coordinate a unified narrative after an incident occurs, but to clearly define job responsibilities, authority boundaries, approval records, compensation structures, and offboarding handover procedures during normal operations. For employees, if they discover that a project is already relying on fabricated returns, tiered rebates, backend market manipulation, collections into personal bank accounts, and delays in withdrawals to sustain itself, they should cut their losses promptly, rather than waiting until a case is brought to prove that they were merely peripheral personnel.

Before launch, clarify these six questions

If you are working on projects involving NFTs, digital collectibles, blockchain game items, membership benefits, AI-generated collectibles, or brand-related digital assets, you may wish to review the following questions first.

Why do users purchase? If the primary reasons are appreciation, recouping costs, rebates, or dividends, rather than content, benefits, and services, the risk profile has already skewed in the wrong direction.

Where are the funds deposited? If funds flow into personal bank accounts, employee accounts, agent accounts, USDT merchant channels, or unidentified third-party accounts, it will be difficult to explain the source of funds later on.

How are transfers conducted? If the platform has already established continuous listings, centralized matching, price stimulation, and fee commissions, it should no longer be characterized as ordinary gifting or transfer.

How is the community managed? If agent training and community scripts consistently revolve around phrases such as “getting in means profit,” “the price will be pumped later,” and “the larger the team, the higher the returns,” these materials will become evidence in the future.

Who has backend access? Loss of control over any permission—such as inventory, rarity, whitelists, airdrops, consignment, withdrawals, refunds, or user data—may drag the platform into criminal proceedings.

How are user complaints handled? Continuing sales, transferring funds, deleting data, shutting down communities, and coordinating a unified narrative to delay refunds will all amplify criminal risks. Conversely, promptly halting high-risk sales, preserving ledgers and logs, explaining the flow of funds, and proposing a genuine refund plan constitute a more stable approach.

NFTs and digital collectibles are not prohibited. The real issue is that a product that could legitimately be structured around cultural creativity, membership, and digital rights must not be transformed into a fundraising scheme, a rebate scheme, a gambling operation, a manipulated trading venue, or a fund channel.

Criminal compliance is not intended to deter entrepreneurs, but to ensure that a project capable of normal operations is not distorted in its sales scripts, fund channels, secondary market transfers, and backend permissions.

For digital collectible projects, the greatest fear is not considering too many risks at the outset, but focusing solely on issuance, user acquisition, and transactions at the start, only to discover later—when users assert their rights, the platform initiates refunds, employees resign, and funds are frozen—that the contracts, ledgers, backend logs, and community scripts cannot withstand scrutiny.

For entrepreneurs genuinely committed to building sustainable projects, it resembles a set of concrete operational practices: funds are deposited into corporate accounts, rights and interests are redeemable, transfers operate within defined boundaries, backend systems maintain audit logs, promotional activities remain within legal limits, and employees are aware of which permissions they must not access.

When these measures are properly implemented, the project ensures that, at least when issues arise, the team can produce documentation to explain its business logic: which funds were received by the company, which rights and interests genuinely exist, which transfers are subject to restrictions, and which employees did not access core permissions. In many cases, an entrepreneur’s ability to clearly articulate these facts is more effective than hastily drafting a “compliance statement.”