Special Disclaimer: This article is an original work by Attorney Shao Shiwei. It reflects only the author’s personal views and does not constitute legal advice or a legal opinion on any specific matter. For reprints, legal consultations, or professional exchanges, please add: sswls66.
In “Can Offshore Incorporation Evade Chinese Jurisdiction? Compliance Misconceptions Web3 Entrepreneurs Must Not Overlook,” Attorney Shao stated:
A compliance misconception easily overlooked by Web3 entrepreneurs and practitioners is that merely registering a project overseas and deploying servers abroad achieves “inherent compliance.”
In practice, however, the core determinant of compliance always lies in the project’s business model, capital structure, and operational substance, rather than its superficial offshore architecture. In other words, overseas incorporation may serve as one element of a compliance framework, but it cannot act as a shield to conceal high-risk commercial conduct. Teams that remain within mainland China and provide services to Chinese users should pay particular attention to the legal boundaries of their projects and the risks of criminal non-compliance.
This article further unpacks the following question for developers: How can one quickly determine whether a Web3 project crosses “criminal-law red lines”? Using four categories of Web3-related illegal risk patterns that frequently arise in practice as examples, we help developers build baseline identification capabilities from the perspectives of project structure, system functionality, and token circulation. Identifying and avoiding these high-frequency project types at an early stage can help keep most criminal legal risks at bay.
It should first be clarified that this article is directed at technical practitioners who seek long-term development in the Web3 industry, especially developers who prioritize compliance building and possess a certain awareness of legal risks. Our analysis focuses on projects with basic compliance awareness and some degree of business planning capability. Sham projects established with the explicit purpose of engaging in illegal fundraising, crypto-related fraud, money-laundering arbitrage, and similar activities are outside the scope of this article.
InPart I《Web3 Developer Pitfall-Avoidance Guide (Part I): Four Types of High-Risk Criminal Project Models That Developers Must KnowIn this article, we systematically analyze four of the most common "criminal-law-level red-line project models." It is evident that developers are often not "outsiders" to legal risks when participating in Web3 projects. Due to their deep involvement in system architecture design and key functional modules, technical roles are frequently at the core of project operations. Once a project model presents compliance risks, whether the participation of technical personnel may give rise to legal liability often becomes a focal point of judicial review.
So, as a developer facing the complex landscape of Web3 projects, how can you determine whether a project itself crosses legal red lines? And how can you timely identify risks and reasonably delineate your own boundaries without possessing comprehensive legal knowledge? We will elaborate on these issues in this article.
2
How to Determine Whether a Web3 Project Crosses Legal Red Lines?
In this section, we will shift our perspective from criminal charges todevelopers' identification dimensions—helping technical personnel identify key high-risk signals that may exist in a project, starting from business logic and system structure.
Such identification does not require developers to possess complete legal knowledge. By mastering a basic framework of "high-frequency patterns + key judgment points," one can preliminarily assess whether a project crosses legal red lines.
Identification Dimension 1: Gambling-Related Activities (Crime of Operating a Casino)
Typical Characteristics: Deposit Channels + Randomized Gameplay + Withdrawal Paths
If a Web3 project constitutes the crime of operating a casino, its key closed-loop elements typically include:
• Whether there are deposit activities, particularly funding through virtual currencies (such as USDT);
• Whether the platform has designed games of chance with uncertain outcomes, such as lotteries, betting, or loot boxes;
• Whether there is a withdrawal pathway, for example, project tokens can be exchanged for mainstream cryptocurrencies and circulated to centralized exchanges (CEXs) or decentralized exchanges (DEXs), and then converted into Renminbi (RMB).
This three-stage process of “deposit–bet–withdrawal” is highly likely to be regarded by judicial authorities as a “gambling-related closed loop.”
Taking Web3 games (GameFi) as an example, when a blockchain gaming projectsimultaneously satisfies the above three criteria, even if the developers are only responsible for modules such as the front-end interface, wallet integration, and reward mechanisms, they may still face significant legal risks due totheir deep involvement in constructing the gambling-related closed loopand face heightened legal risks.
Identification Dimension 2: Pyramid-Scheme-Related Offenses (Crime of Organizing or Leading Pyramid Schemes)
Typical characteristics: user payment + referral commissions + multi-tier rebate chain
The risk associated with such projects lies in whether the incentive mechanism itself constitutes a “pyramid-style rebate structure.” If technical developers are responsible for building functions such as commission calculation systems, tiered permission modules, and node revenue distribution logic, and lack the ability to assess the overall business structure, failing to exercise prudent judgment regarding the “fund flow logic and tiered structure design,” they may inadvertently assist in the technical establishment of a pyramid scheme.
The following are common structural characteristics of pyramid schemes:
-
User payment for membership: Participation eligibility is contingent upon prior actions such as purchasing tokens, making deposits, or buying service packages;
-
Commission rebates for recruiting participants: Inviting others to register or invest entitles the referrer to rewards;
-
Multi-level hierarchy: A hierarchical structure exists wherein rebates are distributed on a tier-by-tier basis with decreasing amounts at each level;
-
Weak product dependency: The project’s profitability does not rely on actual goods or services, but is driven by participant recruitment and commission rebates.
In Web3 promotional strategies represented by “Ambassador Programs,” “Node Incentives,” and “Community Partner Mechanisms,” if the reward model is structured aroundrecruiting participantsand is directly linked topayment obligations and hierarchical structures, careful attention must be paid to whether such arrangements may constitute pyramid selling.
Where technical developers are responsible for building rebate algorithms, hierarchical databases, and user settlement logic, and occupy a core position within the project, they may be deemed accomplices for “providing key technical support,” even if they did not directly participate in promotional activities.
Identification Dimension 3: Illegal Fundraising Offenses (Illegal Absorption of Public Deposits / Fundraising Fraud)
Typical Characteristics: Soliciting funds from the public + promising returns + lacking financial licenses
The identification difficulty for illegal fundraising projects is relatively low, with risk points primarily concentrated in two aspects:
First,the sources of funds are extensive and non-specific, meaning that funds are solicited from the general public; second,promising returns or profits, thereby attracting capital inflows.
In Web3 projects, if “token issuance,” “mining machine investments,” “points redemption,” or “expected returns” serve as the core fundraising mechanisms, such activities may easily fall within the scope of illegal absorption of public deposits or fundraising fraud.
Common high-risk models include:
-
conducting unauthorized public token offerings for fundraising without approval from financial regulatory authorities;
-
The platform promises “principal-guaranteed high returns” or sets fixed returns;
-
Fabricating wealth-management platforms, mining-machine leasing schemes, or dividend mechanisms;
-
Establishing a capital pool that allows users to exchange tokens or points within the platform for withdrawable assets such as USDT.
In judicial practice, whether conduct constitutes the crime of illegally absorbing public deposits is typically determined through a comprehensive assessment against the “four-element standard”: illegality (lack of financial licenses), public solicitation (promotion to unspecified persons), inducement by promised high returns, and social reach (broad sources of funds).
In such projects, if developers are deeply involved inthe design of token issuance logic, point-to-token exchange modules, and wealth-management product systems,even without participating in operations or external promotion, they may be deemed accomplices due to their provision of “key technical support.”
Particularly where the system formsa closed-loop fund flow coupled with return expectations,judicial authorities often include developers within the scope of enforcement actions.
Identification Dimension Four: Involvement in Illegal Business Operations (Crime of Illegal Business Operations)
Typical features: crypto-to-crypto matching, over-the-counter foreign-exchange conversions, and fiat on-ramp/off-ramp channels.
In Web3 projects, the typical risk scenarios for the crime of "illegal business operations" often center on virtual currency platforms suspected of facilitating exchanges between RMB and foreign currencies. This is particularly true when virtual currencies are used as intermediaries for offsetting transactions, which may trigger the legal characterization of illegal business operations involving cross-border foreign exchange settlements.
Based on cases of illegal business operations involving unauthorized foreign exchange handled by our team, it is evident that judicial authorities have continuously intensified their crackdown on such "virtual currency-facilitated foreign exchange" activities in recent years, with enforcement standards becoming increasingly stringent.
The following are common high-risk behavioral patterns:
-
Providing services for depositing, withdrawing, and transferring funds between virtual currencies and RMB;
-
Establishing over-the-counter (OTC) trading modules to facilitate exchanges between cryptocurrencies and fiat currencies;
-
The platform uses currencies such as USDT or BTC to connect end-users with overseas accounts to complete offsetting foreign exchange transactions;
-
Conducting foreign exchange trading businesses or providing settlement and matching services without proper authorization.
In judicial practice, even if the platform itself does not directly hold customer funds, as long as it has establisheda matching and exchange system, exchange matching logic, or a transaction matching interface, the technical party may also be characterized as an accomplice for "organizing and implementing illegal business operations."
Developers should be particularly vigilant in the following three typical scenarios:
-
The project has integrated withOverseas users and onshore fund providers, forming a matched-offset transaction pathway;
-
The platform usescurrencies such as USDT, BTC, and ETH as exchange media, enabling the conversion of RMB into foreign currencies or vice versa;
-
Technical personnel led the development offunctional modules including deposit and withdrawal modules, automated matching programs, and key API interfaces.
Regardless of whether developers directly participate in settlement, as long as the systemhas the capability for "matching + universal convertibility + multi-currency conversion",it is likely to fall within the scope of crackdowns under the crime of illegal business operations.
3
How to accurately identify high-risk Web3 projects and stay away from criminal legal risks?
A common defense raised by many developers after an incident is: "I only developed features according to requirements; I was not aware of the specific operational mechanics."
However, in judicial practice, this argument is often difficult to sustain. The reason is that whether criminal liability arises depends not only on direct participation in unlawful conduct, but also on whether the actor “knowingly” provided substantial assistance to such unlawful conduct through the system they developed.
Under the theory of joint offenders in China’s Criminal Law, as long as the actorknows that another person is committing a crime and nevertheless provides technology, assistance, or facilitates conditions, they may be deemed an accessory or joint offender and bear criminal liability in accordance with the law.
For technical personnel, judicial authorities typically assess whether they “should have known” that the project posed legal risks from the following perspectives:
-
Whether they were core members of the project, such as a technical co-founder, Chief Technology Officer (CTO), or system architect;
-
Whether they were deeply involved in key modules such as the fund structure, token logic, and fiat on-ramp/off-ramp channels;
-
Whether they raised questions or proposed modifications regarding the project’s legality, fund flows, or the compliance of its operational mechanics;
-
Whether they received high compensation, entered into deep cooperation agreements, or enjoyed profit-sharing arrangements, indicating a deep alignment of interests with the platform.
In Web3 projects, technical developers are often not peripheral support roles, but rather key links driving the implementation and operation of the project.
The more a technical professional serves in key roles such as Chief Technology Officer (CTO), system architect, or core developer, the more difficult it becomes to assert defenses such as “I was unaware” or “I was merely an outsourced contractor.” Such core technical personnel are often regarded by judicial authorities as individuals with substantial control over the operation of the project.
Accordingly, how can developers identify risk signals at the early stages of a project, delineate the boundaries of liability, and avoid being held liable involuntarily? The following points constitute essential self-assessment recommendations that technical personnel must review before accepting employment or undertaking collaborative engagements.
Before participating in any Web3 project, developers must possess a basic framework for identifying legal risks. Whether considering employment, outsourced collaboration, or participation as a partner in launching a project, the following three-step self-assessment recommendations are particularly critical:
-
Examine the business model: Does the project involve any of the four high-frequency criminal risk structures, namely gambling (gambling-style mechanics), pyramid schemes (hierarchical recruitment), illegal absorption of public deposits (issuing tokens to absorb capital), or illegal business operations (facilitating currency exchange matching)?
-
Scrutinize the operational logic: Does the project involve token issuance? What is the source of the tokens or points? How do user funds enter the platform? How do funds exit? Who is responsible for redeeming the tokens, and is there a pathway for conversion into fiat currency?
-
Maintain records: Explicitly state in technical agreements and requirement specifications that you are providing development services only and do not assume responsibility for platform operations. Simultaneously, document discussions with the project sponsor regarding matters such as “compliance of gameplay mechanics” and “fund flows,” to serve as evidence for self-protection in subsequent proceedings.
4
Conclusion: Be a Developer Proficient in Both Technology and Law
Whether serving as a core developer, system architect, or technical lead within a startup team, individuals should possess basic capabilities to identify criminal legal risks. Particularly during the initial stages of Web3 projects, it is essential to promptly assess whether the project involves high-risk models such as gambling, pyramid schemes, illegal fundraising, or illegal business operations, so as to provide early warnings, proactively avoid risks, and prevent becoming entangled in criminal liability due to negligence.
In the complex and evolving Web3 ecosystem, only developers who possess both the ability to implement technology and the capacity to identify legal red lines can become Builders with genuine judgment and resilience.
Beyond technical skills, “legal compliance awareness” is an essential core competency for contemporary developers.
The development of the Web3 industry depends on robust compliance frameworks, and developers constitute the most overlooked yet most critical link in this chain. We look forward to collaborating with more technology professionals to help projects launch on a foundation of security and transparency.If you have reflections on project structures, system compliance, and the boundaries of criminal liability, we welcome your insights and dialogue.

Recommended Reading


