In criminal cases involving Web3 projects, the primary question pursued by investigating authorities is often not “What is your job title?” but rather “Where did you direct users?”

An operations staff member may have had no access to the company’s wallets and no authority to determine token prices, yet was responsible for publishing promotional content, maintaining community groups, and directing interested users to customer service representatives; a business development professional may have lacked permission to operate the trading backend, yet received commissions based on the number of new registrations, recharge amounts, or transaction volumes; a community administrator may have appeared merely to answer questions in group chats, while their actual duties included explaining return models, sending account-opening links, and guiding users to purchase USDT and complete recharges.

When the project is later investigated for suspected illegal business operations and other issues, the most common question raised by these employees is: “The business model was decided by the boss; I was only responsible for promotion and never handled company funds. Why are the public security organs still pursuing me?”

The answer is neither that “anyone who has performed operational duties must bear liability,” nor that “as long as one has not handled money, one is absolutely safe.”Whether an employee bears criminal liability ultimately depends on whether they were aware that the project was engaged in illegal or criminal activities, whether their work facilitated core business operations, and what role they actually played in the process of user onboarding, transaction completion, and fund payments.

Illegality of the Project’s Business Does Not Mean That All Employees Commit Crimes

In February 2026, the People’s Bank of China and seven other departments issued the Notice on Further Preventing and Disposing of Risks Related to Virtual Currencies, clarifying that conducting virtual currency exchange, token issuance and financing, and providing information intermediation, pricing, and other services for virtual currency transactions within mainland China constitute illegal financial activities related to virtual currencies; internet enterprises are prohibited from providing services such as commercial display, marketing and promotion, and paid traffic redirection for such activities.

On July 23, 2026, the Shenzhen Municipal Internet Information Office announced a batch of self-media accounts involved in virtual currency violations, including accounts such as “USDT Merchant Exchange Group” and “Weizhi Kuaihuan.” The announcement indicated that these accounts were permanently closed by the platforms for providing marketing and promotional information on virtual currency businesses to users within mainland China and inducing the public to participate in illegal financial activities involving virtual currencies.

However, it is particularly important to distinguish thatthe determination by regulatory rules that a certain type of business constitutes an illegal financial activity, or the closure of an account by a platform due to non-compliant promotion, does not mean that every employee involved automatically commits the crime of illegal business operations.

The crime of illegal business operations requires not only that the conduct violates state regulations, but also that the perpetrator actually engaged in specific illegal business activities or other business conduct that seriously disrupts market order, reaching the threshold of “serious circumstances.” If an employee is evaluated as part of a joint crime, it must further be proven that they shared a joint criminal intent with others and participated in or assisted in the commission of the crime through specific acts.

The adjudication principles reflected in Guiding Case No. 97 of the Supreme People’s Court also indicate that administrative illegality cannot be directly equated with the crime of illegal business operations. When applying the crime of illegal business operations, it remains necessary to examine whether the relevant conduct possesses corresponding social harm, criminal illegality, and the necessity of criminal punishment.

Therefore, determining whether a Web3 employee bears criminal liability should not rely solely on whether the project was ultimately investigated, nor solely on whether the employee received wages from the company. Instead, the analysis must return to the business chain in which the individual actually participated.

Operations, business development (BD), and community user acquisition may enter the project’s operational chain from what appears to be a “promotional role.”

Generally, brand operations are primarily responsible for content creation, event execution, media dissemination, and community maintenance; such work is not directly equivalent to organizing user transactions. However, in certain Web3 projects, there is no genuine separation between brand promotion, user solicitation, account-opening links, asset deposits, and transaction conversion.

For example, operations personnel continuously publish promotional content such as “principal-guaranteed returns,” “fixed returns,” “low-price subscriptions,” or “large-volume acceptance.” After viewing such content, users are guided into private-domain groups, where community personnel send transaction links, wallet addresses, or deposit tutorials. BD personnel are responsible for liaising with key opinion leaders (KOLs), agent teams, and community channels, and receive commissions based on user registrations, deposited amounts, or transaction volumes.

Under this model, front-end promotion is no longer merely an independent branding function but may become a necessary component of the project’s business activities. Investigative authorities typically examine the user conversion pathway step by step: how users learned about the project, who was responsible for building trust, who explained the products and returns, who sent account-opening links, who guided users in purchasing USDT, completing KYC, and making deposits, who urged users when they hesitated, and who received commissions based on the final transaction amounts.

Therefore,whether an employee operated the company’s wallet is not the sole criterion for assessing risk.For a project that relies on community-based user acquisition and private-domain conversion, the continuous and targeted introduction of domestic users into the transaction process may itself constitute substantial assistance to the project’s business operations.

Assessing employee risk by reconstructing four business chains

Whether operations, BD, and community personnel have moved from general support roles into the core operational aspects of the project can be assessed along four dimensions: the content chain, the user acquisition chain, the transaction chain, and the fund flow chain.

This table is not a mechanical standard for determining the establishment of a crime.Even if an employee performed certain tasks listed herein, one cannot directly conclude guilt without considering factors such as working hours, scope of authority, subjective awareness, and the actual operational model of the project.

However, when high-risk conduct across the four links continues to accumulate, and employees can observe users progressing from promotional content into community groups, completing account opening, making payments, and ultimately concluding transactions, while their own compensation is directly tied to transaction volumes, it becomes significantly more difficult for them to justify their entire course of conduct by claiming, “I was only responsible for posting content.”

Why might the defense “I did not know the business was illegal” still be subject to scrutiny?

In cases involving employees, the core dispute is typically not whether they participated in the work, but whether they were aware that the project’s business activities carried risks of criminal or unlawful conduct.

Regarding subjective awareness, investigating authorities will not base their determination solely on an employee’s statement that “I did not know” or “My supervisor did not inform me.” Instead, they will conduct a comprehensive review considering factors such as job authority, internal communications, user complaints, compensation structures, regulatory warnings, and subsequent conduct.

For example: Did the company explicitly discuss prohibitions on conducting business with mainland China users, yet still require employees to continue recruiting new users through Chinese-language community groups? Were employees instructed to replace terms such as “deposit,” “transaction,” and “returns” with coded language? Did the project frequently change domain names, community groups, and collection accounts? Did employees receive notices of platform bans, bank freezes, users’ inability to withdraw funds, or risk alerts raised by compliance personnel? After abnormal circumstances had become concentrated and evident, did employees continue to recruit new users and urge them to make payments?

The isolated occurrence of any one of these circumstances does not, by itself, directly prove that an employee has committed a crime. However, if multiple abnormal facts persist and recur over time, and the employee continues to facilitate user transactions, these facts may collectively influence the assessment of the employee’s subjective awareness.

Conversely, if an employee has a short tenure, receives only a normal fixed salary, has not participated in making return promises, providing trading guidance, or handling funds, and genuinely lacks a comprehensive understanding of the project’s overall business model, and furthermore ceases relevant work promptly upon discovering abnormalities, raises objections, or voluntarily resigns, then these facts should be fully considered in the determination of liability.In a case we previously handled, we organized evidence around the client’s start date, compensation structure, job authority, actual scope of participation, and responsive actions after discovering abnormalities, and submitted a complete defense opinion on this basis, ultimately achieving a favorable outcome of non-prosecution.

Does having no decision-making authority and merely following supervisors’ instructions guarantee exemption from liability?

Joint crime under criminal law does not require every participant to be involved in all stages. Within a project, the person in charge may design the business model, technical staff may build the system, operations and business development (BD) personnel may acquire users, customer service may guide transactions, and finance staff may handle fund settlements. Although the acts performed by different roles vary, they may jointly promote the same business activity.

If operations, BD, or community-management personnel, knowing that the project’s core business is illegal, nevertheless engage over a long and stable period in user recruitment, transaction conversion, or assistance with fund flows, they may be evaluated as participants in a joint crime.An employee’s lack of authority to determine the business model, performance of only partial tasks, or receipt of profits lower than those of the project leader does not automatically preclude criminal liability, but it may affect the employee’s status and the extent of liability within the joint crime.

Under the Criminal Law, individuals who play a secondary or auxiliary role in a joint crime are classified as accomplices. Accomplices shall, in accordance with the law, receive a lighter or mitigated punishment, or be exempted from punishment. Therefore, even if an employee has been determined to have participated in a joint crime, ordinary executing personnel should not be evaluated in the same manner as project initiators, actual controllers, and core management personnel.

Typical cases involving foreign exchange-related illegal and criminal activities, jointly released by the Supreme People's Procuratorate and the State Administration of Foreign Exchange, also demonstrate that platform managers, ordinary staff members, virtual currency traders, and account providers within the same business system may bear different liabilities depending on their specific division of labor, subjective awareness, and participatory conduct. Key focuses in the review of such cases include chat records, bank statements, transaction records, wallet addresses, and the actual division of labor among individuals.

A critical task for lawyers in such cases is to distinguish the company’s overall business operations from the individual conduct of employees, clarifying when the employee joined the company, what authority they held, which users and transactions they actually participated in, what benefits they obtained, whether they were aware of the project’s true operational model, and the extent to which their conduct influenced the project’s operational outcomes.

After a project comes under investigation, what evidence should employees prioritize preserving?

When a project manager becomes unreachable, company group chats are suddenly dissolved, or an employee receives notice from public security organs, the least advisable actions are to immediately delete chat records, exit all groups, or coordinate a unified statement with colleagues. Such actions may result in the loss of evidence favorable to the employee and may also be interpreted as an attempt to evade investigation.

Employees should prioritize preserving employment contracts, job descriptions, salary records, performance evaluation rules, work instructions, and actual deliverables, while fully retaining communication records with supervisors, clients, and other departments. For wallets, backend systems, and fund accounts to which the employee had no authorized access, it is necessary to demonstrate the boundaries between the employee and these relevant components through records of work permissions, approval processes, or internal communications.

If an employee previously raised objections to project risks, refused to participate in receiving funds through personal accounts, requested the removal of promotional content that exaggerated returns, or voluntarily resigned upon discovering anomalies, such records should be preserved promptly.

Conversely, if an employee did participate in user top-ups, fund pooling, or transaction guidance, it is inappropriate to offer only a vague explanation such as “I was just an ordinary employee.” Instead, the employee should accurately detail the period of participation, the users involved, transaction amounts, specific operations performed, and the source of instructions.Whether an employee bears liability must be based on a complete set of facts, rather than determined solely by job title.

Lawyer’s Observations

In Web3 projects, the risks associated with operations, business development (BD), and community management roles often lie not in the job titles themselves, but in how these roles are connected to business outcomes.

Merely drafting general copy, organizing brand events, or maintaining ordinary community groups does not automatically constitute the crime of illegal business operations. However, when an employee’s work continuously facilitates domestic users in opening accounts, purchasing USDT, making top-ups, subscribing to offerings, or participating in unauthorized financial services, and their income is directly linked to user deposits or transaction volumes, the associated risks can no longer be simply dismissed as “the company’s problem.”

For employees, what truly needs to be preserved is not merely the statement “I was just an employee,” but rather complete evidence capable of demonstrating the scope of their work, the boundaries of their authority, their compensation structure, and their subjective understanding. For project operators, it is also impermissible to package all customer solicitation and transaction conversion activities as “brand operations.” Instead, they should re-examine where promotional content ultimately directs users, and determine what functions employees actually performed within the customer, transaction, and fund flows.

The illegality of a project does not mean that all employees are guilty; nor does having never accessed the company’s wallet necessarily mean there is no risk. Criminal liability must ultimately be attributed to specific individuals, distinguishing among those who designed the business model, those who determined its direction, those who facilitated transactions, those who controlled funds, and those who merely performed routine tasks within a limited scope.

/ END.

*This article is an original work of Mankun Law Firm. It reflects only the personal views of the author and does not constitute legal advice or a legal opinion on any specific matter. For reprint permissions or legal consultations, please contact our customer service at: mankunlawyer.

Article Illustration