As digital asset companies mature from experimental ventures into acquisition targets and IPO candidates, the legal questions around them have grown more layered, not less. In this Q&A, Daehoon Park, Founder and Managing Attorney at DP Counsel PLLC, breaks down the structuring considerations that matter most when a business builds a product around blockchain or digital assets, starting with what the asset actually represents rather than what label gets attached to it.

Daehoon also unpacks how M&A diligence changes when a target has issued tokens, held customer assets, or run its own custody infrastructure, and why buyers need to reconstruct a company's regulatory history, not just its current compliance posture. He points to specific risk areas, including private key control, treasury wallet management, and past securities exemptions, that rarely come up in a conventional tech acquisition.

Finally, Daehoon walks through how the SEC's evolving framework, including its March 2026 interpretation and the proposed Regulation Crypto Assets, is reshaping how token offerings get structured today. His answers cut through the "is it a security" shorthand to focus on what actually drives risk: the rights an asset represents, who controls it, and how the regulatory picture can shift even after a deal closes.

Crypto Law Summit runs live webinar sessions with practitioners from across the digital asset legal space throughout the year, covering the regulatory questions founders are actually facing. Join us for the next session to ask questions directly.

Q: What are the biggest structuring considerations for companies incorporating digital assets or blockchain-based products into their business models?

The starting point should be the actual product and operating model, rather than the label attached to it. “Digital asset” can describe very different legal and commercial arrangements, so I would first map what the asset represents, what rights it gives the holder, who issues or controls it, whether it is transferable, who controls custody or private keys, how value moves through the system, and what continuing role the company plays after issuance.

Those facts drive the regulatory analysis. Depending on the structure, a business may need to consider securities and commodities regulation, the federal framework for payment stablecoins, money-transmission and Bank Secrecy Act requirements, sanctions compliance, state licensing, and other applicable regimes. A company that merely uses blockchain as infrastructure presents a very different risk profile from one that issues tokens, holds customer assets, facilitates transfers, or operates a marketplace.

The corporate and contractual architecture should then match the technology. Token rights should be clearly distinguished from equity, governance, or other economic rights unless the parties deliberately intend them to overlap. Ownership of the protocol, software, data, and other IP should be clear, as should custody arrangements, administrative controls, third-party dependencies, and the allocation of operational and regulatory risk.

For cross-border businesses, geography also matters from the beginning. A product that can technically be accessed globally should not automatically be assumed to be legally distributable everywhere.

Because the regulatory framework continues to develop, companies should also distinguish between requirements that are currently effective, statutory provisions that have been enacted but are not yet fully operative, and proposed rules that cannot yet be relied upon.

The broader principle is that regulatory analysis, product architecture, and commercial contracts should be designed together rather than addressed as separate workstreams after the product has already launched.

Q: What unique diligence or regulatory allocation issues come up in M&A deals involving digital asset companies, compared to a traditional tech M&A transaction?

A digital asset transaction starts with the traditional technology-company diligence exercise — corporate ownership, IP, material contracts, employment, cybersecurity, privacy, litigation, and regulatory compliance — but adds several layers that can materially affect both valuation and deal structure.

First, the buyer needs to reconstruct the regulatory history of the product, not just review the company’s current compliance position. That can include how tokens were originally issued and distributed, what representations were made to purchasers, whether securities-law exemptions were relied upon, how secondary trading developed, and whether the business has engaged in custody, staking, payments, exchange, or money-transmission activities. KYC, AML, sanctions, state licensing, and prior regulatory communications may also become significant.

Importantly, a current conclusion that a particular crypto asset is not itself a security does not eliminate the need to analyze whether earlier offers or sales of that asset were made as part of an investment contract. That historical transaction-level analysis can remain important in an acquisition even where the target’s current product presents a different regulatory profile.

Second, diligence has to extend into the technical control structure. It matters who controls private keys, treasury wallets, smart-contract administration rights and protocol upgrades; how token supply and allocations are recorded; whether there have been exploits or security incidents; and whether the target actually owns or controls the technology and digital assets it says it does. These facts can affect both operational risk and the regulatory analysis in ways that often do not have close analogues in a conventional software acquisition.

Third, the findings need to be translated into transaction mechanics. Depending on the diligence findings, a buyer may need specific representations, pre-closing remediation, regulatory or contractual consents, closing conditions, special indemnification, holdbacks, or other tailored risk-allocation mechanisms rather than relying solely on a broad compliance-with-laws representation.

The key difference is that in digital asset M&A, legal, regulatory, and technical diligence are unusually interconnected. A technical feature can change the regulatory analysis, and a historical regulatory issue can in turn change the economics or structure of the acquisition.

Q: How do securities law frameworks in the US shape the way token-related offerings need to be structured today?

The central distinction is between the legal character of the crypto asset itself and the manner in which that asset is offered or sold.

In March 2026, the SEC issued a Commission-level interpretation addressing the application of the federal securities laws to crypto assets, with the CFTC joining the release to provide related guidance under the Commodity Exchange Act. The framework identifies five categories — digital commodities, digital collectibles, digital tools, stablecoins, and digital securities — while recognizing that some assets may have hybrid characteristics or may not fit neatly into a single category.

Digital commodities, digital collectibles, and digital tools, as defined in the interpretation, are not themselves securities. Stablecoin treatment depends on the characteristics of the instrument and the applicable statutory framework. Digital securities remain securities regardless of whether they are recorded or transferred on a blockchain.

Just as importantly, a crypto asset that is not itself a security can still be offered or sold as part of an investment contract where the applicable legal elements are present. Under the current framework, that analysis can include representations or promises of essential managerial efforts from which purchasers reasonably expect profits. The interpretation also addresses circumstances in which a crypto asset may cease to be subject to an investment contract as those facts change.

For issuers, securities analysis therefore needs to occur before the offering architecture and marketing strategy are finalized. Where an offering falls within the securities-law perimeter, the issuer generally needs either registration or an available exemption. In private capital raising, Regulation D may be available. For qualifying offshore offers and sales, Regulation S may provide a safe harbor from Securities Act registration if its conditions are satisfied. Those choices affect investor eligibility, solicitation, disclosure, transfer restrictions, secondary liquidity, intermediary involvement, and ongoing compliance.

The regulatory framework is also continuing to evolve. In August 2026, the SEC proposed Regulation Crypto Assets, which would create tailored offering exemptions for certain crypto-asset transactions and a conditional safe harbor addressing when a crypto asset would no longer be subject to an investment contract. The proposal is significant, but it is not currently an effective rule, so issuers cannot structure a present offering on the assumption that those proposed exemptions or safe-harbor provisions are available.

The practical takeaway is that token design alone does not determine the securities-law result. The rights represented by the asset, the way it is sold, the issuer’s commitments and marketing, the expected role of management, and the intended secondary market all need to be evaluated as part of a single offering structure.

About the Author

Daehoon Park is a corporate and transactional lawyer admitted to practice in New York and the founder and managing attorney of DP Counsel PLLC. He advises companies, founders, executives, business owners, investors, and fund sponsors on corporate and transactional matters involving U.S. law, whether domestic or cross-border. His practice includes mergers and acquisitions, venture capital and other private financings, corporate structuring, ownership and governance arrangements, commercial contracts, and technology transactions.