An ICO, STO and IEO are three legally distinct mechanisms for raising capital by issuing digital tokens on a blockchain. Each carries a different regulatory profile, investor protection standard and legal risk. Understanding which category applies to a given token offering is the first step any founder or legal adviser must take before structuring a fundraise.
This guide defines each term precisely, explains how regulators and courts distinguish between them, identifies the legal frameworks most commonly applied, and outlines the practical consequences of misclassification. It is written for founders, investors and counsel operating across multiple jurisdictions.
ICO - Initial Coin Offering is a fundraising method in which a project issues digital tokens to the public in exchange for established cryptocurrencies or fiat currency, typically before the underlying product or network is operational. The term is modelled on the traditional Initial Public Offering but carries no equivalent statutory definition in most jurisdictions. Tokens sold in an ICO are most commonly utility tokens - instruments that grant the holder access to a future product or service rather than an ownership stake or profit right. However, the economic substance of the token, not its label, determines its legal classification. Regulators in the United States, the European Union, Switzerland and Singapore have each issued guidance confirming that a token marketed as a utility instrument may still constitute a security if it meets the relevant legal test.
STO - Security Token Offering is a token issuance that is explicitly structured as the offer of a security. A security token represents a legally recognised financial interest: equity in a company, a debt obligation, a revenue-sharing right or a fractional interest in a real asset. Because the issuer acknowledges the security nature of the token from the outset, an STO is subject to the full body of securities law applicable in each jurisdiction where it is offered. This means prospectus requirements, investor eligibility restrictions, anti-money-laundering obligations and ongoing disclosure duties all apply. The STO model emerged partly as a regulatory response to the ICO wave, offering a compliant path for tokenised capital markets instruments.
IEO - Initial Exchange Offering is a variant of the ICO in which the token sale is conducted through a cryptocurrency exchange rather than directly by the issuing project. The exchange acts as an intermediary: it performs its own due diligence on the project, lists the token on its platform and manages the sale process. From a legal standpoint, the exchange';s involvement does not change the underlying classification of the token. If the token is a security, the exchange conducting the IEO may itself be acting as an unregistered broker-dealer or securities exchange, creating significant regulatory exposure for both the platform and the issuer.
The central legal question in any token offering is whether the token constitutes a security. The answer determines which regulatory regime applies and which obligations attach.
In the United States, the Securities and Exchange Commission applies the Howey test, derived from a Supreme Court precedent, to determine whether a token is an investment contract and therefore a security. The test asks whether there is an investment of money in a common enterprise with an expectation of profit derived from the efforts of others. Most ICO tokens have satisfied this test in enforcement actions brought by the SEC, regardless of how the issuer labelled them.
In the European Union, the Markets in Crypto-Assets Regulation - commonly known as MiCA - creates a harmonised framework that distinguishes between asset-referenced tokens, e-money tokens and other crypto-assets. Tokens that qualify as financial instruments under the existing Markets in Financial Instruments Directive remain subject to that directive rather than MiCA. This means that STOs in the EU are regulated under MiFID II, requiring a prospectus or an applicable exemption, while utility-type tokens issued in ICOs fall under MiCA';s lighter regime if they do not meet the financial instrument threshold.
In Switzerland, the Financial Market Supervisory Authority published guidance classifying tokens as payment tokens, utility tokens or asset tokens. Asset tokens - the Swiss equivalent of security tokens - are subject to securities law. The Swiss approach has been influential in structuring STOs because Switzerland offers a relatively clear classification framework and a developed legal infrastructure for tokenised assets under its Distributed Ledger Technology Act.
Singapore';s Monetary Authority applies the Securities and Futures Act to determine whether a digital token constitutes a capital markets product. The MAS has issued multiple guidance documents and no-action letters clarifying that tokens which represent ownership rights or debt obligations are regulated as securities, while pure utility tokens are not, provided the utility is genuine and not speculative.
A common mistake among founders is to assume that choosing a favourable jurisdiction for the issuing entity determines which regulatory regime applies to the offering. In practice, the offering is regulated in every jurisdiction where it is actively marketed or where investors are located. A token sold to US persons triggers US securities law regardless of where the issuer is incorporated.
Misclassifying a security token as a utility token in an ICO is the most significant legal risk in this space. Regulators have pursued enforcement actions resulting in rescission orders - requiring issuers to return funds to investors - civil penalties, disgorgement of proceeds and, in serious cases, criminal referrals.
For IEOs, the exchange bears additional exposure. If the exchange conducts a token sale that involves a security without being registered as a broker-dealer or operating under an applicable exemption, it may face the same enforcement consequences as an unregistered securities intermediary. Several major exchanges have settled with regulators on precisely this basis.
For STOs, the legal consequences of non-compliance are more predictable because the regulatory framework is explicit. Failure to file a required prospectus, failure to restrict sales to eligible investors or failure to maintain ongoing disclosure obligations can result in the offering being voidable at the election of investors. This means investors may demand their money back even after the token has appreciated in value, creating a contingent liability that can persist for years.
In practice, founders should consider obtaining a formal legal opinion on token classification before launching any offering. This opinion should address the laws of the issuer';s home jurisdiction, the jurisdictions of target investors and any jurisdiction where the token will be listed or traded. The cost of this analysis is modest compared with the cost of a regulatory enforcement action.
If you are structuring a token offering and need clarity on classification and compliance obligations, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Each of the three offering types requires a different documentation framework.
An ICO typically relies on a White Paper - a technical and commercial document describing the project, the token mechanics and the use of proceeds. In the EU, MiCA now requires White Papers for most crypto-asset offerings to contain specific mandatory disclosures and to be notified to the competent national authority before publication. The White Paper is not a prospectus and does not carry the same liability regime, but it is a regulated document under MiCA and must not contain misleading statements.
An STO requires securities-law-compliant offering documentation. Depending on the jurisdiction and the applicable exemption, this may be a full prospectus approved by a securities regulator, an offering memorandum for a private placement to accredited or professional investors, or a simplified prospectus under a small-offering exemption. The documentation must include audited financial statements, risk factors, a description of the rights attached to the token and the identity of key personnel. Transfer restrictions must be encoded both in the legal documentation and, where technically feasible, in the smart contract governing the token.
An IEO requires the issuer to satisfy the exchange';s own listing requirements in addition to any applicable regulatory obligations. Exchange due diligence processes vary widely. Some platforms apply rigorous legal and technical review; others apply minimal scrutiny. From a legal standpoint, the issuer cannot rely on the exchange';s due diligence as a substitute for its own legal compliance. The listing agreement between the issuer and the exchange is a commercial contract that typically allocates liability for regulatory breaches, and founders should review this allocation carefully before signing.
Across all three models, anti-money-laundering and know-your-customer obligations apply wherever the issuer or the exchange is subject to financial services regulation. In the EU, the Transfer of Funds Regulation and the Anti-Money-Laundering Directives impose obligations on crypto-asset service providers. In the United States, the Bank Secrecy Act applies to money services businesses, a category that may include token issuers depending on the structure of the offering.
Scenario one - a technology startup raising early-stage capital. A software company wants to raise funds to build a decentralised storage network. It plans to issue tokens that will eventually grant holders access to storage capacity on the network. If the network is not yet operational and the tokens are sold primarily on the expectation that they will increase in value once the network launches, regulators are likely to treat the tokens as securities under the Howey test or its equivalents. The appropriate structure is either an STO with full securities-law compliance or a private placement to accredited investors under an applicable exemption, not a public ICO. A common mistake is to launch a public ICO in this situation and rely on the utility label, which has repeatedly failed in enforcement proceedings.
Scenario two - a real estate fund tokenising property interests. A fund manager wants to issue tokens representing fractional ownership interests in a portfolio of commercial properties. The tokens carry rights to rental income distributions and a share of sale proceeds. This is unambiguously a security token offering. The manager must comply with securities law in every jurisdiction where the tokens are offered, obtain regulatory approval or rely on a private placement exemption, restrict transfers to eligible investors and maintain ongoing disclosure obligations. An IEO structure would be inappropriate here because most exchanges are not licensed to facilitate securities transactions, and listing the tokens on an unregulated exchange would expose both the manager and the exchange to enforcement risk.
Scenario three - an established blockchain project conducting a secondary token sale. A project with an operational network and a token already in active use wants to raise additional funds by selling newly issued tokens through a major exchange. If the token is genuinely used for network functions and the sale is not the primary basis for an expectation of profit, the IEO structure may be appropriate. The project should nonetheless obtain legal advice confirming that the token does not meet the security definition in the jurisdictions of target purchasers, and the exchange should confirm that it is not acting as an unregistered securities intermediary.
Many underestimate the ongoing compliance obligations that attach after the initial offering. Token issuers that have conducted STOs face continuing disclosure requirements, restrictions on secondary trading and, in some jurisdictions, obligations to maintain a register of token holders equivalent to a shareholder register.
The regulatory landscape for token offerings has shifted substantially in recent years. The direction of travel in most major jurisdictions is toward greater regulation, not less. The EU';s MiCA framework represents the most comprehensive attempt to create a unified regulatory regime for crypto-assets, and it is influencing regulatory approaches in other jurisdictions.
A non-obvious requirement that frequently surprises foreign founders is the concept of reverse solicitation. Under MiCA, a non-EU crypto-asset service provider may serve EU clients without authorisation only if the client approached the provider on its own initiative. If the provider markets its services to EU clients in any way - including through social media, websites accessible in the EU or intermediaries - the reverse solicitation exemption does not apply and full authorisation is required.
In the United States, the SEC has taken the position that most tokens issued in ICOs are securities, and it has pursued enforcement actions against both issuers and promoters. The Commodity Futures Trading Commission asserts jurisdiction over tokens it classifies as commodities, creating a dual-regulator environment that adds complexity for US-facing offerings.
In the United Kingdom, the Financial Conduct Authority regulates security tokens as specified investments under the Financial Services and Markets Act. The FCA has also introduced a registration regime for crypto-asset businesses carrying out certain activities, including operating a crypto-asset exchange.
Cross-border offerings require a jurisdiction-by-jurisdiction analysis. There is no global passport for token offerings equivalent to the EU prospectus passport. Each jurisdiction must be assessed independently, and the offering must be structured to comply with the most restrictive applicable regime or to exclude investors from jurisdictions where compliance is not feasible.
For assistance navigating multi-jurisdictional token offering requirements, contact info@vlolawfirm.com. We can assist with legal classification, documentation and regulatory filings across relevant jurisdictions.
What is the most important legal distinction between an ICO and an STO?
The core distinction is whether the token constitutes a security under applicable law. In an ICO, the issuer typically asserts that the token is a utility instrument and not a security, though regulators may disagree based on the economic substance of the offering. In an STO, the issuer acknowledges from the outset that the token is a security and structures the offering to comply with securities law. The practical consequence is that an STO requires prospectus-level documentation, investor eligibility restrictions and ongoing disclosure, while an ICO that is later reclassified as a security offering faces retroactive enforcement risk including rescission obligations and civil penalties. The label chosen by the issuer does not bind regulators or courts.
How long does it typically take to structure and launch a compliant STO, and what does it cost?
A compliant STO is a materially more complex undertaking than a public ICO. The timeline from initial legal structuring to launch typically runs from several months to over a year, depending on the jurisdiction, the complexity of the underlying asset and whether a full prospectus or a private placement exemption is used. Legal and advisory fees for a cross-border STO generally start in the mid-to-high tens of thousands of euros or dollars for a private placement structure and can reach several hundred thousand for a full prospectus offering. Regulatory filing fees, smart contract audit costs and exchange listing fees add further to the budget. Founders who underestimate these costs often find themselves unable to complete the offering after committing to investors.
Can an IEO be used as a compliant alternative to a public ICO in regulated markets?
An IEO does not, by itself, resolve the regulatory classification question. If the token being sold in an IEO is a security, the exchange conducting the sale may be acting as an unregistered securities intermediary, and the issuer remains subject to securities law obligations regardless of the exchange';s involvement. In jurisdictions where the token is not a security, an IEO may offer practical advantages - including the exchange';s existing user base, liquidity infrastructure and due diligence credibility - without creating additional regulatory exposure. The key is to resolve the classification question first and then determine whether the IEO structure is appropriate for the token type and target investor base.
ICO, STO and IEO are legally distinct instruments with materially different regulatory profiles. The classification of a token offering depends on the economic substance of the token and the applicable legal test in each relevant jurisdiction, not on the label chosen by the issuer. Misclassification carries serious legal and financial consequences. Founders and investors operating in this space should obtain jurisdiction-specific legal advice before structuring or participating in any token offering.
VLO Law Firms advises international clients on ICO, STO and IEO matters across multiple jurisdictions. We can assist with token classification analysis, offering documentation, regulatory filing strategy and cross-border compliance structuring. To request a consultation, contact: info@vlolawfirm.com