A whitepaper, a countdown timer and a large online community can all exist before a token buyer knows which legal entity receives the money. That missing answer matters more than the presentation.
An initial coin offering, or ICO, distributes tokens to raise funds or bootstrap a network. Buyers may pay with cryptoassets, stablecoins or fiat currency. Legal treatment follows the token’s rights, marketing and jurisdictions involved—not the project’s preferred label.
Start with the issuer and the offering
Identify the legal entity receiving funds, its jurisdiction, registered address and responsible people. Confirm which entity has obligations to buyers and which terms govern the sale. If those basic facts are missing or inconsistent across the website, terms and corporate records, due diligence cannot progress.
Check whether the offering is available lawfully to the buyer’s country and whether registration, authorisation, notification or an exemption is claimed. Verify such claims directly with the relevant regulator or register. “Decentralised,” “utility” and “offshore” are descriptions, not automatic exemptions.
In the European Union, the Markets in Crypto-Assets Regulation establishes rules for public offers and admission to trading of cryptoassets within its scope, including whitepaper and communication requirements. The ESMA MiCA overview also points readers to the current implementation framework. Other jurisdictions use different classifications and exemptions.
Understand what the token actually provides
Read the contractual terms and deployed code, not only the project’s label. Ask:
- Does the token provide access, governance, redemption, revenue, ownership or no enforceable right?
- Who can change supply, freeze transfers, upgrade contracts or move treasury funds?
- Is a promised product live, testable and legally available?
- What happens if development stops or the issuer becomes insolvent?
- Are rights enforceable against an identified entity, or are they only technical features?
The distinction between utility and security token classifications turns on economic substance and jurisdiction rather than branding.
Review allocation, supply and unlocks
Tokenomics should be translated into numbers and dates. Record total and circulating supply, the minting rules, allocations to insiders, treasury and community, vesting schedules, unlocks and any power to amend them.
A large marketing allocation is not evidence of success, and a small team allocation is not proof of fairness. The relevant questions are who controls each wallet, when tokens become transferable and how future supply could affect governance or the market. Verify published addresses and vesting contracts where possible.
Assess the product and technical controls
A repository, audit badge or testnet is useful evidence only within limits. Determine what code was audited, which version is deployed, whether critical findings were resolved and whether privileged keys can override the audited logic. An audit reduces uncertainty; it does not guarantee security.
Check dependencies such as bridges, price oracles, custody providers and centralised frontends. If the token’s value proposition relies on a product that does not exist, the buyer is funding execution risk rather than evaluating an operating network.
The project should explain how sale funds are held, who can spend them and whether milestones constrain release. A multisignature wallet is meaningful only when signers and thresholds are known and independent enough for the stated purpose.
Investigate people and claims
Verify employment history, prior projects and legal names through independent records. Social profiles and conference appearances can support an identity check but do not prove competence or integrity. Anonymous teams are not necessarily fraudulent, but they reduce available accountability and recovery routes.
Partnership logos require confirmation from the supposed partner. Community size can be purchased, and active chats can be coordinated. Neither a listing website nor a large follower count verifies an offering. The exit-scam due-diligence guide explains how to distinguish verifiable warning signs from the mere fact that a project later failed.
Liquidity is not guaranteed
A token sale does not guarantee an exchange listing, a market maker, redemption or an exit price. Thin liquidity and concentrated ownership can make the displayed price impossible to realise at size. Restrictions may also prevent transfer for legal or technical reasons.
Analyse who is expected to buy after the sale and why the token is necessary to the product. Promises of a fixed return, certain listing or risk-free appreciation are warning signs. The FCA’s cryptoasset regulatory information illustrates that regulatory perimeters and promotion rules must be considered rather than assumed away.
A decision checklist
- Verify issuer, jurisdiction, governing terms and regulatory claims.
- Describe the buyer’s rights in one precise paragraph.
- Map supply, insider control, vesting and unlock dates.
- Test the product and compare deployed code with audit scope.
- Verify custody, treasury and privileged-key controls.
- Challenge partnership, adoption and listing claims independently.
- Model complete loss, illiquidity, dilution and enforcement failure.
A decision can stop before every box is scored. If the issuer, governing terms, token rights or custody path cannot be verified, the missing evidence is already material to the result.
Editorial note: this guide was fully reviewed and rewritten on September 3, 2026. Rules differ by jurisdiction; this is general educational information, not legal or financial advice.

