Blockchain and Crypto-assets

We assist issuers, exchanges, wallet providers, and businesses integrating crypto-assets into their business models throughout the entire project lifecycle: legal classification of the token, authorisation as a crypto-asset service provider (CASP), drafting and notification of the white paper, anti-money laundering compliance, and operational resilience.

The context is no longer the experimental landscape of previous years. Regulation (EU) 2023/1114 (MiCAR) has applied since December 2024; the transitional period provided for in Italy ended in mid-2026. Today, providing crypto-asset services without authorisation constitutes the unlawful exercise of a regulated activity, with the resulting administrative and criminal consequences.

We work as a team with the Firm’s technology partners. Classifying a token or assessing a smart contract means reading the code and the law together: it is one of the few areas where legal expertise alone is not enough.

What we do

  • Crypto-asset classification — token as an ART, EMT, or “other crypto-asset” under MiCAR, or as a financial instrument (MiFID II) or excluded category; defensible legal opinions before authorities and counterparties.
  • CASP authorisation and operations — proceedings before the Bank of Italy and CONSOB, organisational and capital requirements, European passporting.
  • White papers — drafting, review, and notification to the competent authorities; liability for inaccurate information.
  • Issuances and placements — crypto-asset offerings, stablecoins (ARTs/EMTs), token sales, and related contractual arrangements (SAFTs, token purchase agreements).
  • Anti-money laundering and travel rule — compliance with Legislative Decree 231/2007, the EU AML Package, and Regulation (EU) 2023/1113 (TFR II) on transfers of crypto-assets.
  • Tokenisation, DeFi, staking, NFTs — analysis of the specific use case, where classification depends on the economic function rather than the name given to the asset.
  • Litigation, criminal defence, and asset recovery — unauthorised activities, fraud, money laundering and self-laundering; blockchain forensics and on-chain tracing to support defence and recovery actions.
  • MiCAR — Regulation (EU) 2023/1114. It provides the single European framework for crypto-assets not already qualifying as financial instruments. It has applied since December 2024; Titles III and IV, on asset-referenced tokens (ARTs) and e-money tokens (EMTs), since June 2024. It distinguishes between ARTs, EMTs, and “other crypto-assets”, with different regulatory regimes. Financial instruments (MiFID II) and, in principle, genuinely unique NFTs remain outside its scope: classification must be based on substance.
  • Italian implementation — Legislative Decree 129/2024. Aligns Italian law with MiCAR and TFR II. It designates the Bank of Italy and CONSOB as competent authorities, with partly overlapping responsibilities. The Bank of Italy’s implementing provisions were issued in 2025.
  • Transitional regime — expired. Operators registered with OAM before December 2024 could operate until mid-2026, provided they had submitted an application by mid-2025. The window has closed: operators active today must be authorised.
  • TFR II — Regulation (EU) 2023/1113. Extends the travel rule to crypto-asset transfers: information on the originator and beneficiary must accompany the transaction. It has applied since December 2024, together with the EBA guidelines issued in 2024.
  • DORA — Regulation (EU) 2022/2554. Since January 2025, CASPs have been included among the financial entities required to manage ICT risk, conduct resilience testing, and oversee critical third-party providers.
  • Criminal law aspects. Unauthorised activities, fraud in offerings, money laundering (Art. 648-bis of the Italian Criminal Code), and self-laundering (Art. 648-ter.1 of the Italian Criminal Code) are recurring risks, addressed through expertise in white-collar crime and digital forensics.

How we work

We do not approach a blockchain project as a purely legal matter. For each mandate, we assess the regulatory framework, technological architecture, and operational and reputational impact together, working as a team with the Firm’s technology partners. We also provide dedicated training.

Would you like to be contacted?


Contact information