Web3 employees may face legal risks for promoting illegal activities

iconTechFlow
Share
AI summary iconSummary
Web3 news reports that employees in roles such as operations, business development, and community management may face legal risks if their work supports illegal financial activities. Even without handling funds, those who guide user onboarding or promote misleading content could be held liable. Legal responsibility depends on whether they knowingly assisted the project’s core illegal operations. As Web3 adoption grows, the line between compliance and liability becomes clearer.

Article by Gao Mengyang

In criminal cases involving Web3 projects, law enforcement agencies often first ask, not "What is your job title?" but "Where did you bring the users?"

An operations staff member may not have access to the company wallet or decide token prices, but is responsible for releasing project promotional content, maintaining community engagement, and directing interested users to customer service; a BD professional may not have access to the trading backend but receives commissions based on new registrations, deposit amounts, or trading volume; a community moderator may appear to simply answer questions in the group, but their actual responsibilities include explaining revenue models, sharing account registration links, and guiding users to purchase USDT and complete deposits.

When the project was later investigated for alleged illegal operations and other issues, the most common question among these employees was: “The business model was decided by the boss—I was only responsible for promotion and never handled company funds. Why are the public security authorities coming after me?”

The answer is neither “anyone involved in operations must be held responsible” nor “those who never handled funds are absolutely safe.” Whether an employee faces criminal liability ultimately depends on whether they recognized that the project was engaged in illegal activities, whether their work contributed to the core operations, and what specific role they played in users joining the project, completing transactions, and transferring funds.

The project's business being illegal does not mean all employees are guilty of a crime.

In February 2026, the People’s Bank of China and seven other departments issued the "Notice on Further Preventing and Handling Risks Related to Virtual Currencies," clearly stating that activities within China such as virtual currency exchange, token issuance financing, and providing information intermediation, pricing, or similar services for virtual currency trading constitute illegal financial activities related to virtual currencies; internet companies are prohibited from offering commercial display, marketing promotion, or paid traffic referral services for such activities.

On July 23, 2026, the Shenzhen Internet Information Office announced a batch of self-media accounts violating regulations related to virtual currencies, including accounts such as "USDT Merchant Communication Group" and "WeiZhi KuaiHuan." The notice stated that these accounts were permanently suspended by the platform for providing marketing and promotional content about virtual currency services within the mainland and inducing the public to participate in illegal virtual currency financial activities.

However, it is important to note that if regulatory rules classify a certain type of business as an illegal financial activity, or if an account is shut down by the platform due to non-compliant promotion, this does not automatically mean that every employee involved is guilty of illegal business operations.

The crime of illegal business operations requires not only that the conduct violates state regulations, but also that the individual actually engaged in specific illegal business activities or other serious disruptions of market order, reaching a level of "serious circumstances." If an employee is to be held jointly criminally liable, it must also be proven that they had a shared intent to commit the crime with others and participated in or assisted in the commission of the offense through specific actions.

The adjudication principles illustrated in Supreme People's Court Guiding Case No. 97 also indicate that administrative violations cannot be directly equated with the crime of illegal business operations. When applying the crime of illegal business operations, it is still necessary to examine whether the relevant conduct possesses corresponding social harm, criminal illegality, and necessity for criminal punishment.

Therefore, determining whether a Web3 employee bears criminal liability cannot rely solely on whether the project was ultimately investigated or whether the employee received a salary from the company; it must instead focus on the individual’s actual involvement in the business chain.

Operations, BD, and community growth may enter the project’s operational chain through a marketing role.

General brand operations primarily handle content creation, event execution, media outreach, and community management; their work does not directly equate to facilitating user trading. However, in some Web3 projects, there is no true separation between brand promotion, user acquisition, account registration links, asset deposits, and trading conversion.

For example, operations staff continuously post promotional content such as “principal-guaranteed returns,” “fixed returns,” “low-price subscriptions,” or “large-scale settlements.” After seeing this content, users are guided to join private communities, where community members then send transaction links, wallet addresses, or deposit tutorials. BD teams are responsible for coordinating with KOLs, agent networks, and community channels, and earn commissions based on user registrations, deposit amounts, or trading volumes.

Under this model, front-end promotion is no longer just an independent branding effort but may become a necessary component of the project’s operational activities. Law enforcement agencies typically review the user conversion path step by step: where users learned about the project, who was responsible for building trust, who explained the product and returns, who sent the account opening link, who guided users in purchasing USDT, completing KYC, and depositing funds, who pressured users when they hesitated, and who received commissions based on the final transaction amount.

Therefore, whether employees have operated the company wallet is not the sole criterion for assessing risk. For a project that relies on community-driven user acquisition and private domain conversion, consistently and precisely guiding domestic users into the trading process can itself provide substantial operational benefits to the project.

Assessing employee risk can reconstruct four business chains.

Whether operations, business development, and community staff have moved from general support roles into the core operational aspects of the project can be assessed across four dimensions: content chain, customer acquisition chain, transaction chain, and fund chain.

This table is not a mechanical standard for determining criminal liability. Even if an employee performed one of the listed tasks, a guilty conclusion cannot be drawn directly without considering the time of the activity, the scope of their authority, their subjective awareness, and the actual operational model of the project.

However, when high-risk behaviors across all four channels accumulate over time, employees can clearly see users progressing from engaging with promotional content, completing account registration, depositing funds, to ultimately executing trades—and their own compensation is directly tied to trading volume. At this point, it becomes significantly harder for them to justify their actions by claiming, “I’m only responsible for posting content.”

"I didn't know the business was illegal"—why might I still be subject to review?

In employee cases, the core issue is typically not whether they participated in the work, but whether they were aware that the project's operations involved illegal or criminal risks.

Regarding subjective awareness, law enforcement authorities will not base their judgment solely on an employee’s statement of “I didn’t know” or “My boss didn’t tell me”; instead, they will conduct a comprehensive review considering job responsibilities, internal communications, user complaints, compensation structure, regulatory alerts, and subsequent actions.

For example, has the company internally clearly discussed refraining from serving users within the mainland, yet still required employees to continue acquiring new users through Chinese-language communities? Has the company mandated replacing terms such as “deposit,” “trading,” and “rewards” with coded language? Has the project frequently changed its domain names, communities, and payment accounts? Have employees received alerts regarding platform bans, bank freezes, users’ inability to withdraw funds, or risk warnings from compliance personnel? After these anomalies have occurred in a concentrated manner, have employees continued to recruit new users and pressured users to make payments?

The presence of any single factor alone cannot directly prove that an employee has committed a crime. However, if multiple anomalous circumstances occur repeatedly over an extended period and the employee continues to encourage user trading, these factors may collectively influence the assessment of their subjective intent.

Conversely, if an employee has been with the company for a short period, receives only a standard fixed salary, has not participated in profit commitments, trading guidance, or fund handling, lacks comprehensive understanding of the project’s overall business model, and promptly halts related activities, raises objections, or voluntarily resigns upon discovering irregularities, these facts should be thoroughly examined in determining liability. In a previous case we handled, we meticulously organized evidence based on the client’s tenure, compensation structure, job authority, actual scope of involvement, and actions taken after discovering anomalies, and submitted a comprehensive defense argument, ultimately achieving a favorable outcome of no prosecution.

Lacking decision-making authority and simply following your boss’s instructions does not automatically exempt you from liability.

In criminal law, joint criminal liability does not require each individual to participate in every stage. In a project, the manager may be responsible for designing the business model, technicians for building the system, operations and business development for acquiring users, customer service for guiding transactions, and finance for fund settlement. Although the actions performed by different roles vary, they may collectively advance the same business activity.

If operations, business development, or community personnel knowingly continue to long-term and consistently handle user acquisition, transaction conversion, or fund assistance for a project whose core business is illegal, they may be deemed complicit in a criminal offense. An employee’s lack of decision-making authority over the business model, involvement in only partial tasks, or receiving lower profits than the project’s principal does not automatically exclude them from criminal liability, but it may affect their role and degree of responsibility within the joint crime.

Criminal law stipulates that individuals who play a secondary or auxiliary role in a joint crime are considered accomplices and shall be punished less severely, mitigated, or exempted from punishment according to law. Therefore, even if employees have been determined to have participated in a joint crime, ordinary executing personnel should not be evaluated the same as project initiators, actual controllers, or core management personnel.

The typical cases of foreign exchange-related criminal offenses jointly released by the Supreme People's Procuratorate and the State Administration of Foreign Exchange also indicate that platform operators, ordinary staff, virtual currency traders, and account providers within the same business system may bear different liabilities depending on their specific roles, subjective awareness, and levels of involvement. Key areas of review in related cases include chat records, bank statements, transaction histories, wallet addresses, and the actual division of responsibilities among individuals.

A lawyer’s crucial role in such cases is to separate the company’s overall operations from the individual actions of employees, clearly establishing when each employee joined, what authorities they held, which users and transactions they actually participated in, what benefits they received, whether they understood the true nature of the project, and the extent to which their actions influenced the project’s operational outcomes.

After a project is under investigation, which evidence should employees prioritize preserving?

When the project lead goes missing, the company group is suddenly disbanded, or employees receive notification from public security authorities, the least advisable action is to immediately delete chat records, leave all groups, or coordinate a unified story with colleagues. These actions may result in the destruction of evidence favorable to employees and could be interpreted as an attempt to evade investigation.

Employees should prioritize preserving employment contracts, job descriptions, salary records, performance guidelines, work instructions, and actual deliverables, while also maintaining complete records of communications with supervisors, clients, and other departments. For wallets, backends, and fund accounts to which they have no access, employees must clearly define their boundaries with relevant processes through work authorization records, approval workflows, or internal communications.

If an employee previously raised objections about project risks, refused to participate in receiving payments into personal accounts, requested the removal of exaggerated return claims, or voluntarily resigned after discovering irregularities, such records must be promptly secured.

Conversely, if you did participate in user deposits, fund aggregation, or transaction guidance, you should not merely offer a vague explanation such as “I am just an ordinary employee.” Instead, you should clearly outline the timing of your involvement, the affected users, the transaction amounts, the specific actions taken, and the source of the instructions. Whether an employee bears responsibility must be determined based on a complete set of facts, not merely on a job title.

Legal observation

In Web3 projects, the risks in operations, business development, and community work often lie not in the job titles themselves, but in how these roles are connected to business outcomes.

Simply writing general copy, organizing brand events, or maintaining ordinary communities does not automatically constitute illegal business operations. However, when employees' work continuously promotes domestic users to open accounts, purchase USDT, deposit funds, subscribe to, or participate in unlicensed financial services, and their income is directly tied to user deposits or trading volumes, the associated risks can no longer be simply dismissed as “a company matter.”

For employees, what truly needs to be documented is not the phrase “I’m just an employee,” but complete evidence proving their job scope, authority boundaries, compensation structure, and subjective understanding. For project teams, it is not sufficient to label all customer acquisition and transaction conversion activities as “brand operations”; they must re-examine where promotional content ultimately directs users and what specific roles employees play within the customer, transaction, and fund chain.

A project being illegal does not mean all employees are guilty; not touching the company’s wallet does not mean there is no risk. Criminal liability must ultimately be assigned to specific individuals, distinguishing between those who designed the business, set the direction, facilitated transactions, controlled funds, and those who merely performed routine tasks within a limited scope.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.