Staking in Regulated Portfolios: How the US, EU, UK, and Asia Treat It
Executive Summary
In February 2023 the SEC forced Kraken to shut its US staking program and pay $30 million[1]. In March 2026 the SEC and CFTC jointly took the opposite position at Commission level: protocol staking, run within stated conditions, sits outside the federal securities laws entirely[2]. Between those two dates, every major financial centre wrote staking rules — and an institution that reads the US reversal as “staking is now unregulated” will mis-book the product in five of the six jurisdictions this report covers. Four findings frame the analysis.
Staking went from enforcement target to licensed product line faster than any crypto activity we track. The institutions that get it right will be the ones that noticed the licences came with key-custody rules attached.
Regulatory Background
What regulators are actually looking at
Staking is the act of immobilizing crypto-assets to support a proof-of-stake network’s consensus mechanism in exchange for validator privileges that generate block rewards — that is the definition the European Commission adopted and the joint EBA-ESMA report carried into the MiCA review[17]. The definition matters less than the four delivery models built on top of it, because every regulator that has acted since 2023 draws its lines between them:
- Solo (self) staking — the asset owner runs its own validator. No regulator we cover treats this as a licensable service; the SEC staff called it “merely engaging in an administrative or ministerial activity”[3] and MAS expressly left self-staking outside its restrictions[18].
- Self-custodial delegation — the owner keeps the keys and delegates validation rights to a third-party node operator. Generally the lightest-touch model, but Germany shows the trap: BaFin’s pre-MiCA practice treated delegated validator rights as potentially licensable “management” of crypto-assets[19].
- Custodial staking (staking-as-a-service) — a custodian or exchange stakes assets it holds for clients. This is where nearly all institutional volume sits, and where nearly all the regulation lands, because the client’s assets leave immediate reach: MAS built its retail prohibition on the finding that once staked, assets “would not be protected by the segregation and custody requirements” imposed on licensed providers[18].
- Liquid staking — the depositor receives a receipt token, one-for-one, evidencing ownership of the staked asset. The SEC staff analyzed the receipt token as deriving its value from the deposited asset rather than from anyone’s managerial efforts[20]. Restaking — recommitting the receipt token itself — was expressly excluded from that analysis and remains the unresolved frontier.
The supervisory concerns are constant across jurisdictions even where the legal instruments differ: slashing (protocol-imposed forfeiture), lock-up and exit-queue liquidity risk, and the insolvency treatment of staked assets. FINMA put the last one bluntly as early as December 2023 — there is “legal uncertainty about the treatment of staked cryptoassets in bankruptcies in certain situations,” and more still when staking is delegated to foreign institutions[21].
Three phases in three years
2023 — enforcement and restriction. The SEC charged Kraken over its staking-as-a-service program in February 2023; Kraken paid $30 million and shut the US program, with the SEC’s then-chair insisting staking-as-a-service providers “must register”[1]. Five months later MAS decided to bar digital payment token providers from staking retail customers’ assets, reasoning that risk disclosure alone could not carry the consumer harm[18]. FINMA closed the year with staking guidance focused on bankruptcy remoteness[21]. Dubai’s VARA, characteristically quieter, had already folded “Staking from Custody Services” into its custody rulebook that August as a licence-stipulated sub-set of custody[8].
2025 — the pivot wave. The SEC dismissed its Coinbase action — including the staking claim — with prejudice in February[22], then its Division of Corporation Finance issued statements concluding that protocol staking (May) and liquid staking (August) do not involve the offer and sale of securities[3][20]. The UK excluded “qualifying cryptoasset staking” from the collective investment scheme definition effective 31 January[14]. Hong Kong’s SFC, executing its ASPIRe roadmap, issued twin circulars on 7 April allowing licensed trading platforms and authorised funds to stake under conditions, with the HKMA mirroring the standards for banks the same day[6][23] and a joint circular extending the regime to intermediaries in September[24]. BaFin mapped custodial staking to MiCA’s custody-plus-transfer services in January[19], and ESMA answered the own-account question in July: client consent cannot authorize a CASP to stake client assets for its own benefit[5].
2026 — consolidation. In March the SEC and CFTC jointly elevated the 2025 staff positions to a Commission-level interpretation published in the Federal Register[2]. The UK made SI 2026/102 in February, converting staking from a carve-out into a directly regulated activity from 25 October 2027, with FCA conduct rules consulting in parallel[15][16]. Abu Dhabi’s ADGM finalised its staking framework in April[25], and the SFC refreshed its funds circular in May with the staking regime carried over intact[26].
No crypto activity in our jurisdiction coverage has reversed regulatory posture this fast: an enforcement priority in 2023 became a licensed, condition-laden product line by mid-2026. But read the three phases carefully and they are not answering the same question. The US answered is staking a securities offering? The EU, Hong Kong, Singapore, and the UAE answered who may stake client assets, and under what custody controls? The UK answered both, in sequence. That difference in the question — not the answers — is what Section 3 works through, because it determines which of your entities carries which obligation.
Analysis: Obligations by Jurisdiction
1. United States: de-classified, not deregulated
The operative position is the SEC/CFTC joint interpretation of 17 March 2026: protocol staking activities, in the manner and circumstances described, “do not involve the offer and sale of a security,” with the CFTC administering the Commodity Exchange Act consistently with that view[2]. That elevated the two 2025 staff statements — protocol staking in May, liquid staking and staking receipt tokens in August[3][20] — from staff views that “ha[d] no legal force or effect” by their own disclaimer into a position the Commission itself now owns in the Federal Register.
The conditions are the compliance program. For custodial arrangements, deposited assets must not be “lent, pledged, or rehypothecated for any reason,” and the custodian must not decide “whether, when, or how much” of a client’s assets to stake[3]. The liquid-staking analysis holds only for one-for-one receipt tokens whose value tracks the deposited asset; a provider that exercises discretion or engineers returns steps outside the statements’ footnoted scope, and restaking is expressly excluded[20]. In other words: the more your staking product looks like a managed yield product, the less of this protection you have. That boundary is exactly where Commissioner Crenshaw aimed both dissents, warning that the analysis “stacks factual assumption on top of factual assumption” and that abandoned enforcement actions “do[] not erase the underlying court decisions” upholding staking-as-a-service complaints[9].
Three residues keep US staking from being a settled question. First, five of the ten 2023 state securities actions over Coinbase’s staking program (California, Maryland, New Jersey, Washington, Wisconsin) remained open as of Coinbase’s FY2025 annual report[10]; the federal reversal does not bind state regulators. Second, the promised “Regulation Crypto Assets” safe-harbor rulemaking had been announced but not adopted as of July 2026[11], and the CLARITY Act — which would codify custodial and ancillary staking services “exclusively administrative or ministerial in nature” — passed the House in July 2025 but has not cleared the Senate[27][12]. Third, the banking agencies have withdrawn their restrictive crypto guidance[28] and the OCC has blessed custody, network-fee, and riskless-principal activity[29], but no interpretive letter expressly authorizes a national bank to run staking; a bank staking program today rests on custody-authority analogy, and your regulatory-affairs team should treat it as a supervisory conversation, not a settled entitlement.
The product and tax layers moved faster than the rulebook. Generic listing standards approved in September 2025 removed the per-product approval bottleneck for ETPs[30]; Grayscale’s Ethereum products became — by the firm’s own Rule 433 announcement, filed on EDGAR — the first ’33 Act ETPs to stake in October 2025 and the first to distribute staking rewards in January 2026[13]. On tax, the deferral theory lost its first merits test in June 2026: the Tax Court in Paschall held staking rewards taxable on receipt on section 61 grounds, the same answer Rev. Rul. 2023-14 gives[31][32]. Accrue at receipt; the deferral argument now needs an appellate rescue.
2. European Union: regulated through the custody door
MiCA never mentions staking: it is not one of the ten crypto-asset services in Article 3(1)(16)[33]. The Commission and ESMA closed that gap with two Q&As that together define the EU regime. Q&A 2067: a CASP staking clients’ assets is providing custody and administration, so it needs the Article 75 authorisation, must be able to return assets per the custody agreement, remains liable for losses, and must obtain explicit client consent because staking affects the client’s ability to access its assets[4]. Q&A 2607 answered the harder conflicts question: under Article 70(1), a CASP may not stake client assets for its own account — “even in cases where the client has explicitly provided consent” — and staking-as-a-service is permissible only where the profits do not solely benefit the CASP[5]. Consent is a necessary condition in Europe, never a sufficient one.
The Article 142 review analysed staking, liquid staking, and restaking at length and proposed no new service category[17] — so this custody-anchored treatment is the EU position for the foreseeable future, not a stopgap. What that leaves is national texture. BaFin reads a custodian’s transfer of custodied tokens into a staking smart contract as a crypto-asset transfer service stacked on custody, while exempting pure validators and node operators[19]; a German CASP staking program therefore wants both permissions in its authorisation. Having sat through more than one MiCA authorisation file review, we would treat the German mapping as the conservative default for any EU passporting strategy: it costs little to include the transfer service, and re-papering an authorisation after launch costs a quarter.
3. United Kingdom: carve-out first, capture second
The UK looks permissive today and is the strictest of the six on a two-year view. Since 31 January 2025, “qualifying cryptoasset staking” (the use of a qualifying cryptoasset in blockchain validation, pooled arrangements included) is excluded from the collective investment scheme definition[14]. That removed the risk that staking providers were unwittingly operating unauthorised CISs, and it imposed nothing in return.
The capture is already law. SI 2026/102, made 4 February 2026, adds “arranging qualifying cryptoasset staking” to the nine new regulated cryptoasset activities, in force 25 October 2027, with the FCA authorisation gateway expected to open from 30 September 2026 and transitional savings for MLR-registered applicants running to 2029[15][34]. The conduct rulebook is consulting now: CP25/40 proposes durable pre-contractual disclosure, express consent to key terms for each staking instance, five-year records covering daily staked amounts, safeguarding status, rewards, consents and losses, and operational-resilience and prudential requirements — while notably dropping the discussion-paper proposal to make firms liable for losses from preventable operational failures[16][35]. The operational consequence: a staking provider serving UK clients should be building its FCA application file and its per-instance consent plumbing this year, not in 2027.
4. Hong Kong: the most prescriptive green light
Hong Kong is the only jurisdiction of the six that wrote a staking rulebook down to the key-ceremony level. The SFC’s April 2025 circular lets licensed platforms offer staking only with prior written SFC approval and under appended licence conditions: the platform must keep “possession or control of all mediums through which the client VAs may be withdrawn” — the withdrawal private key and the pre-signed voluntary exit message — and third-party custody of client assets is flatly prohibited, though outsourcing to third-party validators is allowed with due diligence and a written, regularly reviewed agreement[6]. Staking runs on client standing authority or one-off written direction; the executed risk acknowledgement is waived only for institutional and qualified corporate professional investors[6]. The HKMA imposed mirror standards on banks the same day and expects them to discuss staking plans with it in advance[23]; a September 2025 joint circular extended staking to intermediaries, but only through segregated accounts at a licensed platform or authorised institution[24]. SFC-authorised funds may stake through licensed venues with prior consultation and approval, subject to a liquidity cap[26].
The distinction Hong Kong draws — delegating validation is permitted, delegating custody is not — is the cleanest articulation anywhere of where staking risk actually lives, and it matches what we found running custodian key-management diligence: the party holding the withdrawal key and exit message holds the loss, whatever the validator SLA says.
5. Singapore: a conduct wall, not a licensing question
MAS regulates staking through the conduct guidelines attached to DPT licensing. PS-G03 paragraph 3.7.1(c) directs providers not to stake, or arrange to stake, retail customers’ assets — in force since October 2024 — with “stake” defined broadly enough to cover any smart-contract lock generating fees, rewards or returns[7]. The stated rationale is structural, not paternalistic: MAS concluded disclosure could not cure the harm because staked assets fall outside the segregation and custody protections the licensing regime otherwise guarantees[18]. Accredited and institutional investors can be served, with written risk disclosure and written acknowledgement[7], and self-staking was never restricted. For an institutional desk, Singapore is operationally simple: paper the client classification, paper the acknowledgement, and the regime is satisfied. The gray zone here is entity scoping — the ban attaches to the licensed DPTSP’s arrangements, so groups sometimes book retail-adjacent staking through offshore affiliates; MAS has not blessed that structure, and we would not build on it.
6. UAE and Japan: custody sub-set and perimeter question
Dubai’s VARA treats staking-from-custody as a sub-set of the custody activity: no separate licence category, but the authorisation must be expressly stipulated in the custodian’s licence, staking is limited to assets already under that custodian’s custody, and incremental supervision fees apply[8]. Abu Dhabi’s ADGM finalised its framework in April 2026 on the same axis (custodians stake on explicit client instruction only; discretionary staking requires a managing-assets permission) and extended scope to non-PoS models with materially similar characteristics[25]. Japan’s FSA states the perimeter simply: an exchange receiving crypto-asset deposits for staking needs exchange registration, a borrowing-structured program does not, and a dedicated staking regime remains “a future challenge”[36].
For your controls inventory: every one of these six regimes can be satisfied by the same four artifacts. A custody map showing who holds withdrawal keys and exit messages, a per-client consent record, a slashing/lock-up/exit-queue risk disclosure, and a fee-transparency schedule. What differs is who must file what with whom, and Section 4 reduces that to a comparison your booking-model decisions can use.
Comparative Analysis
The regimes side by side
| US | EU | UK | Hong Kong | Singapore | Dubai (VARA) | |
|---|---|---|---|---|---|---|
| Legal frame | Not a securities offering if administrative/ministerial[2] | Not a MiCA service; ancillary to custody[4] | CIS-excluded now; regulated activity from 25 Oct 2027[14][15] | Permitted via modified licence conditions[6] | Conduct restriction inside DPT licensing[7] | Sub-set of custody activity[8] |
| Gatekeeper | None — self-assess against the interpretation | CASP custody authorisation | FCA permission (gateway from Sep 2026) | Prior written SFC approval per platform | Licence + PS-G03 conduct | Express licence stipulation |
| Custody rule | No lending, pledging, rehypothecation of staked deposits | CASP liable; assets returnable per custody agreement | Safeguarding records; segregation proposed | Platform holds withdrawal keys + exit messages; no third-party custody | Staked assets lose statutory segregation — hence the retail ban | Only assets already in the custodian’s custody |
| Client consent | Not conditioned on consent | Explicit consent required; cannot authorize own-account use[5] | Express consent per staking instance[16] | Standing authority or one-off written direction | Written risk acknowledgement (non-retail) | Explicit client instruction |
| Retail access | Open (five state actions residual)[10] | Open through authorised CASPs | Open now; conduct rules land with the regime | Open with executed risk acknowledgement | Facilitation banned for retail | Per-licence, no outright ban |
Three convergences are strong enough to build a single global control set on: custody control (who holds the withdrawal path), explicit client consent, and slashing/lock-up/exit-queue disclosure appear in every regime that permits custodial staking. The divergences are in legal characterization, gatekeeping, and retail access — which is to say, in which entity needs which permission, not in what the controls look like.
Where the divergence actually bites
1. Same destination, opposite doors. The US and UK both end at supervised staking, but they got there by moving in opposite directions. The US de-classified: staking is not a securities offering, so the federal securities-law burden fell away[2]. The UK re-classified: staking came out of the collective-investment-scheme regime in January 2025 precisely so it could enter a bespoke regulated-activities regime in October 2027[14][15]. A program that is comfortable in the US on the strength of the March 2026 interpretation still needs an FCA permission, a consent-per-instance workflow, and five-year records to serve UK clients eighteen months from now[16]. Treating the US posture as the global template is the single most common planning error we see in staking build-outs.
2. Custody is the real perimeter everywhere except the US. The EU regulates staking through the custody authorisation[4], Hong Kong through withdrawal-key control[6], VARA as a custody sub-set[8], Japan through the deposit-taking line[36], and Singapore justified its retail wall by the loss of custody protections[18]. Only the US frames the question as securities characterization — and even there, the custodial conditions (no lending, no pledging, no discretionary staking) import the same custody discipline through the back door[3]. The practical reading: wherever you operate, the diligence that matters is the one our custody risk assessment runs on key management and segregation — who can sign, who can exit, and whether client assets survive the provider’s insolvency.
3. The retail gate is a spectrum, and it drives booking models. Singapore bans retail facilitation outright; Hong Kong permits it with an executed risk acknowledgement; the UK will permit it under conduct rules; the EU permits it with disclosure and consent; the US leaves it open subject to residual state actions[7][6][16][10]. Institutions running one global staking product tend to converge on the strictest gate they touch — classifying staking as non-retail by default and opening retail access market-by-market — because maintaining six retail-eligibility matrices costs more than the retail revenue in most books.
4. The arbitrage window is closing, not closed. Today a UK entity can arrange staking with no staking-specific permission; from 25 October 2027 that is a regulated activity, and the FCA gateway opens September 2026[15]. The US interpretation stands, but the safe-harbor rulemaking is pending and the CLARITY Act is unfinished[11][12] — a Commission with different priorities could reinterpret; a statute could not be so easily unwound. Anyone pricing a multi-year staking product on today’s lightest-touch reading of either jurisdiction is taking regulatory-reversal risk that the 2023-to-2025 whipsaw should have taught the industry to price.
Structuring against the strictest rule
For a multi-jurisdiction program, the binding constraints are, in practice: Hong Kong’s custody rule (platform-held withdrawal keys and exit messages, no third-party custody)[6], the EU’s own-account prohibition (no staking of client assets for house benefit, consent irrelevant)[5], the UK’s consent-and-records package (per-instance consent, five-year records)[16], and Singapore’s client-classification gate[7]. Build to those four and the US conditions, VARA’s stipulations, and Japan’s perimeter are satisfied incidentally.
Two corpus links close the loop. The withdrawal-key and exit-message requirements are a staking-specific instance of the key-management architecture questions covered in our custody technology assessment — control of the exit path is control of the asset. And on slashing: the SEC treats provider slashing-coverage as an ancillary, ministerial service[3], while the FCA dropped its proposal to mandate compensation for preventable operational losses[16]. No regulator in this set requires anyone to make you whole for a slashing event. Whatever slashing indemnity or insurance your provider offers is a commercial term to be negotiated and read like the insurance wordings in our coverage-gaps assessment — not a regulatory entitlement to be assumed.
Board members should be asking a narrower question than “are we allowed to stake?”: which entity stakes, under whose permission, holding whose keys, with what consent record — because in every jurisdiction reviewed here, that is the question the regulator will ask first.
Report Overview
Published Date
12 Jul 2026
Reading Time
24 mins
Downloads
0
About Author
Yirifi Admin
Published reports
6
Related Reports
No related reports found.