Web3 projects are suspected of illegal operations. Why might the operations, BD, and community personnel also be investigated?

CN
2 hours ago
The project business is illegal, but not all employees will constitute a crime.

Written by: Gao Mengyang

In criminal cases involving Web3 projects, the first question often asked by the investigating authorities is not "What is your position?" but rather "Where did you lead the users?"

An operations staff member may have never accessed the company wallet nor decided on token prices, yet they are responsible for publishing promotional content, maintaining the community, and guiding interested users to customer service; a business development (BD) person may not have the authority to operate the trading backend, yet they earn commissions based on the number of new registered users, deposit amounts, or transaction volumes; a community administrator may seem to only be answering questions in a group chat, but their work actually includes explaining return models, sending referral links, guiding users to purchase USDT, and completing deposits.

When the project is later investigated for issues such as illegal business operations, the most common question among these employees is: "The business model was decided by the owner, I was only responsible for promotion, and I never touched the company’s funds, so why would the public security agency still come after me?"

The answer is neither "Anyone involved in operations must take responsibility" nor "As long as you haven't touched the money, you're absolutely safe." Whether an employee bears criminal responsibility ultimately depends on whether they recognize that the project is engaged in illegal and criminal activities, whether their work has promoted the core business, and what role they have played in the users entering the project, completing transactions, and making payments.

The project business is illegal, but not all employees will constitute a crime

In February 2026, the People's Bank of China and eight other departments issued a notice on "Further Preventing and Handling Risks Related to Virtual Currencies," clearly stating that activities such as engaging in virtual currency exchanges, token issuance financing, and providing information intermediary services and pricing for virtual currency trading within the territory are considered illegal financial activities related to virtual currency; internet companies are prohibited from providing business display, marketing promotion, and paid traffic diversion services for relevant activities.

On July 23, 2026, the Shenzhen Internet Information Office announced a batch of non-compliant self-media accounts related to virtual currencies, including accounts like "USDT Merchant Exchange Group" and "WeChat Quick Exchange." The announcement indicated that the relevant accounts were permanently closed by the platform for providing marketing promotional information for virtual currency businesses and enticing the public to participate in illegal financial activities.

However, it is critical to distinguish that the recognition by regulatory rules that a certain type of business constitutes illegal financial activities, or that a particular account is closed by the platform for non-compliant promotion, does not automatically mean that every employee involved will constitute the crime of illegal business operations.

The crime of illegal business operations requires not only actions that violate national regulations but also that the perpetrator has actually implemented specific illegal business activities or other severely disruptive market behaviors, reaching a level of "serious circumstances." If an employee is assessed as being part of a joint crime, it also needs to be proven that they share a common criminal intent with others and have participated in or aided in the commission of the crime through specific actions.

The guiding case 97 from the Supreme People's Court indicates that administrative violations cannot be directly equated with the crime of illegal business operations. When applying the crime of illegal business operations, it is still necessary to examine whether the relevant actions possess corresponding social harmfulness, criminal illegality, and the necessity of criminal penalties.

Therefore, to determine whether a Web3 employee bears criminal responsibility, one cannot merely look at whether the project was ultimately investigated nor just whether the employee received wages from the company; rather, it should return to the actual chain of business in which the individual was personally involved.

Operations, BD, and Community Engagement May Enter the Project’s Business Chain from "Promotional Positions"

Generally, brand operations are mainly responsible for content creation, event execution, media communication, and community maintenance, and their work does not directly equate to organizing user transactions. However, in some Web3 projects, there is no real separation between brand promotion, user recruitment, referral links, asset deposits, and transaction conversions.

For instance, the operations staff continuously publishes promotional content such as "capital protection returns," "fixed income," "low-cost subscriptions," or "large redemption"; after seeing the content, users are guided to join private groups, and then community members send transaction links, wallet addresses, or deposit tutorials; the BD is responsible for connecting with KOLs, agency teams, and community channels, earning commissions based on user registration numbers, deposit amounts, or transaction volumes.

In this model, front-end promotion is no longer just an independent brand task but may become a necessary component of the project’s operational activities. Investigating authorities will usually gradually review along the user conversion path: where users learned about the project, who is responsible for building trust, who explains the product and returns, who sends referral links, who guides purchasing USDT, completing KYC and deposits, who urges users when they are hesitant, and who collects commissions based on the final transaction amount.

Therefore, whether an employee has operated the company wallet is not the sole criterion for assessing risk. For a project that relies on community customer acquisition and private domain conversion, continuously and accurately bringing domestic users into the transaction phase may, in itself, substantially aid the project's operation.

Judging Employee Risk Can Restore Four Business Chains

Whether operations, BD, and community members have moved from general auxiliary roles into the core operating segments of projects can be assessed from the four dimensions of the content chain, customer acquisition chain, transaction chain, and funding chain.

This table is not a mechanical standard for determining criminal establishment. Even if an employee has executed any of the tasks, one cannot directly conclude guilt without considering their work time, authority range, subjective awareness, and the actual model of the project.

However, when high-risk behaviors within the four chains accumulate, and employees can see users transitioning from promotional content into communities, completing account openings, paying funds, and ultimately forming transactions, their difficulty in explaining all actions with "I was only responsible for sending content" will noticeably increase.

"I didn't know the business was illegal," why could they still be investigated?

In employee cases, the most critical dispute is usually not whether they participated in the work, but whether they knew that the project’s business carried risks of illegality and criminality.

Regarding subjective awareness, investigating authorities will not make judgments solely based on a staff member's statement of "I don’t know" or "The boss didn't tell me," but will conduct a comprehensive review that includes work authority, internal communications, user complaints, pay structures, regulatory notices, and subsequent behaviors.

For example, whether the company has clearly discussed that it cannot conduct business targeting domestic users while requiring employees to continue to recruit through Chinese communities; whether it has asked to replace terms such as "deposit," "transaction," "returns" with euphemisms; whether the project frequently changes domain names, communities, and payment accounts; whether employees have received platform bans, bank freezes, or risk alerts from compliance officers; if abnormal situations have arisen, whether employees still continue to recruit and urge users to pay funds.

The existence of any single situation does not directly prove that the employee has committed a crime. However, if multiple abnormal facts persistently and repeatedly occur, and the employee continues to promote user transactions, these facts may collectively influence the judgment of their subjective awareness.

Conversely, if an employee has a relatively short tenure, receives only regular fixed pay, has not participated in income promises, transaction guidance, or fund handling, and indeed lacks a comprehensive understanding of the project's overall business model, stopping related work promptly upon discovering anomalies, raising objections, or voluntarily resigning, then these facts should be thoroughly examined in responsibility assessments. In a previous case we handled, we focused on the individual’s duration of employment, salary structure, job authority, scope of actual involvement, and response actions after discovering anomalies, and based on this, submitted a complete defense opinion, ultimately achieving a favorable result of non-prosecution.

Does not having decision-making power and just following the boss's arrangements ensure exemption from liability?

Joint crime in criminal law does not require everyone to participate in every step. In a project, the person in charge may design the business model, technicians may build the systems, operations and BD may acquire users, customer service may guide transactions, and finance may handle fund settlements. The actions performed by different roles may differ, yet can collectively drive the same business activity.

If operations, BD, or community members knowingly bear responsibility for user recruitment, transaction conversion, or fund assistance for the project’s core illegal business over a long period, they may be evaluated as participating in a joint crime. Not having decided the business model, merely executing partial tasks, or earning less than the project leader does not automatically exclude the establishment of a crime, but will influence their status and degree of responsibility within joint criminal behavior.

The criminal law stipulates that individuals playing secondary or assisting roles in joint crimes are regarded as accomplices, and accomplices should be given lighter, reduced, or exempted penalties according to the law. Therefore, even if an employee is recognized as participating in joint crime, one cannot evaluate ordinary executors the same way as project initiators, actual controllers, and core management personnel.

Typical cases of illegal currency-related conduct jointly published by the Supreme People's Procuratorate and the State Administration of Foreign Exchange also indicate that within the same business system, platform leaders, ordinary staff, virtual currency traders, and account providers may bear different responsibilities due to their specific roles, subjective awareness, and participation behaviors. The focus of reviewing related cases includes chat records, bank statements, transaction logs, wallet addresses, and the actual division of labor among personnel.

The important work of lawyers in such cases is to separate the overall business of the company from the individual behavior of employees, clarifying when the employee was hired, what authority they hold, what users and transactions they actually participated in, what profits they earned, whether they were aware of the true project model, and to what extent their behavior affected the project’s operational outcomes.

After the project is investigated, what evidence should employees prioritize preserving?

When project leaders become unreachable, company groups suddenly disband, or employees receive notifications from public security authorities, the least advisable action is to immediately delete chat records, exit all groups, or coordinate a unified explanation with colleagues. Such actions may lead to the destruction of evidence favorable to the employee and could also be interpreted as an attempt to evade investigation.

Employees should prioritize preserving labor contracts, job descriptions, wage records, performance rules, work instructions, and actual deliverables, while also retaining complete communication records with superiors, customers, and other departments. For wallets, backends, and funding accounts they had no authority to access, they need to clarify the boundaries between themselves and the relevant links through work authority records, approval processes, or internal communications.

If an employee has previously raised objections regarding project risks, refused to participate in personal account payments, requested the deletion of exaggerated promotional content, or proactively resigned upon discovering anomalies, such records particularly need to be promptly secured.

Conversely, if they did indeed participate in user deposits, fund collections, or transaction guidance, it is also inappropriate to generically explain this with "I'm just an ordinary employee," but rather to accurately detail the time of involvement, involved users, transaction amounts, specific operations, and the source of instructions. Whether an employee bears responsibility needs to be based on complete facts rather than relying on a job title to make a judgment.

Lawyer Observation

In Web3 projects, the risks of operations, BD, and community work often lie not in the job titles but in how those positions connect to business outcomes.

Simply writing general copy, organizing brand events, or maintaining ordinary communities will not automatically constitute the crime of illegal business operations. However, when an employee's work continuously drives domestic users to open accounts, purchase USDT, deposit funds, subscribe, or participate in unlicensed financial businesses, and their income is directly tied to user deposits or transaction volumes, the related risks can no longer be simply understood as "the company's business."

For employees, what truly needs preservation is not merely saying "I'm just working for a wage," but possessing complete evidence to prove their work scope, authority boundaries, pay structure, and subjective awareness. For the project side, it should also avoid packaging all customer recruitment and transaction conversion activities as "brand operations," but should reassess where the promotional content ultimately directs users and what functions employees perform in the customer, transaction, and funding chains.

Illegality of the project does not equal guilt of all employees; never touching the company wallet does not mean there is no risk. Criminal responsibility must ultimately be assigned to specific individuals, distinguishing who designs the business, who sets the direction, who promotes transactions, who controls funds, and who merely performs general work within a limited scope.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink