Web3 Ops and BDs Investigated: Why 'Just Promotion' Isn't a Shield Against Criminal Liability

Key Takeaways

Web3 employees face criminal risk if their promotion, BD, or community roles directly drive illegal transactions. Liability depends on subjective awareness, involvement in conversion chains, and evidence preservation, not just job titles or lack of wallet

Woofun AI reports that in criminal investigations involving Web3 projects, the determination of guilt for operators, business development (BD) staff, and community managers is not based on job titles but on their functional role in driving illegal business operations, as analyzed by Gao Mengyang. The core legal inquiry shifts from an employee’s formal position to the specific user pathways they facilitated, meaning that even without direct access to company wallets or pricing authority, individuals can be held liable if their promotional content, community management, or referral activities directly contributed to the project’s illicit financial flows.

This reality challenges the common defense among staff who claim they were merely responsible for promotion and never handled funds, highlighting that criminal liability is contingent upon subjective awareness of the project’s illegality, the extent of their contribution to core operational mechanisms, and their specific involvement in user onboarding, transaction completion, and payment processing.

The regulatory framework defining these risks was solidified in February 2026, when the People’s Bank of China (PBOC) and seven other departments issued the "Notice on Further Preventing and Addressing Risks Related to Virtual Currencies." This notice explicitly categorizes virtual currency exchange, token issuance and financing, and the provision of information intermediation or pricing services for virtual currency transactions within China as illegal financial activities.

Furthermore, Internet companies are strictly prohibited from offering commercial displays, marketing promotions, or paid traffic referral services for such activities. Enforcement of these rules was demonstrated on July 23, 2026, when the Shenzhen Internet Information Office listed several illegal self-media accounts, including "USDT Merchant Exchange Group" and "Weizhikuaihuan", which were permanently closed for providing marketing information and inducing public participation in illegal virtual currency services.

However, it is crucial to distinguish between administrative violations and criminal liability; merely engaging in activities classified as illegal under regulatory rules or having an account banned does not automatically constitute the crime of illegal business operations. According to Guiding Case No. 97 of the Supreme People’s Court, administrative violations cannot be directly equated with criminal offenses. To establish the crime of illegal business operations, authorities must prove that the perpetrator’s actions violated national regulations and reached a "serious" level of market disruption.

If an employee is considered part of a joint crime, they must also demonstrate shared criminal intent and specific participation or assistance in the illegal acts. Therefore, determining whether a Web3 employee bears criminal liability requires examining the actual business processes they personally engaged in, rather than solely relying on the project’s overall legal status or the employee’s receipt of a salary.

The boundary between legitimate brand operations and criminal participation often blurs in Web3 projects where promotion, user recruitment, and transaction conversion are integrated. Typically, brand operations involve content writing, event execution, media dissemination, and community management, which do not inherently equate to organizing user transactions.

However, in many illicit Web3 schemes, there is no functional separation between these roles. Operators may continuously publish promotional content featuring "guaranteed returns," "fixed returns," "low-price subscriptions," or "large-scale commitments." Upon seeing this content, users are directed to private groups where community members provide transaction links, wallet addresses, or deposit tutorials. BDs connect with KOLs, agency teams, and community channels, receiving commissions based on user registrations, deposit amounts, or transaction volumes. In this model, front-end promotion becomes an essential component of the project’s operational activities rather than independent brand work.

Authorities examine the user conversion path meticulously: identifying where users learned of the project, who built trust, who explained profit models, who sent registration links, who guided USDT purchases and KYC completions, and who received commissions based on final transaction amounts. For projects relying on community-driven customer acquisition and private-domain conversions, continuously introducing domestic users into the transaction process provides substantial support to the project’s operations, making the distinction between "just promotion" and "criminal facilitation" increasingly narrow.

To assess whether employees have transitioned from general support roles to core operational participants, risk evaluation is conducted across four business chains: the content chain, the customer acquisition chain, the transaction chain, and the capital chain. This framework is not a mechanical standard for determining guilt; even if an employee performed tasks within one of these chains, a guilty verdict cannot be reached solely based on working hours, scope of authority, subjective awareness, or the actual project model.

However, when high-risk behaviors accumulate across these chains over time, and an employee observes users progressing from promotional content to joining communities, opening accounts, making payments, and completing transactions, with their earnings directly tied to transaction volumes, it becomes difficult to justify their actions as merely "posting content." The integration of these chains means that an employee’s role in guiding users through each stage—from initial awareness to final payment—can be interpreted as active participation in the illegal business operation, regardless of whether they directly handled the funds.

Subjective awareness is a critical factor in determining criminal liability, particularly when employees claim ignorance of the project’s illegal nature. Authorities do not rely solely on an employee’s assertion that "I didn’t know" or "The boss didn’t tell me." Instead, they conduct a comprehensive review based on job responsibilities, internal communications, customer complaints, compensation structures, regulatory warnings, and subsequent actions.

Key indicators include whether the company explicitly discussed avoiding domestic users yet required recruitment through Chinese-language communities, whether terms like "deposit," "transaction," and "profit" were replaced with code words, whether the project frequently changed domain names, communities, and payment accounts, and whether employees received warnings about platform bans, bank freezes, or compliance officer alerts.

If multiple abnormal facts occur repeatedly over time and the employee continues to push users to transact, these facts collectively influence the assessment of their subjective awareness. Conversely, if an employee has a short tenure, receives a fixed salary, lacks involvement in profit promises or transaction guidance, and stops working or resigns voluntarily upon noticing abnormalities, these factors are thoroughly considered in determining liability.

In one case, evidence organized around the party’s length of service, compensation structure, job responsibilities, and actions after detecting abnormalities led to a favorable outcome of no prosecution.

The dynamics of joint crime further complicate liability assessments, as criminal law does not require every participant to engage in all stages of the illegal activity. In a Web3 project, the person in charge may design the business model, technical staff may build the system, operators and BDs may acquire users, customer service staff may guide transactions, and finance staff may handle settlements. Although their actions vary, they may collectively drive the same illegal business activity.

If operators, BDs, or community staff are aware that the project’s core operations are illegal but still consistently recruit users, convert transactions, or assist with funds, they may be considered part of a joint crime. Not having decision-making power, performing only limited tasks, or earning less than the project leader does not necessarily exempt an employee from liability, but it affects their status and degree of responsibility. Criminal law stipulates that those playing secondary or auxiliary roles are accomplices, who should receive lighter or reduced penalties or be exempted from punishment.

Typical cases of foreign exchange-related illegal crimes jointly released by the Supreme People’s Procuratorate and SAFE illustrate that platform owners, ordinary staff, virtual currency traders, and account providers within the same business system bear different responsibilities based on their specific roles, subjective awareness, and participation behaviors. Key evidence in reviewing such cases includes chat records, bank statements, transaction records, wallet addresses, and the actual division of labor among personnel.

When a project is investigated, employees must prioritize preserving evidence to protect their legal interests. The least advisable actions are deleting chat records, exiting groups, or coordinating unified statements with colleagues, as these may result in the loss of favorable evidence and be interpreted as attempts to evade investigation. Employees should preserve labor contracts, job descriptions, salary records, performance rules, work instructions, and actual deliverables, along with complete records of communications with superiors, clients, and other departments. For wallets, backends, and funding accounts they are not authorized to access, they should use work permission records, approval processes, or internal communications to clarify the boundaries of their involvement.

If an employee previously raised objections to project risks, refused to accept payments into personal accounts, requested the removal of exaggerated profit promotions, or resigned voluntarily due to noticing abnormalities, such records must be preserved promptly. Conversely, if an employee participated in user deposits, fund collection, or transaction guidance, they should accurately outline the timing of their involvement, the users involved, transaction amounts, specific operations, and the source of instructions, rather than simply claiming to be an "ordinary employee."

Woofun AI data shows that the risk for Web3 employees lies not in their job titles but in the connection between their positions and the business outcomes. Simply writing general copy, organizing brand events, or maintaining ordinary communities does not automatically constitute the crime of illegal business operations.

However, when an employee’s work continuously drives domestic users to open accounts, purchase USDT, make deposits, subscribe, or participate in unauthorized financial activities, and their income is directly linked to users’ deposits or transaction volumes, the related risks can no longer be dismissed as "the company’s problem." For employees, what truly needs to be preserved is complete evidence proving their scope of work, boundaries of authority, compensation structure, and subjective awareness. For project owners, they cannot label all customer acquisition and transaction conversion activities as "brand operations" but must re-examine where promotional content leads users and what role employees play in the customer, transaction, and capital chains.

The distinction between operational risk and general tasks is critical in legal defenses. General copywriting, brand events, and ordinary community maintenance do not inherently constitute criminal acts.

However, when an employee’s work directly facilitates unauthorized financial activities, such as guiding users through the entire transaction process, the nature of their role changes. The scope of work, boundaries of authority, compensation structure, and subjective awareness become the primary factors in determining liability. Brand operations that evolve into customer acquisition and transaction conversion mechanisms are viewed differently by authorities. If an employee’s actions are integral to the project’s illegal business model, they cannot claim immunity based on their title alone. The legal system examines the actual impact of their work on the project’s operations, focusing on whether they contributed to the illegal financial activities in a meaningful way.

In conclusion, individual accountability in Web3 crimes is determined by the specific actions and awareness of each employee, not by their job titles or lack of direct fund handling. Project owners who design the business model, decide the direction, drive transactions, and control funds bear the primary responsibility.

However, employees who actively participate in customer acquisition, transaction conversion, and fund facilitation, with full awareness of the project’s illegal nature, also face criminal liability. Those who only perform general tasks within a limited scope, without contributing to the core illegal operations, may be exempted or receive reduced penalties. The key to determining liability lies in distinguishing who designed the business, who decided the direction, who drove transactions, who controlled funds, and who merely performed general tasks. This nuanced approach ensures that criminal liability is assigned fairly, based on actual involvement and subjective awareness, rather than on broad assumptions about job roles.

Comments

Me
Replying to @User
0/800

No comments yet.

Notifications

Sign in to view messages
View all messagesManage subscriptions