Regulation
What Are German eWpG Crypto Securities and How Are They Issued?
eWpG crypto securities explained: the §4 definition, issuance steps, the §16 register, and a straight answer on BaFin smart contract audit requirements.

Lukas Wipf
CPO & Co-Founder
last updated on


Lukas Wipf
CPO & Co-Founder
Share
Contact Us
ONINO provides infrastructure for digital & tokenized financing across the EU and Switzerland.
On this page
Key Takeaways
- A crypto security is an electronic security entered in a crypto securities register under Germany's Electronic Securities Act (eWpG, §4(3)); issuing one means appointing a BaFin-licensed registrar and registering the instrument, with no paper certificate at any stage. - Issuers need no eWpG licence: the licence sits with the crypto securities registrar (§1(1a) sentence 2 no. 8 KWG); an issuer that names no registrar is deemed the registrar itself. - No, BaFin does not require or certify smart contract audits: §16 eWpG prescribes register outcomes, and independent audits are market practice, not law. - The eWpG is technology-neutral; Ethereum and Polygon dominate real issuances (NRW.BANK's €100M Polygon bond, July 2025). - Since the Future Financing Act (December 2023) registered shares qualify as crypto securities; crypto fund units follow a separate route under the KryptoFAV (§ 95(5) KAGB), not the eWpG itself.
What Are eWpG Crypto Securities and How Are They Issued?
Reviewed by Lukas Wipf, CPO & Co-Founder at ONINO, 14.07.2026.
This article is for general information only and does not constitute legal advice.
A crypto security is an electronic security entered in a crypto securities register under Germany's Electronic Securities Act (eWpG, in force since June 2021). Under German civil law these count as full securities: the eWpG treats them as things (Sachen under § 90 BGB; eWpG § 2(3)) for property-law purposes, so ownership passes with legal certainty and no paper certificate exists at any point. A crypto security is not a cryptocurrency, and MiCA does not govern it. It is a regulated financial instrument in digital form. This guide walks through the legal definition, the issuance path, the register, and the compliance requirements for digital securities that follow from them.
What Is a Crypto Security Under §4 eWpG?
A crypto security is an electronic security that is entered in a crypto securities register, as defined in §4(3) of Germany's Electronic Securities Act (eWpG). The eWpG, enacted in 2021, recognises two forms of electronic security: central register securities entered in a central register under §12, and crypto securities entered in a crypto securities register under §16, the register type built for distributed ledger technology.
The statutory definition is short and precise (eWpG §4, gesetze-im-internet.de):
"A crypto security is an electronic security that is entered in a crypto securities register." (§ 4(3) eWpG)
What constitutes the security is the register entry, not a token and not a contract document. The two register types differ in operator, technology, and eligible instruments:
Central register security | Crypto security | |
|---|---|---|
Register type | Central register (§12 eWpG) | Crypto securities register (§16 eWpG) |
Register operator | Central securities depository or licensed custodian | Registrar designated by the issuer; BaFin-licensed financial service provider |
Typical technology | Centralised database | Distributed ledger technology (in practice Ethereum, Polygon, or permissioned chains) |
Typical instruments | Bearer bonds; bearer and registered shares (since the Future Financing Act) | Bearer bonds; registered shares as crypto shares (since the Future Financing Act 2023). Crypto fund units run via the KryptoFAV, not the eWpG. |
Governing provisions | §§ 12 to 15 eWpG | §§ 16 to 23 eWpG |
Can shares be crypto securities? Yes, since the Future Financing Act (in force December 2023): registered shares can be issued as crypto shares via a crypto securities register, while bearer shares remain limited to the central register (McDermott; PayTechLaw).
Fund units fall outside the scope of eWpG § 1. Crypto fund units are enabled instead by the KryptoFAV (Kryptofondsanteileverordnung, based on § 95(5) KAGB), which declares the eWpG rules correspondingly applicable. The February 2026 Location Promotion Act (StoFöG) touched the eWpG only lightly: it repealed § 20 and renumbered § 23, and it deliberately left fund units outside the eWpG itself. For the broader category behind these instruments, see our overview of asset tokenization for regulated securities.
How Do You Issue a Crypto Security Step by Step?
Issuing eWpG crypto securities takes six steps: structure the instrument, draft the terms of issue, appoint a licensed registrar, register the security, confirm the current notification and publication position, then distribute and settle. The issuer needs no eWpG-specific licence for the issuance itself, and no paper certificate is created at any stage.

Structure the instrument. A bearer bond or a registered share (since the Future Financing Act). Fund units sit outside the eWpG and run via the KryptoFAV route instead. Most German crypto securities to date are bonds, which is why digital bond issuance is the standard reference case.
Draft the terms of issue (§4(7) eWpG): the deposited content of the right for which the security is registered, including ancillary provisions. Every register entry must reference the deposited terms clearly and directly (§4(4) eWpG).
Appoint a licensed crypto securities registrar. Name none, and §16(2) eWpG deems the issuer itself the register-keeping entity, which pulls the licence requirement onto the issuer.
The registrar enters the security in the crypto securities register with the particulars required by § 17 eWpG (among others the issuer, holder, issue volume, nominal amount, and the essential content of the right).
Confirm the current notification and publication position. Until February 2026, issuers notified BaFin and published in the Bundesanzeiger (Federal Gazette) under § 20 eWpG, after which the crypto security appeared on BaFin's public list. The StoFöG repealed § 20 with effect from 10 February 2026, removing that formal step. As of July 2026, BaFin continues to maintain its public list of crypto securities, whose pages still cite the former § 20, so confirm current notification practice with your registrar. This is exactly why outdated guides mislead issuers: a step that was mandatory a year ago no longer exists.
Distribute and settle. Prospectus or securities information sheet (WIB) duties run separately under general securities law; the eWpG governs the form of the security, not the offer.
Platforms and banks typically run steps 1, 2, and 6 on issuance infrastructure such as an asset tokenization platform, while steps 3 to 5 sit with the licensed registrar.
Who May Operate the Crypto Securities Register (§16 eWpG)?
The issuer designates the register-keeping entity, and operating a crypto securities register is a financial service under §1(1a) sentence 2 no. 8 KWG that requires BaFin authorisation (BaFin Guidance Notice 03/2023). Name no registrar, and the issuer becomes the register-keeping entity by default and needs the licence itself. That trap is easy to miss.
Here is the statute itself (eWpG §16, gesetze-im-internet.de):
(1) A crypto securities register must be maintained on a tamper-proof recording system in which data are logged in chronological order and stored in a manner protected against unauthorised deletion and subsequent modification.
(2) The register-keeping entity is whoever is designated as such by the issuer vis-à-vis the holder. If no such designation is made, the issuer is deemed to be the register-keeping entity. The issuer may change the register-keeping entity without the consent of the holder or beneficiary, unless the terms of issue (or, in the case of shares, the articles of association of the stock corporation) provide otherwise.
Registrar licensing is a heavy lift: minimum regulatory capital of EUR 150,000, fit-and-proper directors, reliable shareholders, and a sound business organisation covering risk management, IT security, and compliance (FIN LAW). The application must include a business plan covering the first three full financial years (BaFin Guidance Notice 02/2022), and the BaFin procedure typically takes 6 to 12 months (FIN LAW estimate). The registrar's duties fall into four buckets, grounded in eWpG §§ 7, 17 and 18 and the eWpRV (BankingHub):
Provide and administer the technical infrastructure, meaning the tamper-proof recording system.
Document and maintain the register data, including the recording system's characteristics and cryptographic methods.
Manage transactions, including identity proof before transfer entries; the registrar is an obliged entity under the German Anti-Money Laundering Act.
Keep the terms of issue permanently accessible online, linked in the register, with numbered, time-stamped changes.
Do issuers need a BaFin licence to issue crypto securities? No. Issuing a crypto security is licence-free as such; the licence burden sits with the crypto securities registrar, and standard prospectus rules under general securities law continue to apply. That division of duties is precisely why banks and cooperative institutions increasingly position themselves on the registrar side of the market.
Do eWpG Crypto Securities Require Audited Smart Contracts?
No. Neither the eWpG, nor the eWpRV (the ordinance on requirements for electronic securities registers), nor BaFin's published guidance requires a smart contract to be audited or certified before a crypto security can be issued. What the eWpG regulates is the register: a tamper-proof recording system under §16(1) eWpG, registrar duties to keep the register complete, correct, and reflective of the legal situation under §7 eWpG, and a BaFin licence for the registrar under §1(1a) sentence 2 no. 8 KWG. BaFin examines the registrar's technical implementation during the licensing procedure (BaFin Guidance Notice 02/2022), and independent smart contract audits are standard market practice for meeting those integrity duties, not a statutory requirement.
The cleanest way to reason about eWpG smart contract requirements is the Three-Layer eWpG Compliance Model:
Layer 1: Statute. §16(1) eWpG defines outcomes, not technology: the recording system must be tamper-proof, log data chronologically, and protect entries against unauthorised deletion and subsequent modification. The eWpRV adds operational requirements such as identity proof before instructions and state-of-the-art cryptographic methods. No provision mentions an audit certificate.
Layer 2: Supervision. In the registrar licensing procedure, BaFin asks applicants to explain how the recording system is implemented technically and organisationally, alongside IT security, risk management, and compliance arrangements (Guidance Notice 02/2022). BaFin updated that Guidance Notice in February 2025, partly to reflect the transition of IT requirements toward the EU's Digital Operational Resilience Act (DORA). BaFin scrutinises the registrar's implementation once, at authorisation, and then supervises the registrar on an ongoing basis (§11 eWpG). It does not certify individual smart contracts per issuance.
Layer 3: Assurance. Registrars and issuers commission independent smart contract audits voluntarily, because the registrar answers for the integrity of the smart contracts functioning as the recording system, and §18(5) eWpG forces immediate reversal of unauthorised register changes in hack scenarios. That is market practice, not law.
What the law requires | What BaFin checks | What the market does | |
|---|---|---|---|
Legal basis | §16(1), §7 eWpG; eWpRV | §1(1a) sentence 2 no. 8 KWG; Guidance Notice 02/2022; §11 eWpG | None (risk management around §18(5) eWpG reversal duty) |
What is examined | Register outcomes: tamper-proof, chronological, protected against deletion and modification | The registrar's technical implementation of the recording system, IT security, risk and compliance organisation | Smart contract code quality and vulnerabilities |
Who is examined | The register operated by the registrar | The registrar, as licence applicant and supervised firm | The smart contracts of a specific issuance or platform |
When | Continuously, for as long as the register operates | At licensing, then through ongoing supervision | Before or around issuance, at the parties' initiative |
Is an audit certificate required? | No | No | No; commissioned voluntarily |
Which Blockchains Are BaFin-Compliant for eWpG Crypto Securities (Ethereum, Polygon)?
Any recording system that meets §16(1) eWpG qualifies: it must be tamper-proof, log data in chronological order, and protect entries against unauthorised deletion and subsequent modification. Neither the eWpG nor BaFin approves or whitelists specific blockchains; BaFin describes the crypto securities register concept as technology-neutral, with DLT-based systems as the primary focus but room left for other technologies (BaFin, Kryptowertpapierregisterführung overview).
In practice the market has converged on public EVM chains. In July 2025, NRW.BANK issued a €100M blockchain bond on Polygon, a public chain, registered under the eWpG via Cashlink's BaFin-regulated crypto securities registry, with Deutsche Bank, DZ BANK, and DekaBank as joint lead managers (CoinDesk, 10 July 2025). Permissioned and private chains work just as well under §16(1); the statute cares about outcomes, not architecture.
How many crypto securities have been issued in Germany? Germany reached its 100th crypto security issuance in July 2024, in the same week BaFin awarded DekaBank, the securities house serving Germany's savings banks, a full crypto securities registrar licence (Ledger Insights, 5 July 2024). 2024 saw 70 issuances (35 in each half-year), including Siemens' €300M digital bond, Berlin Hyp's €100M mortgage bond, and two KfW issuances totalling €150M; those figures exclude central-register digital bonds such as KfW's €8.5B issued via Clearstream's D7, which are not crypto securities (Ledger Insights, 3 February 2025). BaFin's public list of crypto securities (formerly kept under § 20(3) eWpG, repealed in 2026) remains the most complete public record in practice. Practical follow-up questions on chain choice and token standards are covered in ONINO's tokenization FAQ.
How Does ONINO Handle eWpG Crypto Securities Issuance?
ONINO provides issuance infrastructure for eWpG crypto securities: an asset tokenization platform built for regulated digital securities issuance in the EU, covering instrument structuring, token deployment, and the workflows that connect issuers with BaFin-supervised register operation (ONINO tokenization platform). The point is that platforms, banks, and private market operators can run German-law issuances without building the technical stack themselves.

For decision-makers, the takeaway from the Three-Layer eWpG Compliance Model is practical: choose a structure, secure a licensed registrar relationship early, and treat smart contract audits as risk management rather than a regulatory checkbox. If you are planning a German-law crypto security issuance and want to see eWpG-ready issuance and register infrastructure in practice, book a demo.
Frequently Asked Questions
Do issuers need a BaFin licence to issue eWpG crypto securities?
No. Issuing a crypto security is licence-free in itself. The BaFin licence requirement falls on the crypto securities registrar that keeps the register (§1(1a) sentence 2 no. 8 KWG), not on the issuer. If an issuer names no registrar, it is deemed the registrar and then needs the licence. Standard prospectus rules under general securities law still apply.
Can shares be issued as eWpG crypto securities?
Yes. Since the Future Financing Act (ZuFinG, in force December 2023), registered shares can be issued as crypto shares through a crypto securities register. Bearer shares remain limited to the central register for anti-money-laundering reasons. Bonds are still the most common German crypto security, but the crypto share is now a fully available instrument.
How many crypto securities have been issued in Germany?
Germany passed its 100th crypto security issuance in July 2024, the same week BaFin granted DekaBank a full registrar licence. 2024 recorded 70 issuances, including Siemens' €300M digital bond and Berlin Hyp's €100M mortgage bond. BaFin's public list of crypto securities (formerly kept under § 20(3) eWpG, repealed in 2026) remains the most complete public record in practice.
Can a cooperative bank (Volksbank) issue digital securities to its members?
Yes. A cooperative bank can issue eWpG crypto securities such as digital bonds, or act as a licensed crypto securities registrar for others. Cooperative member shares (Genossenschaftsanteile) are generally not securities, so they sit outside the eWpG; a cooperative bank reaches members through tokenized bonds or funds rather than tokenized membership shares.
Want to learn more how this can be applied to your business?
Read related Articles
eWpG crypto securities explained: the §4 definition, issuance steps, the §16 register, and a straight answer on BaFin smart contract audit requirements.



