In criminal cases tied to Web3 projects, investigators often begin with a practical question rather than a formal one: not what an employee’s title was, but where that employee directed users. In an article published by MarsBit, lawyer Gao Mengyang said operations staff, business development employees and community managers frequently ask the same question after a project is investigated for suspected illegal business activity: if the business model was set by management and they only handled promotion without touching company funds, why are they still being approached by police.
The article’s answer is neither that every operations role creates criminal exposure nor that avoiding direct contact with money guarantees safety. Whether an employee bears criminal liability depends on whether that person recognized the project was engaged in illegal or criminal activity, whether the person’s work advanced the core business, and what role the person played as users entered the project, completed transactions and paid funds.
Illegal business by a project does not mean every employee committed a crime
The article said that in February 2026, eight Chinese authorities led by the People’s Bank of China issued the Notice on Further Preventing and Handling Risks Related to Virtual Currency and Similar Activities. The notice made clear that virtual currency exchange, token issuance and financing, and services such as information intermediation and pricing for virtual currency trading conducted within China are illegal financial activities related to virtual currency. It also said internet companies may not provide commercial display, marketing or paid traffic services for such activities.
It also cited a July 23, 2026 notice from the Shenzhen Cyberspace Administration naming a batch of self-media accounts involved in virtual currency violations, including accounts such as 「USDT商家交流群」 and 「微支快换」. According to that notice, the accounts were permanently shut down by platforms for providing promotional information for virtual currency business to users in China and inducing the public to participate in illegal financial activity related to virtual currency.
Still, the article drew a distinction. A regulatory rule that classifies a line of business as illegal financial activity, or a platform decision to shut down an account for improper promotion, does not automatically mean every employee involved has committed the crime of illegal business operations.
It said the offense requires more than a violation of state rules. Authorities must also show that the person actually carried out a specific illegal business activity or another business act that seriously disrupted market order, and that the case reached the level of 「serious circumstances」. If an employee is to be treated as part of a joint crime, there must also be proof of shared criminal intent and proof that the employee took part in or helped carry out the offense through specific conduct.
The article added that the rule reflected in Guiding Case No. 97 of the Supreme People’s Court shows that an administrative violation cannot be directly equated with the crime of illegal business operations. Courts still need to review the social harm, criminal illegality and necessity of criminal punishment in the conduct at issue.
On that basis, the article said, whether a Web3 employee should bear criminal liability cannot be judged simply by whether the project was investigated or whether the person drew a salary. The review has to return to the business chain in which that employee actually took part.
Operations, BD and community growth roles can become part of the operating chain
Ordinary brand operations work usually covers content writing, event execution, media distribution and community maintenance. By itself, that does not directly amount to organizing user trading. But in some Web3 projects, the article said, there is no real separation between promotion, user solicitation, sign-up links, asset top-ups and trading conversion.
It gave several examples. Operations staff may repeatedly publish messages about 「principal-protected returns」, 「fixed returns」, 「low-price subscriptions」 or 「large-value exchange services」. After seeing that material, users may be directed into private groups, where community staff send trading links, wallet addresses or top-up instructions. BD staff may connect with KOLs, agent teams and community channels, then receive a share based on user registrations, deposit amounts or trading volume.
In that setup, front-end promotion is no longer just standalone brand work. It may become a necessary part of the project’s business activity. The article said investigators will usually trace the full user-conversion path: where the user first learned about the project, who built trust, who explained the product and returns, who sent the sign-up link, who instructed the user to buy USDT, complete KYC and deposit funds, who pressed the user when hesitation appeared, and who later received commissions based on the final transaction amount.
Whether an employee ever operated a company wallet is therefore not the only marker of legal risk. For a project that relies on community-led customer acquisition and private-domain conversion, the article said, consistently and precisely directing users in China into the trading process may itself provide substantial help to the project’s operations.
Four business lines can be used to assess employee risk
Gao wrote that whether operations, BD and community staff have moved from a general support role into the project’s core operating link can be examined across four dimensions: the content chain, the customer-acquisition chain, the trading chain and the funds chain.
The article stressed that this is not a mechanical checklist for finding a crime. Even if an employee performed one of the tasks in those chains, guilt cannot be inferred without looking at working time, scope of authority, subjective awareness and the project’s actual business model.
Even so, the article said the picture changes when high-risk conduct across the four lines keeps stacking up. If an employee can already see users moving from promotional content into community groups, on to account opening, then payment of funds and eventually a transaction, and if the employee’s own pay is directly tied to trading amounts, it becomes much harder to explain the conduct away by saying the role was limited to posting content.
Why 「I didn’t know the business was illegal」 may still be tested
The article said the central dispute in employee cases is usually not whether the person participated in the work, but whether the person knew the project carried illegal or criminal risk.
Authorities will not decide that issue based only on an employee saying 「I didn’t know」 or 「my boss never told me」, the article said. They will review the matter together with the employee’s authority, internal communications, user complaints, pay arrangements, regulatory warnings and later conduct.
It listed several examples: whether the company internally discussed that it could not target users in China but still required staff to attract new users through Chinese-language groups; whether terms such as 「top-up」, 「trading」 and 「returns」 were replaced with coded language; whether the project frequently changed domain names, community groups and receiving accounts; whether staff had received warnings involving platform bans, bank freezes, failed withdrawals by users or compliance alerts; and whether, after unusual events had already appeared in concentration, staff still continued to bring in new users and urge them to pay funds.

Any one of those facts on its own does not directly prove a crime, the article said. But if several abnormal facts appear over a long period and again and again, while the employee continues to push user transactions, those facts may jointly affect the assessment of subjective awareness.
By contrast, if an employee joined only recently, received only a normal fixed salary, did not take part in return promises, trading guidance or fund handling, genuinely lacked a full understanding of the project’s overall business model, and stopped the work, raised objections or resigned after discovering irregularities, those facts should be fully reviewed in any liability analysis.
The article added that in one prior case handled by the author’s team, they organized evidence around the party’s start date, compensation structure, job authority, actual scope of involvement and response after discovering abnormalities, then submitted a complete defense opinion and ultimately obtained a non-prosecution result.
Lack of decision-making power does not automatically remove liability
The article said joint crime under criminal law does not require every participant to handle every link. In one project, the person in charge may design the business model, technicians may build the system, operations and BD staff may bring in users, customer service may guide transactions and finance staff may settle funds. The acts differ by role, but they may still push forward the same operating activity.
If operations, BD or community personnel know that the project’s core business is illegal and still spend a long period steadily handling user solicitation, trading conversion or fund assistance, they may be included in a joint-crime analysis. Not deciding the business model, only carrying out part of the work, or earning less than the project’s controllers does not automatically rule out criminal liability, though it may affect the employee’s position and share of responsibility within the joint offense.
The article cited criminal law rules stating that participants who play a secondary or assisting role in a joint crime are accessories, and accessories should be given lighter punishment, reduced punishment or be exempted from punishment according to law. So even where an employee is found to have taken part in a joint crime, the article said ordinary executors cannot be evaluated in the same way as founders, actual controllers or core managers.
It also referred to representative cases on foreign-exchange related crimes jointly released by the Supreme People’s Procuratorate and the State Administration of Foreign Exchange. Those cases show that, within the same business system, platform heads, ordinary staff, virtual currency traders and account providers may bear different responsibilities because their division of work, subjective awareness and participation differ. The review in such cases focuses on chat logs, bank statements, transaction records, wallet addresses and the actual division of labor among the people involved.
In this type of case, the lawyer’s job, according to the article, is to separate the company’s overall business from the employee’s personal conduct: when the employee joined, what authority the employee had, which users and transactions the employee actually handled, what benefits the employee received, whether the employee understood the project’s real operating model, and how much effect the employee’s conduct had on the project’s end result.
What evidence employees should preserve first after a probe begins
The article warned that when a project leader disappears, a company group is suddenly dissolved or an employee receives notice from police, the least advisable response is to immediately delete chat records, leave every group or coordinate a unified story with colleagues. Those moves may destroy evidence that could help the employee and may also be interpreted as an attempt to evade the investigation.
Employees should first preserve labor contracts, job descriptions, payroll records, performance rules, work instructions and actual deliverables, while also keeping complete communication records with supervisors, clients and other departments. For wallets, back-end systems and fund accounts they were not authorized to access, they should use records of work authority, approval procedures or internal communications to show the boundary between themselves and those links.
If the employee previously raised objections to project risks, refused to receive funds through a personal account, asked for exaggerated return claims to be deleted, or resigned after discovering irregularities, the article said those records are especially important to secure in time.
On the other hand, if the employee did take part in user top-ups, fund collection or trading guidance, the article said it is not helpful to rely on a broad statement such as 「I was just an ordinary employee」. The person should instead sort out the time period, users involved, transaction amounts, specific operations and source of instructions with precision. Whether an employee bears liability has to rest on a complete factual record, not a job title alone.
Lawyer’s observation
The article closed by saying the risk for operations, BD and community work in Web3 projects does not lie in the job title itself. It lies in how the role is connected to the business result.
Simply writing ordinary copy, organizing brand events or maintaining a general community does not automatically amount to the crime of illegal business operations. But if an employee’s work continuously pushes users in China to open accounts, buy USDT, deposit funds, subscribe to products or participate in unlicensed financial business, and if that employee’s income is directly linked to user deposits or trading volume, the risk can no longer be treated as merely 「the company’s issue」.
For employees, the article said, what matters is not a slogan such as 「I’m just working here」, but a full body of evidence showing the scope of work, authority boundaries, compensation structure and subjective awareness. For project operators, the article said they also cannot package all user solicitation and trading conversion as 「brand operations」. They need to reexamine where promotional content ultimately directs users and what function employees actually perform across the customer, trading and funds chains.
A project’s illegality does not mean every employee is guilty, the article concluded. But never touching a company wallet does not mean there is no risk either. Criminal liability ultimately has to be assigned to specific individuals by distinguishing who designed the business, who set the direction, who pushed the transactions, who controlled the funds and who only completed general work within a limited scope.

