In Web3 criminal cases, investigators often start with a practical question rather than a formal one: not what your title was, but where you directed users.

TechFlowPost published an article by Gao Mengyang saying an employee may never have touched a company wallet or set token prices, yet still face scrutiny if the job involved publishing promotional material, running user communities, referring interested users to customer service, explaining return structures, sending registration links, or walking users through buying USDT and making deposits. The same applies to BD staff who were paid commissions based on new registrations, deposit amounts, or trading turnover.
The article says this is why employees frequently ask a similar question after a project is investigated for suspected illegal business operations: if the business model was decided by the boss, and the employee only handled promotion without touching company funds, why would public security authorities still come looking.
Its answer is not that everyone who worked in operations is liable, and not that anyone who did not handle money is automatically safe. The legal question, it says, is whether the employee recognized that the project was engaged in illegal or criminal activity, whether the employee’s work pushed the core business forward, and what role that person actually played in bringing users into the project, completing trades, and making payments.
Illegal business activity does not automatically make every employee criminally liable
The article points to a February 2026 notice jointly issued by eight Chinese authorities including the People’s Bank of China, titled the Notice on Further Preventing and Handling Risks Related to Virtual Currencies. The notice states that virtual currency exchange, token issuance and financing, and information intermediation and pricing services for virtual currency trading conducted within China are illegal financial activities related to virtual currencies. It also says internet companies may not provide commercial display, marketing, promotional services, or paid traffic redirection for such activities.
It also cites a July 23, 2026 notice from the Shenzhen Cyberspace Administration that named a batch of virtual-currency-related self-media accounts, including “USDT Merchant Exchange Group” and “Weizhi Kuaidui.” According to that notice, the accounts were permanently shut down by the platform for providing marketing and promotional information for virtual currency business to domestic users and inducing the public to participate in illegal financial activities involving virtual currencies.
Still, the article draws a line between regulatory violations and criminal liability. A business model may be classified as an illegal financial activity, and an account may be shut down for improper promotion, but that does not mean every employee involved automatically commits the crime of illegal business operations.
It says the offense requires more than a violation of state rules. Authorities must also establish that the person actually carried out a specific illegal business activity or another business act that seriously disrupted market order, and that the case reached the threshold of “serious circumstances.” If an employee is to be assessed as part of a joint crime, there must also be proof of shared criminal intent and proof that the person participated in or helped carry out the offense through specific conduct.
The article adds that the adjudicative rule reflected in Supreme People’s Court Guiding Case No. 97 shows that an administrative violation cannot be directly equated with the crime of illegal business operations. Courts still need to examine the social harm, the criminal unlawfulness, and the necessity of criminal punishment in the conduct at issue.
For that reason, the article says, criminal liability for a Web3 employee cannot be decided only by whether a project was investigated or whether the employee received wages from the company. The analysis has to return to the employee’s actual place in the business chain.
Operations, BD and community growth work can become part of the business chain
The article says ordinary brand operations work usually covers copywriting, event execution, media distribution and community maintenance. That does not, by itself, amount to organizing user trading. In some Web3 projects, however, there is no real separation between promotion, user solicitation, registration links, asset deposits and transaction conversion.
It describes a common pattern. Operations staff repeatedly publish messages about “principal protection,” “fixed returns,” “low-price subscription,” or “large exchange settlements.” Users who see that material are guided into private groups, where community staff send trading links, wallet addresses or deposit tutorials. BD personnel then connect with KOLs, agent teams and community channels, and receive a share based on registrations, inbound funds or trading volume.
Under that structure, front-end promotion is no longer just a brand function. It can become a necessary part of the project’s operating activity. The article says investigators often reconstruct the user conversion path step by step: where users first heard about the project, who built trust, who explained the product and returns, who sent the registration link, who instructed users to buy USDT, complete KYC and deposit funds, who urged hesitant users to proceed, and who later collected commissions tied to the final transaction amount.
That is why, in the article’s view, whether an employee ever operated a company wallet is not the only measure of risk. For a project that depends on community acquisition and private-domain conversion, repeatedly and accurately steering domestic users into trading can itself amount to substantial assistance to the business.
Four business chains can be used to reconstruct an employee’s position
The article proposes four dimensions for assessing whether operations, BD and community staff moved from a general support role into the project’s core operating process: the content chain, the customer acquisition chain, the trading chain and the funds chain.
It cautions that this is not a mechanical checklist for conviction. Even if an employee handled one of those tasks, that fact alone cannot support a guilty conclusion without considering the person’s time on the job, the scope of authority, the employee’s subjective awareness and the project’s actual operating model.
But when high-risk conduct across those four chains keeps stacking up, the picture changes. If an employee can already see users move from promotional content into private groups, complete account opening, pay funds and finish trades, and if that employee’s own compensation is directly tied to transaction amounts, then the claim that the person “only posted content” becomes much harder to sustain.
Why “I didn’t know the business was illegal” may still not end the inquiry
The article says the central dispute in employee cases is usually not whether the person did the work, but whether the person knew the project carried legal and criminal risk.
It says investigators will not rely on a simple statement such as “I didn’t know” or “the boss never told me.” Instead, they review job authority, internal communications, user complaints, the pay model, regulatory warnings and what the employee did after problems surfaced.
The article lists several facts that may be examined: whether the company had internally discussed that it could not target users in mainland China but still required staff to bring in new users through Chinese-language communities; whether words such as “deposit,” “trade” and “returns” were replaced with coded language; whether the project kept changing domains, communities and receiving accounts; whether the employee had seen platform bans, bank freezes, user complaints about failed withdrawals, or risk warnings from compliance personnel; and whether the employee continued attracting users and pushing them to pay after those abnormal signs had already become concentrated.
It stresses that any one of those facts alone does not directly prove a crime. But if multiple warning signs appeared over a long period and repeatedly, while the employee kept driving user transactions, those facts together may shape the assessment of subjective awareness.
The article gives the opposite scenario as well. If an employee joined only briefly, received only normal fixed pay, did not participate in return promises, trade guidance or fund handling, genuinely lacked a full understanding of the overall business model, and stopped the work, objected or resigned after noticing irregularities, those facts should all be fully examined in assigning responsibility.
It adds that in one case previously handled by the author’s side, the defense focused on the employee’s start date, compensation structure, job authority, actual scope of participation and response after discovering abnormalities. After sorting the evidence and submitting a full defense opinion, the case ended with a non-prosecution result.
Lack of decision-making power does not automatically exempt staff
The article says joint crime under criminal law does not require each person to participate in every link. In a single project, the person in charge may design the business model, technical staff may build the system, operations and BD may bring in users, customer service may guide transactions, and finance may handle settlement. The acts differ by position, but they may still push the same business activity forward together.
If operations, BD or community personnel knew that the project’s core business was illegal and still took on user solicitation, transaction conversion or fund assistance over a long period in a stable way, they may be treated as participants in a joint crime. Not deciding the business model, handling only part of the work, or earning less than the project leader does not by itself rule out criminal responsibility, though those factors can affect the person’s status and degree of liability within the joint offense.
The article also notes that Chinese criminal law treats those who play a secondary or assisting role in joint crime as accessories, and says accessories should be given lighter punishment, mitigated punishment, or exempted from punishment according to law. Even when an employee is found to have joined a joint crime, the article says, ordinary executing staff should not be evaluated in the same way as project founders, actual controllers and core managers.
It further cites typical foreign-exchange crime cases jointly issued by the Supreme People’s Procuratorate and the State Administration of Foreign Exchange. Those cases, the article says, show that platform heads, ordinary workers, virtual currency traders and account providers within the same business system may bear different responsibilities depending on their division of labor, subjective awareness and actual conduct. The key evidence in such cases includes chat records, bank flows, transaction records, wallet addresses and the real allocation of work among the people involved.
One major task for lawyers in these cases, according to the article, is to separate the company’s overall business from the individual employee’s conduct: when the employee joined, what authority the employee had, which users and trades the employee actually participated in, what benefits were obtained, whether the employee understood the project’s real operating model, and how much impact the conduct had on the project’s business results.
What evidence employees should preserve first after a project is investigated
The article warns against several immediate reactions when a project leader disappears, a company group is abruptly dissolved, or an employee receives a notice from public security authorities. It says staff should not rush to delete chat histories, exit all groups, or coordinate a unified story with colleagues. Those actions may destroy evidence that could help the employee and may also be viewed as an attempt to evade investigation.
Instead, employees should first preserve employment contracts, job descriptions, wage records, performance rules, work instructions and actual deliverables, while also retaining complete communication records with supervisors, clients and other departments. For wallets, back-end systems and fund accounts they had no authority to access, they should use permission logs, approval procedures or internal communications to show the boundary between themselves and those parts of the business.
If an employee raised objections to project risks, refused to collect funds through a personal account, requested deletion of promotional content that exaggerated returns, or voluntarily resigned after finding abnormalities, those records should be fixed and preserved in time, the article says.
On the other hand, if the employee did in fact participate in user deposits, fund collection or transaction guidance, the article says it is not enough to respond with a broad claim of being “just an ordinary worker.” The person should sort out the period of involvement, the users involved, the transaction amounts, the specific actions taken and the source of the instructions. Liability, it says, must be assessed on a complete factual record, not by a job title alone.
The risk lies less in the title than in the connection to the business result
The article closes by saying that in Web3 projects, the risk for operations, BD and community work often lies not in the name of the position but in how that position connects to the final business outcome.
Writing ordinary promotional copy, organizing brand events or maintaining a general community does not automatically amount to the crime of illegal business operations. But once an employee’s work continuously pushes domestic users to open accounts, buy USDT, deposit funds, subscribe to offerings or participate in unlicensed financial business, and the employee’s income is directly tied to user deposits or trading volume, the risk can no longer be dismissed as merely “the company’s problem.”
For employees, the article says, what matters is not a one-line defense that “I was only working for someone else,” but a full evidentiary record showing the scope of work, the limits of authority, the compensation structure and the employee’s subjective awareness. For project operators, it says, customer solicitation and transaction conversion cannot simply be wrapped in the label of “brand operations.” They need to reexamine where promotional content ultimately sends users, and what function employees actually perform in the customer, transaction and fund chains.
The article ends on a narrow but clear point: a project’s illegality does not mean all employees are guilty, and not touching a company wallet does not guarantee safety. Criminal responsibility must ultimately be pinned to specific individuals by distinguishing who designed the business, who set its direction, who drove transactions, who controlled funds, and who only carried out general work within a limited scope.
The piece was credited to Gao Mengyang and identified “Mankun Blockchain Legal Services” as the source behind the legal analysis.

