Blokchain Basics
•
13
min read

Malaysia Digital Asset Rules: Guide

Malaysia digital-asset rules: regulator licensing for exchanges, IEOs and custody; RM5M capital, RM500M custody threshold, 7-year records.

If you want to run a crypto platform in Malaysia, SC approval comes first. Malaysia treats many digital tokens and digital currencies as securities, so exchanges, token-sale platforms, and custody providers can fall under strict capital-markets rules.

Here’s the short version:

  • I see three main regulated activities: trading, token sales, and custody
  • A digital asset exchange must register as a Recognized Market Operator
  • An IEO platform needs separate approval for token fundraising
  • A custody provider needs its own registration if it holds client assets or private keys
  • Many exchange and IEO operators need at least MYR 5,000,000 in paid-up capital
  • A token issuer can’t just sell to the public on its own; it must go through an approved IEO platform
  • If assets under custody go above MYR 500 million, extra custody rules apply
  • Records for some activities must be kept for 7 years
  • Malaysia has taken action against offshore platforms that target local users, including Bybit in November 2024

What this means for you is simple: the rule depends on what the platform actually does. Listing tokens, holding customer assets, and running fundraising each trigger a different set of duties. And if a platform also touches payments or FX, Bank Negara Malaysia may matter too.

Malaysia Digital Asset Platform Types: Licensing & Compliance at a Glance

Malaysia Digital Asset Platform Types: Licensing & Compliance at a Glance

Quick Comparison

Activity Who regulates it Main approval needed Key point
Digital asset trading Securities Commission Malaysia RMO registration for DAX For secondary-market trading
Token fundraising Securities Commission Malaysia IEO platform approval Issuers must use an approved platform
Client asset custody Securities Commission Malaysia Custody registration Covers safekeeping and key control

So before launching anything in Malaysia, I’d boil it down to one question: Are you trading, issuing, or holding digital assets for others? The answer tells you which rulebook applies and where the legal risk starts.

How Malaysia Classifies and Regulates Digital Assets

The Securities Commission Malaysia and Its Core Rulebooks

The Securities Commission Malaysia (SC) oversees regulated digital-asset activity under the CMSA. The CMSA provides the legal base. The Guidelines on Recognized Markets cover DAXs, while the Guidelines on Digital Assets cover IEOs and custodians.

How Digital Currencies and Digital Tokens Are Classified

The Capital Markets and Services (Prescription of Securities) (Digital Currency and Digital Token) Order 2019 took effect on January 15, 2019. It brings qualifying digital currencies and digital tokens into Malaysia's securities framework.

In plain terms, the classification test looks at whether a token works like an investment contract. That usually means investors pool contributions and expect returns from a promoter's efforts. If an asset meets that test and is treated as a digital asset that is also a security, securities law applies. There is one carve-out: recognized-market trading does not require a prospectus in the usual way.

Which Platform Activities Require Authorization

Three platform activities require SC authorization, and each sits in its own regulatory lane.

Activity Regulatory Category Governing Rulebook
Operating a trading platform for digital assets Digital Asset Exchange (DAX) / Recognized Market Operator (RMO) Guidelines on Recognized Markets
Hosting token fundraising campaigns Initial Exchange Offering (IEO) platform operator Guidelines on Digital Assets
Holding client digital assets and managing private keys Digital asset custodian Guidelines on Digital Assets

This split matters because the rules are not one-size-fits-all. A platform that lists tokens has one set of duties. A custodian that holds client assets and controls private keys has another. And a platform running token fundraising has its own lane to follow.

Run any of these services without SC approval, and the risk is serious. The SC can pursue administrative, civil, and criminal action. That can also reach overseas platforms that target Malaysian investors. If a full-service platform handles trading, fundraising, and custody, it must comply with both frameworks at the same time.

Those classifications shape the listing, custody, disclosure, and market-conduct rules that come next.

Licensing Rules for Exchanges and Token Platforms

Malaysia splits licensing into separate tracks for exchanges and token fundraising. In plain English, a platform that lets people trade digital assets is not licensed the same way as a platform that helps issuers sell tokens.

Digital Asset Exchanges as Recognized Market Operators

A Digital Asset Exchange in Malaysia is a regulated platform for trading digital assets. To operate legally, a DAX must register as a Recognized Market Operator (RMO) under Section 34 of the CMSA and the Guidelines on Recognized Markets, with Chapter 15 setting out the rules for DAX operators.

That RMO status comes with clear entry conditions. Each DAX applicant must be incorporated in Malaysia and have at least RM5,000,000 in paid-up share capital. If the platform runs under a Digital Broker model, it must also keep RM5,000,000 in shareholders' funds at all times.

Who Can Apply and What the SC Reviews

Only Malaysian-incorporated entities can apply. If a platform is based overseas, it cannot apply directly. It must first set up a Malaysian entity and go through the SC registration process.

The SC looks well beyond basic incorporation and capital figures. It checks ownership transparency, and it reviews the backgrounds of directors, senior management, and major owners. It also applies fit-and-proper tests tied to competency, integrity, and clean regulatory and criminal records. On top of that, the business plan must show a clear value proposition for Malaysia's capital market. Simply copying an existing setup is not enough.

The SC also looks at whether the platform is ready to operate in practice, not just on paper. That includes tested trading systems, disaster recovery planning, cybersecurity controls, and written KYC/AML procedures.

Token Offerings and Initial Exchange Offering Rules

Token fundraising follows a different rulebook under the Guidelines on Digital Assets. An issuer cannot sell tokens straight to the public. It must use a registered IEO platform operator, and that operator is responsible for reviewing and approving the offering.

IEO operators must also be incorporated in Malaysia and maintain minimum paid-up capital of RM5,000,000. For issuers, the bar is also clear: they must be locally incorporated, run their main business operations in Malaysia, and raise funds only through an approved IEO platform.

Before launch, the issuer must prepare a whitepaper. That document needs to cover the business model, token rights, risk factors, use of proceeds, and the project roadmap. The IEO operator reviews and approves it before the offering can go live. There is also a firm fundraising cap: an issuer may not raise more than RM100,000,000 during any continuous 12-month period.

Scope Limits and Activities Outside the License

The easiest way to see the split is side by side.

Platform Type Regulatory Instrument Key Licensing Requirement Min. Capital/Financial Conditions Main Operational Scope
DAX Operator (Exchange Model) Guidelines on Recognized Markets (Chapter 15) RMO registration under CMSA Section 34 RM5,000,000 paid-up share capital Secondary market trading of digital assets
DAX Operator (Digital Broker Model) Guidelines on Recognized Markets (Chapter 15) RMO registration + additional financial condition RM5,000,000 paid-up capital + RM5,000,000 shareholders' funds Brokerage of digital assets on behalf of clients
IEO Platform Operator Guidelines on Digital Assets RMO registration for IEO operations RM5,000,000 paid-up share capital Primary token fundraising; issuer due diligence
Digital Asset Custody Provider Guidelines on Digital Assets Separate registration under the relevant guidelines Not stated here Safekeeping of client digital assets; key management

The big point here is that approval is tied to the exact activity. A registered DAX cannot run an IEO just because it already has exchange approval, and a DAX or IEO operator cannot offer custody unless it also has separate registration for custody services.

That line matters. Operating a DAX without RMO registration is an offense under Section 7(1) of the CMSA, and the SC has taken action against unregistered platforms.

Once a platform is licensed, the work doesn't stop there. It still has to meet separate duties tied to listing, custody, and market conduct.

Token Listings, Custody, and Market Conduct Duties

After approval, platforms still have a lot to manage. Listings, custody, and market conduct all sit at the center of that job.

Listing Standards and Token Review

Under Malaysia's SC framework, a token listing is not just a product decision. It's a risk and disclosure review.

Each listing must have a written due-diligence record. That record needs to cover the project, token rights, legal status, disclosure quality, technology risk, liquidity, and the reasons the token was approved or rejected. Thin liquidity is a red flag because it can increase manipulation risk and disrupt orderly trading.

Disclosure standards are strict too. Information must be complete and written in plain language that an ordinary user can understand without legal or technical knowledge. In practice, that puts real weight on the exchange's own review process.

Client Asset Segregation and Custody Controls

Malaysian rules require licensed platforms to keep client assets separate from the platform's own assets. They also must maintain enough custody controls and safeguards. For digital asset exchanges, that means separate wallets, daily reconciliation, and controls against loss, theft, hacking, and unauthorized use.

Private key management gets even closer attention. The SC's materials point to strict expectations around secure storage, role-based access controls, transaction authorization procedures, and annual independent third-party assessments of custody arrangements. If there's a breach, an operational incident, or a custody change, an immediate review is expected.

There's also a threshold rule that matters. If the aggregate value of digital assets under custody goes above RM500 million, the DAX operator must appoint an independent, SC-registered custodian to administer those assets.

These rules shape how client assets must be handled day to day.

Requirement Category Applicable Platforms Source Rule/Guideline Key Operational Duty
Client asset segregation DAX operators and digital asset custodians Guidelines on Recognized Markets; Guidelines on Digital Assets Segregate client assets from platform assets and prevent commingling or misuse.
Trust account handling DAX operators Guidelines on Recognized Markets Hold investor fiat monies in trust accounts at a licensed Malaysian financial institution.
Secure digital asset storage DAX operators and custodians Guidelines on Recognized Markets; Guidelines on Digital Assets Use secure storage with controls against theft, loss, and hacking.
Private key and wallet controls DAX operators and custodians Guidelines on Digital Assets Document key access approvals; separate duties for wallet administration and approvals.
Independent custody assessment DAX operators (above RM500M threshold) Guidelines on Digital Assets Appoint an SC-registered independent custodian; conduct annual third-party reviews.

Market Abuse, Conflicts, and Fair Trading Rules

Licensed platforms must actively support orderly trading and avoid misleading, manipulative, or unfair market practices under SC oversight. That includes controls against market manipulation, insider dealing where it applies, and unmanaged conflicts of interest. It also includes clear order-handling rules and transparent platform procedures.

This can't live only on paper. Surveillance, escalation procedures, and disciplinary processes should be built into daily operations so suspicious activity is spotted and escalated fast.

Conflicts of interest need the same level of care. If a platform has a commercial stake in a listed asset, runs affiliated market-making activity, or has related-party arrangements, those conflicts must be identified, disclosed, and managed through written policies. Related-party interests must be disclosed, recused, and governed by written policy.

Platforms should also have documented triggers for trading halts, circuit breakers, or price limits when volatility turns disorderly.

Disclosures Users Should Receive from Licensed Platforms

Before trading, users should be able to see the basics clearly:

  • Fees
  • Order-matching rules
  • Asset restrictions
  • Withdrawal terms
  • Complaint channels

These points should be disclosed up front. And if the platform's custody or settlement setup affects a user's control over assets, that should be stated plainly too.

Asset-level risk notices matter just as much. If a token is highly volatile, thinly traded, or exposed to protocol risk, that should be spelled out clearly, not hidden inside a broad disclaimer. An ordinary user should be able to understand the product and its main risks without legal or technical knowledge.

Compliance, Enforcement, and Key Takeaways

Day-to-Day Compliance Duties for Licensed Platforms

Licensed platforms have to keep their risk controls, business continuity measures, data integrity checks, recordkeeping systems, and audit trails running at all times.

In plain English, this isn't a one-time setup job. A platform needs named compliance staff, a clear path for escalating issues to senior management and the board, and controls that are reviewed and tested by an independent party. It also needs to spot, contain, investigate, and fix technology, cyber, or operational incidents fast.

AML/CFT Reporting and Recordkeeping Duties

AML/CFT duties don't stop once a customer is onboarded. Platforms must carry out customer due diligence (CDD), monitor transactions, screen for sanctions and politically exposed persons (PEPs), apply extra checks to higher-risk users, and report suspicious activity.

Recordkeeping matters just as much. Digital asset custodians must keep client transaction records and business records for at least 7 years and provide them to the SC if asked. IEO issuers also have to keep offering documents and agreements for 7 years. On top of that, they must provide annual reports and reports every six months for token holders.

How Malaysia Enforces Digital Asset Rules

Once a platform goes live, the SC can act against both unlicensed activity and failures in day-to-day controls. Running a digital asset exchange in Malaysia without SC registration is an offence under Section 7(1) of the CMSA.

In November 2024, the SC acted against Bybit for operating an unregistered DAX in Malaysia. It ordered Bybit to block Malaysian access to its website and apps, stop advertising to Malaysian investors, and close its Malaysia-focused Telegram support group within 14 business days.

By 2024, the SC had already taken action against four unauthorized DAXs in total. In 2025, enforcement was still active, with:

  • 249 investor-alert-list inclusions
  • 175 website blocks
  • 35 Facebook and Instagram website and app blocks
  • 208 Telegram-account block requests
  • 215 social-media interventions

And blocking isn't the only tool on the table. The SC can impose conditions on registration, issue cease-and-desist notices, suspend or revoke authorization, and pursue civil or criminal penalties. Even where there is no fraud, weak controls can still lead to remediation orders or limits on ongoing operations.

Obligation Platform Type Frequency/Trigger Regulatory Source Possible Sanctions for Breach
Maintain risk management, business continuity, data integrity, and audit-trail controls RMO / DAX Ongoing Guidelines on Recognized Markets Suspension/termination conditions, remediation orders, public reprimand, enforcement action
Notify the SC of cyber/technology incidents and take immediate mitigation steps RMO / DAX On incident or near miss SC Technology Risk Management obligations Administrative action, registration consequences, investigation, possible sanctions
Retain client and business records for 7 years Digital asset custodian; IEO issuer Ongoing Guidelines on Digital Assets Breach may support enforcement, reprimand, suspension, or registration action
Provide SC access to registers and requested information RMO / custodian On request / during inspection Guidelines on Digital Assets Enforcement action, directions, possible registration consequences
Publish annual and reports every six months for token offerings IEO issuer Periodic reporting Guidelines on Digital Assets Token-offering breach exposure, SC action, investor-protection measures
Avoid unregistered DAX operations in Malaysia Any DAX operator Immediate; before commencing activity CMSA Section 7(1); SC enforcement materials Public reprimand, cease-and-desist, website/app blocking, and criminal penalties under CMSA framework

Cross-Border Access and Non-Malaysian Service Providers

Being offshore doesn't protect a platform that targets Malaysian users. If a service is in practice aimed at or serving users in Malaysia, the SC can still move against it, no matter where the provider is incorporated.

That makes one point hard to ignore: check whether the exact activity - exchange, custody, token distribution, or fiat-to-crypto conversion - is allowed in Malaysia before moving ahead. EU rules do not replace SC approval in Malaysia. Once assets enter a Malaysian-regulated setting, local licensing and conduct rules still apply.

Main Rules to Remember

The practical point is simple: getting authorized is only the start. Malaysia uses a license-first model. The SC decides who may operate, what they may offer, and how they must comply after launch. Token listings, disclosures, segregation of customer assets, market conduct, AML/CFT controls, and recordkeeping are core duties, not optional add-ons.

The downside of getting this wrong is very real. A platform can face remediation orders, operating limits, public enforcement action, and, in serious cases, criminal liability. The SC's track record shows that it will act against both licensed platforms that break their conditions and offshore operators that target Malaysian users without approval. For any platform operating in or into Malaysia, the message is direct: get authorized, stay compliant, and keep the records to prove it.

FAQs

Do all crypto businesses need SC approval in Malaysia?

The search results provided do not answer whether every crypto business in Malaysia needs approval from the Securities Commission (SC).

Here’s the issue: the sources focus on EU MiCA rules, U.S. regulatory frameworks, and general cross-border compliance standards. They do not give Malaysia-specific guidance on SC approval requirements.

So at this point, the safest takeaway is simple: the available results aren’t enough to confirm or deny that requirement for all crypto businesses in Malaysia.

Can an offshore platform legally serve users in Malaysia?

It depends on Malaysia’s local rules. In many cases, a platform needs to be registered or licensed in Malaysia before it can legally offer services to people who live there.

If a platform operates without that approval, it may not comply with local financial laws. That’s why users should check whether the platform holds the required local licenses before signing up or using its services.

When does a platform need a separate custody license?

Under MiCA, custody is a regulated crypto-asset service. If a platform holds and administers crypto-assets for clients, that activity falls under CASP rules and needs authorization for that specific service.

MiCA links licensing to the services a platform offers. So if custody is part of the business model, the platform needs the right custody authorization.

Related Blog Posts