Introduction
Crypto asset regulation in Turkey under Capital Markets Law has become one of the most important legal developments in the Turkish financial technology and capital markets sector. Until 2024, crypto assets in Turkey were mainly addressed through payment restrictions, anti-money laundering rules and general criminal or civil law principles. With the entry into force of Law No. 7518 on Amendments to the Capital Markets Law, Turkey created a direct statutory framework for crypto asset service providers under Capital Markets Law No. 6362.
This reform placed crypto asset service providers operating or intending to operate in Turkey under the regulatory and supervisory authority of the Capital Markets Board of Türkiye, known as the CMB in English and SPK in Turkish. The SPK announced that Law No. 7518 entered into force after publication in the Official Gazette dated 2 July 2024, and that crypto asset service providers were brought under the Board’s regulatory and supervisory authority within the scope of Capital Markets Law No. 6362.
For crypto exchanges, wallet service providers, custody companies, token projects, fintech companies, foreign platforms, investors and legal practitioners, this change is fundamental. Crypto asset activities in Turkey can no longer be treated as an entirely unregulated technological service. Platforms, custody providers and other crypto asset service providers must evaluate licensing, corporate structure, internal systems, customer agreements, asset segregation, cybersecurity, listing procedures, advertising, transfer rules, foreign platform restrictions and criminal sanctions.
Legal Background of Crypto Asset Regulation in Turkey
The main legal basis of Turkish crypto asset regulation is Capital Markets Law No. 6362, as amended by Law No. 7518. Law No. 7518 introduced new definitions and provisions into the Capital Markets Law, including definitions for crypto asset, wallet, crypto asset service provider, crypto asset custody service, platform and TÜBİTAK. According to the new statutory definition, a crypto asset is an intangible asset that can be electronically created and stored using distributed ledger technology or similar technology, distributed through digital networks and capable of expressing value or rights.
The law also defines a wallet as software, hardware, system or application that enables crypto assets to be transferred and allows crypto assets or private and public keys relating to them to be stored online or offline. A platform is defined as an organization where one or more activities such as crypto asset trading, initial sale or distribution, exchange, transfer and required custody services are carried out.
These definitions are important because Turkish law does not regulate only traditional crypto exchanges. The statutory framework also covers custody, wallet-related private key management, transfer services, first sale or distribution of crypto assets and other activities determined by the CMB. Therefore, a company operating in blockchain, tokenization, custody, exchange, wallet infrastructure or crypto investment services must assess whether its activities fall within the definition of a crypto asset service provider.
Law No. 7518 and the Shift to CMB Supervision
Law No. 7518 made crypto asset service providers part of the capital market regulatory perimeter. The SPK’s 2 July 2024 announcement states that activities such as crypto asset trading, exchange, transfer, custody services required by those activities, and custody or management of wallets or private keys may fall within the law when performed as a regular occupation, commercial activity or professional activity. The SPK also warned that persons failing to comply with statutory obligations may face action under Articles 99/A and 109/A of the Capital Markets Law.
This is a major shift. Before this framework, crypto-related disputes were often handled through general principles such as contract law, tort law, unjust enrichment, fraud, breach of trust, personal data protection and anti-money laundering obligations. After Law No. 7518, the regulatory focus moved toward authorization, institutional supervision, investor protection, asset segregation, custody standards, internal controls and CMB enforcement.
The inclusion of crypto assets under capital market law does not mean that every crypto asset is automatically a security or every token is a capital market instrument. However, it means that service providers dealing with crypto assets may be regulated similarly to capital market institutions where their activities fall within the statutory framework.
Crypto Asset Service Providers
The term crypto asset service provider is one of the central concepts of Turkish crypto regulation. The statutory definition includes platforms, institutions providing crypto asset custody services and other institutions designated under regulations to provide services relating to crypto assets, including initial sale or distribution.
In practice, crypto asset service providers may include:
Crypto asset trading platforms, crypto exchanges, crypto asset custody institutions, wallet and private key custody providers, platforms enabling token initial sale or distribution, platforms offering crypto transfer services, and other entities identified by the CMB.
This broad structure allows the CMB to regulate not only existing exchange models but also future business models. Blockchain technology evolves quickly, and new services may not fit traditional categories. The law therefore gives the CMB flexibility to determine which crypto-related services should be regulated.
Licensing Requirement for Crypto Asset Service Providers
One of the most important rules is that crypto asset service providers must obtain permission from the CMB for establishment and commencement of activities. Article 35/B provides that crypto asset service providers must obtain permission from the Board in order to be established and start operating, and that they may perform only those activities determined by the Board.
This rule creates a two-stage compliance structure. First, a provider must satisfy establishment conditions. Second, it must obtain activity permission and operate within the scope of the authorization granted. A company cannot simply incorporate a technology company and begin crypto exchange or custody activities. It must comply with the CMB’s licensing framework.
The SPK’s application page states that applications by crypto asset service providers must be made using the updated application forms and annexes published on the SPK website, and that applications with missing information, documents or forms not complying with the prescribed format will not be processed. The same page separately identifies establishment applications for new platforms or custody institutions and activity permission applications under the relevant communiqués.
Secondary Regulations: III-35/B.1 and III-35/B.2
The CMB’s secondary regulations are essential for understanding crypto asset regulation in Turkey. On 13 March 2025, the SPK announced that two major communiqués had been published in the Official Gazette and entered into force: the Communiqué on the Establishment and Operating Principles of Crypto Asset Service Providers III-35/B.1 and the Communiqué on the Working Procedures and Principles and Capital Adequacy of Crypto Asset Service Providers III-35/B.2.
The SPK stated that the III-35/B.1 Communiqué regulates issues such as establishment, commencement of activity, activities and suspension of activities of crypto asset service providers, founders and shareholders, share transfers, managers, personnel, organization, internal audit, internal control, risk management systems, information systems, technological infrastructure, document and record systems, independent audit and proof-of-reserve audits.
The SPK also stated that the III-35/B.2 Communiqué regulates services and activities that crypto asset service providers may offer, crypto asset trading environments, custody and transfer of crypto assets, listing of crypto assets on platforms and capital adequacy of crypto asset service providers.
Together, these two communiqués form the practical regulatory backbone of Turkish crypto law. They turn the statutory framework into operational requirements for platforms, custody institutions and other service providers.
Establishment Conditions for Crypto Asset Service Providers
The III-35/B.1 Communiqué sets out establishment conditions for crypto asset service providers. According to the official text summarized in legal databases, crypto asset service providers must be established as joint-stock companies, their shares must be registered shares, shares must be issued against cash, the capital must not be below the minimum amount required by CMB capital adequacy rules, the capital must be fully paid in cash, and the articles of association must comply with the law and relevant regulations.
These rules reflect the capital market law approach. The regulator does not treat crypto platforms as ordinary software companies. Because they handle customer assets, orders, transfers and custody risks, they must meet corporate, financial and governance standards.
The requirement that the company be a joint-stock company is also important for transparency, share transfer control, corporate governance and regulatory supervision. Since share transfers require CMB permission under Article 35/B, unauthorized share transfers cannot be validly recorded in the share ledger where they violate applicable regulatory requirements.
Shareholders, Managers and Fit-and-Proper Requirements
Crypto asset service providers must also satisfy fit-and-proper standards. Article 35/B sets out conditions concerning shareholders and persons connected with the provider. These conditions include restrictions relating to bankruptcy, concordat, liquidation history, cancelled licenses in certain financial sectors and convictions for serious crimes such as embezzlement, bribery, theft, fraud, forgery, abuse of trust, fraudulent bankruptcy, money laundering, terrorism financing, certain cybercrimes and other listed offences.
This matters because crypto asset service providers hold or control assets that may be highly mobile, difficult to recover and vulnerable to cyber or internal misconduct. The law therefore requires trustworthy shareholders and managers. A platform with opaque ownership, unqualified management or criminally risky controllers may not satisfy regulatory expectations.
For investors, fit-and-proper standards are a protection mechanism. For founders, they are a due diligence requirement. Before applying for authorization, founders must review whether shareholders, indirect controllers, board members and managers satisfy statutory and regulatory conditions.
Information Systems and TÜBİTAK Criteria
Crypto regulation cannot be effective without technology regulation. Article 35/B requires crypto asset service providers to make necessary arrangements for secure management of their systems, take required measures and establish internal control units and systems. It also provides that compliance with criteria to be determined by TÜBİTAK regarding information systems and technological infrastructure is required for establishment or commencement of activities.
This is one of the most important differences between ordinary financial regulation and crypto regulation. A crypto platform’s legal compliance depends not only on contracts and capital but also on private key security, wallet architecture, transaction monitoring, cybersecurity, access control, business continuity, disaster recovery and system integrity.
In practice, a crypto asset service provider should prepare an information systems governance framework. This should include cybersecurity policies, key management procedures, multi-signature controls, cold wallet procedures, penetration testing, incident response, logging, authorization matrix, backup systems, vendor risk management and business continuity plans.
Custody of Crypto Assets and Private Keys
Custody is one of the most sensitive issues in Turkish crypto asset regulation. Article 35/C provides that customers’ crypto assets should, as a principle, be held in customers’ own wallets. For crypto assets not held in customers’ own wallets, custody services must be provided by banks authorized under CMB regulation and approved by the Banking Regulation and Supervision Agency, or by other institutions authorized by the CMB to provide crypto asset custody services. Customer cash must be held in banks.
The same provision states that crypto assets held by banks and customer cash in this context are not subject to deposit or participation fund insurance under Article 63 of Banking Law No. 5411. This is crucial for investor protection. Customers should not assume that crypto assets or related cash balances are protected in the same way as insured bank deposits.
The law also gives the CMB authority to set different custody principles for each crypto asset, depending on technological characteristics and the nature or quantity of crypto assets. This flexible power is necessary because custody risks may differ significantly between Bitcoin, Ethereum-based tokens, stablecoins, tokenized securities, utility tokens and other digital assets.
Segregation of Customer Assets
Asset segregation is another core investor protection rule. Article 35/C provides that customer cash and crypto assets are separate from the assets of crypto asset service providers, and that records must be kept accordingly. It also states that customer cash and crypto assets held by crypto asset service providers cannot be seized, pledged, included in the bankruptcy estate or subjected to interim injunction due to debts of the service provider, even for public receivables; similarly, the provider’s assets cannot be seized due to customer debts.
This rule is extremely important. Many crypto disputes around the world have arisen from commingling of customer assets with platform assets. Turkish law expressly adopts segregation to protect customer property rights. If a platform becomes insolvent, customer assets should not be treated as the platform’s own assets.
However, asset segregation is only as effective as the provider’s recordkeeping, wallet structure and audit systems. Platforms must maintain accurate records, reconcile blockchain data with internal ledgers and ensure that customer assets are not misused.
Customer Agreements and Liability Clauses
Article 35/C regulates customer agreements. It allows agreements between crypto asset service providers and customers to be concluded in writing, remotely through communication tools, or by methods determined by the CMB that may replace written form and enable customer identity verification through information or electronic communication devices.
The same article gives the CMB authority to determine the principles concerning agreement content, amendments, fees, expenses, termination and minimum contractual terms. Most importantly, contractual clauses that remove or limit the crypto asset service provider’s liability toward customers are invalid. Platforms must also establish internal mechanisms to resolve customer objections and complaints effectively.
This is a significant consumer and investor protection rule. A platform cannot escape liability by inserting broad disclaimers into user agreements. Standard terms must be reviewed carefully. Clauses concerning hacking, mistaken transfers, system outages, wallet losses, delisting, suspension, liquidation, fees and complaint mechanisms must comply with CMB rules and general Turkish law.
KYC, AML and Customer Identification
Crypto asset service providers must identify customers under the Law No. 5549 on Prevention of Laundering Proceeds of Crime and related legislation. Article 35/C expressly states that crypto asset service providers must identify their customers within the scope of anti-money laundering legislation and other relevant regulations.
This obligation is essential because crypto assets can be used for money laundering, fraud proceeds, sanctions evasion, terrorist financing, ransomware payments, illegal gambling proceeds and other unlawful purposes. Platforms must therefore implement know-your-customer procedures, transaction monitoring, suspicious transaction reporting and risk-based compliance systems.
For customers, this means crypto platforms may request identity documents, address verification, source-of-funds information, beneficial ownership information and additional explanations for unusual transactions. Failure to complete KYC procedures may result in account restrictions.
Listing of Crypto Assets on Platforms
The law requires platforms to establish a written listing procedure for crypto assets that will be traded, initially sold or distributed on the platform, and for termination of trading. Article 35/C states that the CMB may regulate principles and criteria for this process and that technological criteria may be included by obtaining opinions from TÜBİTAK or other relevant institutions where necessary.
Listing is one of the most important legal responsibilities of a crypto platform. If a platform lists a fraudulent, technically defective, highly centralized, manipulated or misleading token without proper review, investors may suffer serious losses. Therefore, listing procedures should examine legal, technical, economic and operational risks.
A strong listing policy should include due diligence on the project team, token economics, smart contract security, supply structure, liquidity, concentration of holdings, legal status, regulatory risk, whitepaper accuracy, blockchain infrastructure, cybersecurity risks and market manipulation risk. Delisting procedures should also be transparent and fair.
Advertising, Marketing and Commercial Communications
Crypto asset service providers must comply with CMB principles concerning publications, announcements, advertisements and all commercial communications. Article 35/C expressly gives the CMB authority over these communications.
This is particularly important in the crypto sector because marketing is often aggressive. Statements such as “guaranteed return,” “risk-free crypto investment,” “certain profit,” “safe token,” “approved by SPK as an investment” or “no loss possibility” may create serious legal risk.
Crypto platforms and token projects should ensure that advertising materials are accurate, balanced and not misleading. Influencer campaigns, social media posts, referral programs, airdrops, staking promotions, launchpad announcements, market commentary and educational content should be reviewed under advertising and capital market compliance principles.
Foreign Crypto Platforms Targeting Turkish Residents
Foreign platforms are a critical part of the Turkish regulatory framework. The SPK’s 2 July 2024 announcement quotes Article 99/A and states that activity by foreign platforms toward persons resident in Turkey, or the offering of prohibited crypto asset activities to persons resident in Turkey, is deemed unauthorized crypto asset service provider activity. The announcement also states that opening a workplace in Turkey, creating a Turkish-language website, or conducting direct or indirect promotion and marketing activities toward Turkish residents is treated as activity directed at Turkish residents.
The SPK required foreign platforms engaging in such activities to terminate activities toward Turkish residents by 2 October 2024. After that date, continued activity in the specified manner may result in application of Articles 99/A and 109/A.
This is a major compliance issue for global crypto exchanges. A foreign license is not sufficient to serve Turkish residents if Turkish law requires CMB authorization. Turkish-language websites, Turkish advertising, Turkish customer support, local representatives, influencer campaigns and onboarding Turkish residents may all create Turkish regulatory exposure.
Transitional Regime and Temporary Lists
The transitional regime created by Law No. 7518 required existing crypto asset service providers to file declarations with the SPK. Under the SPK’s announcement, providers operating as of 2 July 2024 and wishing to continue had to apply by 2 August 2024 with the required information and declarations. Providers that did not wish to continue had to submit liquidation declarations and notify customers without accepting new customers during liquidation.
The SPK publishes a Faaliyette Bulunanlar Listesi and a Tasfiye Sürecinde Olanlar Listesi. However, the SPK expressly states that inclusion in the Faaliyette Bulunanlar Listesi is for public information under the transitional regime and does not mean that the listed entities have been authorized under the relevant legislation.
This distinction is extremely important for investors. Being on the temporary list is not the same as holding a final CMB license or authorization certificate. Investors should check current SPK lists, authorization status and public announcements before choosing a platform.
Unauthorized Crypto Asset Service Provider Activity
Unauthorized crypto asset service provider activity is a criminal offence. Law No. 7518 added Article 109/A to Capital Markets Law No. 6362. Under this provision, natural persons and authorized representatives of legal persons found to be operating as crypto asset service providers without permission may be punished with imprisonment from three to five years and a judicial fine from five thousand to ten thousand days.
The SPK has also warned that where customers of institutions that chose liquidation or failed to apply within the required period request transfers, failure to fulfill such transfer requests may constitute unauthorized crypto asset service provider activity under Article 109/A.
This is not merely an administrative issue. Founders, directors and authorized representatives may face criminal exposure. Therefore, platforms must not operate without proper authorization, and persons offering crypto exchange, custody, transfer or wallet management services professionally must seek legal advice before acting.
Embezzlement in Crypto Asset Service Providers
Law No. 7518 also introduced a special criminal provision for embezzlement in crypto asset service providers. Article 110/A provides that board chairpersons, board members and other personnel of crypto asset service providers who embezzle money, documents, goods or crypto assets entrusted to them due to their duties may be punished with imprisonment from eight to fourteen years, judicial fine and compensation of the provider’s loss.
This provision responds to one of the greatest risks in crypto markets: internal misappropriation of customer assets. Because crypto assets can be transferred quickly and irreversibly, internal fraud can cause large losses in a short time. Turkish law therefore treats embezzlement by crypto service provider personnel as a serious offence.
Platforms must implement strict internal controls, multi-signature approvals, segregation of duties, access logs, independent audits and real-time monitoring to prevent internal misuse.
Internet Content Removal and Access Blocking
Law No. 7518 strengthened the CMB’s authority over internet-based violations. The amended provisions allow the CMB to decide on removal of content or blocking of access regarding internet publications in the context of certain capital market violations, including market abuse, insider trading and market manipulation examinations. The decision is sent to the Access Providers Association for implementation.
This is particularly relevant in crypto markets, where unauthorized platforms, fraudulent token promotions, phishing websites, fake exchange pages and misleading investment advertisements are often distributed online. The CMB’s authority to remove content or block access provides a regulatory tool against unlawful crypto activities targeting Turkish investors.
Crypto Assets as Capital Market Instruments
Law No. 7518 also allows the CMB to determine principles for issuing capital market instruments as crypto assets instead of dematerialized issuance monitored by the Central Registry Agency. The law states that where capital market instruments are issued as crypto assets, rights, assertion against third parties and transfer are based on records in the electronic environment where they are created and stored; the CMB may also require integration with the MKK system.
This is a major development for tokenization. It creates a possible legal basis for tokenized securities, blockchain-based capital market instruments and digital registry models. However, such instruments must comply with CMB rules. A token representing a capital market instrument cannot be issued freely outside the regulatory framework merely because it is technologically implemented on blockchain.
For companies planning tokenized securities, legal review is indispensable. The project may require CMB approval, prospectus or issue document analysis, MKK integration, custody rules, investor rights rules and disclosure obligations.
Investor Protection Under Turkish Crypto Regulation
Investor protection is the core policy behind Turkish crypto regulation. The law introduces several protective mechanisms: licensing, CMB supervision, fit-and-proper requirements, internal control, risk management, TÜBİTAK technology criteria, customer agreement rules, invalidity of liability-limiting clauses, complaint mechanisms, KYC, asset segregation, custody rules, advertising control, listing procedures and criminal sanctions.
However, investors should understand the limits of legal protection. Crypto asset regulation does not mean that crypto prices are guaranteed. It does not mean that all listed tokens are risk-free. It does not mean that stablecoins are free from depeg risk. It does not mean that custody eliminates all cyber risk. It also does not mean that customer cash or crypto assets are covered by deposit insurance. Article 35/C expressly states that relevant cash and crypto assets are not subject to deposit and participation fund insurance under Banking Law No. 5411.
Therefore, Turkish crypto regulation protects investors against institutional misconduct and regulatory gaps, but it does not remove market, liquidity, technology, cyber, smart contract or token issuer risks.
Compliance Checklist for Crypto Asset Service Providers
A crypto asset service provider operating or planning to operate in Turkey should complete a detailed compliance checklist.
First, determine whether the activity falls within crypto asset service provider activities under Capital Markets Law. Second, incorporate or restructure as a joint-stock company where required. Third, ensure that shares, capital, articles of association and corporate objects comply with CMB requirements. Fourth, review shareholder and manager fit-and-proper conditions. Fifth, prepare establishment and activity permission applications using SPK forms. Sixth, establish internal control, internal audit, risk management and compliance systems. Seventh, obtain technology infrastructure review according to TÜBİTAK criteria. Eighth, implement custody, private key management and asset segregation procedures. Ninth, prepare customer agreements and complaint mechanisms. Tenth, establish AML/KYC systems. Eleventh, create listing and delisting procedures. Twelfth, review advertising and social media communications. Thirteenth, prepare independent audit and proof-of-reserve audit processes. Fourteenth, ensure records are accurate and accessible for CMB supervision.
This checklist should be completed before launch. Waiting until after customer onboarding may create criminal and administrative exposure.
Practical Checklist for Investors
Investors using crypto platforms in Turkey should also act carefully.
First, check whether the platform appears on the SPK’s current lists and whether it has final authorization. Second, understand that temporary listing is not final authorization. Third, read the customer agreement carefully. Fourth, verify custody and withdrawal rules. Fifth, understand that customer cash and crypto assets are not deposit-insured. Sixth, avoid platforms promising guaranteed returns. Seventh, be cautious with tokens promoted through influencers or social media. Eighth, keep transaction records, wallet addresses, screenshots and correspondence. Ninth, use strong authentication and security measures. Tenth, seek legal advice immediately if withdrawals are blocked, transfers are refused, assets disappear or the platform enters liquidation.
Investors should also understand that self-custody carries its own risks. If a customer holds crypto assets in their own wallet, loss of private keys, phishing, malware or mistaken transfers may cause irreversible loss. The legal framework recognizes self-custody as a principle, but self-custody requires technical competence.
Legal Risks for Token Projects and Web3 Businesses
Token projects, launchpads, decentralized finance protocols, NFT platforms and Web3 businesses should not assume that decentralization removes Turkish legal risk. If the project targets Turkish residents, sells tokens, enables trading, provides custody, manages wallets, organizes first sale or distribution, or promotes investment-like expectations, Turkish capital market rules may become relevant.
The most important legal question is whether the token expresses a value or right and whether the activity is carried out commercially or professionally. If a token resembles a capital market instrument, provides financial rights, is sold broadly to investors or is listed on a regulated platform, additional CMB analysis may be required.
Projects should review tokenomics, whitepaper claims, marketing language, investor rights, governance rights, revenue-sharing mechanisms, staking returns, buyback promises, liquidity support and exchange listing arrangements.
Disputes in Turkish Crypto Asset Law
Crypto disputes in Turkey may arise from unauthorized platforms, blocked withdrawals, hacking, internal embezzlement, wallet errors, mistaken transfers, fraudulent token sales, misleading advertisements, delisting, liquidation, failure to return assets, P2P fraud, phishing, AML account freezes, inheritance disputes and tax or enforcement issues.
The correct legal route depends on the facts. Possible remedies may include CMB complaints, criminal complaints, civil lawsuits, interim injunction requests, enforcement proceedings, blockchain tracing, bank record requests, platform record requests, MASAK-related processes and claims against directors or service providers.
Evidence is critical. Investors should preserve account records, transaction hashes, wallet addresses, screenshots, e-mails, SMS messages, platform announcements, KYC records, withdrawal requests and bank transfer records.
Conclusion
Crypto asset regulation in Turkey under Capital Markets Law is now a developed regulatory field. With Law No. 7518, crypto asset service providers were brought under the supervision of the Capital Markets Board of Türkiye. The law introduced definitions for crypto assets, wallets, platforms, crypto asset service providers and custody services, and created licensing, custody, asset segregation, customer protection, foreign platform restriction and criminal sanction mechanisms.
The 2025 communiqués, III-35/B.1 and III-35/B.2, provide the operational details of this regime. They regulate establishment, activity permission, shareholders, managers, organization, internal control, risk management, information systems, technological infrastructure, independent audit, proof-of-reserve audit, services, trading environments, custody, transfer, listing and capital adequacy.
For platforms and custody providers, compliance is now a legal necessity. For investors, the new framework offers stronger protection but not a guarantee of profit or deposit-style insurance. For foreign platforms, targeting Turkish residents without authorization creates serious risk. For token projects and Web3 businesses, legal analysis is required before marketing, listing or distributing tokens in Turkey.
In conclusion, Turkish crypto regulation is no longer based on uncertainty alone. It has moved into the capital market law framework with licensing, supervision and sanctions. Any crypto exchange, custody provider, wallet business, token project, foreign platform, investor or institutional client dealing with Turkish crypto markets should obtain professional legal advice before acting, because the consequences of non-compliance may include administrative sanctions, access blocking, criminal liability and loss of customer trust.
Yanıt yok