This post uses hypothetical scenarios for illustrative purposes only. It does not describe any actual client, transaction, or representation, and is not legal advice.
Download: Protocol Acquisition Diligence Checklist (.docx) — a companion resource for this post. Adapt with counsel before use.
A common 2026 crypto M&A conversation looks like this. A well-funded acquirer — a public company chasing a stablecoin rail, a hedge fund building an on-chain treasury strategy, a larger protocol looking to absorb a competitor — decides it wants to buy a protocol. Not a company that owns a protocol. The protocol itself. The smart contracts, the brand, the community, the token supply, the treasury, and whatever share of governance can be transferred in a single transaction. The acquirer’s M&A team opens a familiar playbook — SPA, escrow, indemnification, disclosure schedules — and immediately runs into a target that has no clean cap table, no corporate seller, and a governance body that is not a board of directors but a rolling token-holder vote. The playbook does not fit.
Protocol-level M&A is real, closing at increasing frequency in 2026, and the deals that work follow a pattern that looks nothing like what a traditional M&A lawyer expects on day one. Here is how it maps out in practice.
First — the three flavors of crypto M&A
Both sides often use the phrase “acquire the protocol” to mean three different transactions. The paper has to reflect which. The traditional acqui-hire is closest to standard M&A — the target is a Delaware C-corp or a Cayman foundation that owns the protocol IP, employs the engineers, controls the admin keys, and holds the treasury. The buyer executes a stock purchase or a merger, steps into the corporate seat, and inherits the protocol relationship. This flavor works when the protocol has never really been decentralized and the buyer wants to preserve the operational team, which is often the actual value.
The protocol-only acquisition is a different animal. The buyer is not buying the corporate seller. The buyer is buying a defined bundle — the smart contract admin authority, the trademark, the reference-client repository, the front-end domain, the governance-facilitation contracts, and sometimes an agreement from the founding team not to build a competing protocol for a period of years. The corporate seller may continue to exist as a services company, may be wound down, or may be spun into a separate deal. The Protocol Purchase Agreement — which is not any standard M&A form — has to enumerate what is being transferred and how, because there is no corporate wrapper carrying the assets.
The treasury acquisition is the newest and the strangest. The target is a DAO — a Wyoming DUNA, a Marshall Islands DAO LLC, a Cayman foundation with an on-chain governance overlay — that has accumulated a large treasury and either wants to sell it, wants to acquire another protocol using it, or wants to be acquired by a buyer who is really only interested in the treasury. The transaction papers itself in on-chain governance votes, token swaps, and treasury-migration ceremonies, and the traditional-M&A concept of “closing” collapses into a series of block-height events.
Second — what “ownership” even means when there’s no cap table
In a corporate deal, the answer to “what does the buyer own after closing” is a share certificate and a board seat. In protocol M&A the question splits into four separate ownership layers. Token allocation is the first — a defined share of the outstanding supply transferred, vested, or held in a treasury pool the buyer directs. Governance rights are the second — a council seat, a veto over parameter changes, or a temporary supermajority during transition, all of which have to be encoded in the governance contracts, the foundation charter, or a side agreement with the DAO. Treasury custody is the third — diligence of every wallet, multisig, timelock, and off-chain custody arrangement, with a ceremony at close that transfers control. Admin-key authority is the fourth and most underestimated — proxy upgrade keys, guardian keys, emergency-shutdown authority, oracle-update permissions. The transfer of those keys is the transfer of the protocol. If the ceremony is done wrong, the buyer owns a set of wallets and a treasury but does not own the ability to change the protocol.
Third — diligence looks nothing like corporate diligence
The diligence process on a protocol acquisition breaks the traditional M&A checklist. Code audit is now central — not because the buyer wants to know whether the software works, but because unresolved audit findings are exploitable liabilities that survive closing. Every audit engagement, every finding, every remediation status, every follow-up audit becomes part of the diligence file.
Protocol history is the second addition. The buyer needs to walk every past incident — exploits, near-misses, white-hat rescues, bug-bounty payouts, admin-key mistakes, governance attacks. This is not a hypothetical exercise; on-chain history is public and the buyer will be judged post-close by what the community already knows.
Governance vote history is the third. Every past proposal, every vote outcome, every quorum result, every unusual voting pattern. The diligence file has to include a governance memo that would survive review by a securities regulator asking whether the protocol has ever been meaningfully decentralized.
Treasury reconstitution rights and admin-key transfer mechanics round out the diligence file. The buyer needs a written key-rotation plan reviewed by counsel and by security engineers, executed with witness-adequate documentation, and audited against on-chain events after close. Every meaningful protocol M&A deal that has gone wrong post-close has an admin-key story at the center of it.
Fourth — the regulatory posture is the whole conversation
Every protocol acquisition sits inside a regulatory posture that the deal cannot ignore. The SEC’s theory that a protocol issuer is a securities issuer runs through SEC v. Kik Interactive, Inc., No. 19-cv-5244 (S.D.N.Y. 2020), SEC v. Telegram Group Inc., No. 19-cv-9439 (S.D.N.Y. 2020), SEC v. LBRY, Inc., No. 21-cv-260 (D.N.H. 2022), and SEC v. Terraform Labs Pte. Ltd., No. 23-cv-1346 (S.D.N.Y. 2024). If the buyer becomes the “issuer” post-transaction, the buyer inherits the securities exposure. If the buyer’s purchase itself involves the distribution of tokens as consideration, the transaction may be an issuance of unregistered securities on the buy side. The CFTC angle emerges when the protocol involves a commodity token or a derivatives product — the CFTC v. Ooki DAO default judgment, No. 22-cv-05416 (N.D. Cal. 2023), extended DAO liability directly to token-holders participating in governance, and Sarcuni v. bZx DAO, No. 22-cv-618 (S.D. Cal. 2023), carries the same posture in private litigation. FinCEN reaches the transaction when the protocol operates as a money transmitter, with state MSB registrations layering on top — Florida’s DBPR under FL Ch. 560, New York’s BitLicense, California’s DFPI. A protocol acquisition that does not diligence the state MSB stack has not diligenced its own regulatory ceiling.
Fifth — how the DAO actually approves being sold
The mechanics of the sale vote turn a protocol M&A conversation from a two-party negotiation into a governance event. If the target is a DAO or a foundation with a token-holder overlay, the transaction requires a governance vote — and the vote has to pass under the DAO’s own rules. Quorum is the first mechanical question; many DAOs have never had a vote reach quorum on an important question. Passage thresholds vary widely, and the deal cannot proceed if the threshold is unreachable. Sybil protection is the second. Nothing prevents a sophisticated actor from borrowing enough tokens to swing a vote unless the governance architecture is designed to prevent it — snapshot at a pre-announcement block, delegated voting, quadratic voting, or a foundation-council override on a hostile vote are the common defenses. Deal announcements have to be timed around this risk.
Sixth — deal papering in the absence of a clean corporate seller
The Protocol Purchase Agreement is not a form document. It borrows from the SPA, from the asset-purchase agreement, and from the technology-transfer agreement, and it has to solve four problems that traditional M&A does not.
Reps and warranties keyed to on-chain state is the first. The seller’s reps have to speak to smart-contract security, admin-key custody, treasury holdings verifiable on-chain, governance-vote history, and the absence of undisclosed exploits or unresolved audit findings. The buyer’s reliance is meaningful only if the reps track on-chain observable facts and the buyer performs the observation.
Indemnification without a corporate obligor and its escrow substitute is the second. If the target is a DAO, there is no continuing corporate entity to sue. The workaround is a treasury holdback governed by a smart-contract escrow that releases over time and can be clawed back on defined breach events. The clawback conditions have to be codeable, not just definable, and the choice of oracle, custodian for the multisig, and dispute-resolution mechanism are all deal terms.
Founder rollover and retention is the third. In a foundation-plus-C-corp target, the founders are often paid partially in continued token vesting, key-person retention agreements, and non-compete undertakings. The non-compete has to be enforceable in the founders’ home jurisdictions — a Florida-based founder benefits from FL § 542.335’s employer-friendly posture; a California-based founder faces Bus. & Prof. Code § 16600’s near-per-se ban.
Seventh — what goes wrong post-close
The failure modes on a protocol acquisition are predictable. Treasury drift is the first — after close, the treasury composition begins to shift because the new owner is trading, staking, or deploying it into strategies the community did not anticipate; written treasury policies, publicly communicated at announcement, mitigate this. Orphaned admin keys are the second — somewhere in the transaction a signer transfers keys and something in the ceremony misfires, leaving a wallet that should have been retired with residual authority. Detailed key-transfer documentation and independent post-close verification prevent this. Community exodus is the third; retention conversations that begin at announcement, not at close, are what keep the community intact. Governance capture attempts are the fourth — the acquirer often needs to hold a permanent stake sufficient to defeat a hostile vote, at least during the transition period, and that stake has to be modeled into the deal economics.
Download: Protocol Acquisition Diligence Checklist (.docx) — a companion resource for this post. Adapt with counsel before use.
For related discussion, see our overview of the foundation and DAO wrapper choice for high-growth crypto companies, our note on the board consent that supports a token generation event, and our earlier piece on a foundation-led acquisition of a spun-out protocol. For the CFTC’s DAO liability posture, see the Ooki DAO default judgment press release.
If you are structuring a protocol-level M&A transaction — as buyer, seller, or DAO council — feel free to reach out to our firm manager, Magda, at Magda@montague.law, or fill out our contact form. Mention you read this post.


