Cryptocurrency and the Law Across the Arab World: A Plain Guide for Business

SUMMARY

Cryptocurrency and the law across the Arab world varies greatly. The UAE, Bahrain, and Jordan have established licensing frameworks. Virtual asset service providers in Dubai must hold a licence from VARA under Dubai Law No. 4 of 2022. Egypt and Kuwait impose outright prohibitions backed by criminal penalties. Saudi Arabia and Lebanon remain unregulated but not criminalised for individuals. Across all ten jurisdictions, cryptocurrency is pseudonymous ,not anonymous  making it substantially more traceable than cash and enabling fund recovery when legal steps are taken quickly.

What this guide covers

Part One: What cryptocurrency is, how it works, and who the actors are. Followed end to end, from your bank account and back.
Part Two: How fraud happens in the crypto world, and what can be done when it does.
Part Three: The legal position in Lebanon, the United Arab Emirates, Saudi Arabia, Bahrain, Qatar, Egypt, Kuwait, Oman, Jordan and Iraq.

Table of Contents

PART ONE: What Cryptocurrency Is and How It Works

Most explanations of cryptocurrency fail for the same reason. They begin with the technology. They talk about decentralisation, cryptography and distributed consensus, and by the third paragraph the reader has quietly decided this is not for them.

So let us begin somewhere else: with five hundred dollars sitting in a bank account, and follow it step by step, all the way into cryptocurrency and all the way back out again. At every stage we will stop and ask two questions: what is actually happening here, and who is involved?

By the end of Part One you will understand how cryptocurrency works, not in outline, but properly. Part Two examines how fraud happens in this world, because that knowledge is what protects you. Part Three sets out where the law stands across ten Arab countries, because the same activity that is licensed in one is a criminal offence in anothe

Start Here: Understand What a Blockchain Actually Is

Money in a bank is not a thing. It is a record. Your bank keeps a list, and on that list is a line saying you own a certain balance. Nothing physical corresponds to it. The bank owns the list, the bank maintains the list, and the bank alone can amend the list. Trust in your money is trust in that institution.

Cryptocurrency asks a simple question: what if the list were kept by everybody, instead of by one institution?

That is all a blockchain is. It is a list of who owns what, held not on one company’s servers but on thousands of independent computers around the world simultaneously, each holding a full copy, each constantly checking the others. There is no master copy, because every copy is the master copy.

When a bank fails, or freezes an account, or makes an error, the list changes and you have little recourse. When thousands of independent copies must agree before a single line changes, no single party can quietly rewrite history. That is the whole idea. Everything that follows is engineering.

Your $500 dollars: Follow the complete journey into cryptocurrency and back

The following eight steps trace what actually happens when an ordinary person buys, holds, sends, and converts back cryptocurrency. Each step involves a different actor with different legal obligations — understanding this is what makes it possible to identify where things go wrong and what can be done about it.

Step 1: Decide what you are buying: Comparison of Bitcoin, Ether, and Stablecoins

Not all cryptocurrencies are the same, and the differences matter commercially. The table below covers the three categories most relevant to businesses and individuals in the Arab world.

Bitcoin was the first, and it behaves like a scarce commodity. Its supply is capped. People hold it as a long-term store of value. Its price moves considerably.

Ether is the fuel of the Ethereum network, which can run small programmes called smart contracts. Think of Bitcoin as digital gold and Ethereum as a machine that also happens to have a currency.

Stablecoins are the category most businesses actually need. A stablecoin is a token designed to hold a steady value, backed one to one by a real currency held in reserve. The best known is Tether, written USDT, which tracks the US dollar. One USDT is intended to always be worth one dollar. Stablecoins let value move across the world in minutes without the price moving underneath you. For this example, you decide to buy 500 USDT.

Note on stablecoins
A stablecoin is issued by a company. Bitcoin has no issuer, no head office and no telephone number. Tether (USDT) has all three. This single fact becomes critical in Part Two — it is the difference between an academic trail and a real legal remedy when funds are stolen.

Step 2: Choosing the exchange

Cryptocurrency lives on a blockchain, but your dollars live in the banking system. Something has to connect the two. That something is called an exchange, and it is the single most important actor in this entire story.

Here is what surprises most people: an exchange is an ordinary company. It has offices, employees, shareholders, a bank account and a licence. It is not a blockchain. It is not decentralised. It is a business, and because it is a business, it is subject to law. Binance, Coinbase and Kraken are the largest international examples, and regional platforms operate under regional licences.

This is where you go with your five hundred dollars.

Note carefully that “initial approval” or “in-principle approval” is not a full licence. It does not authorise a firm to hold your money.

The choice of exchange is the most consequential decision in the entire process, and here is the test that matters: Which authority regulates this platform, and does its licence actually cover the service being offered?

In Dubai, that authority is VARA. In Bahrain, the Central Bank of Bahrain. In Jordan, the Jordan Securities Commission. If a platform cannot be found on a regulator’s public register, you have no protection whatsoever if something goes wrong. Note carefully that “initial approval” or “in-principle approval” is not a full licence.

This is where you go with your five hundred dollars.

Note carefully that “initial approval” or “in-principle approval” is not a full licence. It does not authorise a firm to hold your money.

Step 3: Opening the account — what KYC really means for your identity

You provide your passport, proof of address and, increasingly, evidence of where your money came from. This is called Know Your Customer  universally shortened to KYC.

Most people experience it as bureaucratic friction. Understand what it is: at this moment, your real legal identity becomes permanently attached to everything you will subsequently do with that cryptocurrency. The exchange has your passport. Your bank transfer is recorded. A file exists connecting a human being to a set of blockchain addresses.

This is the “doorway” through which the supposed anonymity of cryptocurrency is pierced. It is also, as we will see in Part Two, the reason stolen funds can sometimes be recovered.

Who is involved at this stage: you, the exchange, the exchange’s compliance department, its bank, and behind them the financial regulator and the financial intelligence unit of the relevant country.

Step 4: Funding the account and placing the order

You transfer $500 dollars from your bank to the exchange by bank transfer or card. Your bank sees this payment. In some countries as we will see in Part Three, your bank is forbidden to process it at all.
The exchange credits your account with $500 dollars you place an order to buy USDT.

The exchange does not create the cryptocurrency you buy, and usually does not sell it to you from its own pocket. It runs a marketplace, an order book, matching your order against someone else selling. The counterparty may be another customer or a professional trading firm known as a market maker. You pay a small fee, generally a fraction of a percent, and receive slightly less than 500 USDT.

Nothing has yet touched the blockchain. So far you have simply changed the internal records of a company.

Step 5: Where your cryptocurrency actually is

Your exchange account now shows 499 USDT. Where is it? It is held by the exchange, in the exchange’s own wallets, mixed with other customers’ funds. The exchange holds the keys. You hold a claim against the exchange. This is called a custodial arrangement, and it is precisely analogous to a bank deposit: you do not have coins, you have a promise.

That promise is only as good as the company. If the exchange is hacked, becomes insolvent, or has been mixing customer assets with its own money, your claim may be worth very little. This is not theoretical. It is the single most common way people have lost large sums in this industry, and it has nothing whatsoever to do with the blockchain.

Step 6: Taking custody yourself

To hold cryptocurrency properly, you withdraw it to your own wallet. The word “wallet” is the most misleading term in the industry, because a wallet contains no money at all.

A wallet is a pair of cryptographic keys.

The public address is a long string of characters that works exactly like an IBAN. You give it to people so they can send you value. It is safe to publish.

The private key, together with the seed phrase that can regenerate it, is what authorises spending. It functions as signature and PIN combined.

Your money is not inside the wallet. Your money is a line on the blockchain, sitting at your address, visible to the entire world. The private key is simply the only thing in existence that can move it.

The single most important rule in cryptocurrency: whoever holds the private key controls the funds. There is no branch manager. There is no password reset. There is no chargeback. Lose the key and the value is unreachable forever. Let somebody steal it and they will move everything, immediately, without the possibility of reversal.

A wallet kept on an internet-connected device is a hot wallet: convenient, more exposed, fine for small working balances.
A wallet kept offline on a dedicated hardware device is a cold wallet, and anything of real value belongs there.

Step 7: What happens when you send cryptocurrency

Suppose you now send 100 USDT to a supplier. Watch what the network does.

You enter the supplier’s address and the amount. Your wallet uses your private key to produce a digital signature, proving the instruction came from the owner of that address without ever revealing the key itself.

The signed instruction is broadcast to the entire network and lands in a public waiting area. Every computer on the network can see it, and can verify the signature independently.

The instruction is given a hash: a unique digital fingerprint, a long string of characters produced by running the data through a mathematical function. Change one character of the transaction and the hash changes completely. This transaction hash is the permanent, unalterable reference number of that transfer. It never changes and can never be reissued.

In any theft, the transaction hash is the most valuable piece of evidence in existence.

You also pay a small network fee, which is not paid to any company. It is paid to whichever participant does the work of writing your transaction into the permanent record. Which brings us to how the record is actually written.

How the blockchain record is written: blocks, hashes, and the chain

Transactions waiting in the public holding area are gathered up in batches. Each batch is called a block.

A participant collects the waiting transactions, verifies every signature, discards anything invalid, and packages the rest into a block. The block’s entire contents are then run through the hashing function, producing that block’s unique fingerprint.

Now comes the elegant part, and the reason the whole system works.

Every block contains, inside it, the hash of the block that came before it.

Block 1001 stores block 1000’s fingerprint. Block 1002 stores block 1001’s fingerprint. And so on, in an unbroken sequence stretching back to the very first block ever created.

Consider what this means for a forger. To alter a transaction in block 1000, you must change its contents. Changing its contents changes its hash. But block 1001 contains a copy of block 1000’s old hash, which no longer matches. So block 1001 must be rewritten too, which changes its hash, which breaks block 1002. The forger must rewrite every subsequent block, faster than the entire rest of the world is producing new ones, on thousands of computers that each hold the original and will simply reject the altered version.

This is what “immutable” means. Not that the record is guarded, but that the record guards itself.

 

Who owns the computers?

This is the question everybody asks. Nobody owns the network. There are three distinct roles, and they are frequently confused.

  • Nodes are computers that keep a full copy of the ledger and independently check every rule. They are run by hobbyists, businesses, universities, researchers and exchanges. They earn nothing. They run because participants want to verify the network for themselves rather than trust somebody else’s word. A node costs an ordinary computer and requires nobody’s permission. Anyone reading this could run one this week. Their collective role is decisive: nodes reject anything invalid, and no miner can force them to accept a bad block.

  • Miners exist on Bitcoin. They compete to solve a deliberately expensive mathematical puzzle, and the winner earns the right to add the next block, receiving newly created coins plus transaction fees. This process is called proof of work, and the expense is the point: attacking the network would cost more than it could ever yield. Miners are typically specialised businesses running large data centres, though individuals participate by joining mining pools that combine everyone’s power and share the rewards proportionally.

  • Validators exist on Ethereum and most newer networks. Rather than burning electricity, they lock up a quantity of cryptocurrency as a security deposit, and the software selects among them to propose and confirm blocks. Behave dishonestly and the deposit is destroyed. This is proof of stake. Validators are individuals, dedicated staking services and large exchanges.

    Can you become one? Yes, and this is genuinely important. There is no application, no gatekeeper and no licence. To mine you buy hardware and pay for electricity. To validate you stake capital and run software. Permission is never required. Capital and equipment are.

    Do companies control these networks? No single company controls Bitcoin or Ethereum. But honesty requires acknowledging that power is more concentrated than the word “decentralised” implies. Bitcoin’s mining power is concentrated among a handful of large pools. Ethereum’s staked capital is concentrated among major staking providers and exchanges. Their relative shares shift continually. This is a legitimate governance concern. It does not, however, give any of them ownership of the ledger, for the reason set out next.

What if one of them acts in bad faith?

A fair question, and the answer has two halves.

A miner or validator cannot steal your coins. They do not hold your private key. They cannot produce your signature. A block containing a forged transaction is rejected by every honest node on the network the moment they see it. Your funds are protected by mathematics, not by anyone’s good character.

A miner or validator can refuse to include your transaction. This is called censorship, and the practical consequence is delay, not loss. Your transaction waits, and the next participant includes it, because they want your fee. Only a coordinated majority of the entire network could exclude you permanently. Acquiring that majority on a large network would cost a fortune and would destroy the value of the very asset being attacked. On small, low-value blockchains such attacks have genuinely happened.

 

The most important exception : everything above concerns decentralised networks. Stablecoins are not decentralised. USDT is issued by Tether Limited, which retains the technical power to freeze specific addresses and render the tokens in them unusable. It has done so extensively, assisting authorities in major seizures including the recovery of approximately USD 61 million in USDT linked to investment fraud. For a victim of theft, this single fact is the difference between an academic trail and a real remedy

For a victim of theft, this single fact is the difference between an academic trail and a real remedy. Stolen Bitcoin cannot be frozen by anybody. Stolen USDT can be, if the right application reaches the issuer, through the right channel, quickly enough.

Step 8: Converting back to dollars

Eventually you want your money back in your bank account. You send cryptocurrency back to the exchange, sell it for dollars, and withdraw to your bank. This is called the off-ramp, and it is the mirror image of the door you came in through and the most important structural fact in the entire system.

To turn cryptocurrency into money you can spend at a shop or pay a salary with, it must pass through a regulated business with identity records and a banking relationship. There are very few such doors in the world, and every one of them keeps records. A thief holding stolen cryptocurrency therefore possesses an asset whose every movement is published permanently, and which must eventually pass through a door that demands a passport.

Is cryptocurrency anonymous? No

This is the most expensive misconception in the market, and it costs people money in both directions. Criminals rely on the myth of anonymity. Investigators rely on the reality of traceability.

The correct word is pseudonymous. An address is a string of characters, not a name. In that narrow sense it does not announce who owns it. But every transaction that address has ever made is public and permanent, and the moment funds touch a regulated exchange that has performed identity checks, the pseudonym can be matched to a person.

Compare it with cash. If a thief steals a suitcase of banknotes and spends it in a market, that money is gone. Every banknote carries a serial number, but nobody records it as the note changes hands, so the trail exists in theory and evaporates in practice.

Cryptocurrency is not anonymous money. It is the most traceable money that has ever existed.

Every transfer is automatically stamped with its unique hash and published — together with the sending and receiving addresses, the amount and the time — on a public record that is never erased. Nobody chooses to write it down. The network does it, every time, forever.

How tracing actually works in practice:

Anyone can inspect a blockchain using free public search tools called block explorers. Enter a transaction hash or an address and the complete history appears.

Professional investigation adds layers to this.

It begins from the transaction hash, the anchor of everything, which is why preserving hashes immediately after a theft is the single most important thing a victim can do.

Stolen funds are then moved through a sequence of addresses to create distance from the crime, a process called layering. Each move is public.

Investigators then perform clustering. By studying behaviour, for example several addresses being used together to fund a single payment, analysts group addresses that are probably controlled by the same person or entity. Scattered anonymous-looking addresses become an identifiable actor.

Frequently they find a convergence wallet: a single address at which funds from many separate victims, or many separate routes, arrive together. This is often the decisive forensic finding, because it links otherwise unconnected thefts to one controlling hand.

Finally, the funds reach an off-ramp. That is where the pseudonym meets the passport, and where legal process can be directed

From theft, through layering and clustering, to the off-ramp where the pseudonym becomes a name

How reliable is any of this?

A distinction must be drawn carefully, because public discussion routinely confuses two entirely different things. The core technology has proved remarkably reliable. Bitcoin’s ledger has run continuously since 2009. It has never been successfully forged. Its cryptography has not been broken.

Almost every large loss has occurred somewhere other than the blockchain. Losses happen at exchanges that were hacked or that collapsed while holding customer money. They happen when private keys are stolen through phishing or malware. They happen through fraudulent projects and human error. In each case the ledger recorded the transfer perfectly and permanently. It simply had no opinion about whether the transfer was authorised.

The summary for any business is therefore short. The ledger is trustworthy. The people and companies around it are the risk. Your diligence belongs on the counterparty, never on the mathematics.

PART TWO: How Fraud Happens, and What Can Be Done

Cryptocurrency fraud is not sophisticated in the way people imagine. It rarely defeats the technology. It defeats the person.

The principal frauds: how each one works

Investment fraud, known in the industry as "pig butchering".

By a wide margin the most financially destructive fraud in the world today. A stranger makes contact through a dating application, a social network, a messaging group, or an apparently accidental wrong number. Over weeks or months they build a genuine relationship — romantic, social or professional — and never ask for money. Eventually they mention an investment, on a platform that looks entirely legitimate and shows impressive returns. A small early withdrawal is permitted, cementing trust completely. Deposits grow. When the victim attempts a substantial withdrawal, it is blocked, and demands appear for taxes or unlocking charges. Then the platform, and the person, vanish.

These are not individuals. They are industrial operations run from fortified compounds, often staffed by trafficked workers who are themselves victims. Artificial intelligence has multiplied their reach, sustaining fluent, tireless conversation in any language, at scale, with convincing deepfake video.

Approval phishing and wallet drainers

Technically distinct and growing fast. The victim visits a convincing fake website: a token giveaway, an airdrop, a decentralised exchange. They are asked to connect their wallet, then to click “Approve”. By approving, they sign a smart contract granting the attacker permission to move tokens out of the wallet. No password was stolen. No key was disclosed. The victim authorised it, usually without understanding what they authorised, and the wallet may be emptied weeks later, long after the interaction was forgotten.

Seed phrase phishing

The crudest, and still among the most effective. A fake support agent, a cloned exchange login page, or a friend’s compromised account asks for the recovery phrase. Anyone holding that phrase controls the wallet absolutely. No legitimate service ever asks for it, under any circumstances.

Rug pulls

Developers launch a token, generate excitement, attract money, then withdraw the liquidity and disappear. Anonymous teams, unaudited contracts and short liquidity lock periods are the classic warning signs.

Fake exchanges and impersonation

Cloned websites, near-identical domain names, and AI-generated deepfake videos of prominent figures promising to double any cryptocurrency sent to them.

Custodial failure and commingling

Less dramatic and frequently more costly. A platform holds customer assets, mixes them with its own funds, suffers trading losses, and conceals the shortfall. The application works. The balances display. The yield accrues. Everything appears normal, right up until the withdrawal button stops working, and the customer discovers that their balance was an unsecured claim against an insolvent company.

Recovery fraud: the second theft

After a loss, the victim is contacted by a “recovery service”, a “blockchain investigator”, or a purported law firm claiming to have located the funds and requesting an advance fee. This is deliberate revictimization of somebody already identified as vulnerable. Legitimate recovery is pursued through lawyers and law enforcement. It is never initiated by a stranger who contacts you first.

Why recovery is genuinely possible

Because of everything established in Part One: the thief has taken an asset whose every movement is published permanently, and to spend it they must pass through a door that keeps records. Three levers exist.

The exchange. If stolen funds reach a licensed exchange, that exchange holds identity records and can freeze the account. It will act on proper legal process from a competent authority.
The stablecoin issuer. If the stolen asset is a centrally issued stablecoin such as USDT, the issuer can freeze the specific addresses holding it. This has been done repeatedly and at very large scale in cooperation with law enforcement.

The criminal process. A criminal complaint engages the state’s investigative and coercive powers: formal requests to exchanges and issuers, cross-border mutual legal assistance, and asset freezing by financial intelligence units. In the United Arab Emirates, the Financial Intelligence Unit’s power to suspend transactions and freeze suspected proceeds of crime under the 2025 anti-money-laundering framework is directly relevant, and Dubai Police maintain a dedicated cybercrime capability that has featured prominently in major cross-border operations.

Enforcement has become markedly more capable. Coordinated international operations have produced substantial arrests, the closure of scam compounds and the freezing of very large sums.

Recovery is never guaranteed. But it is not a fantasy either, and the variable that decides it is almost always speed.

What to do if it happens to you

Time is the single greatest determinant of recovery. Funds move through layering and reach off-ramps within hours. The following steps should be taken in order, without delay.

IMMEDIATE ACTION CHECKLIST

  1. Stop. Send nothing further. No release fee, no tax, no additional deposit. Every such payment is part of the fraud.

  2. Preserve the evidence before doing anything else. Record every transaction hash, every wallet address, exact dates and times, amounts, and the blockchain used. Screenshot the platform, the conversations, the profiles, the websites and the full URLs. Save emails and messages in original form. Fraudulent platforms and accounts are deleted within days.

  3. Secure what remains. If a private key or seed phrase may be compromised, move remaining assets to a new wallet created on a clean device. If you signed wallet approvals, revoke them.

  4. Report immediately. Time is the single greatest determinant of recovery. Funds move through layering and reach off-ramps within hours. Report to the competent police or cybercrime authority without delay.

  5. Notify the exchange and the issuer. If funds have reached an identifiable exchange, notify it in writing at once. If the asset is a stablecoin, alert the issuer. Formal freezing requires legal process, but early notice preserves the possibility.

  6. Instruct blockchain tracing. Professional tracing establishes the flow of funds, identifies clusters and convergence wallets, and locates the off-ramp. This is the evidential foundation of any freezing application.

  7. Take legal advice on the forum. Where the funds sit, where the perpetrator acted, and where you suffered loss may be three different countries. Choosing the right jurisdiction and the right procedural route is a legal question with material consequences.

  8. Refuse every unsolicited recovery offer, without exception.

Protecting yourself in advance

Because the technology is transparent, protection is almost entirely a matter of diligence about people and platforms.

  • Identify the regulator and confirm one exists. If the country has no regulator for cryptocurrency, understand that you have no recourse at all.
  • Verify the licence and match it to the activity. Confirm the platform appears on the regulator’s public register and that the licence covers the exact service offered. An initial approval is not a licence to hold your money.
  • Treat these as red flags: no verifiable licence; a vague or concealed legal entity; guaranteed or unusually high returns; aggressive referral schemes; anonymity promoted as a feature; urgency and pressure; any request to send funds to a personal account or unrelated third party; and any investment introduced by somebody you met online.
  • Never disclose a seed phrase. Nobody legitimate will ever ask.
  • Use a hardware wallet for anything significant, and a separate low-value wallet for unfamiliar applications.
  • Review and revoke wallet approvals periodically.
  • Verify addresses in full, every character, before sending. Malware substitutes addresses in the clipboard.
  • Keep meticulous records, including every transaction hash.

PART THREE: Cryptocurrency Law Across the Arab World

There is no single Arab position on cryptocurrency. The region contains some of the world’s most advanced digital asset frameworks and some of its most categorical prohibitions sometimes a short flight apart. The same conduct that requires a licence in Dubai is a criminal offence in Cairo.

Overview: Three categories across ten jurisdictions

The regulated jurisdictions:

United Arab Emirates

The UAE has built what is widely regarded as one of the world’s most comprehensive digital asset frameworks. Its defining feature is that supervision is divided among several authorities, each with a defined lane.

In Dubai, the Virtual Assets Regulatory Authority (VARA) was created by Dubai Law No. 4 of 2022, making it the world’s first dedicated virtual assets regulator. It licenses and supervises virtual asset service providers across Dubai, excluding the DIFC free zone, and operates under Rulebook Version 2.0, in force since 19 June 2025. Licensable activities include exchange, broking, custody, lending, transfer, management and advisory services.

At federal level, virtual assets used for investment were historically supervised by the Securities and Commodities Authority under Cabinet Resolution No. 111 of 2022. That authority has been restructured into the Capital Market Authority, effective 1 January 2026. A cooperation arrangement means a Dubai VARA licence also secures federal registration, removing the former burden of dual licensing.

The Central Bank of the UAE regulates payment tokens under its Payment Token Services Regulation. Dirham-backed stablecoins fall exclusively under the Central Bank, and algorithmic and privacy-focused tokens are prohibited. Federal Decree-Law No. 6 of 2025 further expanded regulated financial activities to include the provision of payment services using virtual assets.

The DIFC (through the DFSA) and ADGM (through the FSRA) operate separate and respected regimes, favoured by institutional participants in custody, tokenisation and digital securities.

Cutting across all of this, Federal Decree-Law No. 10 of 2025 on combating money laundering and the financing of terrorism, with its executive regulation Cabinet Resolution No. 134 of 2025, brings virtual asset service providers within the scope of regulated reporting entities and strengthens the powers of the Financial Intelligence Unit, including suspension of transactions and freezing of suspected criminal proceeds. Where digital assets are stolen, Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes supplies the criminal backbone, covering unauthorised access, electronic fraud and obtaining funds by unlawful electronic means.

Bahrain

Bahrain moved first in the region. The Central Bank of Bahrain introduced its Crypto-Asset Module in February 2019, covering the licensing and supervision of crypto-asset exchanges together with trading, dealing, advisory, portfolio management and custody. The Module was amended in 2023 and in July 2025 a dedicated Stablecoin Issuance and Offering Module was added, addressing issuance, reserves and redemption. Bahrain’s practical advantage is institutional simplicity: a single regulator oversees the entire framework, in contrast to the UAE’s multi-authority structure.

Jordan

Jordan represents the most striking legal shift in the region. For roughly a decade, the Central Bank of Jordan effectively barred banks and financial institutions from dealing in cryptocurrency. That era has ended. Law No. 14 of 2025 Regulating Dealings in Virtual Assets was published in the Official Gazette on 16 June 2025 and took effect on 14 September 2025. The Jordan Securities Commission is the licensing and supervisory authority. Operating exchanges, broking, custody, transfer services and token issuance all require a licence.

Point to note:

The law does not expressly address personal, non-commercial dealing by individuals. Jordanian practitioners have identified this silence as a genuine ambiguity requiring clarification. Anyone operating commercially must hold a licence; personal dealing sits in uncharted territory.

The grey and partial jurisdictions

Saudi Arabia

Saudi Arabia occupies the region’s most consequential grey zone.

There is no comprehensive legislative framework. Cryptocurrency is not explicitly prohibited, and no provision criminalises personal ownership. But it enjoys no legal recognition, it is not legal tender, and it operates under a risk-averse posture maintained by the Saudi Central Bank (SAMA) and the Capital Market Authority, both of which have warned publicly about the risks of dealing in unregulated digital assets.

The practical consequences are significant. Financial institutions do not deal in crypto assets. There is no domestic licensed exchange and no local fiat on-ramp. Residents commonly access international platforms, but without any domestic consumer protection: if a platform fails or funds are stolen, there is no local regulator to whom recourse can be had.

The Kingdom is simultaneously active in blockchain infrastructure and central bank digital currency work, and a digital asset framework has been widely anticipated. Given the size of the market, its introduction would be the most consequential regulatory event in the region.

Oman

Oman is moving deliberately. The Capital Market Authority, now the Financial Services Authority, announced in February 2023 its intention to establish a comprehensive Virtual Assets Regulatory Framework covering crypto assets, tokens, exchanges and initial coin offerings, and issued a public consultation paper in July 2023. VASP registration requirements and AML/CFT controls have been introduced.

Two points require care. The Central Bank of Oman has repeatedly stated that it has licensed no entity to trade cryptocurrencies in Oman, and Omani currency law does not extend legal tender status to digital currencies. General law continues to apply, in particular the AML/CFT regime under Royal Decree No. 30 of 2016, whose broad definition of “funds” captures assets in electronic or digital form

Qatar

Qatar’s approach is frequently misunderstood, and the distinction is important.

Qatar Central Bank Circular No. 6 of 2018 prohibited financial institutions in Qatar from dealing in cryptocurrencies. In December 2019 the Qatar Financial Centre Regulatory Authority issued an alert prohibiting virtual asset services within or from the QFC.

In September 2024, the QFC Authority and the QFCRA jointly introduced the Digital Assets Regulations 2024 and the Investment Token Rules 2024. This is a genuinely sophisticated framework. It provides legal recognition for tokenisation, establishes property rights in tokens and underlying assets, addresses custody, transfer and exchange, licenses token service providers, and recognises smart contracts.

But the framework expressly defines “Excluded Tokens”, a category comprising cryptocurrencies, stablecoins and central bank digital currencies, on the basis that these function as currency substitutes. They fall outside the framework entirely.

The result: Qatar has built serious legal infrastructure for tokenising real world assets such as real estate and sukuk, while continuing to exclude cryptocurrency itself. For crypto exchange, payment or custody activity, Qatar is not open.

Lebanon

Lebanon presents the sharpest divergence between law and reality anywhere in the region.

There is no dedicated statute. The position rests on regulatory measures. Banque du Liban Notice No. 900 of 19 December 2013 warned banks and financial institutions against dealing in digital currencies. In 2018 the Capital Markets Authority prohibited licensed financial institutions from issuing, marketing or trading cryptocurrencies. Formal banking rails are therefore closed.

Individuals, however, are not criminalised for holding or using cryptocurrency, and no licensing regime exists to be complied with.

Following the banking collapse of 2019, deposit freezes and the collapse of the Lebanese pound, cryptocurrency became a practical necessity for a large part of the population. Dollar-pegged stablecoins, principally USDT, now function as a de facto medium of exchange and store of value, transacted through peer-to-peer markets, over-the-counter brokers and messaging-application groups. Authorities have exercised practical tolerance.

The general AML/CFT framework under Law No. 44 of 2015 continues to apply, supervised by the Special Investigation Commission, Lebanon’s financial intelligence unit, which holds powers to freeze assets.

The consequence for anyone transacting in Lebanon is stark. There is no regulator to complain to, no licence to verify, and no consumer protection. Official engagement with the sector has begun, but as matters stand Lebanon is unregulated rather than regulated.

 

Cross-border jurisdiction note:

Where legal disputes touch multiple jurisdictions — as is common in cryptocurrency matters involving Lebanon-based parties and UAE or European counterparties — the lis pendens principle may determine which court takes precedence. See our guide: fakhrylawfirm.com/what-is-the-lis-pendens-legal-principle/

The prohibited jurisdictions:

Egypt

Egypt maintains one of the clearest prohibitions in the region, grounded in statute rather than circular.

Article 206 of the Central Bank and Banking System Law, promulgated by Law No. 194 of 2020, prohibits issuing cryptocurrencies, trading in them, promoting them, and establishing or operating platforms for their circulation, without a licence from the Central Bank of Egypt. Penalties include imprisonment and substantial fines.

Two features make this a de facto blanket ban. The prohibition extends beyond trading to promotion and to operating platforms. And the Central Bank has issued no licences, meaning the licensing exception exists on paper only. The CBE has issued repeated public warnings, and Dar al-Ifta issued a non-binding religious ruling in 2018 declaring cryptocurrency transactions impermissible.

Adoption among the Egyptian population has nevertheless been substantial, driven by currency devaluation and inflation. This creates acute legal exposure, and means Egyptian residents who suffer crypto theft have no domestic framework within which to seek recovery.

Kuwait

Kuwait’s position is the most categorical in the Gulf.

On 17 July 2023 a coordinated set of instruments imposed what the authorities themselves described as an absolute prohibition on dealing in virtual assets. These comprised a circular from the Central Bank of Kuwait; Capital Markets Authority Circular No. 10 of 2023; Insurance Regulatory Unit Circular No. 6 of 2023; and Ministerial Circular No. 1 of 2023.

The prohibition is comprehensive. It bars the use of virtual assets as a means of payment, bars dealing in them as investments and the offering of related services, prohibits the issuance of licences for virtual asset services while confirming that none had ever been issued, and completely bans mining. Penalties under Article 15 of AML/CFT Law No. 106 of 2013 apply. The measures were expressly framed as strengthening compliance with FATF Recommendation 15.

Iraq

Iraq’s prohibition is directed principally at the financial system.

The Central Bank of Iraq first prohibited the use of cryptocurrencies by statement in 2017. The position was formalised through Circular No. 125/5/9 of 22 November 2021, barring banks, non-bank financial intermediaries and electronic payment service providers from dealing in virtual assets. A further directive of 26 March 2022 aligned the position with FATF recommendations, imposed enhanced due diligence, and prohibited the use of payment cards and electronic wallets for cryptocurrency transactions.

There is therefore no lawful on-ramp or off-ramp through the regulated Iraqi financial system, and crypto obligations are unlikely to be enforceable, the asset having no legal recognition.

No specific statute criminalises simple possession or peer-to-peer trading by individuals, leaving a genuine grey zone. But the general anti-money-laundering framework applies and enforcement has tightened, particularly in the Kurdistan Region. Anyone treating the absence of an individual prohibition as permission is taking a serious risk.

Frequently Asked Questions

What is cryptocurrency, in one sentence?

It is value recorded as entries on a shared public ledger, called a blockchain, which is maintained simultaneously by thousands of independent computers rather than by a single bank or institution.

Through an exchange, which is an ordinary company subject to law. You open an account, prove your identity, transfer money from your bank, and buy. The critical question is always which authority regulates that exchange.

No single person or company controls a major public blockchain. Nodes verify it, and miners or validators add new blocks. Anyone may become any of these without permission. Stablecoin issuers, however, are companies and can freeze specific addresses.

Nothing is lost. Your transaction waits, and another participant includes it in order to earn your fee. A miner cannot steal your funds, because they do not hold your private key.

Yes, for licensed operators. Virtual asset service providers in Dubai must hold a licence from VARA under Dubai Law No. 4 of 2022. The VARA Rulebook 2.0, in force from June 2025, governs exchange, custody, broking, lending and advisory services. Personal holding of cryptocurrency is not prohibited.

It is not prohibited for individuals, but it is not regulated or legally recognised. There is no domestic licensed exchange and no formal consumer protection framework. SAMA and the Capital Market Authority have both issued public warnings about the risks of dealing in unregulated digital assets.

Sometimes. Never guaranteed, but genuinely possible. The trail is permanent and public, and thieves must pass through regulated exchanges to convert crypto into spendable money. Stablecoins such as USDT can be frozen by their issuer. Success depends overwhelmingly on speed and on preserving transaction hashes immediately after the theft.

A transaction hash is the unique permanent fingerprint assigned to every cryptocurrency transaction. It is produced by running the transaction data through a mathematical function; change one character and the hash changes completely. In any theft or dispute, the transaction hash is the single most important piece of evidence. it anchors the entire chain of tracing.

A wallet is a pair of cryptographic keys, not a container of money. The public address (like an IBAN) receives value; the private key authorises spending. The cryptocurrency itself never leaves the blockchain — the wallet simply holds the key that can move it. Whoever holds the private key controls the funds absolutely.

An investment fraud is one in which the fraudster builds a genuine relationship with the victim over weeks or months before introducing a fake investment platform showing impressive returns. A small early withdrawal is permitted to build trust; then deposits grow until a large withdrawal is attempted and blocked. These operations are run at industrial scale, often by trafficked workers, and AI is now used to sustain contact at scale across multiple languages.

Stop sending any further funds. Preserve every transaction hash, wallet address, date and screenshot before anything else — fraudulent platforms disappear within days. Report to the relevant cybercrime authority immediately. In the UAE, notify VARA and consider alerting the stablecoin issuer if the asset is USDT. Instruct professional blockchain tracing as soon as possible. Time is the decisive factor in any recovery attempt.

A hot wallet is connected to the internet — convenient for frequent transactions but more exposed to hacking and phishing. A cold wallet is kept offline on a dedicated hardware device; it is substantially more secure and appropriate for any significant holding. Anything of real value should be stored in cold storage, with a separate hot wallet used only for small working balances.

In closing

Cryptocurrency is neither magic nor menace. It is a transparent system of digital value in which every movement is recorded permanently on a public ledger, making it substantially more traceable than the cash in your pocket. The technology has proved reliable. The risk lies almost entirely with the people and companies that surround it.

For businesses and investors across the Arab world, the legal position is the first question, not the last. In the UAE, Bahrain and Jordan, regulated participation is possible and increasingly institutional. In Egypt, Kuwait and Iraq, participation carries direct legal exposure. In Saudi Arabia, Lebanon, Oman and Qatar, the position is partial, evolving or silent, and silence offers no protection.

The correct approach is neither to fear this technology nor to chase it. It is to verify the regulator, verify the licence, preserve the evidence, and understand that the permanence of the blockchain is not a threat to be feared but the most powerful investigative instrument the financial system has ever possessed.

Continue the conversation

We are organising an online seminar examining cryptocurrency from a legal perspective: how these systems work, where liability sits, how regulators across the region are responding, and what businesses must do to participate lawfully.

If you would like to attend, please share your email address with us and we will send you the details. 

We would also be glad to hear from you if:

1- You have been the victim of a cryptocurrency fraud or theft. Time is the decisive factor in these matters. Preserve your transaction hashes and all correspondence, and seek advice quickly.

2- You are establishing or expanding a business involving virtual assets and need to identify the right jurisdiction, secure the correct licence, and build a compliance framework that will withstand supervision.

Speak With Our Team

 

Fakhry Law and Business Consultancy FZE advises businesses and individuals across the UAE, Lebanon and Saudi Arabia on digital asset matters, including regulatory compliance, licensing, fraud recovery and cross-border enforcement. Our team combines deep knowledge of UAE virtual asset law with practical experience of cross-jurisdictional disputes — the combination that matters when funds have crossed borders and time is short.

To discuss a cryptocurrency matter — whether a fraud, a compliance question, or a business establishing operations in a regulated jurisdiction — contact us at info@fakhrylawfirm.com or visit www.fakhrylawfirm.com.

This article is provided for general information only and does not constitute legal advice. The legal frameworks described are evolving rapidly across all ten jurisdictions. Specific laws, regulators and licensing statuses should be verified against official sources at the time of reliance. For advice on a particular matter, please consult a qualified legal professional admitted in the relevant jurisdiction.

Scroll to Top