India Taxes Crypto. But Who Is Accountable When Things Go Wrong?

Experts say India's crypto laws remain fragmented despite growing adoption.
When WazirX was hit by one of India's largest cryptocurrency hacks in 2024, resulting in the theft of crypto assets worth around USD 230 million from one of its multisignature wallets, thousands of users found themselves asking a question that Indian law has yet to answer convincingly: if a crypto exchange loses customer assets, who is legally responsible? As the platform entered a restructuring process and litigation unfolded across jurisdictions, the episode exposed a gap that extends beyond cybersecurity or blockchain technology.
India has steadily built rules to tax, monitor and scrutinise virtual digital assets (VDAs), but it has not yet developed a comprehensive legal framework defining the rights of investors or the duties owed by crypto businesses that hold their assets.
This gap also helps explain why the Reserve Bank of India (RBI) has remained firmly opposed to legalising private cryptocurrencies.
Much of the public debate has focused on the central bank's concerns over monetary sovereignty, financial stability and capital flows. However, the absence of a legal architecture governing the relationship between crypto businesses and their customers presents another challenge. Without clear rules on custody, accountability and investor protection, recognising crypto within the formal financial system raises questions that extend well beyond the technology itself.
In India, the legal identity of crypto remains unsettled.
As Anirudh Rastogi, Founder of Ikigai Law, points out, India still lacks a statutory characterisation of crypto assets outside the Income-tax Act.
"The vacuum is being filled by courts to some extent, not Parliament. We know what it is not. It is not currency or legal tender (settled since IAMAI v. RBI and repeated by the RBI); it is likely not a 'security' unless a specific token is structured or notified to fall within section 2(h) of the SCRA, which no general instrument does," Rastogi says.
More importantly, he argues, there is no dedicated market regulator or legal framework prescribing standards for crypto businesses. The Prevention of Money Laundering Act (PMLA) framework provides the compliance backbone for anti-money laundering purposes, but it was never designed to function as a market conduct regulator.
That distinction is crucial. Anti-money laundering laws require exchanges to identify customers, maintain records and report suspicious transactions. They do not prescribe how customer assets should be safeguarded, whether they must be segregated from the exchange's own assets, what capital requirements an exchange should maintain, how proof of reserves should be verified, or what remedies customers have if assets are lost or mismanaged. Nor do they establish a comprehensive mechanism for addressing market manipulation, governance failures or investor grievances.
The WazirX episode brought these questions into sharp focus. The resulting litigation highlighted how difficult these questions become when the legal framework itself remains underdeveloped.
Anu Tiwari, Head - Fintech & Financial Services Regulatory, Senior Director- Cyril Amarchand Mangaldas, Singapore, notes that lawyers advising clients today rely on a patchwork of laws rather than a dedicated crypto statute. Depending on the issue involved, they turn to the Income-tax Act, PMLA, the Information Technology Act, the Consumer Protection Act and Foreign Exchange Management Act (FEMA).
While this patchwork may address specific disputes, Tiwari identifies decentralised finance (DeFi), crypto derivatives and cross-border transactions as some of the most significant unresolved legal issues.
These developments challenge traditional regulatory assumptions built around identifiable intermediaries and territorial transactions, making it increasingly difficult to apply conventional legal principles without specific legislative guidance.
India is not alone in confronting this dilemma. Countries that initially adopted restrictive approaches have also discovered that limiting crypto activity does not necessarily eliminate the legal questions it creates.
Nigeria's banking restrictions pushed much of the market towards peer-to-peer transactions rather than curbing demand, prompting policymakers to gradually move towards a more comprehensive regulatory framework.
Even China, despite maintaining one of the world's strictest prohibitions on cryptocurrency trading, continues to grapple with offshore crypto activity and the regulatory challenges that accompany it.
The experience of these jurisdictions suggests that while restrictions may address certain macroeconomic concerns, they do not, by themselves, resolve questions of investor protection, accountability or legal certainty.
Other jurisdictions have instead attempted to answer these questions through dedicated legislation.
The European Union's Markets in Crypto-Assets (MiCA) Regulation imposes obligations on crypto-asset service providers relating to custody, governance, disclosure and the safeguarding of customer assets.
Singapore has similarly strengthened oversight of digital payment token service providers through licensing and customer protection measures.
These frameworks do not eliminate the risks associated with cryptocurrencies, but they seek to define, before a crisis occurs, who owes duties to investors and what standards those entities must meet.
For Indian policymakers, the next chapter of the crypto debate is no longer simply about whether private cryptocurrencies should be legalised. It is about whether an ecosystem that is already taxed, monitored and actively used by millions can continue without clearly defining the legal responsibilities of those who hold, manage and safeguard investor assets.
Until that question is answered, every major crypto dispute, from WazirX today to the next unforeseen crisis, will continue to test the limits of a legal framework that remains a work in progress.
