TetraMesa

  • About Us
  • Services
  • Clients
  • Contact
  • Blog

RWA, Meet RWL, Part 3: Permissionless Does Not Mean Trust-Free

July 24, 2026 By Scott

Part 3 of 6 in “Real World Assets (RWA), Meet Real World Lies (RWL): Knowing What You Own in the Tokenized World,” a series about what tokenized assets represent, how information about them reaches the blockchain, and why none of this eliminates the need for trust.

Parts 1 and 2 examined the underlying assets and the data used to describe them. Now we turn to the people and institutions responsible for that information.

Before getting into that, it’s worth clearing up two terms that tend to get used somewhat loosely.

Permissionless and Trustless Aren’t the Same Thing

We’ll often hear about blockchain values like “Permissionless” and “Trustless.” They’re decent terms for what they’re trying to express. Though what we’ve done is taken some words we’ve had handy and applied them to new things because we lacked anything more precise.

In this context, “Permissionless” means that someone can participate in a network without first receiving approval from a central gatekeeper. There are “permissioned” blockchains that are different, but basically, you or I could find any one of several networks tomorrow and launch a token based project without asking anyone for permission. And we can participate in various existing decentralized activities without any permission. This doesn’t mean we’re not beholden to our local laws, taxes, etc. It just means no one can technically stop us.

Now, “Trustless” is a related but different claim. In its stronger sense, it means you do not have to rely on the honesty or competence of specific counterparties, specifically in terms of transaction completeness. Trustless is closely tied to transaction completeness / settlement finality. Verification is handled by cryptography, consensus rules, and code rather than by people or institutions. So it’s not that anything is trustless per se, more that you can supposedly operate some tools safely in an otherwise potentially trustless environment. Just because you don’t need permission to hold or transfer tokens or perform other actions does not mean you can stop worrying about whether underlying claims regarding what you might be trading are true. This strong form of trustlessness mainly applies to native on-chain assets (like BTC itself). As soon as you introduce real-world assets, the situation changes.

Let me try to put it this way…

  • A token transfer may be trust-minimized.
  • But the claim the token represents (ownership of a building, gold in a vault, a loan, an invoice, etc.) still depends on off-chain facts and institutions.

So the on-chain transaction can be complete and final, while the real-world meaning of that transaction still requires trust. That’s a distinction worth being clear about. The movement of the token can be relatively trust-minimized. The truth of what the token is supposed to represent usually is not.

So… You may not need permission to acquire or transfer a token. But you still need someone to confirm that the building exists, the title is valid, the gold is in the vault, the borrower is real, the invoice is legitimate, and the issuer has not pledged the same asset somewhere else. Blockchain does not eliminate this need for trust. For a pure transfer of Bitcoin, the system comes reasonably close to trustless. For everything else, especially real-world assets, not so much. It just moves the trust boundary. Or, more accurately, it often creates yet another trust surface that has to be managed.

Reality of Lies & Fraud

Are all the bad guys really bad? Not necessarily. At least, maybe not at first. Let’s do a taxonomy of bad actors. This is where our deeper risk lies, for all of us, both individually and systemically. To be sure, there’s some other potential systemic risks in our financial world. We’ve seen them, right? But right now, we’re layering more stuff on top of more stuff. And then increasingly using autonomous agents to act on various triggers. The speed with which things can happen is only going to get faster. And could be anytime. So bad actors might increasingly have asymmetrically more powerful impact than ever before; whether by accident or on purpose. Collectively, we’re going to need to deal with such things more decisively. Because the cascading risks potentially magnify like never before. And this is just with people; before we add in an AI agent or swarm of them getting up to some mischief, whether intentional or by accident.

So let’s look at a taxonomy of “bad” as I’m going to loosely define it.

Not Really Bad, Until They Are

There’s a category of people who didn’t begin with criminal intent. They got ahead of their skis, panicked, and made increasingly bad decisions while trying to avoid a loss, embarrassment, or professional failure.

Someone doesn’t immediately report a problem because they want enough time to understand it. Someone delays an announcement because a financing deal might solve the issue. Someone tells themselves that changing one assumption is defensible because the original estimate was uncertain anyway. Responsible people could report what happened, take the loss, and deal with the consequences. Or they could convince themselves that the problem is temporary. They may not have started out intending to commit fraud. But at some point, recovering from the mistake becomes less important than hiding it. Either way, the cover-up becomes the business.

Regardless, investors may not care much about that distinction after the money is gone.

Incentive-Blinded

Next, we also a large category of people who may not think they are lying at all. They are arguably “not evil” either, just also not quite as innocent.

Their compensation depends on a valuation. Maybe their company needs another funding round. Their property needs to maintain a certain occupancy rate and they’re really, really close to it. If you just count in a certain way, that threshold is kind of valid, right? Their token needs to remain fully collateralized. Their fund cannot afford to report a major write-down.

So assumptions become more optimistic. Exceptions become normal. Appraisals stretch. Expenses get classified creatively. Bad debts remain “temporarily delayed.” Models are adjusted until they produce an acceptable answer. And it’s hard to back out.

Sometimes fraud begins with an explicit lie. Other times though, it begins with an individual or whole organization slowly deciding not to not raise and hand and question something or to not ask difficult questions.

Intentionally Bad

This one is easy to classify. Outright fraud. Intentional. And we’ll just leave very large scale State actors out of this one for now. That’s it’s own special topic.

In these cases, maybe the asset never existed. The contract was completely fabricated. The warehouse contained rocks instead of metal. The same collateral was pledged several times. One issue with any representation of an asset, including a token, is that the same underlying claim can be pledged or re-used in ways that are hard to detect, especially when contracts sit behind multiple entities. Tokenization adds another layer; it does not automatically make those overlapping claims visible.

Regardless of circumstances, in this category of outright intentionality, these people are lying. And they know it.

By the way, one challenge in some areas of tokenization is some behaviors detrimental to investors might not even be illegal. At least not yet. They may be unethical, but since tokenization is developing faster than some legal and regulatory frameworks, so there are genuine gray areas. IOSCO’s 2025 tokenization report identifies unresolved or developing concerns involving investor protection, conflicts of interest, asset ownership, settlement, custody, disclosure, and operational responsibility. BIS has similarly noted continuing legal, governance, and regulatory uncertainty around tokenized assets.

The Watchers and Enablers

There is one more category that matters: the people who are supposed to be watching. These include boards, auditors, banks, appraisers, rating agencies, regulators and I’m sure we could add more categories.

Most are not necessarily participants in the fraud. But they may be inattentive, conflicted, underfunded, overly deferential, or dependent on information supplied by the same people they are supposed to evaluate. Some follow their contract requires and nothing more. Some notice warning signs but do nothing. Some are paid by the organization being examined. Others are simply fooled.

The Missing Reality Audit

Here is where RWA still fails completely. It’s in the idea of a continuous, reliable audit of real-world reality. In fairness, this is just my opinion based on admittedly incomplete overall marketplace information. I’m sure there’s areas where this is getting fixed. But we sure don’t have it worked out yet. And there is also – again, my opinion – a need to more fully solve clarity around issues of identity as a prerequisite. After all, who cares about an audit if you can’t know who’s providing it and their credibility?

For traditional and generally fungible financial assets, the problem may be more manageable. Public securities, bank deposits, government bonds, and exchange-traded commodities operate within mature systems of registries, custodians, clearinghouses, auditors, regulators, and standardized reporting. And even with all this, sometimes these systems fail.

For physical assets, especially unique assets such as real estate, machinery, aircraft, art, stored commodities, and infrastructure, we are not there yet with established data flows. I would argue that we’re not even close. And again, maybe I’m overstating this. There are a variety of companies now trying to wrestle with these complicated chains of evidence. So there’s progress. It’s happening. But at least for now, if looking at having a go with some of these things, you’re own diligence had likely be a bit more hands on until it’s all worked out.

Oracles matter as technical infrastructure. So do Onchain records, tamper-resistant logs and similar. None of them solves the underlying truth problem.

A blockchain can establish that a particular piece of information was submitted, by a particular source, at a particular time. It can make that submission difficult to alter later. A smart contract can then act on it automatically. But the blockchain cannot climb into a warehouse and count the gold. And not only can it not inspect an apartment building, but how would it determine an evaluation. Yes, maybe one day some IoT sensors or robots could help. Still, it cannot determine whether a tenant exists, whether a lease has an undisclosed side agreement, whether the roof is failing, whether an appraisal was manipulated, or whether the property manager quietly stopped reporting delinquent rent. Maybe some of these things could be technically tracked, but they’re not yet. Take delinquent rent. How? You’d need banking access plus clear identification of a tenant’s particular payment.

As the Bank for International Settlements explains in its discussion of the oracle problem, smart contracts can execute using externally supplied information regardless of whether that information is accurate. That’s the difference between data integrity and reality integrity.

The data may be delivered perfectly, but the reality behind it may still be false, intentionally or not.

Final World on Permissions & Trust

Once upon a time, most people were born, raised, worked, and died within a handful of miles of the same town. We didn’t need elaborate worldwide credit and reputation systems. People generally knew who’s word was good, who paid their debts, who did competent work, and who should not be trusted with the church picnic money.

That system had plenty of problems of its own, of course. But it did contain a kind of continuous local reputation audit. As society became more mobile and commerce became national and then global, we replaced local knowledge with institutions. Banks, accounting firms, credit bureaus, courts, regulators, insurers, title registries, professional licenses, inspections, certifications, and corporate reporting all became proxies for personal familiarity.

Then we invented blockchain. Permissionless participation does not make the underlying real-world claims trust-free. The need for reliable information and accountable counterparties remains.

Part 1 classified the underlying assets and rights. Part 2 classified the information needed to describe them and the sources from which that information may come. This article looked at the people and institutions responsible for reporting, checking, and acting on that information.

Part 4 looks at several uncomfortable examples of what happens when those trust structures fail, even when auditors, regulators, custodians, exchanges, banks, boards, or other supposed watchers are already present.

AI Disclosure: I used AI to help with these articles. The concepts are mine. The opinions and assertions are mine; though of course not necessarily unique. The drafts are mine. AI is used for spell/grammar check and sometimes to fill out a few example bullet points I may have missed, and – just as with search – find relevant references. Any additional claims that an AI may insert are manually checked and edited by me. All reference sources are manually checked by me. (Most were actually known prior to draft and may have even be the inspiration behind some articles.) Perhaps obviously, I’ll also use AI tools to generate graphics.

Filed Under: Crypto

Recent Posts

  • The Interface Taxonomy Beyond APIs (2 of 5)
  • Product Leader Mental Models of Connectivity Beyond APIs (1 of 5)
  • Poor PMs Guide to AI Image Generation Workflow With n8n
  • The Tokenization Taxonomy: A Practical Map of Assets, Rights, Services, and Credentials
  • RWA, Meet RWL, Part 6: The Token Is Not the Thing

Categories

  • Analytics
  • Book Review
  • Crypto
  • Marketing
  • Product Management
  • Tech / Business / General
  • Travel
  • UI / UX
  • Uncategorized

Location

We're located in Stamford, CT, "The City that Works." Most of our in person engagement Clients are located in the metro NYC area in either New York City, Westchester or Fairfield Counties, as well as Los Angeles and San Francisco. We do off site work for a variety of Clients as well.

Have a Project?

If you have a project you would like to discuss, just get in touch via our Contact Form.

Connect

As a small consultancy, we spend more time with our Clients' social media than our own. If you would like to keep up with us the rare times we have something important enough to say via social media, feel free to follow our accounts.
  • Facebook
  • LinkedIn
  • Twitter

Copyright © 2026 · TetraMesa, LLC · All Rights Reserved