
Part 3 of “RWA, Meet RWL: Knowing What You Own in the Tokenized World,” a multi-part series.
Part 1 looked at what the tokenized asset actually is. Part 2 looked at the data used to describe it. This part gets to the harder problem: the people and institutions responsible for reporting, checking, and acting on that information.
Let’s Start with Two Terms
We’ll often here about blockchain values like “Permissionless” and “Trustless.” These are somewhat decent terms for what they represent. Though as is often the case, what we’ve done is taken some words we’ve had handy and applied them to new things because we lacked anything more precise.
The words work, but there’s some nuance to them, so let’s clear this up before going further. In this context, “Permissionless” means that someone can participate in a network without first receiving approval from a central gatekeeper. That’s easy enough. Yes, there are “permissioned” blockchains that are different, but basically, you or I could find any one of several networks tomorrow and launch a little token based project without asking anyone for any permission at all. And we can participate in various existing decentralized activities without any permission. This doesn’t mean we’re not beholden to our local laws, taxes, etc. It just means no one can technically stop us.
Now, “Trustless” is a related but different claim. In its stronger sense, it means you do not have to rely on the honesty or competence of specific counterparties, specifically in terms of transaction completeness. Trustless is closely tied to transaction completeness / settlement finality. Not other aspects of things. Verification is handled by cryptography, consensus rules, and open code rather than by trusting people or institutions. So it’s not really that anything is trustless per se, more that you can supposedly operate some tools safely in an otherwise potentially trustless environment. Just because you don’t need permission to hold or transfer tokens or perform other actions does not mean you can stop worrying about whether underlying claims regarding what you might be trading are true. This strong form of trustlessness mainly applies to native on-chain assets (like BTC itself). As soon as you introduce real-world assets, the situation changes.

Let me try to put it this way…
- A token transfer may be trust-minimized.
- But the claim the token represents (ownership of a building, gold in a vault, a loan, an invoice, etc.) still depends on off-chain facts and institutions.
So the on-chain transaction can be complete and final, while the real-world meaning of that transaction still requires trust. That’s a distinction worth being clear about. The movement of the token can be relatively trust-minimized. The truth of what the token is supposed to represent usually is not.
So… You may not need permission to acquire or transfer a token. But you still need someone to confirm that the building exists, the title is valid, the gold is in the vault, the borrower is real, the invoice is legitimate, and the issuer has not pledged the same asset somewhere else. So blockchain does not eliminate trust. For a pure transfer of Bitcoin, the system comes reasonably close to trustless. For everything else, especially real-world assets, not so much. In many RWA structures, blockchain does not remove the need for trust; it just moves the trust boundary. Or, more accurately, it often creates yet another trust surface that has to be managed.
Now that this is all cleared up, let’s move on…
Reality of Lies & Fraud
Are all the bad guys really bad? Not necessarily. At least, maybe not at first. Let’s do a taxonomy of bad actors. This is where our deeper risk lies, for all of us, both individually and systemically. To be sure, there’s some other potential systemic risks in our financial world. We’ve seen them, right? But right now, we’re layering more stuff on top of more stuff. And then increasingly using autonomous agents to act on various triggers. The speed with which things can happen is only going to get faster. And could be anytime. So bad actors might increasingly have asymmetrically more powerful impact than ever before; whether by accident or on purpose. Collectively, we’re going to need to deal with such things more decisively. Because the cascading risks potentially magnify like never before.
So let’s look at a taxonomy of “bad” as I’m going to loosely define it.

Not Really Bad, Until They Are
These types of individuals aren’t evil. They may end up doing some bad things with good intent, or out of personal fear. Or just things got away from them a bit. Someone makes a mistake. A project runs over budget. A property develops a serious problem. Inventory disappears. An investment goes bad. A company misses its numbers. And so on. Insert your own scenario. Shtuff happens, right?
Responsible people could report what happened, take the loss, and deal with the consequences. Or they could convince themselves that the problem is temporary. Most people most likely do the right thing here. We hear all about it in management, right? Speak up early. Deal with it. I’m not sure if there’s any studies on how often normal people just do the right thing every day. And after all, they don’t typically make the news.
Others though, might bury things, at least for awhile. Maybe next quarter will be better. Maybe the investment will recover. Maybe the missing money can be replaced. (This is the one that appears to be among the most dangerous.) Maybe the repairs can wait. Maybe no one will notice. Maybe the company can borrow enough to get through it. (Maybe I can double-triple down on something risky and recover myself and no one will ever have to know.) And guess what? We also don’t really know how many get away with this. There’s probably no good way to even study it. But how many folks maybe did get lucky and pull themselves out of a death spiral?
So maybe in these situations, someone delays a report. Changes a number. Backdates a document. Moves money from one account to another. Tells an auditor that the supporting records are coming and reassure customers that everything is fine.
They may not have started out intending to commit fraud. But at some point, recovering from the mistake becomes less important than hiding it. Things start piling up. And it may become a matter of something no longer being just a mistake, but either a desire to hide a very real serious problem or just avoid siple shame. Either way, the cover-up becomes the business.

I think we’ve all seen this sort of thing on occasion. And we maybe even have some degree of empathy here. Someone – as they say – got a bit ahead of their skis. (Well, those of us who like to ski may say that anyway, but you get the idea.) We even have a legal system that usually accounts for this. That is, intent matters. Or at least it can both in terms of verdicts, offered deals, or sentences.
Incentive-Blinded
Next, we also a large category of people who may not think they are lying at all. They are arguably “not evil” either, just also not quite as innocent.
Their compensation depends on a valuation. Maybe their company needs another funding round. Their property needs to maintain a certain occupancy rate and they’re really, really close to it. If you just count in a certain way, that threshold is kind of valid, right? Maybe a loan requires a minimum debt-service ratio. Their token needs to remain fully collateralized. Their fund cannot afford to report a major write-down. One time, I was working with a real estate broker. And he told me something about a deal I was working on. He did it to try to give me an advantage. He was “on my side.” At least, I think that’s what he thought he was signaling. But what he was really signaling is that he couldn’t be trusted. Could I have used the information to my benefit? Probably. Was it illegal? I’m not even sure; I think it was on the edge. Would anyone have known? Probably not. But leaving aside just pure ethics, maybe I’d have started down that path to the dark side and things could unravel. It might be hard to avoid such things, because the little steps seem so innocuous, so little, not really of any consequence at all. But sometimes, such things tend to cascade. So I bowed out of this one. Is it because I’m personally some paragon of virtue? Hardly. I’ve made mistakes of course. But my lesson from them was to trust that sense of “bad smell” for something. I think maybe for most of us, we get a bit lucky if we’ve had a bad experience or two. The lucky part is it’s something bad enough to hurt us enough that we can be sensitive to something, but not quite bad enough to do permanent damage.
Once upon a time, I was helping build out a sales team. And someone asked me who I was looking for. (Forgive me if you’re heard this because I think I wrote about this one.) I said, “I want a guy in his 40s with two kids in school, a mistress and either or both a drug and gambling problem. THAT guy is motivated to sell!” Of course, this was meant sarcastically. You don’t want that. That’s a perfect example of someone who will be incentivized by all the wrong things, and probably do the kinds of wrong things that would lead to large problems. But you see the point. Incentives can be subtle.
So assumptions become more optimistic. Exceptions become normal. Appraisals stretch. Expenses get classified creatively. Bad debts remain “temporarily delayed.” Models are adjusted until they produce an acceptable answer. And it’s hard to back out. Have you ever watched one of those cop shows where someone outright lies to an officer, then they get shown a video, and they still say, “well, that’s not true.” Is it because they really believe it? Maybe that’s even the case. Maybe their brain just won’t let them because the pain of the shame is worse than what might be about to happen to them. I don’t know.
Most of us may be able to point to a spreadsheet, policy, appraisal, smart contract, or expert opinion supporting a number. That does not make the number true. Sometimes fraud begins with an explicit lie. Other times though, it begins with an individual or whole organization slowly deciding not to not raise and hand and question something or to not ask difficult questions.
Intentionally Bad
Then there are the easy ones to classify. Outright fraud. Intentional. And we’ll just leave very large scale State actors out of this one for now. That’s it’s own special topic.
Here, in these cases, maybe the asset never existed. The contract was completely fabricated. The same collateral was pledged several times. Customer money was diverted. The audit confirmation was forged. The warehouse contained rocks instead of metal. The reported revenue was invented. Let me pick on one of these a bit more, “The same collateral was pledged several times.” You know, one issue with tokenization or anything representing something else is that if not careful, it could be used and re-used in unknown ways. And that can be hard to detect. And there’s this idea of “rehypothecation” where an asset may legitimately be used to back up multiple claims. That might even be perfectly legal, but also not smart in some cases. Or riskier. Which is maybe fine, but is it still fine if the relationship and risk is obscured from those who may have investments in assets along such dependent chains? What blockchain oracle can report on this when even the real world contracts for such things are obscured behind multiple shell companies and arcane or even hidden contractual and banking relationships? The point is, tokenization adds a layer to whatever the asset is. Did anything get added or removed to the legal relationship of “the thing” that changes the nature of it in ways that are unclear?

Regardless of the circumstances, in this category of outright intentionality, these people were not unlucky. They were not overly optimistic. They were lying. They are lying. And they know it.
By the way, one challenge in some areas of tokenization is some behaviors detrimental to investors might not even be illegal. At least not yet. They may be unethical, but since tokenization is developing faster than some legal and regulatory frameworks, so there are genuine gray areas. IOSCO’s 2025 tokenization report identifies unresolved or developing concerns involving investor protection, conflicts of interest, asset ownership, settlement, custody, disclosure, and operational responsibility. BIS has similarly noted continuing legal, governance, and regulatory uncertainty around tokenized assets.
By the way, some behavior detrimental to token holders may not even be clearly illegal. At least not yet, and not under a rule written specifically for tokenization. It may be unethical, misleading, or plainly hostile to investors while still sitting in a regulatory gray area. Of course, “there isn’t a token rule for this yet” does not mean existing fraud, securities, contract, or consumer-protection laws disappear. It may simply mean no one knows exactly which law applies until a regulator, court, or bankruptcy judge finally decides. IOSCO’s 2025 tokenization report identifies unresolved or developing concerns involving investor protection, conflicts of interest, asset ownership, settlement, custody, disclosure, and operational responsibility.
The Watchers and Enablers
There is one more category that matters: the people who were supposed to be watching. Who are supposed to be watching. These include boards, auditors, banks, appraisers, rating agencies, regulators and I’m sure we could add more categories.
Most are not necessarily participants in the fraud. But they may be inattentive, conflicted, underfunded, overly deferential, deliberately narrow in their work, or dependent on information supplied by the same people they are supposed to evaluate. Some do exactly what their contract requires and nothing more. Some notice warning signs but conclude that investigating further is someone else’s responsibility. Some are paid by the organization being examined. Some are simply fooled.
This is all a fairly simple as a taxonomy. The harder part is figuring out which kind of actor you are dealing with before anything collapses.
The Missing Reality Audit
Here is where RWA still fails completely. It’s in the idea of a continuous, reliable audit of real-world reality.
For traditional and generally fungible financial assets, the problem may be somewhat more manageable. Public securities, bank deposits, government bonds, and exchange-traded commodities operate within mature systems of registries, custodians, clearinghouses, auditors, regulators, and standardized reporting. And even with all this, sometimes these systems fail.
For physical assets, especially unique assets such as real estate, machinery, aircraft, art, stored commodities, and infrastructure, we are not there yet. I would argue that we’re not even close.
Oracles matter as technical infrastructure. So do Onchain records, tamper-resistant logs and similar. None of them solves the underlying truth problem.
A blockchain can establish that a particular piece of information was submitted, by a particular source, at a particular time. It can make that submission difficult to alter later. A smart contract can then act on it automatically. But the blockchain cannot climb into a warehouse and count the gold. And not only can it not inspect an apartment building, but how would it determine an evaluation. Yes, maybe one day some IoT sensors or robots could help. Still, it cannot determine whether a tenant exists, whether a lease has an undisclosed side agreement, whether the roof is failing, whether an appraisal was manipulated, or whether the property manager quietly stopped reporting delinquent rent. Maybe some of these things could be technically tracked, but they’re not yet. Take delinquent rent. How? You’d need banking access plus clear identification of a tenant’s particular payment.
As the Bank for International Settlements explains in its discussion of the oracle problem, smart contracts can execute using externally supplied information regardless of whether that information is accurate. That’s the difference between data integrity and reality integrity.

The data may be delivered perfectly, but the reality behind it may still be false, intentionally or not.
Permissionless Does Not Mean Trust-Free
Once upon a time, many people were born, raised, worked, and died within a handful of miles of the same town. We didn’t need elaborate worldwide credit and reputation systems. People generally knew whose word was good, who paid their debts, who did competent work, and who should not be trusted with the church picnic money.
That system had plenty of problems of its own, of course. But it did contain a kind of continuous local reputation audit.
As society became more mobile and commerce became national and then global, we replaced local knowledge with institutions. Banks, accounting firms, credit bureaus, courts, regulators, insurers, title registries, professional licenses, inspections, certifications, and corporate reporting all became proxies for personal familiarity.
Then we invented this blockchain thing and, perhaps ironically, described some of it as permissionless.
Permissionless means that someone can participate in a network without first receiving approval from a central gatekeeper. It does not mean that every real-world claim presented through that network is true.
You may not need permission to acquire or transfer a token. But you still need someone to confirm that the building exists, the title is valid, the gold is in the vault, the borrower is real, the invoice is legitimate, and the issuer has not pledged the same asset somewhere else.
So blockchain does not eliminate trust. Okay, for a transfer of Bitcoin, perhaps. For everything else? No so much. In many RWA structures, blockchain just moves the trust boundary. Or maybe just creates yet another trust surface area with which to contend.
Next in the series: Part 4 looks at several uncomfortable examples of what happens when those trust structures fail, even when auditors, regulators, custodians, exchanges, or other supposed watchers are present.