RWA tokenization issues an onchain token that represents a legal claim on an off-chain asset: a Treasury bill, a fund unit, a loan book, a building. The asset stays with a custodian and the claim on it settles onchain. The token does not produce the return; the underlying asset does. That is why the legal wrapper around the claim, not the smart contract, is the part that decides whether the design holds.
The token contract is the last decision, not the first. The wrapper, the custodian and the transfer-restriction rules fix what the token can legally be and who is allowed to hold it, and all three are settled before a line of Solidity is worth writing.
Scroll to see the full diagram
What actually moves onchain, and what does not
Nothing physical moves. A Treasury bill sitting in a custody account stays in that custody account. What tokenization creates is a transferable record of a claim on that asset, held in a smart contract instead of on a transfer agent's ledger, and settled by a state change on a blockchain instead of by a book entry two days later.
That distinction sets the whole design. The token inherits its economics from the underlying: a tokenized Treasury fund yields what Treasuries yield, minus fees, and a tokenized loan pool pays what the borrowers pay. Tokenization changes distribution, settlement and transferability. It does not manufacture return. An RWA design that needs a token-layer yield mechanism to look attractive is telling you the underlying asset is not carrying its weight, and that is a business problem, not a mechanism problem.
The wrapper decides the regime before the contract does
Before the token exists, someone has to answer a legal question: what is the holder actually holding? An equity interest in a fund. A note. A beneficial interest in a trust. A direct property right. The answer is written into offering documents and entity formation, not into Solidity, and it decides which regulator has jurisdiction over the thing you just built.
In the EU that boundary is drawn in statute. MiCA does not apply to crypto-assets that qualify as financial instruments, deposits or funds, which means a tokenized bond or fund unit stays under MiFID II and existing EU securities law rather than entering the MiCA regime at all.1 Getting that call wrong is expensive in either direction: a crypto-asset compliance program built for an instrument that was a security the whole time, or securities machinery bolted onto something that was not.
The harder question is what the claim is worth when the issuer fails. The BIS Committee on Payments and Market Infrastructures put it directly in its 2024 report to the G20: legal risk in token arrangements arises because the application of existing law to tokens is not clear or certain, and questions may arise as to whether certain tokenised assets reflect a legal claim or property right at all.2 The same report notes that protections attached to conventional transactions, such as the automatic bankruptcy stay covering US repo, may not extend to tokenised versions of those transactions.2
In our view this is the most under-priced risk in the category. Bankruptcy remoteness is not a feature you switch on in a contract. It is an outcome of entity structure, asset segregation and the insolvency law of one specific jurisdiction, and it gets tested per jurisdiction, not per protocol.
Scroll to see the full diagram
Custody, the transfer agent, and the attestation gap
Two roles get conflated constantly. The custodian holds the asset. The transfer agent maintains the register of who owns the claim and is the party that mints and burns. In BlackRock's BUIDL those are Bank of New York Mellon and Securitize respectively, with PricewaterhouseCoopers as auditor.6 Three counterparties, three separate failure surfaces, and a founder should be able to name all three for their own structure.
The gap that keeps opening in this category is between what an issuer says is backing the token and what the reserve actually holds. The CFTC's October 2021 order against Tether and Bitfinex is the documented version: fines totalling $42.5 million, $41 million of it against Tether, over claims that the stablecoin was fully backed by US dollars.5 The contract worked exactly as written. The representation about what sat behind it did not match.
So the attestation question is not whether reserves are attested. It is at what frequency, by whom, against what standard, and what a holder can do on the day the attestation and the token supply disagree. Monthly attestation on a daily-redeemable token is a thirty-day blind window by construction, and that window is where the whole design either holds or does not.
Transfer restrictions are the token design
Permissioned tokens are the norm in institutional RWA issuance, and the two standards in real use handle it differently. ERC-3643, the T-REX standard, requires the token to be used together with an onchain identity system and states that it must be able to apply any rule of compliance required by the regulator or by the token issuer.3 Every transfer is checked against an identity registry and a compliance contract before it settles, and the issuer retains freeze, pause, forced-transfer and recovery powers.
ERC-1400 takes a partition-based approach. The specification splits a holder's balance into partitions, each carrying its own metadata and its own transfer restrictions, and the worked case it gives is a balance divided between tokens issued in the primary issuance and tokens received through secondary trading.4 It is an umbrella rather than a single interface, pulling together differentiated ownership with transparent restrictions, onchain restriction checking with error signalling, off-chain data injection for transfer restrictions and issuance and redemption semantics, document and legend management, and controller operations covering forced transfer. That is how one token ends up carrying a US Reg D lockup in one partition and a freely tradable block in another. One terminology warning, because older write-ups will trip you up: the specification as it now reads uses partition throughout and never uses the word tranche, which was the wording of the 2018 draft discussions before the rename.4 Worth knowing too that ERC-1400 is a de facto standard maintained outside the formal EIP process rather than a merged, numbered EIP, so treat it as widely adopted rather than canonical.
Both paths carry the same cost, and it is the one founders discover late. A token that reverts on transfer to an unverified address cannot sit in a permissionless AMM pool, cannot be posted as collateral in a lending market that knows nothing about your identity registry, and cannot cross a generic bridge. You are choosing your distribution surface at the same moment you choose your compliance stack. Write down the venues you actually need before you pick the standard, not after.
BUIDL end to end, with the numbers
The BlackRock USD Institutional Digital Liquidity Fund is the most fully documented lifecycle in the category, so it is worth walking as published. An investor completes KYC and AML checks through Securitize, the transfer agent. Funds wired and confirmed by 2:30 PM ET result in BUIDL tokens minted to that investor's whitelisted wallet. The fund is a British Virgin Islands entity offered under the US Securities Act Reg D exemption, with Bank of New York Mellon as custodian.6
Redemption runs the same path in reverse. The holder files a redemption request through Securitize, and the tokens have to arrive in the transfer agent's redemption wallet by 3:00 PM ET. The transfer agent then instructs the USD or USDC wire and burns the matching tokens.6
The scale is real. BUIDL's total asset value read $2,673,461,059 on 3 August 2026, up close to 20% against the prior thirty days, on a dashboard that updates continuously.6 Read that as a point-in-time figure rather than a fixed market constant; it will be a different number by the time you check it.
Now count the onchain surface in that lifecycle. Mint, transfer, burn. The identity check, the wire, the cutoff windows, the NAV strike and the custody are all off-chain and contractual. That ratio is what people mean when they say RWA tokenization is mostly a legal product with an onchain settlement layer attached, and it is the reason the diligence budget should follow the wrapper rather than the repository.
Redemption is where the structure gets tested
Every RWA token carries a price that originates off-chain: a NAV strike, a servicer's loan tape, an appraisal. Whatever publishes that number onchain is an oracle whether or not anyone calls it one, and it introduces three specific exposures. Staleness between strikes. A single privileged writer who can be wrong or compromised. And an open question about what the contract does when the feed simply stops.
Staleness is structural and needs no attacker to hurt. If NAV strikes daily and the token trades continuously, there is a window every day in which the onchain price is a historical number. For a Treasury fund that window is close to harmless. For tokenized private credit, where the underlying can be marked at par right up until the borrower misses, the same window is a real mispricing surface.
The second test is capacity. Redemption requests arrive at blockchain speed. The underlying settles at whatever speed the underlying settles at. If the redemption promise is faster than the liquidation cycle of the asset behind it, you have built a maturity mismatch and labelled it a feature. Honest designs state a cutoff, a settlement window and explicit gating conditions in the offering documents, rather than discovering all three under pressure.
We have not found a court-documented case of a NAV oracle failure inside a tokenized security. That absence is not reassurance. The category is young, and most of these structures have not been through a default cycle in tokenized form yet.
What we tell founders to settle first
Five decisions, in this order, before any contract work starts. What the claim is legally, and which entity in which jurisdiction issues it. Who custodies the asset and who acts as transfer agent, and whether those are the same party (they should not be). Which transfer-restriction standard, chosen against a written list of the venues you need to reach. What the redemption mechanics are, including cutoff, settlement window and gating. And what the attestation cadence is measured against the redemption cadence.
Reverse that order and you get the pattern we see most often: a finished token contract, a custody relationship signed in a hurry to fit it, and a legal wrapper reverse-engineered around choices that were already locked. The contract was the cheap part of the build. The wrapper is the product.
One caution covering all of the above. Whether a specific tokenized instrument is a security, and whether a specific structure achieves bankruptcy remoteness, is fact-specific and jurisdiction-specific, and that call belongs to your counsel. This page is reference material for design work. It is not legal advice, and it is not a recommendation to buy, sell or hold any asset.
Common questions
Is tokenized real estate a security?
It depends on what the token gives the holder, not on the asset class. A token conveying a passive interest in a pooled vehicle run by a sponsor is the classic fact pattern regulators analyse as an investment contract. A token that is a direct, recorded property interest is a different question and usually turns on local property and land-registry law. Neither answer travels across jurisdictions, so it is a question for counsel on the specific structure.
What is the difference between RWA tokenization and a stablecoin?
A payment stablecoin is engineered to hold one fixed unit of value and pays the holder nothing. An RWA token passes through the economics of a specific underlying asset, so its value tracks that asset and it may distribute yield. The regulatory treatment splits accordingly, and a tokenized bond or fund unit generally stays inside existing securities law rather than a crypto-asset regime.1
Does tokenizing an asset make it more liquid?
Not on its own. Tokenization makes an asset transferable on a shorter settlement cycle, which is a precondition for liquidity rather than liquidity itself. If the token is permissioned so only verified wallets can hold it, the eligible buyer set is the same one you had before, now on faster rails. Liquidity comes from more eligible buyers and a venue where they meet.
What token standard should an RWA issuance use?
ERC-3643 and ERC-1400 are the two in institutional use. ERC-3643 checks every transfer against an onchain identity system and a compliance contract, and keeps freeze and recovery powers with the issuer.3 ERC-1400 splits balances into partitions, each with its own metadata and transfer restrictions, and adds document management and error signalling.4 Pick against the venues you need to reach, because both restrict where the token can travel.
Who holds the asset in an RWA tokenization?
A regulated custodian holds it, and that should be a different party from the entity minting and burning tokens. In BlackRock's BUIDL, Bank of New York Mellon custodies the assets while Securitize acts as transfer agent and handles issuance and redemption.6 Separating those roles is what makes an attestation meaningful, because the party holding the asset is not the party reporting on it.
See RWA Tokenomics Design for how this applies in practice.
Sources
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA), Article 2
EUR-Lex, Official Journal of the European Union, 2023
Article 2(4) excludes crypto-assets qualifying as financial instruments, deposits or funds from MiCA's scope. - Tokenisation in the context of money and other assets: concepts and implications for central banks
Bank for International Settlements, Committee on Payments and Market Infrastructures, 2024
Section 4.1 sets out legal risk in token arrangements, including whether a tokenised asset reflects an enforceable legal claim or property right. - EIP-3643: T-REX, Token for Regulated EXchanges
Ethereum Improvement Proposals, 2021
Permissioned token standard requiring an onchain identity system and a compliance contract on every transfer. - ERC-1400: Security Token Standards (specification text)
SecurityTokenStandard/EIP-Spec, by Dossa, Ruiz, Vogelsteller and Gosselin, 2018
Splitting a holder's balance into partitions each with separate metadata, the primary-issuance against secondary-trading example, and the four sub-standards it requires: ERC-1410 differentiated ownership, ERC-1594 restriction checking with error signalling and issuance and redemption semantics, ERC-1643 document and legend management, ERC-1644 controller operations. Read 3 August 2026: this text and ERC-1410 use partition throughout and contain no instance of tranche, while the linked discussion threads (ethereum/EIPs issues 1410 and 1411) still use the earlier tranche wording. Maintained outside the formal EIP process. - CFTC Orders Tether and Bitfinex to Pay Fines Totaling $42.5 Million (Release No. 8450-21)
U.S. Commodity Futures Trading Commission, 2021
Enforcement order over claims that USDT was fully backed by US dollars. The documented attestation-gap precedent. - BUIDL: BlackRock USD Institutional Digital Liquidity Fund, asset page
RWA.xyz, 2026
Issuance and redemption mechanics, custodian, transfer agent, auditor and legal wrapper, plus total asset value read on 2026-08-03. Figures update continuously.
Last reviewed 2026-08
Know the terms but not sure how they apply to your project? That is what an engagement is for. We design, document, and stress-test the whole token economy inside the Tokenomics Data Room.
100+ projects advised. Complete tokenomics in 4 to 6 weeks.