Off the Books: Blockchain Analytics and the RWA Register Problem

Off the Books: Blockchain Analytics and the RWA Register Problem
Table of contents
    • The ECB found that none of the largest tokenized money market funds is fully on-chain, and around half still use a traditional book-entry ledger as the primary record of ownership. Analytics reading those chains is reading a notification layer.
    • Crypto analytics was built to de-anonymize a pseudonymous ledger. ERC-3643 tokens are identity-bound at the gate through an allow list the fund administrator already maintains, so the clustering and attribution machinery that justifies the tooling has almost nothing left to infer.
    • There is very little secondary market to surveil. In a panel of Ethereum RWA tokens, the median token-month showed roughly 19 active addresses and 69 holders, and the BIS found that about 90% of BUIDL and WTGXX each sit with four wallet addresses.
    • The genuine crypto-native exposure is the cash leg and the wrapper layer. Stablecoins account for 84% of illicit transaction volume, and the BIS notes that wrapping fund tokens or trading them on platforms lets investors bypass allow lists in practice.
    • Institutional volume is moving to ledgers built not to be read. DTCC is bringing DTC-custodied Treasuries onto the privacy-preserving Canton Network, and the UK’s digitally native gilt runs on HSBC Orion, a permissioned bank platform.

    Elliptic published a note on 8 July explaining why it had bolted a second pricing feed onto its platform, and the opening line is the most honest sentence any analytics vendor has written about real-world assets. A transfer of 40,000 units of a token could be worth $4 or $400 million, and a blockchain that records the movement in otherwise perfectly transparent detail will not tell you which. Every leg of the transaction is there. The amount is denominated in the token, and the token has no price the ledger knows anything about, which is why Elliptic went and partnered with CoinGecko rather than pretend the gap did not exist.

    The same structure runs through everything else analytics is being asked to do for tokenized assets. The chain records that something moved. It does not record what the thing was worth, and for a large share of the tokenized fund market it does not record who owns it either. The industry has spent two years selling RWA surveillance as an extension of crypto transaction monitoring, and the extension only works where the on-chain record is load-bearing. In most of this market it is not.

    Half the tokenized fund market keeps the legal register off-chain

    The European Central Bank ran the systematic version of this check and published it in its April 2026 Macroprudential Bulletin, covering the largest tokenized money market funds globally and in the EU. Its finding is blunt. None of the largest TMMFs can be classified as fully on-chain, because their underlying assets and key processes remain partially off-chain, and around half of the funds still use a traditional book-entry ledger as the primary record of ownership, meaning fund shares legally change hands only after that ledger is reconciled with the DLT. In the ECB’s own table, both BUIDL and BENJI carry “Traditional” in the official record column. Only one fund in the sample, JTRSY, tokenizes its assets in full.

    So when a compliance team watches BUIDL move on Ethereum, it is watching a reconciliation trigger. The transfer that shows up on the block explorer is a message to a transfer agent, and the ownership change happens when the agent updates a database that no analytics vendor can see. The ECB counts over half of the largest funds using third-party transfer agents and about a third outsourcing both share tokenization and investor access, so the database in question frequently belongs to a fourth party neither the fund nor the investor operates.

    The BIS notes that NAV calculation relies on pricing information usually provided once per business day by off-chain services the blockchain reads through oracles, and that custody and proof of ownership of the underlying investments are still performed off-chain. So the price is a daily import, the assets sit in a custodian’s records, and the register may live in a transfer agent’s database. Three of the four things a compliance team needs to know about a tokenized fund share are somewhere other than the chain it settles on.

    The SEC drew the same line in its staff statement on tokenized securities on 28 January 2026, and the taxonomy is more useful than the headline everyone quoted about securities laws still applying. Staff separate the case where an issuer integrates DLT into the master securityholder file, so that a transfer of the crypto asset is the transfer of the security, from the case where the issuer keeps the master file off-chain and the token transfer merely operates to notify the issuer to record the change. Both are legal. They are entirely different objects for anyone building surveillance, because in the first the chain is evidence of ownership and in the second it is evidence of an instruction.

    Singapore’s Project Guardian reached the same three-way split from the operational side in its Operationalising Tokenised Funds guide, sorting share registers into Digital Mirror, Digital Twin, and Digital Native archetypes. A Digital Mirror is a copy. Watching a copy and calling the result an audit trail is a category error that survives mostly because nobody selling the tooling has an incentive to name it.

    The fight over which register counts is now in front of US regulators, with the Securities Transfer Association writing to the Commission on 1 July 2026 to argue that any innovation exemption or permanent framework should apply only to issuer-sponsored tokens, on the grounds that a token not authorized by the corporation and not reflected in its shareholder records is not a share of that corporation at all. Eli Cohen at Centrifuge read the letter as the trade body protecting its franchise, telling CoinDesk that transfer agents are paid by issuers and their business shrivels if non-issuer securities take hold, which is a fair reading of the incentive and does not make the underlying point wrong. Fairmint’s Joris Delanoue put it in the form that should be pinned above every RWA compliance roadmap, that a blockchain is not the source of truth and the issuer-authorized shareholder register is.

    Allow lists broke the heuristics the tooling runs on

    Crypto analytics earns its keep by inferring identity from behavior. Common-input heuristics, change-address detection, timing correlation, and a decade of accumulated attribution data exist because Bitcoin and Ethereum addresses are pseudonymous and somebody has to work out which exchange, mixer, or ransomware crew sits behind a cluster. Every vendor pitch leans on the size of that attribution graph, and it is a real asset in the market it was built for.

    Permissioned RWA tokens invert the premise. ERC-3643, the standard behind most regulated institutional tokenization, binds each holder to an on-chain identity through ONCHAINID and enforces eligibility inside the token contract, so a transfer to an unverified wallet fails at the contract rather than in a policy review afterward. The BIS description in Bulletin 115 is precise about who holds the knowledge. Investors are onboarded by the fund administrator, which creates and maintains an allow list of wallets that satisfy AML and fund-specific requirements, and the token’s isVerified and canTransfer functions check that register before a transfer proceeds.

    Nothing in that flow needs a clustering heuristic. The administrator already knows the beneficial owner of every wallet on its list, because it put them there, and it can freeze a balance, force a transfer, or recover a lost wallet through the standard’s agent role. That is the enforcement power crypto analytics exists to substitute for in markets that have none. Chainalysis has published a clear primer on ERC-3643 that walks through exactly this architecture without quite drawing the conclusion, which is that on the permissioned leg the value analytics adds sits in screening a wallet against sanctions and illicit-exposure data at onboarding, while the attribution work has already been done by someone with better information.

    Elliptic’s RWA page lists money laundering through fractionalization as a typology transaction monitoring catches, describing a bad actor making dozens of small investments in a tokenized real estate property across different wallets to keep under reporting thresholds. On a permissioned token that scenario requires the administrator to have allow-listed every one of those wallets after running KYC on each, which makes it a customer due diligence failure at the gate rather than a pattern hiding in the transaction graph. The typology is entirely real on permissionless wrappers. Importing it wholesale into the permissioned market describes a control gap the token standard was written to close.

    But the BIS flags the crack in the model, and it is the part worth building for. Allow lists only constrain direct holding, and the wrapping of fund tokens into stablecoins or the ability to trade them freely on platforms can let investors bypass the lists in practice. Each fund maintains its own list, which duplicates work and fragments the environment into controlled and uncontrolled compartments. The surveillance problem is the token that leaves the compartment inside a wrapper rather than the allow-listed transfer between two known institutions, and that is a tracing problem of exactly the kind these tools are good at. The BIS suggests the durable fix is trusted wallet ID systems shared across funds and backed by ongoing compliance monitoring, which would replace duplicated per-fund lists with shared infrastructure an analytics provider could plausibly operate. That is a different product from transaction monitoring, and the market structure is pointing at it fairly clearly.

    There is almost no secondary market to surveil

    Market surveillance is the other pillar of the RWA analytics pitch, covering wash trading, coordinated accumulation, circular trading to inflate volume, and the rest of the market-abuse catalog imported from equities, and all of it assumes there is a market there to abuse.

    An empirical panel of Ethereum RWA tokens published on arXiv in May 2026 measured what is there, using RWA.xyz token-level data across Treasury-backed, gold-backed, and private-credit categories. The median token-month carries a log active-address value of 2.944 and log holders of 4.227, which is roughly 19 active addresses and 69 holders in a month. BENJI and STAC show near-zero turnover in several months while holding non-trivial asset value, and BUIDL combines large scale with modest participation breadth and uneven activity. Only gold-backed tokens such as PAXG and XAUT show broad holder bases and persistent activity, which makes sense, because those are the ones being used like a commodity rather than parked as collateral.

    Concentration finishes the argument, since the BIS found that for BUIDL and for the WisdomTree Government Money Market Digital Fund, around 90% of total holdings sit with only four wallet addresses each. Coordinated trading among four institutional holders the fund administrator already knows by name is not the sort of pattern that needs a detection model.

    On RWA.xyz on 6 August 2026, total distributed asset value across all tokenized RWAs stood at $37.89 billion, and the ten largest tokenized real estate assets on the platform sum to roughly $146 million between them. Tokenized equities run at about $2 billion, and most of that follows the third-party synthetic model rather than anything recorded on an issuer’s books. Six years of real estate tokenization decks have produced a category that is a rounding error against tokenized Treasuries, and no amount of surveillance sophistication changes what is not trading.

    The tokenized credit book on RWA.xyz runs to a few billion dollars with the largest individual positions in the hundreds of millions, and the arXiv panel found private-credit-related tokens the weakest of its three categories on observed liquidity. What determines whether those tokens are worth par is whether the borrowers underneath them are paying, which lives in servicer reports and loan tapes and never touches a block explorer. A tokenized loan that has stopped performing looks identical on-chain to one that has not, right up to the moment somebody writes it down.

    Where the analytics is doing real work

    Subscriptions and redemptions in most large TMMFs settle in fiat or stablecoins, with two funds in the ECB sample operating solely in stablecoins, which means the money entering and leaving a regulated fund arrives as USDC or USDT from a wallet with a history. Chainalysis reports in its 2026 Crypto Crime Report that illicit addresses received at least $154 billion in 2025, up 162% year on year, and that stablecoins now account for 84% of illicit transaction volume. Screening a subscription wallet before it becomes a fund shareholder is the single highest-value thing an analytics platform does in this stack, and it has nothing to do with the tokenized share itself.

    Elliptic’s cross-chain crime research identifies more than $21.8 billion in illicit and high-risk crypto laundered through cross-chain methods, and the wrapper problem the BIS describes is a cross-chain problem the moment a fund token is bridged, repackaged, or pledged into a lending protocol on another network. Chasing a claim on a money market fund through three bridges and a wrapper is exactly the work Reactor and Investigator were built for.

    The third is the permissionless wrapper market, and here the STA letter is unexpectedly useful as a threat model. It notes that many third-party tokens can be transferred permissionlessly between wallets without sufficient controls to prevent sanctioned persons or blocked jurisdictions from holding economic exposure to US public companies, and it asks the Commission to require embedded transfer controls rather than assume disclosure will do the work. A trade body for transfer agents arguing for on-chain screening is a decent signal that the AML exposure sits in the synthetic layer rather than the issuer-sponsored one.

    The STA letter records that three crypto-native tokenization platforms were recently required to cancel trades and refund customers when they could not source the SpaceX shares needed to back their pre-IPO tokens. On-chain, those tokens looked fine. They minted, transferred, and settled correctly, and every heuristic in every platform would have passed them, because the thing that was missing was in a share register nobody was watching.

    The transparency sold as a control is also being named as a risk

    Both the BIS and the ECB reach the same conclusion about public-ledger visibility from the financial stability side, and it cuts against the direction of the compliance pitch. The BIS argues that the transparency of blockchain-based transactions compounds liquidity risk by acting as a coordination device among investors, because redemptions are immediately visible to every market participant and the risk of a run rises as confidence in a fund wanes. The ECB pushes it further, noting that real-time transparency combined with 24/7 cross-border tradability could amplify first-mover incentives, particularly for tokenized shares in partially tokenized funds where the token can move considerably faster than the fund underneath it.

    That is the same visibility analytics vendors sell as the reason tokenized markets will end up safer than traditional ones, and both readings are correct at once. A fund treasurer deciding whether to put a share class on a public chain is weighing a genuine trade-off rather than picking up a free audit trail, and the trade-off explains a fair amount of institutional preference for permissioned infrastructure that has nothing to do with wanting to hide anything. A fund that can be watched redeeming in real time by every counterparty it trades with has acquired a new failure mode alongside the new transparency.

    The volume is moving to ledgers built not to be read

    The more institutionally serious tokenization gets, the less of it lands on a chain a vendor can index. DTCC and Digital Asset are bringing DTC- and Fed-eligible securities onto the Canton Network, starting with US Treasuries custodied at DTC, and Canton’s entire selling proposition is that it is a public chain where transaction data stays confidential, because institutions will not expose client identity, position, or intent to a block explorer. HM Treasury picked HSBC Orion for the Digital Gilt Instrument on 12 February 2026, a digitally native sovereign bond rather than a wrapper around an existing gilt, which is the architecture where on-chain analysis would be authoritative, and it runs on a permissioned bank platform rather than anywhere a third party can look.

    The trajectory is uncomfortable for the vendor model, because where the chain is the register the ledger is usually closed, and where the ledger is open the chain is usually a mirror. The overlap where a public chain carries the authoritative record of a regulated asset is real but narrow, running to six of the thirteen funds in the ECB’s table, and even in those six the underlying assets stay off-chain.

    Vendors know this and are buying coverage rather than arguing with it. Elliptic added support for Robinhood Chain on 30 June 2026, a layer 2 built specifically for tokenized stocks, and the $120 million it raised in May 2026 came from Nasdaq Ventures, Deutsche Bank, One Peak, and the British Business Bank, which tells you who expects to be buying this. Chasing chains is a rational strategy, and it does nothing at all for the case where the asset sits on a ledger designed to refuse the query.

    The rulebook the tools were built for does not cleanly apply

    Most RWA compliance content walks straight past a mismatch at the definitional layer, because the FATF’s virtual asset definition excludes digital representations of securities and other financial assets that are already covered elsewhere by the FATF. A tokenized security is therefore not a virtual asset in the FATF sense, so the crypto travel rule that the entire VASP compliance stack was built to serve is not the instrument that governs it, and the obligations flow instead through the AML regime that already applies to the fund, its transfer agent, and the securities intermediaries around it.

    Europe encodes the same split. MiCA explicitly excludes financial instruments, leaving tokenized securities under MiFID II and the existing prospectus and market-abuse machinery, and the SEC statement says the same thing in its own language. Elliptic’s own RWA explainer hedges it accurately, saying entities that custody or facilitate transfers of tokenized securities “may be treated” as VASPs, which is the correct amount of uncertainty and also an odd foundation for a product category.

    The practical consequence is that a tokenization platform buying crypto analytics to satisfy an obligation should be able to name the obligation. If the answer is the securities AML regime, the tooling is a control that helps discharge a duty that predates it, and the parts of the regime that bite hardest, meaning suitability, transfer restrictions, beneficial ownership, and market abuse in a real venue, are not on-chain problems. If the answer is the crypto regime, the platform is probably dealing with a synthetic or wrapper product, and the analytics is doing the job it was designed for.

    What to ask before buying the surveillance

    Start with which ledger is authoritative for the specific instrument, because that answer determines whether monitoring produces evidence or a shadow. Ask whether the vendor covers the venue where the asset settles, since coverage of sixty public chains is worth nothing if the asset lives on Canton or a bank platform. Ask where the price comes from and how stale it can get, because a monitoring alert denominated in tokens is not a monitoring alert. And ask what happens at the redemption boundary, where a stablecoin arrives from a screened wallet and leaves as a wire, since the handoff between the on-chain and off-chain compliance systems is where both of them stop looking.

    None of this argues against the tooling. Screening subscription wallets, tracing wrapped fund tokens across bridges, and monitoring the permissionless synthetic layer are all real work with real risk attached. The overclaim is the framing that puts blockchain analytics at the center of RWA compliance, when in the part of the market institutions are using, the ledger is a mirror, the identities are already known, the holder count is in the dozens, and the thing most likely to go wrong is a share that was never there.

    Frequently Asked Questions (FAQ)

    Does blockchain analytics work for tokenized real-world assets? +

    It works for parts of the stack. Wallet screening at onboarding, tracing fund tokens that get wrapped or bridged, and monitoring permissionless synthetic products are genuine uses. What it cannot do is verify ownership when the legal register is off-chain, which the ECB found is the case for around half of the largest tokenized money market funds, or value a transfer without an external pricing feed.

    Why does it matter whether the blockchain is the official record? +

    Because it determines what an on-chain transfer proves. Where the issuer integrates DLT into the master securityholder file, moving the token moves the security. Where the master file stays off-chain, the token transfer is a notification that triggers a database update elsewhere, so the chain shows an instruction rather than a change of ownership.

    Do clustering and attribution heuristics work on RWA tokens? +

    Mostly they have nothing to do. ERC-3643 binds holders to verified on-chain identities from an allow list the fund administrator maintains, so the administrator already knows who each wallet belongs to. The exception is when tokens leave the permissioned compartment through wrappers or platform trading, which the BIS identifies as a real bypass.

    Can you detect market manipulation in tokenized assets? +

    Not in most of them, because there is not enough activity to manipulate. The median Ethereum RWA token-month in the arXiv panel shows roughly 19 active addresses and 69 holders, and the BIS found about 90% of BUIDL and WTGXX each held by four wallet addresses. The permissionless synthetic equity market is a more plausible surveillance target.

    Do tokenized securities trigger the crypto travel rule? +

    Not straightforwardly. FATF excludes digital representations of securities already covered elsewhere in the Recommendations from its virtual asset definition, and MiCA excludes financial instruments from its scope. Obligations flow through the securities AML regime that already applies to the fund and its intermediaries, and vendors hedge accordingly on whether custodians of tokenized securities count as VASPs.

    Where is institutional tokenization volume going? +

    Toward ledgers that are not publicly readable. DTCC is tokenizing DTC-custodied Treasuries on the privacy-preserving Canton Network, and the UK's Digital Gilt Instrument runs on HSBC Orion with the ledger as the sole legal record. Both are architecturally hostile to third-party chain analysis.

    CryptocurrencySafetyWalletWeb 3.0
    Signed, Sealed, Drained: How Backdoors Drain Crypto Wallets
    The biggest losses of 2023-2026 broke no cryptography. Bybit’s $1.5bn drain ran through a sound multisig and clean contracts; the attacker only changed what the signers saw. Four mechanisms recur and braid together: poisoned software supply chains, tampered signing interfaces, laundered authority via approvals and off-chain signatures, and privileged paths hidden in contracts, proxies and [&...
    2 months ago
    Safety
    Recovery Scams: Why Most “Crypto Recovery Services” Are Actually Frauds
    Fraudsters weaponize the emotional exhaustion and desperation of previous scam victims, often buying or sharing contact lists within criminal networks to initiate a second round of fraud. Due to the immutable nature of public blockchains, confirmed transactions cannot be reversed. Any service promising a technical “hack-back” or guaranteed recovery is a scam. Fraudulent services rely [...
    3 months ago
    Crypto CrimeRegulationSafety
    Follow the Coin: How Investigators Turn Public Ledgers Into Evidence
    The “follow the money” model still works. Investigators trace funds on-chain until they hit an exchange, then subpoena the KYC records. Mixers and privacy coins make tracing harder, but not impossible. Mixer takedowns produce historical data that feeds future investigations. International cooperation is built in. MLATs, Europol, and FinCEN’s Rapid Response Program move evidence a...
    3 months ago