Oops, we broke tokenization
Published

Tokenization is having its moment. There are hundreds of billions of dollars of money market funds, treasuries, private credit and dollars tokenized on public ledgers as I write this, and every bank deck has a slide about it. At Notabene we watch trillions of dollars in tokenized value flow across the network every year, so I get to see the scale of this up close. And somewhere along the way we managed to break the word. Not the technology. The word. We took a perfectly good, perfectly honest engineering term and quietly loaded it with a meaning it was never carrying, and now half the industry is reasoning about tokenized assets using a mental model that is just wrong.
Let me try to explain how that happened, because I think it’s a special case of a mistake we make over and over again in this industry, and once you see the shape of it you start seeing it everywhere.
What is a token, actually?
Strip away the excitement and a token is a very small thing. It’s a fungible entry on a ledger, usually a public blockchain. That’s it. Tokenization is a way to store and move a fungible claim. It is a storage-and-transfer mechanism, and it is a genuinely good one: fast, programmable, settles in seconds, moves around the world on a Sunday night.
Notice what that definition does not include. It says nothing about what the claim is. Nothing about who owes you, what they owe, whether they’re good for it, or what happens if they aren’t. A token tells you how a claim is stored and transferred. It tells you nothing about the rights and obligations underneath, and the rights and obligations are the actual asset. Everything I’ve ever written here eventually comes back to that one distinction.
Here’s the funny part. The word “token” was never confused about this. A token has always been a stand-in, never the thing itself. The New York subway minted its own token in 1953 because the fare went to fifteen cents and there was no fifteen-cent coin. The token was worth a ride because the Transit Authority honored it, not because the brass was worth anything. A casino chip is worth $25 because the cage redeems it, and worthless on the sidewalk outside. A nineteenth-century shopkeeper’s token was a redeemable proxy for coin the realm hadn’t minted enough of. For a few hundred years a token has meant: a placeholder that is good because someone stands behind it.
So the word is honest. We’re the ones who stopped listening to it.
We didn’t always call them tokens
Worth remembering that “token” is a fairly recent import, even inside crypto. Those of us who were kicking around financial cryptography before Bitcoin, the e-gold and DigiCash and GoldMoney crowd, mostly called these things what they plainly were: assets. Digital assets, digital currencies, digital bearer certificates. That word carried the right baggage. An asset is a right, it has an issuer, it sits on somebody’s balance sheet. The vocabulary did some of your thinking for you, in the right direction.
Bitcoin changed the words. Satoshi called them coins, and that’s a bad skeuomorphism of its own. There is no coin. No metal, no mint, no milled edge, just an unspent output on a ledger. But a coin on Bitcoin is endogenous, so the borrowed word is mostly harmless: there’s no issuer for it to lie about.
“Token”, for an asset issued on top of a chain rather than native to it, comes later. The Mastercoin whitepaper, J.R. Willett’s 2012 “Second Bitcoin Whitepaper”, is arguably where it first gets attached to a user-issued asset on a blockchain. But the word really got its legs with ERC-20, the Ethereum token standard written by my friend Fabian Vogelsteller with Vitalik Buterin in 2015. ERC-20 is literally titled a “Token Standard”, and once anyone could mint one with a few lines of Solidity, “token” quietly became the default noun for the entire category. A naming decision in a GitHub issue became the name of an asset class.
I was one of the people who fought this, and I’ll be honest, it was a losing battle from the start. A handful of us old timers in the crypto space spent 2015 and 2016 gently insisting that these things were assets: the word already existed, and it already did the right thinking for you. We were right, and it didn’t matter. “Token” had a standard, a one-line mint, and a GitHub issue behind it, and that beats being right about vocabulary every single time. The term stuck. We lost. Here we are.
And now that casually chosen word eats a staggering amount of the world’s regulatory and legislative energy. MiCA, the GENIUS Act, the whole global “is it a security” industry: legislatures on three continents are drafting law around a noun we picked almost by accident, and around the baggage that quietly rode in with it. That’s the thing about borrowing a word. You borrow its entailments too, and sometimes the entailments end up in front of a parliamentary committee.
The skeuomorphism move
Here’s the pattern, and I’ll own up front that I’ve been calling it the wrong name, then tell you why I keep using it anyway.
We engineers get excited about a mechanism, and then we reach for a familiar real-world word to make it legible. We borrow the word. And then, without noticing, we start reasoning about the new thing using the old thing’s full meaning. I’ve been calling this conceptual skeuomorphism: the same move as the fake leather stitching on a calendar app or the shutter sound on a silent phone camera, applied to concepts instead of pixels.
A purist will stop me right here, and they’re correct. Skeuomorphism is specifically copying the form of an old object without its function. The leather look without leather. The word “token” copies no form at all, so strictly this isn’t skeuomorphism. It’s a leaky abstraction, in Joel Spolsky’s sense, or a conceptual metaphor in Lakoff’s. Fine. I concede the term. But I keep reaching for “skeuomorphism” because it points at something the drier words miss, and I’ll come back to why at the end, because crypto is absolutely full of real skeuomorphs and some of them matter enormously.
Whatever you call it, here’s the mechanism of the damage: the metaphor leaks its entailments. The word “token” drags in bearer instrument, self-contained, trustless, mine because I hold it. The engineering thing carries none of that on its own. We picked up the word and inherited a bundle of assumptions we never checked.
Where the bad intuition came from
It came from Bitcoin and Ethereum, which is where almost everyone first met a token. And on those networks the intuition is correct. The rights are endogenous: native to the network, defined by the protocol itself. A bitcoin really is bearer-like and self-contained, because there’s no issuer behind it, no one to call, nothing exogenous to the chain. Hold the key, hold the coin. That’s a real and beautiful property.
Then we took that intuition and pointed it at a tokenized treasury bill.
A stablecoin or a real-world asset is exogenous. Its rights and obligations don’t come from the chain. They come from an issuer, a contract, a reserve account, double-entry bookkeeping, and in most cases a few centuries of case law. The token is just the wrapper. And the moment you treat that wrapper as if it were Bitcoin-shaped, as if holding it were the whole story, you’ve made a category mistake, and it’s an expensive one.
| Bitcoin | A stablecoin (USDC) | A tokenized T-bill (BUIDL) | |
|---|---|---|---|
| What you hold | the asset itself | a claim on Circle’s reserves | a share in a money market fund |
| Where the rights come from | the protocol (endogenous) | an issuer + reserve account | a fund prospectus + securities law |
| Counter-party | none | Circle | BlackRock, the fund, the custodian |
| If the issuer fails | n/a | you’re an unsecured creditor | you’re a fund investor in a queue |
| What the token is | the thing | a bearer IOU | a share-register entry |
Same shape on a block explorer. Three completely different animals.
The leak that actually costs money
This isn’t a tidiness complaint. The “a token is Bitcoin-shaped, self-contained, final the instant it lands” intuition makes people forget the single most important fact about a stablecoin or an RWA token: it is a claim on an issuer. The skeuomorphism hides the counter-party risk.
USDC is roughly a $60 billion claim on Circle’s reserves. Hold USDC and you are an unsecured creditor of a company, and the token’s finality on-chain tells you exactly nothing about whether the redemption will be there on the bad day. BlackRock’s BUIDL crossed a couple of billion dollars as a feeder into a money market fund. The token is a share-register entry. A tokenized treasury feels as bearer and final as a bitcoin, settles like one, looks like one in your wallet, and carries the full issuer and custodial risk of the fund behind it. The whole category of tokenized treasuries grew past eight billion dollars in 2025 on the strength of that good feeling.
Counter-party risk never disappears. It only moves around and, if you’re not careful, hides. That’s the line I keep coming back to, and tokenization is the best hiding spot we’ve ever built for it. The risk didn’t go away when the T-bill went on-chain. It just stopped being visible, because the wrapper looks like the one thing in crypto that genuinely has no counter-party.
The other token, the one in your login
There’s a second engineering life for this word, and it rhymes with the first, so let me take
the detour. Open the headers on almost any request your browser makes to a modern app and
you’ll find a line that reads Authorization: Bearer something. Most of modern
authentication, OAuth, your API keys, your logged-in session, runs on bearer tokens.
Look at what security engineers did there. They borrowed “token”, and then they borrowed bearer too, straight out of finance. A bearer instrument is one where whoever physically holds it owns the right, no name on it: cash, a bearer bond, a theatre ticket. Lose it and you’ve lost the value, with nobody to call.
Here’s the difference that matters. In authentication, that name is honest. A bearer token really does behave like a bearer bond: whoever holds it can use it, no questions asked, which is exactly why good security people treat bearer tokens as dangerous. They scope them tightly, expire them fast, and never log them. “Bearer” there is a warning label, and it does its job.
Now swing back to the blockchain side. We imported the exact same bearer intuition, hold it and it’s yours, final the instant it lands, and we pointed it at assets that are not bearer at all: the exogenous ones, with an issuer standing behind them. The auth world borrowed “bearer” and was honest about the risk the word names. The crypto marketing borrowed the same intuition and pretended the risk wasn’t there. Same skeuomorphism, opposite honesty. Is “bearer token” itself a clean skeuomorphism? It’s dubious, and I think it’s the good kind: the form and the function genuinely match, so the borrowed word earns its keep. Hold that thought, because it’s the whole distinction I land on at the end.
So who broke it?
Here’s where I want to be fair, because “engineers broke tokenization” is a good joke and only half true.
Engineers coined the word, honestly. As a piece of engineering vocabulary, ERC-20’s “token” was perfectly good: here is a standard interface for a fungible ledger entry, go nuts. The leak was always latent in the abstraction, but in 2015 nobody was getting hurt by it.
Then 2017 happened. And the people who really broke the word weren’t naive engineers. They were founders, marketers, and a remarkable number of securities lawyers, and they broke it on purpose. The SEC’s DAO Report in July 2017 said the obvious thing: run the Howey test and most of these tokens are securities. The industry’s response was not to accept that. It was to invent the “utility token”, to build the SAFT, and to insist with a straight face that a token was a new kind of asset with its own novel nature, something the old law simply couldn’t reach.
Think about what that argument requires you to believe. It requires the token to be the substance, not the wrapper. Because if a token is just a mechanism carrying whatever rights the issuer and the law assign, then Howey reaches straight through it and grabs the security underneath. The whole “tokens are too novel for the old rules” position depended on the category mistake being true. The skeuomorphism wasn’t an accident of jargon at that point. It was load-bearing for the regulatory arbitrage. Eight years later the SEC’s Hester Peirce put the counter in one sentence: tokenized securities are still securities, and blockchain has no magical power to change the nature of the underlying asset. She’s right, and she shouldn’t have had to say it.
So: engineers built a leaky abstraction, and then an entire industry drove a truck through the leak because the truck was full of money. And I’ll implicate my own tribe while I’m here, because plenty of us engineers got rich off those token offerings and loved the idea that we were building something completely new, which made the category mistake a very comfortable thing to believe. Both things are true. Tell both.
“But surely tokens need new law?”
This is where I have to correct my own earlier writing, because I’ve said “tokenization needs no new law” in a way that’s too strong, and a careful reader, a lawyer especially, will catch it.
Here’s the honest version. You have to decompose the claim into two parts, because they have opposite answers.
The substance needs no new law. What you actually own, the rights and obligations, already has a legal nature. A tokenized share is a share. A tokenized note is a note. A tokenized dollar is a deposit or an e-money claim or a money market share, and we have centuries of law for every one of those. People who say “we need a whole new legal framework to explain what a token is” are usually making the category mistake out loud. Often what they actually want is to escape an existing answer they don’t like, securities law most of the time, and that’s a legitimate but completely separate argument that should be made honestly and on its own, not smuggled in disguised as “tokens are novel.”
The plumbing genuinely does need new law, and it’s already getting it. This is the part I under-weighted. The mechanism introduces operational facts the old law never contemplated. Atomic settlement with no gap between trade and settlement. A registered security moving peer-to-peer like a bearer asset while the issuer’s register still names someone else as the owner. The same on-chain value rehypothecated through three protocols automatically with no custodian in the loop. Irreversible finality sitting underneath a legal system that assumed transactions could be unwound. None of that is about what you own. All of it is about how possession, transfer and finality now work, and that “how” is where real new law is being written.
And the most interesting bit, the one that genuinely sharpens the thesis rather than denting it: the new UCC Article 12 deliberately makes control of certain digital records legally dispositive. Take control of one in good faith, for value, and you can take it free of prior claims, defeating the old rule that you can’t pass better title than you have. That is the law electing to let the token mechanism carry legal weight, on purpose, by choosing to. Which is exactly my point turned right-side up. The token mechanism is neutral. The legal effect is assigned to it by the surrounding structure, not inherent in it. Under Article 8 the on-chain holder of a tokenized security is not the holder of record at all and the issuer’s register governs; under Article 12 control of the record can be made dispositive and bearer-like. Both regimes exist in the same body of law at the same time. The token doesn’t decide which one you get. The structure around it does. The mechanism never carried the meaning. We assign the meaning, and the whole job is to assign it on purpose instead of by accident.
In Rich Hickey’s terms, the word “token” complects the storage mechanism with the asset’s legal substance. The work, as always, is to decomplect them: this is the rail, that is the claim, and they are not the same thing.
The twist: not every skeuomorph is the villain
Now let me come back to why I won’t give up the word “skeuomorphism”, even though the purist was right that it’s imprecise.
Because crypto is full of actual skeuomorphs, the real form-without-function kind, and they’re doing something I learned about the hard way. The “wallet” that holds no money and is really a keyring. “Minting” and “burning.” The “vault.” The little coin icons. None of that is technically necessary. All of it is borrowed form, and a lot of it is load-bearing for trust.
I know this because I bet against exactly this once and lost. Years ago I built Agree2, an e-signature company, around the same time as DocuSign. I was right on the law and right on the tech: a contract doesn’t need a handwritten-looking scribble, it needs a provable audit trail and genuine agreement. So we stripped the scribble out as pointless theater. DocuSign kept it, the fake handwritten signature on top of the PDF, completely vestigial, and they won. Because the people sending contracts aren’t lawyers, and the scribble is how they trust the thing. The skeuomorph I dismissed as decoration was carrying the trust.
So here’s the distinction I actually care about, and it’s why I keep the word. There are two kinds of skeuomorphism in this industry, and they have opposite verdicts:
- The visual skeuomorphs, the wallet, the mint, the coin, the vault, are mostly good. They’re the bridge that lets a normal person trust something deeply strange. Strip them too early and you lose, the way I lost with Agree2.
- The conceptual skeuomorphism, token = the asset itself, is the one that does real damage, because it doesn’t build trust, it misplaces it. It points your trust at the wrapper and away from the issuer who actually owes you.
Keep the leather stitching that helps people trust the calendar. Throw out the idea that the stitching is holding the pages together.
Decomplect the token from the claim
So here’s where I’ve landed, for now. I don’t think we should retire the word “token”, and I definitely don’t think we need a new legal cosmology to house it. I think we need to do the one boring, unglamorous thing this whole industry keeps avoiding: decomplect the rail from the claim.
A token is a verb pretending to be a noun. It’s how the claim moves, not what the claim is. Every time you look at a tokenized asset, ask the two questions the word is begging you not to ask: who owes me, and what happens if they can’t pay? If the answer is “no one, it’s endogenous,” congratulations, you’re holding something Bitcoin-shaped and the skeuomorphism is finally telling the truth. If the answer is a company, a fund, a reserve account, then you’re holding a claim with a counter-party, and no amount of on-chain finality changes that. The ledger moved the wrapper. It didn’t move the risk.
We didn’t break tokenization. The technology works great. We broke the word, by letting it do our thinking for us. The fix isn’t new law or new tech. It’s paying attention to a distinction a subway token understood in 1953.
I’m still sharpening this one, the boundary between the skeuomorphism that builds trust and the one that misplaces it is the part I’m least finished with, so push back if you see it differently. It connects to a lot: smart contracts that aren’t contracts, balance sheets on blockchains, and the four flavors of the dollar, which was this same argument about money fifteen years before I had the word for it.