RWA: Past, Present and FutureChapter 4 of 12
Who holds the keys to a tokenized fund
On an ordinary crypto token, whoever holds the private key controls the balance. On a tokenized fund, the issuer's transfer agent can freeze your tokens, move them to another address or destroy them, and securities law requires that it can. This chapter explains what you legally own, how token standards write those powers into code, who held them in three large funds when I read their contracts in September 2026, and who takes the loss when a product fails.
What you'll learn
- Explain what legal claim stands behind a fund token and why the transfer agent's register outranks the blockchain.
- Tell ERC-20, ERC-1400, ERC-3643, DS Protocol and Solana's token extensions apart by where each one puts the rules.
- Read who can freeze, pause, force a transfer or upgrade a token contract, and check whether they ever did.
- Name five ways an RWA product ends and who carries the loss in each.
In this chapter
What you own when you hold the token
A fund token records a share in a fund, and the official record of who owns that share is kept by a licensed firm.
A transfer agent is the licensed firm that keeps a fund's official list of shareholders, as chapter 1 explains. A master securityholder file is the official record of every holder's account under SEC Rule 17Ad-10, and for shares that exist only electronically the rule allows it to be several linked computer files. A public blockchain can be one of those files.
Securitize, the SEC-registered transfer agent behind BlackRock's BUIDL fund, describes exactly that arrangement in its 2026 filings. Wallet addresses, balances and purchase dates sit on a public chain. Names, home addresses and tax numbers stay off-chain. The chain holds part of the register, and the transfer agent holds the rest.
The hard case is a disagreement between the two. For BUIDL, Steakhouse Financial quoted the fund's offering memorandum in April 2024: legal title follows the register of members kept by the transfer agent, and where that register and the blockchain differ, the register decides. Newer filings turn the wording around. BlackRock's filing of 8 May 2026 for a new OnChain Shares class of its registered money-market funds says the on-chain record, together with the off-chain file that maps wallets to people, conclusively governs ownership unless one of the two systems fails.
For a holder this reverses the usual crypto instinct. If a contract shows a balance that the register does not, the register binds, and after a bug or a theft the reconstruction starts from the register. That same control is why the transfer agent needs keys to the token.
Why a legal security token needs a back door
A plain token moves whenever its owner signs. A security cannot work that way, because the law attaches conditions to who may hold it and requires someone to be able to override the holder.
ERC-20 is the basic Ethereum token standard. It has one transfer rule: if the sender has the balance, the balance moves. Securities law adds five questions to every movement: who may hold the security, when they may move it, how much they may hold, what happens after a court order, and who supervises all of it.
The court order is the part that forces the design. A transfer agent has a legal duty to carry out court orders and to correct errors in the register. One that cannot technically move shares cannot do the job it is registered for, so a compliant token must let someone other than the holder change a balance. Five powers do that work, and they differ in what the holder can get back:
- Freeze: blocks one address from sending or receiving. The balance stays where it is.
- Pause: stops every transfer of the token at once, for all holders.
- Forced transfer: moves tokens from a holder to another address without the holder's consent. The tokens still exist, so they can be returned. In BUIDL the function is called
seize. - Clawback: removes tokens from a holder without sending them to anyone. On Stellar, where Franklin Templeton's BENJI fund lives, a clawback destroys the balance.
- Upgrade: replaces the contract's code while balances stay put. An upgrade can add or remove any of the four powers above.
Asking whether an issuer can freeze your tokens gets the same answer for every compliant product. Three questions separate products instead: how narrowly each power is written, who holds the key to it, and whether an outsider can see when it is used.
Four places to write the rules
Every token standard built for securities carries these powers. What differs is where the rules live: in one contract, in swappable modules, in the token program of the chain, or in the network itself.
ERC-1400 was the first attempt, a family of Ethereum proposals that introduced two lasting ideas. A balance can be split into partitions, such as locked and unlocked shares, and a wallet can ask the contract whether a transfer will pass before sending it. The family was never finalized, and no large product in this market runs on it in 2026.
ERC-3643, also known as T-REX, is the open standard that finished the job. Tokeny developed it, Ethereum accepted it as a final standard in 2023, and the ERC3643 Association now maintains it. Before any transfer the token asks two registries. An identity registry links each wallet to an ONCHAINID, an identity contract that holds signed claims from verifiers, such as "this entity is an accredited investor", stored as references and hashes rather than passport scans. A compliance contract holds modules the issuer can add or remove without touching the token: a cap on holders, a ban on US persons, a 12-month lock-up. The standard names its powers openly, including forcedTransfer, setAddressFrozen, pause and recoveryAddress, which moves a balance to a new wallet when an investor loses a key. Recovery and confiscation run on the same machinery.
DS Protocol is Securitize's own architecture. It belongs to no public standard and its source code carries an UNLICENSED header, but the code is verified on-chain and anyone can read it. It spreads the rules across separate service contracts for roles, the investor registry, compliance and lock-ups. BUIDL runs on it, and so do other Securitize funds such as Apollo's ACRED.
Solana's Token-2022 program takes a third route. The rules are extensions switched on when a token is created. A permanent delegate can move or burn tokens from any holder, a freeze authority can lock accounts, and a transfer hook runs the issuer's own program on every transfer. Other extensions have no equivalent elsewhere: a transfer fee, interest that accrues inside the balance, and confidential transfers that hide amounts.
Stellar needs no contract at all. The issuer sets flags on its own account and the network enforces them: auth_required means nobody holds the asset without approval, auth_revocable lets the issuer freeze a holder, and auth_clawback_enabled lets it take tokens back.
Reading the keys on three real funds
Four terms describe who holds a power. An externally owned account, or EOA, is an address controlled by a single private key rather than by code. A multisig is a wallet that acts only when a set number of named signers approve, written as X of Y. A timelock is an enforced delay between ordering an admin change and the change taking effect, which gives holders time to leave. A proxy is a small contract that forwards every call to another contract, so the logic can be swapped while balances stay put.
I read the admin setup of three large tokenized Treasury funds on 4 September 2026: BUIDL and Ondo's OUSG on Ethereum, and Franklin Templeton's BENJI on Stellar.
In BUIDL, seize requires the TRANSFER_AGENT role, the second-lowest of the four roles DS Protocol defines, held that day by one EOA and one contract. Every seizure emits its own Seize event, so no use can be hidden from an indexer. The reason attached to a seizure is free text, with no link to a court order or document. The stronger power sits elsewhere: setTarget on Securitize's own forty-line proxy replaces the entire implementation in one call. One EOA held it, the same address held the top MASTER role, and neither a timelock nor a multisig stood in front of it. The chain cannot show what sits behind that key. It may be a hardware security module with an internal approval process at Securitize, and on-chain that looks identical to one person with one key.
OUSG has no function that can move a holder's balance to another address. A function that burns from any address exists behind a BURNER_ROLE, and a scan of every role grant since deployment showed that nobody has ever held it. Ondo split the remaining powers across three multisigs: token administration at 4 of 7, the identity registry at 3 of 5, and an emergency pause at 1 of 9, so any one of nine people can halt the token while destructive changes need four. The freeze runs through the KYC registry. Removing an address makes its transfers fail, and no event announces that anyone was frozen.
BENJI's issuer account had all three Stellar control flags switched on. Its master key carried weight zero, so it could not sign alone, and ten signers carried weight three against a medium threshold of two. A clawback falls under that threshold, which means any one of the ten signers can take BENJI from any account. Changing the flags themselves needs two of them.
A power that exists is not a power that was used
A contract can hold a power for years without anyone touching it, and only the event log shows which case you are looking at.
I scanned BUIDL's Ethereum contract from its deployment on 1 March 2024 to 4 September 2026. It showed zero Seize events and the token had never been paused. It also showed 208 Burn events, which cannot be split into redemptions and confiscations without reading the free-text reason on each one. For BENJI, the last 200 issuer operations contained no clawback, but they covered about seven and a half hours of a fund that has existed since 2021.
The contract also exposes the rule set. BUIDL's compliance contract allowed 1,999 investors and had used fewer than one slot in twenty, with a lock-up of 24 hours. The fund is closed to a narrow group of investors, and holding periods are short.
Each chain also implements the power differently. When I read Avalanche, Solana and Aptos on 5 September 2026, Avalanche had a seize function behind a standard upgrade pattern, Solana used Token-2022's permanent delegate held by a program whose own upgrade key is a plain private key, and Aptos blocked ordinary transfers at the level of the token standard. I found a seize-equivalent on all four chains and a multisig on none, and use on the three non-Ethereum chains was not checked.
Five ways a product ends, and who pays
Admin keys are only one of the risks a holder carries. Five endings have actually decided outcomes so far, and each lands on a different party.
An asset can default. The loss then shows up in the NAV, the fund's net asset value per share, and holders absorb it the way any credit investor would. Maple lived through this in 2022, when the trading firm Orthogonal defaulted on about 36 mn USD across eight loans after hiding its exposure to FTX.
A contract can be hacked. Here the compliance machinery cuts in the holder's favour: a thief who takes a whitelisted token can send it only to allow-listed addresses, and the transfer agent can reverse the theft with the same forced transfer that makes the product uncomfortable to hold.
The issuer can go bankrupt. Whether the holder owns shares in a fund with segregated assets or holds an unsecured claim on the issuer depends on the legal wrapper, the three levels set out in chapter 1. The custodian can go bankrupt too, and then the question is whether the assets were held apart or sat on the custodian's own books.
The fifth ending is the most common, and in it nothing breaks. Anchorage bought Mountain Protocol and stopped new USDM from being minted on 12 May 2025. From 22 August 2025 the token was no longer backed by Treasury bills or redeemable at 1 USD from the issuer, and its backing became USDC in a Uniswap pool. The bills were sound to the end. The issuer used a right the terms had given it from the start.
What to watch next
- A timelock or multisig on BUIDL's upgrade key: this would remove the largest single-key risk in the biggest fund, and it shows up on-chain the day the proxy owner changes.
- The first public seizure in a large fund: a
SeizeorforcedTransferevent would show what the power is used for in practice, and whether the reason field carries a court reference or a line of free text. - BlackRock's OnChain Shares class going live: a registered money-market fund whose official ownership record is the chain would test the "chain plus identity file" model at scale.
- More SEC letters like the FOBXX one: each letter tells issuers which register designs the regulator accepts, and the condition so far has been transfer agent control.
- ERC-3643 in a top-ten fund: adoption by a large issuer would show whether the open standard can win where the value sits.
Key takeaways
- A fund token is a line in an official register kept by a transfer agent, and when the chain and that register disagree, the register or the architecture filed with the regulator decides.
- Every standard built for securities lets someone other than the holder freeze, move or remove a balance, because a transfer agent must be able to carry out court orders.
- A forced transfer leaves tokens that can be returned, a clawback destroys them, and an upgrade can rewrite every other power, which usually makes it the strongest key in the system.
- Standards differ mainly in where the rules live, and the largest funds run on proprietary code or network flags rather than on the most open standard.
- Key hygiene varies more than the standards do: in September 2026 one fund put its upgrade behind a single key, another split its powers across three multisigs, and none used a timelock.
- A power that exists and a power that was used are different findings, and each needs its own reading of the event log on every chain the product runs on.
- Admin keys are one risk among several, and the most common ending is an issuer closing the product under terms it wrote on day one.
Glossary
- Transfer agent
- the licensed firm that keeps a fund's official list of shareholders and carries out court orders against it.
- Master securityholder file
- the official record of holder accounts under SEC Rule 17Ad-10. For electronic-only shares it may be several linked files, one of which can be a blockchain.
- Forced transfer
- moving a holder's tokens to another address without consent. Named
seizein DS Protocol andforcedTransferin ERC-3643. - Clawback
- taking tokens from a holder without sending them anywhere. On Stellar the balance is destroyed, so nothing is left to return.
- Externally owned account (EOA)
- an address controlled by one private key rather than by code. The chain cannot show what approval process sits behind it.
- Multisig
- a wallet that acts only when X of its Y named signers approve.
- Timelock
- a forced delay between ordering an admin change and the change taking effect.
- Proxy
- a contract that forwards calls to a replaceable implementation, so code can change while balances stay.
- Permanent delegate
- a Solana Token-2022 extension naming an account that can move or burn tokens from any holder and cannot be revoked like an ordinary approval.
- ONCHAINID
- the identity contract behind ERC-3643, which stores signed claims about an investor instead of personal data.
Go deeper
- What a tokenized real-world asset actually is: the three legal levels behind "the token represents the asset", which decide who you are in a bankruptcy.
- Getting prices on-chain: NAV, oracles and proof of reserve: the same pattern of an off-chain source of truth and an on-chain copy, applied to prices.
- Which blockchains RWAs live on, and why: what these compliance checks cost in gas and in composability.
- Securitize: the company behind DS Protocol and BUIDL's transfer agent.
- 🟢 Ethereum Improvement Proposals, "ERC-3643: T-REX, Token for Regulated EXchanges", https://eips.ethereum.org/EIPS/eip-3643
- 🟢 Stellar Developers, "Control access to an asset with flags", https://developers.stellar.org/docs/tokens/control-asset-access
- 🟢 Solana Program Library, "Token-2022 extensions", https://spl.solana.com/token-2022/extensions
Sources
🟢 primary · 🟡 credible secondary · 🔴 tertiary (never used to cite a number)
- 🟢 Author's on-chain read, Ethereum, 4 Sep 2026: BUIDL proxy
0x7712c34205737192402172409a8F7ccef8aA2AEc, Trust Service0x3a68756d0335e75c909ba1e8fefc1d4832c36c60, compliance configuration0x1dc378568cefd4596c5f9f9a14256d8250b56369, and an event-log scan from block 19,343,277. - 🟢 Author's on-chain read, Ethereum, 4 Sep 2026: OUSG implementation
0x1CEB44b6E515aBf009E0CCb6ddaFD723886cf3Ff, allRoleGrantedevents since block 16,234,210, and Safes0xaed4caf2e535d964165b4392342f71bac77e8367,0x5ae21c99fc5f1584d8cb09a298cffd92b5d178efand0x2e55b738f5969eea10fb67e326bee5e2fa15a2cc. - 🟢 Author's on-chain read, Stellar, 4 Sep 2026: BENJI issuer account
GBHNGLLIE3KWGKCHIKMHJ5HVZHYIK7WTBE4QF5PLAKL4CJGSEU7HZIW5(flags, signer weights, thresholds, trustlines, last 200 operations). - 🟢 Author's on-chain read, Avalanche, Solana and Aptos, 5 Sep 2026: BUIDL token
0x53fc82f14f009009b440a706e31c9021e1196a2f(Avalanche), mintGyWgeqpy5GueU2YbkE8xqUeVEokCMMCEeUrfbtMw6phr(Solana), fungible asset0x50038be55be5b964cfa32cf128b5cf05f123959f286b4cc02b86cafd48945f89(Aptos), with supplies of each class. - 🟢 US Code of Federal Regulations, 17 CFR 240.17Ad-10, https://www.law.cornell.edu/cfr/text/17/240.17Ad-10
- 🟢 Securitize Holdings, Form S-1 and Form 424B3, 2026, https://www.sec.gov/Archives/edgar/data/2094496/000162828026054866/securitizeholdings-424b3.htm
- 🟢 BlackRock Liquidity Funds, Form 485APOS, 8 May 2026, SEC EDGAR: OnChain Shares class, BNY Mellon Investment Servicing as transfer agent, https://www.sec.gov/Archives/edgar/data/97098/000119312526214958/d45978d485apos.htm
- 🟢 Securitize, press release on the launch of BUIDL, 20 Mar 2024
- 🟢 Ethereum Improvement Proposals, "ERC-3643", https://eips.ethereum.org/EIPS/eip-3643
- 🟢 Stellar Developers, asset control flags and signer thresholds, https://developers.stellar.org/docs/tokens/control-asset-access
- 🟢 Solana Program Library, Token-2022 extensions, https://spl.solana.com/token-2022/extensions
- 🟢 Mountain Protocol, "USDM Wind-Down Overview", 15 Aug 2025.
- 🟡 Steakhouse Financial, analysis of BUIDL's offering memorandum, Apr 2024.
- 🟡 The Defiant and Crowdfund Insider, reports on the SEC no-action letter for FOBXX, Aug 2026.
- 🟡 Spark, "Tokenized Private Credit", Aug 2026: Maple's 2022 losses, including Orthogonal Trading's 36 mn USD default.