Pond Street Ledger

Who Actually Holds the Share Behind Your Stock Token

A tokenized equity is only as good as the chain of custody underneath it. Here is who holds the underlying share, where the token sits in the legal queue, and what each link can do to you.

✓ 1593.efrogs.eth2026-09-118 min

A tokenized stock is a claim, and every claim has a counterparty. The trading experience hides this well. You swap a stablecoin for a token on a decentralised exchange, the balance appears in your wallet, and nothing about that flow tells you who is holding the share of stock that gives the token its value, under what law, or what happens to you if that party fails. This piece walks the chain of custody from the exchange floor to your wallet and names the point at which each link can hurt you.

The chain of custody, link by link

Start at the top. A share of a US listed company almost never exists as a certificate in anyone's drawer. It sits in a central securities depository, immobilised, and ownership is tracked as book entries down a pyramid of brokers and banks. A tokenization programme plugs into that pyramid at some level: it opens an account with a broker or a custodian bank, buys the share, and leaves it there. That custodian is link one. Link two is the issuing entity, the legal person that owes you something in exchange for the token. Link three is the smart contract that mints and burns the token. Link four is your wallet, or whoever holds its keys.

The important thing about this arrangement is that the custodian usually has no idea you exist. Its client is the issuer, not the token holder. From the depository's point of view there is one account holding N shares. The subdivision of that position into thousands of tokens happens entirely offchain in the issuer's records and onchain in a token contract, and neither of those is visible to the entity that actually has the stock.

What the token is, legally

This is where programmes diverge, and where reading the offering document actually pays. Broadly there are three shapes. The first is a direct-title arrangement, in which the token is registered as evidence of ownership of the share itself and the register of the company or a transfer agent recognises the holder. The second, and by far the most common for foreign listed equities, is a debt or note structure: the issuer sells you a tracker certificate that promises the economics of one share, backed by a share it has bought and pledged. The third is a fund or trust wrapper, where the token is a unit in a vehicle whose only asset is the stock.

Only the first makes you a shareholder. The other two make you a creditor or a unit holder, which is a different queue in an insolvency and a different set of rights while everything is going fine. A note holder does not vote. A note holder typically receives a cash payment mirroring a dividend rather than the dividend, which can have different tax treatment in the reader's jurisdiction. A note holder in a poorly structured programme ranks alongside every other unsecured creditor of the issuer, which is why the well built programmes use bankruptcy-remote special purpose vehicles whose only business is holding the collateral.

Segregation is the whole argument

The question that decides how bad a failure gets is whether the underlying shares are segregated from the issuer's own assets and from other clients' assets. Omnibus accounts, where many clients' holdings sit in one account in the custodian's books, are cheap and operationally simple. Fully segregated accounts, one per vehicle, cost more and settle more slowly, but they make it far easier for an administrator to identify which shares belong to which claim and hand them over rather than pool them.

The tradeoff being made is cost and speed against clarity in a failure. Omnibus buys tighter spreads, because the operator can net internally and does not pay per-account custody fees. Segregation buys a shorter, less contested path from a bankruptcy filing to shares in the hands of the people who paid for them. Neither is fraud. But a programme that has chosen omnibus and does not say so is telling you something about its disclosure culture.

Proof of reserves is a photograph, not a guarantee

Most serious programmes publish attestations: an independent firm confirms that on a given date the custody accounts held at least as many shares as there were tokens outstanding. That is worth having. It is not the same as an audit of the issuer, and it is emphatically not a statement about encumbrance. A share can be present in the account and simultaneously lent out, pledged, or subject to a repo. Attestations vary widely in whether they address this, and the ones that matter say explicitly that the assets are unencumbered.

The onchain half of the proof is easier. Token supply is public, and anyone can read it from the contract. What cannot be read from the contract is whether the mint authority is a multisig, a single key, or an upgradeable proxy that can be pointed somewhere else. That is a custody question too. The key that can mint unlimited tokens is functionally as dangerous as the key that can move the shares.

What can go wrong, ranked by how likely it is

In order of frequency rather than drama: an oracle marks the token at a stale price and someone trades against it, which is a pricing failure rather than a custody failure but is often mistaken for one. A transfer restriction in the token contract freezes a wallet, usually because of a sanctions screen, and the holder discovers that the asset was permissioned all along. A corporate action is processed late and the token's economics diverge from the stock's for a few days. The issuer suspends creations and redemptions during a stressed market, at which point the token trades at whatever the secondary market says rather than at parity. And, rarest and worst, the custodian or the issuer fails, and the answer to who owns the shares becomes a matter for a court in whichever jurisdiction the vehicle was incorporated.

What to read before you hold one

Four documents, in this order. The offering or terms document, to establish whether you are a shareholder, a creditor or a unit holder. The custody disclosure, to find the name of the custodian and whether the accounts are segregated. The latest attestation, to see whether it covers encumbrance and how recent it is. And the token contract itself, to see who can mint, who can freeze, and whether the code can be upgraded. If a programme makes any of those four hard to find, the difficulty is the disclosure.

Where this is heading

The direction of travel is toward structures where the token is the register entry rather than a receipt pointing at one, because that collapses the chain of custody from four links to two and removes the creditor problem entirely. Getting there requires transfer agents and depositories that will treat a blockchain record as authoritative, which is a legal and operational change rather than a technical one, and it is proceeding jurisdiction by jurisdiction. Until then, the honest description of most tokenized equity is a well collateralised claim on a company that holds a share for you, and the quality of any given one is a question about that company.