The RWA tokenization spectrum: from no claim to native claim

Two tokens can wear the same label, pay the same yield, and differ by orders of magnitude in what you legally own. A five-level spectrum for tokenised RWAs.

The RWA tokenization spectrum: from no claim to native claim

What does the holder of a "tokenised real-world asset” actually own.

The question is more interesting than it sounds. Two tokens that both wear the label can differ by orders of magnitude in what they are legally. One can be a direct interest in a ring-fenced vehicle that owns the asset; another can be subordinated debt against an operating company that holds the asset as one of many balance-sheet items. The yield can be the same. The aggregator dashboard can read "bankruptcy remote: confirmed" for both. The legal recovery profile if either issuer fails is not in the same league.

Most public commentary on tokenised RWAs talks about the operational surface - admin keys, oracle freshness, redemption queues, smart-contract audits. That surface matters and is the right surface to inspect for ordinary failures: a stale oracle, an admin key compromise, a gated redemption. But it is the wrong surface for the failure modes that hurt most: the issuer fails, the regulator acts, the program is terminated, the underlying goes to zero. For those scenarios, the load-bearing fact is not how the token transacts. It is what the token is.

This article proposes a five-level spectrum, indexed L0 to L4 and labelled by structural type, for what a tokenised RWA is. The market is currently compressed at the bottom of the spectrum and prices yield without pricing the level. That compression is a temporary mispricing, not a permanent state.

The spectrum

Each level is named twice: by index, so it can be cross-referenced cleanly, and by a structural label, so it can be read. For each level, three coordinates: the legal status of the token, what survives if the issuer fails, and what the holder can actually do with it.

L0 - Operating-company debt

The token is a debt instrument issued by an operating company. The operating company holds (or claims to hold, often through downstream intermediaries) something it calls a real-world asset. The holder is a creditor of the operating company; commonly an unsecured, sometimes a contractually subordinated creditor.

Pattern marker: the conditions of issue contain explicit subordination language; the issuer reserves rights to substitute the underlying reference asset, change its risk profile, or terminate the program; the legal opinions, where they exist, are about a fund or a vehicle one or more layers down the chain, with no direct claim flowing back to the token holder.

If the operating company fails, the holder waits in line behind senior creditors. The "real" asset is the operating company's asset, encumbered by all of the operating company's other obligations. There is no segregation in any robust sense. There may not even be a ring-fenced vehicle - the asset can sit on the operating company's general balance sheet alongside everything else it owns.

This is the most common structure in the current "tokenised RWA" market because it is the cheapest and fastest to ship. It does not require a securitisation lawyer, a special-purpose vehicle, an independent board, or a jurisdiction-specific statute. It requires a smart contract and a subscription agreement. The token can have beautiful on-chain mechanics; the underlying claim is thin.

L1 - Wrapper SPV beneficial interest

A dedicated special-purpose vehicle exists, and the token represents a beneficial interest in it. Better than L0 because there is a named vehicle between the holder and the operating sponsor. Worse than L2 because the vehicle is not bankruptcy-remote in any robust sense.

Pattern marker: the SPV exists, is named in the documentation, and may even have its own bank account. But the bankruptcy-remoteness opinion either does not exist or is hedged with conditions the sponsor controls - no commingling, no other indebtedness, independent director consents, non-petition undertakings. The directors are sponsor-affiliates without genuine independence. The SPV could in principle be consolidated with the sponsor under substantive consolidation doctrines in adverse scenarios.

If the sponsor fails, the holder is better off than at L0 because there is a vehicle to fight for. But the fight is not statutory - it is contractual and depends on the documents holding up under stress. The difference between a properly ring-fenced vehicle and one that merely looks like one lives in the documents, not in the marketing material.

L2 - Dedicated bankruptcy-remote vehicle

The vehicle is properly ring-fenced by jurisdictional design, not just by contract. Two common archetypes:

Luxembourg securitisation compartment under the Securitisation Act of 22 March 2004 (as amended in 2022). Within a single securitisation undertaking, multiple compartments can be created, each with its own assets, its own creditors, and its own waterfall. The compartments are statutorily ring-fenced: creditors of one compartment have recourse only to that compartment's assets. The 2022 modernisation expanded financing flexibility and clarified the regime.

Cayman Islands segregated portfolio company (SPC) under Part XIV of the Companies Law. The SPC is a single legal entity but with statutory segregation of "portfolios"; portfolio assets are ring-fenced from the liabilities of other portfolios. Cayman courts have upheld the ring-fencing under stress: in Re Centaur Litigation Unit Series 1 Ltd, despite roughly US$27 million of fraud and intermingling of assets across portfolios, the court refused to pool. The statutory architecture survived even bad-actor conduct.

Both architectures require: independent directors with genuine independence, transaction documents preventing voluntary insolvency filings, non-petition covenants, no commingling, and legal opinions on bankruptcy-remoteness that are not conditioned on the sponsor's good behaviour. Done properly, the vehicle's failure does not propagate to other vehicles within the same umbrella, and the sponsor's failure does not propagate to the vehicle.

Done improperly, the architecture exists on paper and pierces under stress. The space between L1 and L2 is a continuum, not a binary; only the legal opinions and the document review tell you which side a given product is on.

If the holder holds a beneficial interest in a properly constructed L2 vehicle, what survives if the sponsor dies is the vehicle itself. The vehicle has its own legal life, severable from the sponsor.

L3 - One-to-one legal replication

The on-chain token is the security, under a jurisdiction-specific DLT statute. Not a representation of the security, not a digital twin - the legal instrument exists in token form, with the chain serving as the authoritative register.

Switzerland's DLT Act (private-law components in force from 1 February 2021, remaining components from 1 August 2021) created a new category of security under Articles 973a et seq. of the Code of Obligations: the "ledger-based" or "register uncertificated" security. Under Article 973d para. 1, a registered uncertificated security can only be transferred and asserted via the on-chain register - replacing the prior requirement for written assignments and making the chain the legally operative venue for transfer. Article 973d para. 2 imposes four mandatory requirements on the register: holder power of disposal, integrity protection, clear rights documentation, and independent access without third-party intervention.

Germany's eWpG (effective 2021) recognises electronic securities registers in two flavours - central registers operated by traditional CSDs and crypto securities registers maintained on DLT - making the on-chain register one of two statutorily recognised forms. The initial scope was bearer bonds; the regime has been progressively extended.

Luxembourg's Law of 22 January 2021 amended the financial sector law and the dematerialised securities law to recognise DLT-based electronic recording systems for the issuance and conversion of dematerialised securities.

Liechtenstein's TVTG (effective 1 January 2020) took a different architectural choice. Rather than enabling a specific category of security, it implemented the "Token Container Model": a token is a container, the right represented is the content. The act provides a generalised civil-law basis for the ownership, transfer, and enforcement of rights in tokens - any right, not just financial instruments. This puts Liechtenstein structurally in a different place from its civil-law neighbours: the TVTG is a horizontal token-rights framework rather than a vertical securities enablement.

At L3, the holder owns the security directly, enforceable by chain state under a statute that treats the chain as the authoritative register. The legal classification is "registered security" or its statutory equivalent - which means regulated capital can hold it under existing frameworks for those instruments, with no special accommodation needed.

L4 - Native legal claim

The token is the legal claim itself. There is no off-chain referent. The statute recognises a fully native digital instrument: governance, distributions, dissolution rights all attach to the token itself, with no parallel paper.

Wyoming's DAO Supplement (codified at Title 17, Chapter 31 of the Wyoming Statutes) is the leading example. A DAO is a limited liability company organised under Chapter 31, registered with the Secretary of State, named with "DAO", "LAO", or "DAO LLC". A member's ownership right may be "ascertainable from a blockchain on which the organization relies to determine a member's ownership right" - meaning the chain can be authoritative for the cap table. Where the articles of organisation and a smart contract conflict, the smart contract prevails (subject to narrow exceptions for formation provisions). The membership interest may be characterised as a "digital security" or "digital consumer asset" under W.S. 34-29-101.

At L4, the cap table is the chain. There is no off-chain register to reconcile against. Governance, distributions, and dissolution are encoded in the smart contract and given direct legal force.

L4 is rare in tokenised RWA today because the use case for which native-statute entities are best suited (true digital-first organisations with no off-chain footprint) is not the use case most tokenised RWAs are trying to solve. Most tokenised RWAs are trying to put an off-chain asset onto a chain. L4 puts a chain-native organisation into law.

Why the level matters

Three reasons, ordered by audience.

For holders, insolvency outcomes diverge sharply. An L0 holder is an unsecured (often subordinated) creditor of a single operating entity, joining the queue of general creditors if the entity fails. An L1 holder owns a beneficial interest in a wrapper that may or may not survive a substantive-consolidation challenge. An L2 holder owns a beneficial interest in a vehicle that survives the sponsor's death by statutory design - the vehicle has its own legal life. An L3 holder owns the security itself, enforceable on the chain by force of law. An L4 holder owns the claim natively - the chain is the legal register. The same yield maps to materially different recovery profiles when stress arrives.

For protocols accepting RWAs as collateral, liquidation outcomes diverge. Seizing an L0 token in a liquidation does not transfer the underlying asset - it transfers a subordinated debt claim that must be enforced against the issuer's estate in some bankruptcy court. Seizing an L2 token transfers a beneficial interest in a vehicle that has its own legal life and is severable from the sponsor. Seizing an L3 token transfers the security itself, with all the secondary-market depth that comes with regulated-instrument status. The servicing burden - what the protocol or its liquidator must do to realise value after seizure - scales sharply with the level. A protocol that prices L0 collateral at the same LTV as L2 collateral is mispricing the tail by a wide margin.

For issuers and capital, the level determines which capital can hold the asset. Regulated capital cannot hold what cannot be cleanly classified. An institutional fund or a bank treasury cannot hold "subordinated debt against an operating company that points at an asset" without significant work to fit it into an investment mandate. The same fund can hold a registered security cleanly. The structural level is therefore a positioning choice - it determines the addressable capital base. L0 reaches retail and crypto-native funds; L2 begins to reach regulated allocators; L3 reaches them with no additional friction; L4 reaches the subset that has built the rails to hold native digital instruments.

The market today does not price this. Yields cluster by underlying strategy - the credit fund, the Treasury wrapper, the private credit pool - not by structural level. A "tokenised credit fund" yielding 9% can sit at L0 or L2; the L0 product carries materially more tail risk for the same coupon. As regulated capital enters tokenised RWA at scale, the products that survive at the top of the spectrum will be the ones designed for that capital base. Products at the bottom will face migration pressure: they either move up the spectrum, find a permanent home in a market that values yield more than structural rigor, or contract.

The jurisdiction race

The structural level a product can reach is bounded by the legal jurisdiction it operates in. Without a DLT-recognising statute, L3 and L4 are structurally impossible: the law does not recognise the chain as the register. With one, products can move up the spectrum without ceremony.

Civil-law jurisdictions have been more active than common-law ones at the high end of the spectrum. Switzerland's DLT Act enables L3 cleanly: a defined category of registered uncertificated security, transferable only via the on-chain register, with four mandatory technical requirements that any qualifying register must meet. Germany's eWpG enables L3 progressively - initially limited to bearer bonds, expanding over time to other instrument classes. Luxembourg permits DLT-based recording for dematerialised securities under its 2021 amendment, with the 2022 securitisation modernisation reinforcing the L2 backstop for vehicle-based issuance. Liechtenstein took the most generalised approach with the Token Container Model: a horizontal token-rights framework rather than a vertical securities enablement, giving a civil-law basis for any tokenised right.

The common-law side runs differently. Delaware amended its General Corporation Law (sections 219, 224, 232) in 2017 to permit corporate stock ledgers on blockchain; shares tracked on a blockchain are legally classified as uncertificated securities under existing law. This is enabling but not transformative: the existing legal classification continues to apply, the blockchain is one of several permitted register technologies. Wyoming pushed further with the DAO Supplement, creating a native vehicle for chain-first organisations - L4 territory. The Cayman Islands provides the dominant L2 infrastructure through the SPC regime, which is statutory ring-fencing inside a common-law framework.

The EU's MiCA, in force since 2024, deliberately carved out financial instruments under MiFID II - ESMA has been clear that tokenised financial instruments remain financial instruments under MiFID II regardless of the technological form, applying a substance-over-form test to crypto-asset classification. MiCA governs the bulk of crypto-asset markets (asset-referenced tokens, e-money tokens, "other" crypto-assets) but leaves tokenised securities under the existing MiFID/CSDR/prospectus apparatus. The dual regime now in place in EEA jurisdictions - MiCAR for crypto-assets, national DLT statutes for securities - reflects a deliberate division: securities law was already there; MiCA fills the gap below it.

Two implications of this geography. First: the available structural level for a product depends not just on the issuer's design choices but on the jurisdiction it can credibly operate in. A product that wants L3 status needs an issuer domiciled in a jurisdiction with a DLT-securities statute and a register that meets that statute's requirements. Second: regulated capital follows legal clarity. The jurisdictions that have shipped DLT statutes are the ones positioned to host the next generation of tokenised securities at scale. The jurisdictions that have not are not.

The marketing collapse

Most tokenised RWA assessments inspect the on-chain surface and stop there. The structural level is harder to read because it lives in legal documents written for lawyers, not in marketing decks written for investors. A few patterns explain why the spectrum is hard to see from outside:

The vocabulary is the same across all five levels. "RWA tokenisation", "tokenised fund", "tokenised credit", "tokenised treasury" - these phrases are used interchangeably by issuers at L0, L1, L2, and L3. They are descriptions of intent, not of legal architecture.

Aggregator labels typically apply to the wrong layer. When an aggregator reports "bankruptcy remote: confirmed", that label usually refers to the underlying fund or vehicle that ultimately holds the asset - which may be L2 or higher. The wrapper that the holder actually holds, layered between the holder and that underlying, can sit at L0 or L1. The label is true and irrelevant at the same time.

The structural facts live in instruments that are filed once and rarely re-read. Subscription agreements, conditions of issue, prospectuses, and the supporting legal opinions are where the spectrum-level lives. Marketing decks summarise strategy and underlying, almost never the holder's legal position relative to either.Reading past these patterns needs a structured approach. Five questions to apply to any collateral asset. They are generic on purpose - the specifics change by asset class (stablecoin, yield vault, tokenised RWA, structured product), but the structure of the inquiry does not. For a tokenised RWA, the first question is the spectrum; the rest sit on top of it.

1. What does the collateral represent? For a tokenised RWA, the answer is a position on the L0-L4 spectrum: subordinated debt against an operating company, a beneficial interest in a wrapper SPV, a beneficial interest in a ring-fenced vehicle, the security itself under a DLT statute, or the native legal claim. For a stablecoin, the answer is the backing structure (reserves, collateral, algorithmic). For a yield vault, the answer is what the depositor token represents in the underlying strategy. The same question, category-specific answers.

2. What can affect its value? Underlying asset performance, issuer credit, structural level, regulatory exposure. The spectrum determines how much of which kind of risk attaches to the holder. At L0, the operating company's general credit risk dominates the position regardless of how the underlying performs. At L2, the wrapper insulates the holder from the sponsor's solvency. At L3, the underlying's own risk is what remains; the issuer's credit no longer enters the answer.

3. How can the value be redeemed, and how fast? Primary redemption mechanics, cadence, gates, secondary-market depth, the relationship between on-chain trading and off-chain settlement. The spectrum level shapes the answer here too. An L3 security can sit in regulated infrastructure with deep secondary-market trading; an L0 token's redemption is a bilateral primary-only process subject to the issuer's discretion. A vault wrapper that consumes an RWA inherits the underlying's redemption profile and adds its own queue mechanics on top.

4. What can block redemption? Issuer discretion, statutory gates, regulatory action, insolvency proceedings, settlement-cadence mismatches between on-chain expectation and off-chain mechanics. At L0, the operating company's insolvency blocks redemption directly because the holder is a creditor of that company. At L2, the wrapper's bankruptcy-remote status changes what can and cannot block; the sponsor's failure does not freeze redemption from the vehicle. At L3, the security's transferability is standard; the underlying's settlement is a separate question, blocked only by the normal regulatory and operational gates that apply to that instrument class.

5. Who can change the answers to 1-4? Amendment rights, admin powers, controller mechanics, governance pathways. An issuer that reserves the right to substitute the underlying, modify the redemption schedule, or terminate the program holds option value the holder pays for. ERC-3643's controller mechanics and ERC-1400's controller force-transfer make this layer explicit on-chain; an L0 issuer's reserved discretion in the conditions of issue makes it implicit but no less real. The breadth of mutability at this layer determines how stable the answers to the first four questions actually are - and how much of the marketing narrative is structural fact versus current discretionary policy.

The five questions are not specific to RWAs. They apply equally to a stablecoin (what backs the peg, what can affect the backing, redemption speed, gate mechanics, issuer mutability), to a yield vault (what the deposit token represents in the strategy, strategy risk, redemption queue, withdrawal gates, governance powers), or to any collateral that is not cash. The RWA spectrum is what the framework gets to when question 1 is applied with full depth to a tokenised real-world asset. The rest of this article has been question 1.

If question 5 reveals broad discretion - particularly to alter the bankruptcy-remoteness scope or the legal classification of the token - the product sits lower on the spectrum than the marketing implies. The misclassification pattern is structural: the marketing speaks to question 1 at one level, and the answer to question 5 quietly moves the asset to a lower one.

A note on token standards. The dominant security-token standards on Ethereum - ERC-3643 (the T-REX framework) and the ERC-1400 family (ERC-1410 partitions, ERC-1594 core restrictions, ERC-1643 documents, ERC-1644 controller operations) - encode operational compliance machinery: identity verification, whitelist enforcement, restricted transfer logic, document binding, controller force-transfer. They presuppose a regulated issuer with off-chain KYC/AML infrastructure and a permissioned investor base. They do not specify the legal claim structure of the underlying asset. A token implementing ERC-3643 perfectly can sit at any level of the spectrum - the standard polices who can hold and transfer the token, not what the token represents legally. ESMA's substance-over-form test confirms the same conclusion from the regulator side: the technical form does not determine the substantive legal classification. The token standard is operational infrastructure; the structural level is determined elsewhere.

There is a missing piece worth naming. A standard could encode the structural level itself as an on-chain property - a field that expresses the current state of the representation, placing the token at L0 through L4 with reference to the legal opinions and statutes supporting the classification. The hard requirement is that the property cannot be set by the issuer. Issuer self-classification has the same incentive problem as a borrower setting its own credit rating: the answer rewards optimism. The property should be set by external validators - qualified legal or audit firms - through attestations carried on-chain, ideally with multiple independent attesters for higher-confidence classifications, and with the cost of a false attestation borne by the attester to keep incentives aligned. The mechanics are recognisable: attestation infrastructure already exists in usable form, the rating-agency analogy is the right reference for the role design, and the legal classification is interpretive enough that re-attestation as governance or regulatory conditions change must be part of the design. A standard that polices who can hold a token without saying what the token is, legally, leaves the most consequential fact off-chain. A standard that surfaces the spectrum level under external validation would make the misclassification pattern this article describes substantially harder to sustain. Whether one arrives is a different question. Standards do not emerge from articles. They emerge after the industry has waded through a valley of pain that makes the missing standard's absence operationally costly. The case for this one is being built in advance: every unverified L0 product marketed as L2 today is raising the eventual cost of that crossing.

The broader frame

The spectrum is one axis. There are others.Tokenised RWA does not sit in isolation. It ends up inside vaults. Vaults sit inside lending protocols, collateralised stablecoin systems, structured products, leverage engines. Each consuming layer adds its own dimensions: redemption mechanics, oracle freshness, admin powers, withdrawal queues, governance and upgrade paths, liquidator economics, custodial chains. A holistic underwriting framework for any of these systems has to integrate the structural level of the RWA with the operational characteristics of the wrapper, the redemption profile of the vault, the protocol that consumes it, and the broader market context it lives in.

This article is narrow on purpose. Get the spectrum right first. The on-chain mechanics, which deserve their own treatment, are an independent axis - a product can have immaculate operational hygiene at L0 (which produces the dominant failure mode: clean machinery on top of a thin claim) or rough mechanics at L2 (where the structural floor is high but the day-to-day is noisy). Mixing the two axes into a single "is this safe" question is the dominant analytical failure in the current market.

The market today is compressed at the bottom of the spectrum because the bottom is the cheapest place to ship. Counsel fees are low, jurisdiction overhead is minimal, on-chain machinery is what the analyst community knows how to assess, and yield is what the buyer reads. As regulated capital enters at scale, as more jurisdictions ship DLT statutes, as the protocols consuming tokenised RWA as collateral mature their risk frameworks, the compression eases. The structural level becomes priced. The products built for the top of the spectrum from the beginning are positioned to capture that capital. Those that were not face a structural disadvantage that on-chain transparency cannot fix.

The question to ask of any tokenised RWA is not "is it on-chain" or "is it audited" or "is the redemption transparent". It is: at what level of the spectrum does my claim sit, and is that level appropriate for the use I am making of it. A collateral protocol seizing in a liquidation needs L2 or above to be confident of what it has taken. An allocator holding to maturity may tolerate L1 if pricing reflects it. A market maker quoting two-way needs L3 or above to operate inside the existing securities infrastructure. The structural level is the common language across these audiences. The rest of the framework specialises by use.

The five questions - what the collateral represents, what affects its value, how it redeems, what blocks redemption, who can change those answers - are the spine of any collateral assessment, applied to anything that is not cash. They are generic on purpose. The RWA spectrum developed in this article is what question 1 looks like when applied with full depth to a tokenised real-world asset; questions 2 through 5 sit on top, each shaped by where the asset sits on the spectrum. A holistic underwriting framework - for an RWA, a vault, a stablecoin, a structured product, a token of any kind - is the same five questions applied honestly, then composed across the layers the product sits inside.

The answer is in the subscription agreement.


Stay updated on all things Sprinter, and onchain credit, by following us on X, joining our Telegram, and reading more on our website and docs.