ProcessPhygital Assets
Designing the ownership lifecycle of a phygital item, from first claim to redemption
When a product ships with a digital twin token, someone must decide how the buyer claims it, what happens when the item is resold with or without the token, and what redemption, repair, loss and theft do to the record. This process sets out each lifecycle stage with its controls and exceptions, for both models: the token travels with the object, or the object stays in a vault while the token trades.
On this page
- Two custody models: the token travels with the object, or the object stays in the vault
- The phygital ownership lifecycle at a glance
- Seven stages from factory to retirement, with their controls
- A first claim, message by message
- Exceptions that separate a token from its object
- When a phygital token becomes a regulated product
- How ownership tokens relate to digital product passports
- Questions and answers
- Sources
Two custody models: the token travels with the object, or the object stays in the vault
The model decides what the token means. Mixing the two without saying so is the most common source of disputes between holders and issuers.
| Aspect | Token travels with the object | Object vaulted, token trades |
|---|---|---|
| Who holds the item | The owner, at home or in a shop | A custodian, such as a vault operator or the brand itself |
| What the token represents | A certificate of authenticity and history for an item anyone can inspect | A claim to take delivery of a specific item held in custody |
| How resale works | Item and token change hands together, ideally in one checked handover | The token changes hands; the item stays put until redemption |
| What redemption means | Usually nothing: the token remains the item's record | The holder surrenders the token and the custodian ships the item |
| Main risk | Token and object part company | The custodian fails, loses the item or cannot show it still holds it |
| Typical goods | Fashion, watches, trainers, art editions | Fine wine, bullion, trading cards, collectible spirits |
Both models can share one identifier and record design; they differ in custody, insurance and promises.
The phygital ownership lifecycle at a glance
- Enrolment
Identifier, item details and an unclaimed token are bound at manufacture or authentication.
- First claim
The buyer proves possession and receives the token.
- Resale
Ownership moves, with or without the object, after authenticity checks.
- Service and repair
Authorised events are appended to the history.
- Exceptions
Lost tags, theft reports and disputes are handled by written procedure.
- Redemption or retirement
The token is burned or marked final and the record is closed.
Seven stages from factory to retirement, with their controls
Enrol the item and bind the identifier
Bind the tag or code to the item record at manufacture, or at authentication for older items. Record who enrolled it, where and on what evidence, and mint the token into an issuer-controlled account, not straight to a customer. ColdAI's phygital framework uses NFC chips, QR attestations and supply-chain oracles for this binding1. Load tag keys under a documented procedure, since anyone holding them can make convincing fakes.
Let the first buyer claim the token
The claim must show that the claimant holds the object now. A fresh cryptographic tap is the best evidence; a scratch-off code inside sealed packaging is a cheaper alternative. Hold transfers for a short cooling-off period so a token claimed with a stolen item can be reversed, and offer a hosted account, created with an email address or brand login, for buyers without a crypto wallet.
Transfer ownership on resale
For items that travel with their token, move token and object in one checked handover: the seller starts the transfer, the buyer taps the item to prove it arrived, and only then does the token move. Some designs require a signature from the item's chip for any transfer, as the draft ERC-5791 proposes for Ethereum5. Treat royalties as a commercial term, not a control: on Hedera, NFT royalty fees apply when value and token move in one transaction, and the network cannot enforce them if the parties split the exchange2.
Hold vaulted goods under attestation
When the object stays in custody, the token is only as good as the custodian. Publish regular custody attestations, ideally from an independent inspector, record insurance and item condition, and define redemption: who may request it, which identity and sanctions checks apply, shipping, duties and timing. Lock the token once a redemption is accepted so it cannot be sold while the item is in transit.
Append service and repair history
Authorised repairers add events such as a strap replacement or a movement service without changing earlier entries, and replacement parts with their own identifiers are recorded as new links. A history only the brand can write is simpler; one approved repairers can write is more useful but needs a maintained list of who is authorised.
Handle exceptions by procedure
Lost or damaged tags, theft, disputed ownership and a token sold apart from its object each need a written procedure stating the evidence required, who decides, and what the public record shows while a case is open.
Redeem or retire the token
For vaulted goods, redemption returns the token to the issuer, which burns it and releases the item. For items that travel with their token, retirement marks the record final at end of life or recycling while keeping the history readable for anyone checking a later resale claim. Never reissue a retired identifier.
A first claim, message by message
- Buyer's phone
Taps the item and submits the claim.
- Embedded NFC tag
Returns a link with a fresh cryptographic code.
- Brand claim service
Verifies the tap and applies the claim rules.
- Token ledger
Holds the token and its current owner.
- Buyer's account
Hosted or self-custody wallet that receives the token.
Exceptions that separate a token from its object
The token is sold but the seller keeps the item
Early signalA transfer completed with no tap from the object, or a non-delivery complaint.
MitigationRequire a tap from the item to complete transfers of token-with-object goods, and state in the terms that the token alone gives no right to the item.
A stolen item is offered for resale
Early signalA theft report from the registered owner, with a police reference.
MitigationFlag the record so verification pages show the open report, and pause transfers if the token design allows it. On the Hedera Token Service, freeze and wipe keys make that possible, but a key type not set when the token is created cannot be added later, so decide before launch3.
The tag is lost, damaged or replaced
Early signalFailed taps on an item the owner can otherwise show they hold.
MitigationRe-enrol the item through an authorised inspection, link the new tag to the old record and revoke the old identifier so a salvaged tag cannot be reused.
Two people claim the same item
Early signalA dispute raised by a buyer, a seller or a marketplace.
MitigationSuspend transfers while the case is open, decide on documented evidence such as receipts and transfer logs, and record the outcome in the history.
The brand or custodian stops trading
Early signalThe verification service or the custody attestations stop updating.
MitigationKeep ownership on a public network, publish the verification method, escrow tag keys and records, and agree in advance how vaulted items return to holders.
When a phygital token becomes a regulated product
How ownership tokens relate to digital product passports
A digital product passport under the EU's Ecodesign for Sustainable Products Regulation is a compliance record about a product model, batch or item, with access levels for consumers, repairers and authorities. An ownership token is a commercial record of who holds one specific item. The two can share an identifier and a data carrier, but they answer to different rules and audiences, so keep them as separate records that reference each other. Our digital product passport use case covers the passport side.
Questions and answers
What if someone sells the token but keeps the physical item?
In a token-with-object design, the terms should say the token records authenticity and history and is not title to the item, and transfers should require a tap from the object so a seller cannot complete one without handing it over. Marketplaces can hold payment until the buyer's tap succeeds. In a vaulted design the reverse applies: the token is the claim, and the custodian releases the item only to whoever redeems it.
Can a stolen item be flagged on its phygital record?
Yes, if the design allows it. The verification page can show an open theft report as soon as the registered owner files one with supporting evidence, which deters resale through checked channels. Pausing or reversing token transfers needs administrative keys on the token, which buyers may see as central control, so publish when and how they will be used. Flags should be resolved or expire through a documented review.
Who controls the record if the brand stops trading?
That depends on choices made at launch. If ownership lives on a public network and the verification method is published, holders can still show what they own, even if the brand's own pages disappear. Cryptographic tags are harder, because their keys sit with the brand or its supplier, so plan an escrow arrangement or a handover to an industry body. Vaulted goods need contracts covering how items return to holders.
Sources
- Phygital Assets: framework and delivery approach — ColdAI
- Custom token fees — Hedera documentation · checked 10 October 2026
- Define a token — Hedera documentation · checked 10 October 2026
- Regulation (EU) 2023/1114 on markets in crypto-assets (MiCA) — EUR-Lex · checked 10 October 2026
- ERC-5791: Physical Backed Tokens (draft) — Ethereum Improvement Proposals · checked 10 October 2026