RWA risks and due diligence

A tokenized real-world asset can lose value even when the asset behind it is sound. The risks sit in the structure around the token—how it's backed, who holds it, and whether you can redeem it.

12 minutes
RWA risks and due diligence

A tokenized real-world asset (RWA) can lose value even when the asset behind it is sound. A token is a claim on that structure, not the asset itself, so evaluating an RWA means evaluating the structure, not just the asset it tracks. Common RWA risks sit in the structure around the token: how it's backed, who holds the underlying asset, whether you can redeem it, how it's regulated, the code it runs on, and the parties you're relying on. For what tokenized real-world assets are and how they work, start with what are tokenized real-world assets. This article assumes previous knowledge, and focuses on how to assess RWA risks before investing.

Disclaimer: This guide is for educational purposes only. It is not financial advice, not a solicitation, and not for UK audiences. Tokenized real-world assets are risky and not suitable for all users; eligibility, redemption terms, and regulatory treatment vary by product and jurisdiction.

Why is RWA risk different from other digital asset risks?

Every RWA has two parts: the underlying asset, held offchain in the traditional world—a vault, a bank account, a brokerage—and a digital token on a blockchain network that represents a claim on it. Because either part can fail on its own, RWAs have unique risks versus other types of digital assets. For example, the offchain side can break while the token works perfectly: the asset may not exist, may be poorly safeguarded, or may be worth less than the token claims. Or the offchain side can be sound while the token's contract is exploited onchain. Owning the token means carrying both of these exposures at once, and the blockchain can vouch for neither the asset in the vault nor anything beyond its own ledger. Evaluating an RWA therefore means examining both sides, because a weakness in either can cost you.

This is also why "backed 1:1" is a starting point, not an answer. Backed by what, held by whom, verified how, and redeemable under what terms are the questions that actually determine risk.

Tokenization changes how an asset moves, not what it is. It can make an asset easier to move, hold, and combine with other onchain assets, and it can compress settlement from days to seconds. What it cannot do is remove the conventional financial risks of the asset underneath; it layers blockchain risk on top of them. An RWA therefore carries two sets of risk at once: the offchain risks of the asset and its custodians, and the onchain risks of the token, its code, and any bridges or protocols it touches.

Main types of RWA risk

Backing risk: does the asset behind the token really exist?

Backing is the pool of real assets an issuer holds to stand behind its tokens—the reserves that are supposed to give each token its value. Backing risk is the chance those reserves aren't what, where, or how much the token claims. A token described as fully backed should hold reserves that genuinely exist and match the tokens in circulation. One described as overcollateralized—backed by more value than it issues, as a buffer—should keep that buffer intact when prices move sharply against it. The composition of the backing matters as much as its size: cash and short-term government debt hold up under stress far better than collateral that is volatile, illiquid, or issued by the project itself. Stablecoins are the clearest example of how the backing model drives the risk.

Two things separate strong backing from weak. The first is the liquidity of the reserves: assets that can be sold quickly at a predictable price can meet a wave of redemptions, while illiquid ones may have to be sold at a loss, or can't be sold in time at all. The second is transparency of composition: a token backed by a named, verifiable basket of high-quality assets is easier to trust than one backed by holdings no one can inspect, or by the issuer's own token. A buffer of extra collateral helps but guarantees nothing—if that collateral is volatile and prices fall faster than the system can liquidate it, even an overcollateralized token can end up under-backed. What matters is not whether the backing holds today, but whether it would hold on the worst day.

Custody risk: who holds the asset, and is it protected?

Custody is the safekeeping of the underlying asset—where it physically sits and who is responsible for it. Custody risk is the chance that whoever holds it fails, mishandles it, or can't prove it's really there. A well-structured RWA keeps that asset with a regulated custodian—a licensed institution whose business is safekeeping—in accounts segregated from the issuer's own, so the issuer's failure doesn't put the backing at risk. The evidence is usually an attestation: an independent firm periodically confirming the reserves exist. Two limits matter. An attestation is a point-in-time check, not a continuous guarantee, and it is not a full audit. And "verified" is only as strong as who verified it, and how often. For the practical steps of checking an issuer's reserves, custodian, and history, use MetaMask's how to verify RWA tokens checklist.

"Bankruptcy-remote" is a term worth scrutinizing rather than trusting. It means the underlying assets are meant to sit in a separate legal entity, so that if the issuer becomes insolvent, those assets can't be seized by the issuer's creditors. Whether that protection actually holds depends on how the structure is built and which jurisdiction's insolvency law governs it—a claim to verify, not to accept at face value. Segregation is important for the same reason: assets pooled in the issuer's operating accounts are far more exposed than assets held apart at an independent custodian. When you read an attestation, note who signed it, how recent it is, how often they are produced, and whether the issuer has committed to a fuller independent audit over time.

Redemption and liquidity risk: can you actually get your money back?

Redemption is how you turn the digital token back into the value it represents—either by returning it to the issuer for the underlying asset, or by selling the token to another holder. Redemption risk is the chance that a route is closed, slow, or costly at the moment you need it. Many RWAs restrict direct redemption to verified or institutional holders, and add minimums, lockups, or fixed settlement windows—leaving an ordinary holder to exit by selling on the secondary market, meaning to other buyers rather than back to the issuer. That introduces liquidity risk: if trading is thin, the token can change hands below the value of the asset it represents, and when that market is closed it may not track the underlying at all. Redemption and liquidity risk bite hardest precisely when many holders want out at once.

It's useful to separate the two exits. Primary redemption returns the token to the issuer for its underlying value; a secondary sale trades it to another buyer on an exchange or a DEX—a decentralized exchange that runs on code rather than a company. If primary redemption is gated—limited to certain holders, or paused under stress—the secondary market is the only way out, and its price can diverge sharply from the asset's net asset value (NAV) exactly when you most want to sell. For assets with fixed trading hours, such as stocks, a token that trades 24/7 can also drift from the last real price overnight and on weekends. What's worth establishing before holding is which redemption route is actually open to you, what it costs in time and fees, and how deep the secondary market runs on an ordinary day.

Regulation is how the law classifies and governs a tokenized asset—whether it counts as a security, who is allowed to offer it, and who is allowed to hold it. Regulatory risk is the chance that classification is unsettled, or shifts after you already hold the token. Tokenized securities in particular sit in an actively contested area. In a January 2026 staff statement on tokenized securities, the SEC's Divisions of Corporation Finance, Investment Management, and Trading and Markets said that a security's format—onchain or offchain—does not change how the federal securities laws apply, but the statement carried no legal force of its own and left the operational questions that matter most to holders unresolved. Rules on token offerings, broker-dealer custody, and what can even be called a "tokenized share" were still unsettled and case-by-case as of 2026. Jurisdiction compounds this: many RWAs are geo-restricted, commonly unavailable to US persons, and the venue where a token trades applies its own geoblocking. A product that's compliant for one user in one country may be off-limits, or carry different protections, for another.

Regulatory risk isn't only about a future rule change; it's also about the terms you're accepting today. Many RWAs are structured to be sold outside the US, which is why access is often blocked for US persons and why the investor protections you'd expect from a domestic product may not apply. If an issuer later has to restructure to meet new rules, that can affect eligibility, redemption, or even which holders can keep the token. And because enforcement can move faster than legislation, a product operating in a legal gray area can have its access or listings curtailed with little notice. Treat the current legal status as a snapshot, and check it for your own jurisdiction rather than assuming a global answer.

Smart contract risk: what can break on blockchain networks?

A smart contract is the onchain code that runs the token—creating it, redeeming it, and enforcing its rules automatically, without a company in the loop. Smart contract risk is the chance that code contains bugs or can be exploited. The token, its mint-and-redeem logic, and any protocol that uses it as collateral all run on such code, and audits reduce this risk without removing it. RWAs that span multiple blockchains add bridge and interoperability risk, since cross-chain infrastructure has historically been a frequent target. The more onchain machinery sits between you and the underlying asset, the more surface area there is for something to break.

Two features deserve attention. Many RWA tokens use upgradeable contracts and administrative keys—controls that let the issuer change the token's logic or restrict transfers. That's useful for compliance, but it also means a small set of privileged keys can alter how the token behaves, a real risk if those keys are poorly secured or held too narrowly. RWAs also rely on oracles—services that feed the real-world price of the asset onto the blockchain—and if an oracle is wrong, delayed, or manipulated, redemptions and any lending built on the token can misprice. Every extra network, bridge, or protocol a token touches adds another way a single failure can reach your holdings. Fewer moving parts, reputable audits, and careful key management all point to lower onchain risk, though none reduce it to zero.

Counterparty risk: who are you really trusting?

A counterparty is any party you're relying on to make the token good—the issuer and everyone behind it: the broker-dealer, the custodian, the firm that verifies the backing, and any settlement partner. Counterparty risk is the chance one of them fails to do its job. The token is ultimately a claim on this chain of parties, not a direct claim on the underlying asset registered in your name. If a key counterparty fails, is compromised, or simply doesn't perform, the token holder is exposed even if the asset itself was fine. Concentration matters here too: a structure that leans on a single custodian or a single point of failure is riskier than one with redundancy.

Counterparty risk is easy to underestimate, because it stays invisible until something breaks. Mapping the chain behind a token is what makes it visible: who issues it, who holds the asset, who verifies the backing, who processes redemptions—and how much of that rests on a single firm. A track record helps, and so does transparency: issuers that clearly disclose their partners, legal structure, and what happens in a failure give you more to evaluate than those that don't. Every RWA requires some trust; the point is to know exactly who and what is being trusted, and how much rides on any single link.

What should you check before buying an RWA?

Before holding any tokenized real-world asset, work through the structure behind it rather than the marketing around it. That means asking:

  • What exactly the token represents: Economic exposure, or legal ownership? Total return, or price only? This determines what you're actually buying.

  • What backs the token, and how is that proven: The backing model, the named custodian, and the verification method and cadence—not just the phrase "backed 1:1."

  • Who holds the asset, and is it protected if the issuer fails: Segregated, regulated custody and bankruptcy-remoteness are what separate a robust structure from a fragile one.

  • How do you get your money back: Who can redeem, under what minimums, lockups, and windows—and what secondary-market liquidity exists if you can't redeem directly.

  • Is it legal for you, and could that change: Your jurisdiction's treatment, eligibility restrictions, and how settled (or unsettled) the regulatory picture is.

  • What's the onchain risk: Audit status of the token and any protocol using it, plus any crosschain exposure.

For the hands-on version of these checks—where to find attestations, how to confirm a custodian, what an issuer's disclosures should contain—follow the how to verify RWA tokens guide. This framework is about knowing which questions matter and why; that checklist is about answering them.

What are the red flags in a tokenized asset?

Some warning signs recur across risky RWAs. Any single one is a reason to do additional research about the digital asset before interacting with it.

  • Vague backing. "Fully backed" with no named assets, custodian, or attestation cadence.

  • No independent verification, or attestations from an unnamed party, produced rarely or not at all.

  • Unclear redemption. No plain answer to who can redeem, how, and how fast, or redemption that can be paused at the issuer's discretion.

  • Opaque structure. No disclosure of the issuer, its legal setup, or what happens to holders if it fails.

  • Heavy centralization. Broad admin-key powers, a single custodian, or a single oracle with no fallback.

  • Marketing over mechanics. Emphasis on yield and upside with little detail on how the asset is held, verified, or redeemed.

What does a well-structured RWA look like?

The six categories above describe what can go wrong. They also describe, in reverse, what a sound structure looks like: reserves in liquid, named assets that match the tokens in circulation; the underlying asset held by a regulated custodian in segregated accounts; independent verification produced on a stated cadence; redemption terms that are published rather than discretionary; audited contracts with narrow administrative powers; and a disclosed chain of counterparties with no single unexplained point of failure. None of that removes risk. What it does is make the risk legible, so it can be assessed rather than guessed at.

Tokenized assets available through MetaMask are issued by Ondo Global Markets, which tokenizes US stocks, ETFs, commodities, and treasuries on Ethereum and BNB Chain, with holdings self-custodied in the user's own wallet rather than held by MetaMask. Self-custody addresses one narrow slice of the picture—it removes the intermediary between a holder and their token—but it changes nothing about the structure behind the token itself. The backing, custodian, verification cadence, and redemption terms are Ondo's, and they are what determine the risk. For more about what tokenized assets Ondo isssues and how they're structured, see what is Ondo Stocks.

How does RWA risk vary by asset type?

These categories apply to every RWA, but their weight shifts by asset. Tokenized Treasury bills concentrate risk in issuer structure, redemption terms, and regulatory treatment more than in price volatility. Tokenized stocks add the live question of shareholder rights and the unsettled legal status of third-party tokens. Stablecoins center on peg, reserve composition, and redemption. Matching the general framework to the specific asset type is the last step before deciding whether a given product suits your goals and risk tolerance.

Frequently asked questions about RWA risks

Califica la traducción
  • MetaMask
    MetaMask

    MetaMask, anteriormente Consensys Software Inc, es la plataforma financiera self-custodial más grande del mundo, que ofrece a las personas un único lugar para guardar, gastar, ahorrar y hacer crecer su dinero tanto en criptoactivos como en activos tradicionales. La compañía está construyendo la plataforma de consumo donde esto ocurre, reuniendo pagos, ahorros, inversiones y activos digitales en una experiencia fluida y unificada. Habiendo evolucionado a partir de la wallet self-custodial más utilizada del mundo, MetaMask otorga a los usuarios control directo sobre su dinero y activos, con presencia en aproximadamente 190 países. MetaMask ha desempeñado un papel fundamental en el crecimiento de Ethereum desde 2016. Hoy, MetaMask se sitúa en el centro de la economía onchain, construyendo el sistema operativo para el Open Money y poniendo a las personas en pleno control de su vida financiera.

    Leer todos los artículos