Field Notes · 01 · The Replication Problem
Anti-counterfeiting technology has a counterfeiting problem.
Most of the authentication features used on consumer products are also sold on the same wholesale marketplaces as the products they're meant to protect. A look at how the four most common technologies work, and how each is being replicated in the open.
There are two questions worth asking about any authentication technology.
- Can it be replicated?
- Is it being replicated right now, on the open market?
Holograms
Sold by the roll. Customized in a week.Custom security holograms with QR codes, tamper-evident "VOID" patterns, and logo lockups are sold openly on industrial marketplaces, to anyone with a credit card. They are the same product category that brands buy to put on their own packaging. Authentication vendors increasingly describe standalone holograms as a brand cue, not a security control.
Source: Alibaba security hologram listings, verified Apr 2026
Serialized QR Codes
A real serial number on a fake product still scans.A serialized QR is just printed ink. Photograph a real one, reprint it on a counterfeit, and the scanner reads valid, because the database confirms the serial exists, not that this physical box is the one that exists. The industry's response is "non-cloneable QR codes." The existence of that product category is itself proof that standard QR is clonable.
Source: Pharmaceutical Security Institute, 2024 incident trends; arXiv 2404.07831 on protected QR
Phosphor Security Inks
"Anti-counterfeit" phosphor sold by the gram.Upconversion phosphors marketed for security applications (IR-excited, visible-emission) are wholesale commodities. Once a counterfeiter knows the wavelength your reader checks, they can buy compatible chemistry off-the-shelf and approximate the signature. A covert marker is only covert if its chemistry isn't on a wholesale catalog.
Source: Alibaba anti-counterfeiting phosphor listings, verified Apr 2026
RFID + NFC Tags
The chip is genuine. The product isn't.Encrypted NFC chips raise the cost of cloning at the chip level. But the chip is still attached to packaging, and packaging gets peeled from genuine units and re-applied to fakes. The reader confirms the chip. Nothing confirms the contents. Authenticating the chip is not authenticating the product.
Source: NXP NTAG 424 DNA datasheet; industry literature on chip-to-product separation
Anything applied is anything replicated.
If a security feature can be bought, copied, or transferred, it sits on top of the product, not inside it.
Embedded markers sit inside the material.
An embedded marker is incorporated into the substrate during manufacturing. Into the ink. Into the fiber. Into the plastic, film, or coating. There is no surface to peel, no label to swap, no chip to transfer, because there is no separate component.
- Nothing on top. Nothing to peel.
- Nothing visible. Nothing to copy.
- Nothing separable. Nothing to transfer.
How embedded authentication is implemented in practice.
Sub-micron crystal taggants are dispersed into the substrate during manufacturing: into ink, fiber, polymer, or coating. They are not a layer applied on top of the product. They are part of the product. Field and lab readers detect them at parts-per-million to parts-per-trillion sensitivity, returning a quantitative signal rather than a visual yes-or-no.
What this brief tried to make visible.
- The most common authentication technologies (holograms, serialized QR, security phosphors, RFID) can be replicated.
- Replication isn't theoretical. It's an active marketplace, often on the same wholesale platforms as the products being protected.
- A feature that can be peeled, copied, or transferred sits on the product. A feature that cannot is part of the product.
Alibaba security hologram listings, verified Apr 2026 · Pharmaceutical Security Institute, 2024 incident trends · arXiv 2404.07831 on protected QR · Alibaba anti-counterfeiting phosphor listings, verified Apr 2026 · NXP NTAG 424 DNA datasheet