Confidential — authorized recipients only
DSCSA requires every unit to carry a unique serial number. It does not require anyone to check whether that serial has already been used. MedAuth closes that gap.
Counterfeit and falsified medicines remain a persistent and evolving threat — both within the regulated supply chain and across the far larger online and illicit markets.
Existing systems have advanced compliance and traceability. They can confirm that a serial number was legitimately issued. What they cannot yet do is verify that the physical unit in hand is the original, detect when that serial has already been used, or make large-scale cloning economically unviable.
MedAuth is designed to close this gap. It introduces the missing authentication layer — one that maintains a living state for every unit, decommissions product at the point of dispensing, renders large-scale counterfeiting economically unattractive, and extends protection into the online channel through proactive intelligence and rapid enforcement.
The U.S. drug supply is among the safest in the world, protected by a closed distribution system and DSCSA regulation. Counterfeits still enter — through illegal online sales, smuggling, unauthorized distributors, and occasionally the legitimate supply chain itself.
Pills mimicking oxycodone/M30, Xanax, Adderall and other common medications, mass-produced in unregulated labs, sold via social media, the dark web, or street dealers. They frequently look nearly identical to the real thing.
CBP and FDA regularly intercept shipments of counterfeit or unapproved pharmaceuticals — including injectables such as Ozempic/Wegovy analogs, Botox, and erectile dysfunction drugs — arriving from China, Hong Kong, India, and elsewhere, often by mail.
Illegally compounded versions of popular drugs, especially GLP-1 medications like semaglutide and tirzepatide, have raised ongoing quality, sterility, and counterfeit concerns since official shortages ended.
Counterfeits that successfully penetrate the closed, regulated U.S. supply chain — the Ozempic-style cases above. These are rare: estimates put counterfeits at less than 1% of medicines sold through traditional U.S. brick-and-mortar pharmacies. When they occur, volumes are usually hundreds to low thousands of units before detection and seizure. DSCSA and manufacturer controls are designed primarily to stop this category.
This is where the large economic numbers come from: illegal online pharmacies and direct-to-consumer sales (WHO estimates more than 50% of medicines from many online sources are counterfeit or substandard), street and social-media sales of fentanyl-laced pills, gray-market diversion, and global activity — WHO estimates roughly 1 in 10 medicines in low- and middle-income countries is substandard or falsified.
Products leave a manufacturer's authorized network — through excess inventory, returns, theft, or improper sales — and re-enter via secondary or unauthorized distributors, especially during shortages. Counterfeiters exploit this by inserting fakes that look authentic with forged or incomplete documentation.
Pharmacies or smaller distributors buy outside strict authorized channels when demand is high — repeatedly seen with Ozempic/semaglutide. In the Dec 2025 incident, the FDA and Novo Nordisk confirmed the fakes were distributed outside Novo Nordisk's authorized supply chain yet still reached the legitimate U.S. drug supply.
Counterfeits reuse real lot numbers, copy packaging closely, and exploit incomplete scanning or verification at intermediate steps. Differences — like EXP/LOT text placement on Ozempic pens — eventually allow detection, but not always before the product moves downstream.
These create opportunities for bad actors offering "bargains" — the same dynamic behind most of the incidents above.
Sell directly to consumers, often never touching the regulated physical supply chain at all. NABP estimates 30,000–40,000 such pharmacies are active in the U.S. at any given time — the primary channel through which most consumer-facing counterfeits are sold.
These figures capture lost legitimate sales, enforcement and investigation costs, healthcare costs and productivity losses from harm, tax revenue losses, and reputational and innovation impacts.
Three incidents, three variations on the same underlying weakness — a serial number that was never checked for prior use.
Multiple counterfeit packages all carried the exact same serial number: 430834149057. Novo Nordisk confirmed a real, legitimate lot NAR0074 existed with 100,000+ units — but only products combining that lot with that specific serial were counterfeit. Many physical packages sharing one identical serial is direct evidence of cloning. Detection came from visual and investigative review plus lab testing — not from a verification system automatically rejecting the second or third appearance of the serial.
Counterfeits used an authentic lot number paired with illegitimate serial numbers, all beginning with the digits 51746517. Novo Nordisk and the FDA explicitly described these serials as illegitimate — fabricated or patterned rather than exact copies of already-dispensed genuine packages. Identification relied on the lot + serial pattern, packaging and visual differences, and the fact that the products came from outside Novo Nordisk's authorized supply chain.
Primarily identified through packaging differences — the placement of the EXP/LOT text on the pen label. An authentic lot number was reused, with public alerts focused less on serial-number patterns for this batch.
The Drug Supply Chain Security Act requires unique product identifiers (serialization) on packages — NDC, unique serial number, lot, and expiration date, in both human-readable form and a 2D DataMatrix barcode — trading only with authorized partners, electronic exchange of transaction information, the ability to verify a product identifier against the manufacturer's records, and clear processes to quarantine, investigate, and report suspect or illegitimate products.
In practice, DSCSA verification is primarily a check that a product identifier was legitimately issued by the manufacturer. A scan is essentially an enquiry: "Did you assign this exact serial number to a package?" It does not automatically detect or reject the same serial when scanned a second, third, or later time, the way a true one-time-use or decommissioning system would.
This limitation has been explicitly discussed in industry and congressional materials — a Serial Number Decommissioning Pilot examined exactly this problem: counterfeiters reusing packaging with valid serials, because verification alone does not block reuse after dispensing.
MedAuth is not another serialization or compliance tool. It is the missing authentication and economic layer that sits on top of DSCSA. MedAuth is an additive authentication and economic-deterrence layer that sits on top of existing DSCSA infrastructure. It does not replace serialization, EPCIS, or VRS systems.
Every dispensable unit becomes a live cryptographic token with a strict, enforceable lifecycle. The first legitimate scan advances its state. Any later scan of the same token — anywhere — is immediately detected as a conflict. When the product is dispensed, the token is permanently closed. Cloning no longer scales; every successful fake sale destroys the value of a genuine unit the counterfeiter already had to buy.
Every unit gets a token — software/QR-based by default, with optional cryptographic NFC for high-value products.
The first legitimate scan advances the token state. Any subsequent scan of the same token anywhere in the network triggers an immediate STATE CONFLICT — DUPLICATE DETECTED alert.
A pharmacist dispense scan — or consumer plus pharmacist two-way authorization — permanently marks the token as Dispensed, closing the reuse loophole.
Cloning a genuine serial consumes the original token's value. Large-scale counterfeiting becomes financially unviable, because every successful fake sale destroys the value of a genuine unit already paid for.
Parent-container scans automatically update child units, matching real-world DSCSA/EPCIS aggregation and scanning practices.
An optional consumer-side check of packaging and visible contents against manufacturer reference images, to detect genuine-packaging / counterfeit-contents attacks.
Patients can verify authenticity directly, and receive retroactive alerts if a problem with their specific unit is discovered later.
Gate actors — manufacturer, distributor, regional DC, pharmacy, hospital, and finally the consumer — scan through a role-based MedAuth interface. Each scan checks and updates a blockchain-backed state machine, which exchanges data with existing EPCIS infrastructure (TraceLink, Systech, and others) via API, in real time. No manufacturer's current serialization line has to change to plug in.
A proactive Online Intelligence Layer monitors marketplaces, social platforms, and known rogue sources primarily through official brand-protection channels (Amazon Brand Registry, eBay VeRO, etc.), commercial intelligence partnerships, and public data. Confirmed threats generate evidence packages for rapid takedowns and feed risk signals back into the MedAuth manufacturer dashboard and consumer app.
Continuously discover listings and sellers offering suspected counterfeit or unauthorized versions of protected drugs.
Score and prioritize them by risk.
Generate actionable evidence packages.
Drive rapid takedowns and feed intelligence back into MedAuth — manufacturer dashboards and consumer app warnings.
Create a closed loop: online detections improve physical-chain detection, and physical-chain detections seed new online monitoring.
Confirmed threats route through official channels — Amazon Brand Registry, eBay VeRO, Meta, Google — with parallel reporting to FDA MedWatch, NABP, or state boards where appropriate. Outcomes tracked: takedown success rate, time to removal, and reappearance rate, feeding back into the detection models.
MedAuth operates across two channels — the licensed supply chain and the online counterfeit marketplace. Each channel detects threats the other cannot see. The Intelligence Bridge is the real-time data-sharing layer that connects both, turning isolated detections into a continuously learning threat network. With it, every detection on either channel immediately strengthens the defence on the other.
Most solutions in the market still operate inside the old paradigm: better tracing, better labels, better databases, better compliance reporting. MedAuth changes the paradigm on three levels:
Tracks the live state of each physical unit — not merely the history of a serial number.
Large-scale cloning becomes unprofitable by design. The larger the counterfeit operation, the faster it generates detectable conflicts and destroys its own economics.
Closes the loop from manufacturer to patient, and extends coverage into the online environment where much of the volume moves.
The result is a system that is additive to DSCSA, accessible beyond only the largest enterprise manufacturers, and built to make counterfeiting a losing economic proposition rather than merely a detectable one.
"This is the shift from 'we can trace what happened' to 'counterfeiting no longer pays.'"
Mapped against the four entry vectors and the online channel. MedAuth does not claim to make counterfeiting impossible — it aims to make large-scale, profitable insertion of counterfeits into any channel that intersects with a scanning point — or that appears online — much harder and economically unattractive.
We don't lean on the word "blockchain" — several players in this space have piloted distributed-ledger approaches too. Our sharper claim is the behavioral state machine and economic-deterrence layer running on top of it — paired with an online intelligence layer addressing the channel where most counterfeit volume actually moves, something none of the players below cover at all.
| Player | What it covers | What it doesn't |
|---|---|---|
| TraceLink | Dominant DSCSA network / compliance platform | Complementary, not competing — MedAuth is designed to sit on top of infrastructure at this scale, not replace it |
| Systech (UniSecure / artAI) | Optical / e-fingerprint and AI packaging authentication | Enterprise-focused, higher cost, limited consumer-gate emphasis |
| Covectra (AuthentiTrack / StellaGuard) | Mature serialization + patented holographic consumer label — the closest existing consumer-facing authentication | No state machine, no economic self-defeat mechanism, no multi-level aggregation identity checks |
| ForgeStop | Cryptographic NFC specialist — higher per-unit cost, strong for high-value product | Potentially complementary — NFC hardware paired with a MedAuth state machine |
| Others — rfxcel / Antares, OPTEL, AlpVision, Identiv | Various serialization, optical, or NFC-based approaches | — |
Enterprise pricing is dominant across this landscape. MedAuth's software/QR-based option is built as a low-cost, per-unit path — designed for accessibility to mid-size manufacturers, not just the largest enterprise accounts.
Proactive Online Intelligence Layer, real-time cross-gate duplicate detection, mandatory decommissioning, economic self-defeat, and AI contents verification — delivered as one integrated solution. Not publicly offered as a single platform by major players.
Manufacture → scan → dispense → duplicate attempt → conflict alert. Watch the full token lifecycle run in the live POC.
The manufacturer dashboard, consumer app alerts, and the online intelligence layer, in practice.
Additive to your existing DSCSA lines. One webhook and reference images — no re-platforming, no new packaging hardware required for the software tier.
A defensible mechanism with patents pending, a proof-of-concept already running, and a second market opportunity in luxury goods.
Positioned as a Technology Service Provider extending existing Authorized Trading Partner and DSCSA obligations — not competing with them.