Confidential — authorized recipients only

SMARTURBUILD LLC · PATENT PENDING
Problem How It Enters Evidence DSCSA Gap Solution — Offline — Online Coverage Market See in Action Contact
00 Confidential — Manufacturers · Investors · Regulators

Counterfeit medicine is still reaching patients — inside a fully serialized supply chain.

DSCSA requires every unit to carry a unique serial number. It does not require anyone to check whether that serial has already been used. MedAuth closes that gap.

Patient holding a serialized PainRelief medicine box at home
$37–162B
Annual U.S. biopharma revenue lost to counterfeiting (Pacific Research Institute)
30–40K
Active illegal online pharmacies in the U.S. at any given time (NABP)
<1%
Of medicine dispensed through licensed U.S. pharmacies is estimated counterfeit
$110–130B+
Combined U.S. OTC + supplement market exposed to counterfeit/adulteration risk
MedAuth — Executive Summary

Counterfeit and falsified medicines remain a persistent and evolving threat — both within the regulated supply chain and across the far larger online and illicit markets.

Existing systems have advanced compliance and traceability. They can confirm that a serial number was legitimately issued. What they cannot yet do is verify that the physical unit in hand is the original, detect when that serial has already been used, or make large-scale cloning economically unviable.

MedAuth is designed to close this gap. It introduces the missing authentication layer — one that maintains a living state for every unit, decommissions product at the point of dispensing, renders large-scale counterfeiting economically unattractive, and extends protection into the online channel through proactive intelligence and rapid enforcement.

MedAuth — introduction

On This Page

01 The Problem

Counterfeit medicines in the United States — confirmed, and ongoing.

The U.S. drug supply is among the safest in the world, protected by a closed distribution system and DSCSA regulation. Counterfeits still enter — through illegal online sales, smuggling, unauthorized distributors, and occasionally the legitimate supply chain itself.

Boxes moving through a supply chain scanner with one flagged for a duplicate serial number
A duplicate serial number moving undetected through a scan-accepted chain.

FDA-reported cases

Ozempic
Semaglutide
Multiple warnings. The most recent (updated Dec 5, 2025) involved FDA seizure of dozens of counterfeit 1mg pens that had entered the legitimate U.S. drug supply chain — labeled with an authentic lot number (PAR1229), identifiable by the placement of the EXP/LOT text on the pen label. Earlier incidents date back to 2023.
Detected byLab testing & visual review — not automated verification
Biktarvy / Descovy
Gilead Sciences
Between 2021 and 2025, Gilead uncovered an unauthorized U.S. distribution network that sold over $250 million in counterfeit and tampered HIV medications. Criminal rings bought empty authentic bottles from patients — often low-income or homeless individuals — refilled them with incorrect pills or other drugs (including painkillers and antipsychotics), and resold them with fake documentation. 85,000+ fake or altered bottles entered regular pharmacies.
Detected byPatient complaints — wrong pills and adverse effects after taking the medicationSource: Gilead Sciences public statements; Reuters, Xtalks, Pharmaphorum
Alli
Orlistat capsules
Counterfeit capsules sold through U.S. online retailers, Jun 2025.
Detected byHaleon's internal brand-monitoring team
Botox
Allergan / AbbVie
Between November 2023 and April 2024, a multi-state outbreak of botulism-like illnesses across 9–11 U.S. states sickened 17–22 people. The infections were linked to unsafe counterfeit versions of Botox purchased from unauthorized, unlicensed online sources and administered in non-medical settings by untrained individuals.
Detected byMulti-state public health outbreak investigation (CDC)Source: FDA drug alert; Allergan Aesthetics official statement
Other documented cases include Muro 128 ophthalmic products, among earlier FDA counterfeit alerts.
Not one of these was caught by the technology built to prevent counterfeit. Every case was found by accident, complaint, or investigation after the fact.

Fentanyl-laced counterfeit pills — the DEA's primary focus

Pills mimicking oxycodone/M30, Xanax, Adderall and other common medications, mass-produced in unregulated labs, sold via social media, the dark web, or street dealers. They frequently look nearly identical to the real thing.

  • 47M+ fentanyl-laced counterfeit pills and ~10,000 lbs of fentanyl powder seized by the DEA in 2025 — equivalent to hundreds of millions of potentially lethal doses
  • Seizures continued into 2026, including a 1.7M-pill bust in Colorado (late 2025)
  • DEA's "One Pill Can Kill" campaign: as little as 2mg of fentanyl can be lethal, and visual inspection alone cannot reliably distinguish real pills from counterfeit

Other seizures & trends

CBP and FDA regularly intercept shipments of counterfeit or unapproved pharmaceuticals — including injectables such as Ozempic/Wegovy analogs, Botox, and erectile dysfunction drugs — arriving from China, Hong Kong, India, and elsewhere, often by mail.

Illegally compounded versions of popular drugs, especially GLP-1 medications like semaglutide and tirzepatide, have raised ongoing quality, sterility, and counterfeit concerns since official shortages ended.

02 How It Enters — And How Big This Really Is

Online vs. Offline — two very different battlegrounds.

01 · The licensed chain

Counterfeits that successfully penetrate the closed, regulated U.S. supply chain — the Ozempic-style cases above. These are rare: estimates put counterfeits at less than 1% of medicines sold through traditional U.S. brick-and-mortar pharmacies. When they occur, volumes are usually hundreds to low thousands of units before detection and seizure. DSCSA and manufacturer controls are designed primarily to stop this category.

02 · The broader illicit market

This is where the large economic numbers come from: illegal online pharmacies and direct-to-consumer sales (WHO estimates more than 50% of medicines from many online sources are counterfeit or substandard), street and social-media sales of fentanyl-laced pills, gray-market diversion, and global activity — WHO estimates roughly 1 in 10 medicines in low- and middle-income countries is substandard or falsified.

Five documented ways a fake reaches a patient.

Vector 01

Gray-market & secondary wholesale diversion

Products leave a manufacturer's authorized network — through excess inventory, returns, theft, or improper sales — and re-enter via secondary or unauthorized distributors, especially during shortages. Counterfeiters exploit this by inserting fakes that look authentic with forged or incomplete documentation.

Vector 02

Unauthorized sourcing by trading partners

Pharmacies or smaller distributors buy outside strict authorized channels when demand is high — repeatedly seen with Ozempic/semaglutide. In the Dec 2025 incident, the FDA and Novo Nordisk confirmed the fakes were distributed outside Novo Nordisk's authorized supply chain yet still reached the legitimate U.S. drug supply.

Vector 03

Sophisticated mimicry

Counterfeits reuse real lot numbers, copy packaging closely, and exploit incomplete scanning or verification at intermediate steps. Differences — like EXP/LOT text placement on Ozempic pens — eventually allow detection, but not always before the product moves downstream.

Vector 04

High-demand products & shortages

These create opportunities for bad actors offering "bargains" — the same dynamic behind most of the incidents above.

Vector 05

Illegal online pharmacies

Sell directly to consumers, often never touching the regulated physical supply chain at all. NABP estimates 30,000–40,000 such pharmacies are active in the U.S. at any given time — the primary channel through which most consumer-facing counterfeits are sold.

Diagram: closed-loop supply chain on the left, illegal online sales, smuggling, and unauthorized distributors feeding a counterfeit RX bottle on the right
How a system built as a closed loop still gets counterfeit product to a patient's hand.
Most counterfeit risk for consumers still comes from unregulated online sources or illicit street sales — especially fentanyl-laced pills — but the cases that reach licensed pharmacies show real, residual gaps in the regulated chain.

The Scale of the Problem

$200–400B+
Estimated global counterfeit pharmaceutical market, per year
$37–162B
Annual U.S. biopharma revenue lost to counterfeiting (Pacific Research Institute)
<1%
Of medicine sold through licensed U.S. pharmacies is estimated counterfeit
~1 in 10
Medicines in low- and middle-income countries estimated substandard or falsified (WHO)

These figures capture lost legitimate sales, enforcement and investigation costs, healthcare costs and productivity losses from harm, tax revenue losses, and reputational and innovation impacts.

03 The Evidence

The Ozempic cases show exactly how the gap gets used.

Three incidents, three variations on the same underlying weakness — a serial number that was never checked for prior use.

Dec 2023 · Lot NAR0074

One identical serial, cloned across many packages

Multiple counterfeit packages all carried the exact same serial number: 430834149057. Novo Nordisk confirmed a real, legitimate lot NAR0074 existed with 100,000+ units — but only products combining that lot with that specific serial were counterfeit. Many physical packages sharing one identical serial is direct evidence of cloning. Detection came from visual and investigative review plus lab testing — not from a verification system automatically rejecting the second or third appearance of the serial.

Apr 2025 · Lot PAR0362

Fabricated serials, patterned rather than cloned

Counterfeits used an authentic lot number paired with illegitimate serial numbers, all beginning with the digits 51746517. Novo Nordisk and the FDA explicitly described these serials as illegitimate — fabricated or patterned rather than exact copies of already-dispensed genuine packages. Identification relied on the lot + serial pattern, packaging and visual differences, and the fact that the products came from outside Novo Nordisk's authorized supply chain.

Dec 2025 · Lot PAR1229

Packaging differences caught what the serial check didn't

Primarily identified through packaging differences — the placement of the EXP/LOT text on the pen label. An authentic lot number was reused, with public alerts focused less on serial-number patterns for this batch.

04 The DSCSA Gap

What DSCSA Actually Does

The Drug Supply Chain Security Act requires unique product identifiers (serialization) on packages — NDC, unique serial number, lot, and expiration date, in both human-readable form and a 2D DataMatrix barcode — trading only with authorized partners, electronic exchange of transaction information, the ability to verify a product identifier against the manufacturer's records, and clear processes to quarantine, investigate, and report suspect or illegitimate products.

In practice, DSCSA verification is primarily a check that a product identifier was legitimately issued by the manufacturer. A scan is essentially an enquiry: "Did you assign this exact serial number to a package?" It does not automatically detect or reject the same serial when scanned a second, third, or later time, the way a true one-time-use or decommissioning system would.

Diagram: an original unit vs. a cloned counterfeit unit both scanning as accepted through the supply chain, caught only later by red-flag investigation
The system caught them — but not through "this serial has already been seen."

How verification actually works

  1. A trading partner sends a verification request — usually via the Verification Router Service (VRS) or equivalent.
  2. The manufacturer's system checks its commissioning database: "Does this NDC + serial + lot + expiry match a serial I issued?"
  3. The response is essentially Verified or Not Verified — some manufacturers add status like recalled, expired, or suspect.
  4. There is no DSCSA requirement to decommission a serial when the product is dispensed, and no mandatory real-time tracking of every prior scan across the network — so a counterfeit reusing a genuine, already-dispensed serial will often still return "Verified."

This limitation has been explicitly discussed in industry and congressional materials — a Serial Number Decommissioning Pilot examined exactly this problem: counterfeiters reusing packaging with valid serials, because verification alone does not block reuse after dispensing.

DSCSA serialization confirms a serial is genuine — a scan is an enquiry against the manufacturer's issuance records, not a one-time token that fails on reuse. That is a recognized residual gap in the current U.S. framework.
05 The MedAuth Solution

An additive authentication and economic-deterrence layer — not a replacement for DSCSA.

MedAuth is not another serialization or compliance tool. It is the missing authentication and economic layer that sits on top of DSCSA. MedAuth is an additive authentication and economic-deterrence layer that sits on top of existing DSCSA infrastructure. It does not replace serialization, EPCIS, or VRS systems.

Brick-and-Mortar Pharmacies — The Licensed Supply Chain

Every dispensable unit becomes a live cryptographic token with a strict, enforceable lifecycle. The first legitimate scan advances its state. Any later scan of the same token — anywhere — is immediately detected as a conflict. When the product is dispensed, the token is permanently closed. Cloning no longer scales; every successful fake sale destroys the value of a genuine unit the counterfeiter already had to buy.

LIVE TOKEN LIFECYCLEONE UNIT, ONE TRUTH
Manufactured
Shipped
At Distributor
At Regional DC
At Pharmacy
Dispensed
Returned by Customer
Awaiting scan…
Manufactured → Shipped → At Distributor → At Regional DC → At Pharmacy → Dispensed → Returned by Customer

MedAuth Core Mechanisms

Dynamic cryptographic token

Every unit gets a token — software/QR-based by default, with optional cryptographic NFC for high-value products.

Real-time duplicate detection

The first legitimate scan advances the token state. Any subsequent scan of the same token anywhere in the network triggers an immediate STATE CONFLICT — DUPLICATE DETECTED alert.

Mandatory decommissioning

A pharmacist dispense scan — or consumer plus pharmacist two-way authorization — permanently marks the token as Dispensed, closing the reuse loophole.

Economic self-defeat

Cloning a genuine serial consumes the original token's value. Large-scale counterfeiting becomes financially unviable, because every successful fake sale destroys the value of a genuine unit already paid for.

Inherited state transitions

Parent-container scans automatically update child units, matching real-world DSCSA/EPCIS aggregation and scanning practices.

AI visual verification

An optional consumer-side check of packaging and visible contents against manufacturer reference images, to detect genuine-packaging / counterfeit-contents attacks.

Consumer verification & safety envelope

Patients can verify authenticity directly, and receive retroactive alerts if a problem with their specific unit is discovered later.

MedAuth Architecture diagram showing gate actors, the MedAuth app, blockchain layer, state machine, and existing EPCIS infrastructure
MedAuth Architecture — an additive layer above existing EPCIS/DSCSA infrastructure.

Gate actors — manufacturer, distributor, regional DC, pharmacy, hospital, and finally the consumer — scan through a role-based MedAuth interface. Each scan checks and updates a blockchain-backed state machine, which exchanges data with existing EPCIS infrastructure (TraceLink, Systech, and others) via API, in real time. No manufacturer's current serialization line has to change to plug in.

Online Pharmacy — Outside the Licensed Supply Chain

A proactive Online Intelligence Layer monitors marketplaces, social platforms, and known rogue sources primarily through official brand-protection channels (Amazon Brand Registry, eBay VeRO, etc.), commercial intelligence partnerships, and public data. Confirmed threats generate evidence packages for rapid takedowns and feed risk signals back into the MedAuth manufacturer dashboard and consumer app.

Proactive Online Intelligence — Detection to Takedown

Monitor

Continuous discovery

Continuously discover listings and sellers offering suspected counterfeit or unauthorized versions of protected drugs.

Verify

Risk scoring

Score and prioritize them by risk.

Action

Evidence packages

Generate actionable evidence packages.

Feedback

Rapid takedowns

Drive rapid takedowns and feed intelligence back into MedAuth — manufacturer dashboards and consumer app warnings.

Loop

Closed loop

Create a closed loop: online detections improve physical-chain detection, and physical-chain detections seed new online monitoring.

Diagram: Proactive Online Intelligence — Monitor, Intelligence and Verification, Action and Takedown, Feedback and Risk Signals, leading to a Safer Online Ecosystem
The four capabilities running as one continuous, closed-loop system.

Confirmed threats route through official channels — Amazon Brand Registry, eBay VeRO, Meta, Google — with parallel reporting to FDA MedWatch, NABP, or state boards where appropriate. Outcomes tracked: takedown success rate, time to removal, and reappearance rate, feeding back into the detection models.

The Intelligence Bridge — One Platform, Two Channels, One Shared Intelligence Layer

MedAuth operates across two channels — the licensed supply chain and the online counterfeit marketplace. Each channel detects threats the other cannot see. The Intelligence Bridge is the real-time data-sharing layer that connects both, turning isolated detections into a continuously learning threat network. With it, every detection on either channel immediately strengthens the defence on the other.

The Intelligence Bridge diagram: licensed supply chain and online counterfeit marketplace both feeding real-time data and threat signals into MedAuth's shared intelligence layer, producing unified threat intelligence and stronger defence for both channels
One shared intelligence layer, two channels, one continuously learning threat network.

Most solutions in the market still operate inside the old paradigm: better tracing, better labels, better databases, better compliance reporting. MedAuth changes the paradigm on three levels:

Shift 01

Authentication, not just traceability

Tracks the live state of each physical unit — not merely the history of a serial number.

Shift 02

Prevention through economics

Large-scale cloning becomes unprofitable by design. The larger the counterfeit operation, the faster it generates detectable conflicts and destroys its own economics.

Shift 03

Full-chain coverage

Closes the loop from manufacturer to patient, and extends coverage into the online environment where much of the volume moves.

The result is a system that is additive to DSCSA, accessible beyond only the largest enterprise manufacturers, and built to make counterfeiting a losing economic proposition rather than merely a detectable one.

"This is the shift from 'we can trace what happened' to 'counterfeiting no longer pays.'"

06 Coverage Assessment

Where MedAuth is strong — and an honest account of where it isn't.

Mapped against the four entry vectors and the online channel. MedAuth does not claim to make counterfeiting impossible — it aims to make large-scale, profitable insertion of counterfeits into any channel that intersects with a scanning point — or that appears online — much harder and economically unattractive.

Sophisticated mimicry / serial cloning

Very Strong

Still the core design target. Dynamic token + centralized state machine detects the second use of any serial or token. Economic self-defeat makes large-scale cloning unprofitable. AI visual verification adds a layer against high-quality packaging copies. Mandatory decommissioning closes the "reuse the serial after the genuine pack is gone" loophole that pure DSCSA leaves open.

Gray market & fake insertion

Strong

Excellent at detecting the counterfeit-insertion part — duplicate or unknown tokens are flagged at the next scanning gate. Scan-in/scan-out integrity and geography-mismatch detection flag product appearing in unexpected places. Limitation: pure diversion of genuine product (with no counterfeiting involved) remains only partially visible.

Unauthorized sourcing by trading partners

Strong

Strong at the receiving gate — cloned or fabricated identifiers scanned inbound trigger Unknown Token, Duplicate Token, or State/Geography Mismatch. Pharmacy inbound scanning plus dispense decommissioning reduces further movement. Limitation: if the receiving party simply does not scan, detection is delayed until a later gate or consumer scan.

High-demand / shortage exploitation

Moderate–Strong

Raises the cost and detection risk of inserting fakes into any channel that eventually gets scanned. Real-time alerts and manufacturer dashboards give brand teams faster visibility when suspicious activity spikes around high-demand products. The Online Intelligence Layer adds earlier visibility into online offers that typically surge during shortages.

Online / illicit direct-to-consumer channel

Moderate–Good

With the Online Proactive Intelligence Layer now actively monitoring marketplaces, social platforms, rogue sites, and public data — primarily through official brand-protection channels such as Amazon Brand Registry and eBay VeRO, plus commercial intelligence partnerships and regulatory lists. Confirmed threats feed risk signals into the Manufacturer Dashboard and can trigger warnings in the Consumer App. When a consumer does scan a product bought online, the absence of any legitimate pharmacy dispensing event, combined with token and AI visual checks, provides an additional detection layer. Limitation: effectiveness still depends on the quality of detection/takedown success and on consumers choosing to verify products — purely offline illicit sales that never appear online or reach a scanning point remain out of reach.

What we are still not claiming

  • Trading partners who deliberately avoid scanning remain a blind spot until the product reaches the next scanning gate or a consumer.
  • Pure diversion of genuine product — with no counterfeiting involved — is only partially visible.
  • Online listings that successfully evade detection or reappear under new domains can still reach consumers until they are identified and removed.
  • Very low-volume, highly targeted insertion can still stay below the radar of both gate-level and online detection.
  • The hardest residual physical case — genuine packaging with substituted contents — is addressed by AI visual verification, but still depends on consumer scanning and image-matching accuracy.
  • Street-level and purely offline illicit markets (e.g., fentanyl-laced pressed pills sold face-to-face or only on closed social channels) are largely outside MedAuth's current reach.
With the addition of the Online Proactive Intelligence Layer, MedAuth now provides meaningful coverage across both the regulated/gray physical supply chain and the dominant online illicit channel. It remains strongest where counterfeits intersect with serialization, scanning, or detectable online listings, and it continues to be honest about the residual gaps that no single technology can fully close.
07 Market Position

A crowded field of serialization tools. A different category of protection.

We don't lean on the word "blockchain" — several players in this space have piloted distributed-ledger approaches too. Our sharper claim is the behavioral state machine and economic-deterrence layer running on top of it — paired with an online intelligence layer addressing the channel where most counterfeit volume actually moves, something none of the players below cover at all.

PlayerWhat it coversWhat it doesn't
TraceLink Dominant DSCSA network / compliance platform Complementary, not competing — MedAuth is designed to sit on top of infrastructure at this scale, not replace it
Systech (UniSecure / artAI) Optical / e-fingerprint and AI packaging authentication Enterprise-focused, higher cost, limited consumer-gate emphasis
Covectra (AuthentiTrack / StellaGuard) Mature serialization + patented holographic consumer label — the closest existing consumer-facing authentication No state machine, no economic self-defeat mechanism, no multi-level aggregation identity checks
ForgeStop Cryptographic NFC specialist — higher per-unit cost, strong for high-value product Potentially complementary — NFC hardware paired with a MedAuth state machine
Others — rfxcel / Antares, OPTEL, AlpVision, Identiv Various serialization, optical, or NFC-based approaches

Enterprise pricing is dominant across this landscape. MedAuth's software/QR-based option is built as a low-cost, per-unit path — designed for accessibility to mid-size manufacturers, not just the largest enterprise accounts.

What sets MedAuth apart

Proactive Online Intelligence Layer, real-time cross-gate duplicate detection, mandatory decommissioning, economic self-defeat, and AI contents verification — delivered as one integrated solution. Not publicly offered as a single platform by major players.

08 See in Action

The proof-of-concept, end to end.

Manufacture → scan → dispense → duplicate attempt → conflict alert. Watch the full token lifecycle run in the live POC.

A Quick Look Inside MedAuth

The manufacturer dashboard, consumer app alerts, and the online intelligence layer, in practice.

Online Intelligence Layer listing summary showing a monitored marketplace listing and seller details
Online Intelligence — monitored listing summary
Online Intelligence Layer risk score breakdown showing weighted contributing factors
Online Intelligence — risk score breakdown
Consumer app AI verification alert showing potential packaging discrepancies and a risk score
Consumer App — AI visual verification alert
Consumer app recall alert showing a recalled batch and pharmacist contact prompt
Consumer App — recall alert
Distributor inbound scan showing an expired batch alert on both the handheld scanner and dashboard
Distributor Scan — expired batch blocked at inbound dock
MedAuth admin dashboard showing supply chain state, live alert feed, and counterfeit intelligence
Admin Dashboard — live supply-chain state, alerts, and counterfeit intelligence
09 Let's Talk

One Solution. Three Wins.

Manufacturers

Close your brand-protection gap

Additive to your existing DSCSA lines. One webhook and reference images — no re-platforming, no new packaging hardware required for the software tier.

Investors

A category with no direct incumbent

A defensible mechanism with patents pending, a proof-of-concept already running, and a second market opportunity in luxury goods.

Regulators

Strengthens DSCSA, doesn't replace it

Positioned as a Technology Service Provider extending existing Authorized Trading Partner and DSCSA obligations — not competing with them.