The Theft Test
Everything you own that matters is a promise with your name on it. Digital money tokens keep trying to forget this.
A pickpocket lifts your wallet on the tram. Inside: forty euros in notes, a bank card, a driving licence, and a photograph of your children.
Run the inventory of what the thief now has.
The forty euros are his. He can spend them within the hour, and no shopkeeper will ask a question. The bank card dies the moment you ring the bank; by evening it is a rectangle of dead plastic. The driving licence gets him nothing: the right to drive lives in a register at the transport authority, attached to your name and your record, and a laminated card cannot carry it away. The photograph is worthless to him and irreplaceable to you — a first hint that value can live somewhere other than in the thing itself.
One wallet, four objects. The thief profits from exactly one of them. (BTW: In Web3, their profits now exceed $80 billion)
That asymmetry deserves a closer look, because it explains why five hundred years of finance has moved in a single direction — and why the loudest movement in digital money has spent fifteen years marching the other way.
The test
Here is a test you can run on anything you own. If a thief takes the artefact, does the thief get the value?
Steal the deed to my house and you own no house. The land registry still lists my name, and the registry is what the law reads. You hold paper. Steal my car keys and you can move the car for a while — that is possession — but every record that matters still says the car is mine, and the police read records, not pockets. Steal a share certificate and the company’s register still pays the dividend to me. Steal my wedding ring and you have a small amount of gold; the marriage is unbothered.
Now steal a fifty-euro note. It is yours. Completely, instantly, anonymously yours. The note carries no memory of me. It has no issuer to ring, no register to consult, no terms attached. Whoever holds it, has it.
The note is the exception, and the exception is deliberate. Nearly everything of consequence in your life is arranged so that the answer to the test is no. Your home, your salary, your pension, your insurance, your degree, your company: all of them are structured so that taking the token gets a thief nothing. Civilisation looked at the bearer object — the thing whose holder is its owner — and judged it a fine design for pocket change and a reckless design for everything else. Digital bearer objects just digitalize the recklessness.
Possession and ownership
The test works because it splits apart two ideas that everyday language runs together.
Possession is a fact of physics. Who holds the thing; where the atoms are. A camera could verify it.
Ownership is a fact of agreement. Who the rest of us recognise as holding the rights — to use, to sell, to exclude, to collect the rent. No camera can see it; it lives in records, in law, and in the shared willingness to honour both.
A squatter possesses a house without owning it. A landlord owns a house he has not visited in years. And when possession and ownership point at different people, ownership wins — in every jurisdiction, every time — because courts enforce ownership, and courts read registers, contracts and evidence. They do not weigh atoms.
Value follows ownership. And ownership, examined closely, is a relationship: identified parties, agreed terms, a history of how the right was legally acquired, and someone with the standing to enforce it. Your house is a relationship with a land registry. Your salary is a relationship with an employer. Your deposit is a relationship with a bank. Your pension is a relationship with a fund, wrapped in decades of terms.
Possession is physics. Ownership is agreement. Your wealth is a portfolio of promises with names attached.
You have already voted
None of this is a theory anyone needs to sell you. You have voted already, and you vote again every month.
When your salary arrives, you take it as numbers in an account, even though banknotes are legal tender and the account balance is, legally, merely your bank’s promise to pay. Given the choice between the object and the promise, you take the promise — every month, without a second thought. Your savings sit as entries in a ledger; a few coins ride in your coat for the parking meter. The money your old age depends on lives in the most paperwork-wrapped, relationship-heavy instrument available.
Ask yourself why.
The promise can do things the object cannot. The account survives the stolen card and the house fire. It earns interest, pays the bills on schedule, refuses the transfer that looks wrong and reverses the one that was. It carries your name, so it can be inherited by your children, frozen by a court when that protects you, and recovered when you forget the code. The banknote, or any other bearer instrument, has one talent: it changes pockets.
We keep objects for small, fast, forgettable payments — exactly the payments where anonymity helps and terms would be a burden. For everything with weight, we choose the named promise. Wherever people have both options, the pattern holds.
What a promise can do
Set the capabilities side by side and the design question answers itself.
An object supports one operation. It moves. Hand to hand, pocket to pocket. That is the complete feature list of a coin, and of anything built to behave like one.
A recorded agreement between identified parties supports at least four.
It can say *who*. The agreement knows its parties. It can be enforced against one and inherited by another, and it can tell an honest holder from a thief.
It can say *if*. Payment on delivery. Refund on failure. Payout on damage. Interest on time. The condition lives inside the arrangement itself.
It can say *no*. The licence suspends. The account declines the suspicious transfer. The card dies in the pickpocket’s hand.
It can say *undo*. The fraudulent payment reverses. The clerical error corrects. The dispute resolves, and the record shows how.
Now count the parties. Even the plainest real trade has three: a buyer, a seller, and the settler — the bank that moves the money between them. A slightly less plain one adds delivery terms, a payment deadline, insurance on the cargo, a warranty, and a path to unwind the whole arrangement if the goods never arrive. That is an ordinary Tuesday for any business, and every clause of it sits comfortably inside an agreement. Try engraving “net thirty days, insured, refundable” on a coin.
The real economy runs on *who*, *if*, *no* and *undo*. The object offers *moves*.
The guarded room
In fairness to the object: there are places where it is exactly the right design.
A casino chip is money — inside the casino. The building checks who comes through the door. Staff watch every table. The cage redeems chips for cash and files a report when the sums get interesting. Within that room the chip works beautifully: fast, anonymous at the table, final. Carry it into the street and it turns back into painted clay, because the room was doing all the work — identity at the door, eyes on the table, settlement at the cage.
Coat-check tickets, arcade tokens, festival wristbands: the same design, the same dependence on a small supervised space with a short clock and a guarded door. Bearer objects are honest technology for closed rooms.
The trouble begins when someone proposes them as the architecture of the open economy. For fifteen years, the project of putting value “on-chain” has been, at bottom, a project of manufacturing digital bearer objects — coins and tokens whose holder is their owner, spendable by whoever knows the key. The engineering is frequently brilliant. The premise is the fifty-euro note, rebuilt in mathematics: whoever holds the key, has it. And on these networks the theft test is administered daily, at scale, by professionals. Lose the key, lose everything; there is no issuer to ring. The industry’s own history of hacks and stranded fortunes is a long, expensive demonstration of what happens when pocket-change architecture is asked to carry pensions.
When a token claims to represent something in the world — a house, a share, a euro — the test exposes a second flaw. Steal the house-token and a court will still read the land registry. The legal owner remains the legal owner; token and reality have come apart, and reality wins. Every time. A token that must forever defer to a register somewhere else is a receipt dressed up as the asset.
Five centuries, one direction
Zoom out, and the history of finance reads as one long migration away from the object.
Gold was heavy and stealable, so merchants left it with goldsmiths and traded the receipts. The receipts were still bearer paper — still stealable — so banks replaced them with accounts: ledger entries with names attached. Bearer bonds, which paid whoever clipped the coupon, were retired across the developed world within living memory, largely because anonymous value in object form proved a gift to thieves and launderers. Share certificates became register entries. The cheque, a written instruction between named parties, gave way to the transfer, a pure ledger operation. Cash itself, the last bearer object most of us still touch, shrinks year by year as a share of payments.
Every step traded the same comfort for the same safety: the feel of holding a thing, exchanged for a promise with a name on it. Every step met resistance — paper was distrusted, then accounts, then cards — and every step won, because named promises can be recovered, corrected, inherited, audited and enforced, while an object can only be held.
Against that backdrop, consider what digitisation ought to mean. The direction of travel is five hundred years old: away from the thing, towards the recorded relationship. A digital economy built in that direction digitises the agreement itself — the parties, the terms, the conditions, the evidence — and makes it move at the speed of the network. Building digital coins instead, bearer objects made of mathematics, runs the migration in reverse. The sixteenth century, refactored.
The right question
So when someone shows you the future of money, or of ownership, you have an instrument to hand.
Run the theft test. If whoever holds the key holds the value, you are looking at a bearer object, and you may ask why finance spent five centuries retiring that design for everything larger than pocket change.
Then ask the ownership questions. Who are the parties? What are the terms? When something goes wrong, who can say no, who can undo, who enforces? If the answers are nobody, nothing and no one, you have learned what the thing is for.
The unit of value in a modern economy is the agreement: identified parties, explicit terms, verifiable evidence, and a path to enforcement. The economy is the agreements. It always has been. Whatever we build next should be made of the same material.

Great observations on the nature of money as information. Monetary information is a binary number in the digital record of a bank account, or information expressed as the sum of the numbers embedded in specially designed objects: the coins and banknotes.
In the case of coins and bank notes, the objects originate from the central bank, which sold these objects to banks for their face value.
In the case of banknotes it is an IT system that has been programmed to uphold specific systems invariants when it modifies the values in a payment: 1) the sum of the recorded monetary values of the two parties in a payment, payer and payee is the same before and after a payment 2) a payment only happens if its owner allows it.
Digital public money is held in direct ownership by its owner in an e-vault.
The e-vault is a specially designed, dedicated and personalised physically secured custodial device that holds money as digital information.
That device implements ownership of the money. The device also implements software to transfer monetary value to a new owner, to be spend by loading the transferred value into the new owners e-vault. This software obeys the two system invariants for an IT system that implements money.
A payment in digital public money is instantaneously final: any monetary digital information always has an owner. Digital money send by the payer in a payment has the payee as its owner.
The e-vault is personalised to securely recognise personal device used by the owner of the money. It recognises payment authorisation only fror these devices. The money in an e-vault is un-stealable.
This digital money uses tokens, a personalise hardware token to spend it, and a software token to transport it. Both tokens have the owner's name on them, or, rather, a cryptographic pseudonym for the owner.