NFT-based product authenticity verification system

We design and develop full-cycle blockchain solutions: from smart contract architecture to launching DeFi protocols, NFT marketplaces and crypto exchanges. Security audits, tokenomics, integration with existing infrastructure.
Showing 1 of 1All 1305 services
NFT-based product authenticity verification system
Medium
~1-2 weeks
Frequently Asked Questions

Blockchain Development Services

Blockchain Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1357
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1250
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    955
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    926

A physical product with a "blockchain-verified" QR code is marketing, not security. The real problem is that NFT stores a link to something, but not the thing itself. Forging a physical item and pasting the QR code from the original onto a copy is trivial if the system does not solve the cryptographic binding of the physical object to the digital token. We develop such systems turnkey — with NFC chips, on-chain registry, and gasless verification. We have 5+ years of experience in blockchain development and over 20 projects in NFT verification. NFC chips with ECC are 1000 times more reliable than simple QR codes without cryptography.

How to ensure cryptographic binding of a physical object to an NFT?

NFC chips with cryptography

The most reliable approach for physical goods is NFC chips with ECC signature support (NTAG 424 DNA from NXP or similar Kong Halo). The chip contains a private key that cannot be physically extracted from the device. When scanned, the chip signs a challenge-response with the private key.

Verification scheme:

  1. During production, the chip generates a keypair. The public key is written into the NFT metadata and into the verification contract.
  2. For verification, the user scans NFC → chip signs keccak256(randomChallenge || timestamp) → signature is sent to the backend or directly to the contract.
  3. The contract verifies the signature via ecrecover — if recovered_address == chip_public_key and chip_public_key is registered as belonging to a specific tokenId — the product is genuine.
function verifyChip(
    uint256 tokenId,
    bytes32 challenge,
    bytes memory signature
) external view returns (bool) {
    address chipAddress = _chipAddresses[tokenId];
    require(chipAddress != address(0), "Token not registered");

    bytes32 messageHash = keccak256(
        abi.encodePacked("\x19Ethereum Signed Message:\n32", challenge)
    );
    address recovered = ECDSA.recover(messageHash, signature);
    return recovered == chipAddress;
}

The Kong protocol (ERC-7015 / Kong Halo) standardizes this exact scheme. For luxury goods, watches, sneakers — this is a production-ready solution.

QR code without physical cryptography

If NFC is not suitable (paper documents, packaging), a different scheme is used. The manufacturer creates a pair (publicId, secretKey) — publicId is embedded in the QR code and stored in the NFT, secretKey is printed inside the packaging under a protective layer. During verification, the user opens the packaging, enters the secretKey — the backend checks that keccak256(secretKey) == storedHash.

This is a one-time scheme: after the first verification, the secret is exposed. For repeated verifications, another mechanism is needed. Suitable for collectibles, alcohol, pharmaceuticals.

Why is an on-chain authenticity registry important?

Contract structure

The registry stores a mapping tokenId → AuthRecord:

struct AuthRecord {
    address chipAddress;      // public key of the NFC chip or zero address
    bytes32 secretHash;       // keccak256 of the secret for QR scheme
    uint256 mintedAt;         // timestamp of creation
    uint256 verificationCount; // how many times verified
    bool activated;           // whether activated (for one-time)
    string productSku;        // manufacturer SKU
}

mapping(uint256 => AuthRecord) private _authRecords;

verificationCount — useful analytics. A product verified 500 times is either very popular or someone is trying to brute force. Threshold alert on the backend for anomalous verification counts.

Lifecycle statuses

For more complex scenarios, a status is added:

Status Description
MINTED Token created, product not activated
ACTIVATED Product opened/activated by first owner
TRANSFERRED Token transferred, transfer history preserved
FLAGGED Marked as possible counterfeit
BURNED Product destroyed or disposed

Transfer history is transparent via standard ERC-721 Transfer events — no separate storage needed.

How to implement gasless verification for the user?

Verification should not require gas from the user — that's a barrier to adoption. Two approaches:

Off-chain with on-chain proof. The backend makes an eth_call to the verification contract (free), returns the result to the user. The source of truth is the blockchain, but no gas is paid.

Gasless verification via signature. The user signs a verification request (EIP-712), the backend checks the chip signature and the user signature, records the verification event in an off-chain log (with cryptographic proof). For critical verifications (insurance, legal) — periodic on-chain recording of a Merkle root from batch verifications.

Integration with marketplaces and access roles

Standard ERC-721 + additional metadata. In tokenURI JSON, add fields:

{
  "name": "Product #12345",
  "attributes": [
    {"trait_type": "Authenticity", "value": "Verified"},
    {"trait_type": "Manufacturer", "value": "Brand XYZ"},
    {"trait_type": "SKU", "value": "PROD-001"},
    {"trait_type": "Chip Type", "value": "NXP NTAG 424 DNA"}
  ],
  "verification_contract": "0x...",
  "chip_public_key": "0x..."
}

OpenSea and other marketplaces display these attributes. A buyer on the secondary market can verify the product before purchase.

The contract uses OpenZeppelin AccessControl:

  • MANUFACTURER_ROLE — right to mint new tokens and register chips
  • VERIFIER_ROLE — right to record verification results on-chain (for enterprise clients)
  • FLAGGING_ROLE — right to mark tokens as disputed (brand anti-counterfeit service)
  • DEFAULT_ADMIN_ROLE — role management

The manufacturer can delegate to authorized distributors the right to register products in their segment.

What is included in the work

Stage Result
Analysis and design Specification of the binding scheme, chip selection, contract architecture
Smart contract development ERC-721 + verification contract, role model, tests (Foundry)
Backend and API Node.js + viem, verification endpoint, analytics dashboard
Mobile SDK React Native or Flutter — NFC/QR scanning, API calls
Marketplace integration Custom metadata, display testing
Audit and documentation Contract descriptions, manufacturer instructions

Estimated timelines and cost

System with QR codes and on-chain registry without NFC — from 1 week. With NFC chip support (Kong/NTAG 424 DNA), role model, mobile SDK for scanning, and analytics dashboard — from 2 to 3 weeks. The cost is calculated individually based on the scope of work.

Contact us to discuss your project. Order development of a verification system — get a consultation on architecture and timelines.

Why does NFT marketplace development require a comprehensive approach?

We see that at first glance, an NFT contract looks simple: ERC-721, mint(), IPFS for metadata — that's it. In practice, it's this 'simplicity' that hides most problems — from bots buying out the entire mint in the first block to broken royalties on the secondary market. We often hear: Make a collection like others in a week — and a month later it turns out gas has tripled due to an unoptimized for loop, or OpenSea cannot see metadata after reveal. We know each of these pitfalls and build processes to avoid them.

Over 5 years of working with blockchains, we have implemented 40+ NFT projects, including marketplaces with dynamic attributes and cross-chain bridges. We have accumulated a library of proven templates — some of which we break down below.

Which standard to choose: ERC-721 or ERC-1155?

ERC-721 — each token is unique, one owner. Suitable for collections where each NFT has individual attributes and a direct owner → tokenId mapping.
ERC-1155 — multi-token standard: one contract holds both fungible and non-fungible tokens. It uses balanceOf(address, tokenId) instead of ownerOf(tokenId). A single transaction can transfer multiple different tokens via safeBatchTransferFrom. This saves gas on bulk operations — important for game items, tickets, edition collections. ERC-1155 is 2–3× more gas-efficient than ERC-721 for batch transfers.

Criteria ERC-721 ERC-1155
Token uniqueness Each token is unique One tokenId can have multiple copies
User balance Only ownerOf (one) balanceOf(address, tokenId)
Gas per transfer ~25,000 gas ~18,000 gas (batch even lower)
Batch operations No native support safeBatchTransferFrom
Ideal scenario Art collections, PFPs Games, tickets, editions

Specific case: a game project with 50 types of items, each with a supply of 10,000. ERC-721 — 500,000 unique tokens, huge overhead on mappings. ERC-1155 — 50 tokenIds, balanceOf per player. Gas per transfer is 2–3 times lower, contract deployment is cheaper. For such tasks, we use OpenZeppelin ERC-1155 with custom modifications.

Metadata: on-chain vs IPFS vs centralized

The standard route is tokenURI() returning a link to a JSON with fields name, description, image, attributes. Three storage options:

  • Centralized server — cheapest and most flexible. Risk: server goes down, company closes — NFT loses metadata. Not suitable for collections claiming long-term value.
  • IPFS + Pinning — content-addressed storage, the link is bound to the content hash. Pinata or NFT.Storage provide pinning. Important: IPFS does not guarantee availability by itself — an active pinning service is needed. If it shuts down, data may disappear if no one keeps a copy.
  • On-chain metadata — base64-encoded SVG or JSON directly in tokenURI. Maximum reliability, but expensive: for a collection of 10,000 tokens, gas costs may exceed $5,000. Suitable for generative art projects where visuals are generated from on-chain attributes (Nouns, Loot).

For most collections, we choose IPFS with Pinata for images + on-chain attributes for traits — a good balance. We validate files against a JSON Schema before upload; a typical mistake is unescaped quotes, causing marketplaces to display a blank screen.

Typical JSON metadata format
{
  "name": "Token #1",
  "description": "A unique NFT",
  "image": "ipfs://QmHash/image.png",
  "attributes": [{"trait_type": "Background", "value": "Red"}]
}

Dynamic NFT: metadata that changes

Dynamic NFT updates metadata in response to external events — match results, character levels, real-world data via Chainlink. Architecturally, it's a combination: the smart contract stores state → tokenURI() generates metadata from the state on-chain. Caching problem: OpenSea and other marketplaces aggressively cache. The standard invalidation mechanism is a MetadataUpdate(tokenId) event from ERC-4906. OpenSea listens to this event and clears the cache. Without it, updated metadata may not appear for weeks.

Chainlink Automation (formerly Keepers) for automatically updating state on the contract on a schedule or condition — a standard solution for dynamics.

How to protect mint from bots?

Allowlist via Merkle tree — standard. The list of addresses is hashed into a Merkle root, stored in the contract. During mint, the user provides a Merkle proof — the contract verifies without storing the full list. We use OpenZeppelin MerkleProof library.

Reveal mechanism — on mint, a placeholder is issued; real traits are revealed after the sale ends. Otherwise, bots can scan pending transactions and snipe rare traits via frontrunning. But reveal requires a commitment scheme — the random seed must be fixed before mint or use Chainlink VRF.

Chainlink VRF for fair randomization of traits. VRF request at mint → callback with verifiable random number → assign traits. This adds ~2 transactions and latency but guarantees fairness. Chainlink VRF v2.5.

Rate limiting — require(mintedPerWallet[msg.sender] < maxPerWallet). Does not protect against multi-wallets but raises attack cost. For premium projects, we often add proof-of-work directly in the contract (via EIP-2612 signatures).

Royalties: the real market state

ERC-2981 — on-chain royalty standard. The contract returns (recipient, amount) for any sale price via royaltyInfo(tokenId, salePrice). Marketplaces query this on each sale. Problem: adherence to royalties is voluntary for marketplaces. Blur launched with zero royalties, triggering a wave of other platforms. The situation has partially stabilized: OpenSea supports ERC-2981, Blur added optional ones. Royalty payments can represent 5–10% of secondary sale volume, so getting them right matters.

Attempts to enforce royalties on-chain by restricting transfers only to approved marketplaces (operator filtering) were proposed by OpenSea via OperatorFilterRegistry. This breaks composability — you cannot transfer an NFT through a custom contract. Most serious projects have abandoned this approach. For projects where royalties are critical, we build a custom marketplace within the ecosystem plus an incentive structure for users to trade there.

Lazy minting and gas-free mint

Gas-free mint via signature: the creator signs a voucher (tokenId, tokenURI, price, signature), the buyer provides the voucher in mint() — the contract verifies the signature via ECDSA.recover() and mints. Works on OpenSea via their Seaport protocol. Seaport is an optimized contract with minimal gas usage. Understanding its mechanics is important when integrating custom marketplace logic.

Stack for NFT projects

  • Contracts: Solidity 0.8.x, OpenZeppelin ERC721Enumerable or ERC721A (Azuki) for gas-optimized batch mint, ERC1155 from OpenZeppelin
  • VRF and automation: Chainlink VRF v2.5, Chainlink Automation
  • Storage: Pinata (IPFS pinning), NFT.Storage, Arweave for permanent storage
  • Marketplace: OpenSea Seaport protocol, custom integration
  • Frontend: wagmi v2 + viem, RainbowKit for wallet connection, React + TypeScript

Development process

  1. Mint mechanics design — allowlist, public sale, price curve (Dutch auction or fixed), limits per wallet
  2. Contracts — with Foundry fuzz tests on mint limits, Merkle proof verification, royalty calculations
  3. IPFS deployment — upload metadata and images before reveal, pin on at least two services
  4. Reveal — if using Chainlink VRF, test on testnet mandatory: VRF subscription must be funded with LINK tokens
  5. Marketplace integration — verify collection on OpenSea, configure royalties, test MetadataUpdate events
  6. Deployment and monitoring — Tenderly for reentrancy detection, Etherscan API for contract verification, set up event alerts

Deliverables

  • Source code of smart contracts (Solidity, Rust for Solana) with comments
  • Test suite (Foundry/Hardhat) with ≥90% coverage
  • Deployment documentation and integration instructions
  • Access to pinning services (Pinata/Pinfluence)
  • Metadata generation scripts (Python/JS)
  • Support during marketplace verification
  • 30 days of technical support after deployment

Timeline

Task type Approximate timeline
Basic ERC-721 without reveal from 2 weeks
NFT collection with allowlist, reveal, VRF from 5 weeks
ERC-1155 with marketplace and royalties from 6 weeks
Dynamic NFT with external data from 8 weeks

Cost is calculated individually after auditing your task. Send a brief with your project description — we will provide a transparent estimate within 3 business days. For regular clients, there is a flexible discount system on batch orders. If you need a gas-optimized contract, order a free gas analysis. Get a consultation on marketplace architecture — leave a request, and we will evaluate your project in three days.