Livre des Crus

Technology

Two layers.
Two codes. One title.

Livre des Crus adds a neutral ownership layer on top of the producer authentication that already exists. Here is exactly how it works — and the one thing a ledger cannot do alone.

The promise

Everything a bottle must prove.

Is it real? Where has it been? Is it mine? One title holds the answer to all three.

Livre des Crus sealOne title

Authenticity

Is it real?

Provenance

Where has it been?

Ownership

Is it mine?

On the bottle

The bottle proves itself.

01

Verify — anyone, no middleman

Every bottle is minted by the château as a unique title on a public ledger. Scan its code and anyone can confirm it is genuine and see the live title — current owner, full provenance, and “alive / consumed” status. Nothing to trust but the chain.

02

Retire — a secret revealed by opening

Beneath a tamper-evident capsule sits a hidden secret that opening the bottle is the only way to expose. Scanning it retires the title forever — so an opened bottle can never pass as sealed, and an authentic empty is worthless to a counterfeiter.

The château mints, ownership moves on the chain with every sale, and opening retires the title for good. The record is public, permanent, and owned by no one.

The bottle lifecycle

Four on-chain events.

  1. Mint — at the château

    The producer's signing key creates a title: a unique bottle ID; producer, cuvée, vintage, format and lot; a hash commitment to the secret code; and the producer's signature. The producer is the sole authority that can mint.

  2. Transfer — négociant → auction → collector

    Two problems solved together: money-vs-title atomicity, via smart-contract escrow (title moves only when payment clears); and title-vs-bottle atomicity, via the custody handshake below and, for investment wine, vaulting.

  3. Consume — burn-on-open

    Opening exposes the secret code. The chain checks it against the commitment stored at mint, records a Consumed event, and permanently burns the title. This is the mechanism that defeats the refill attack — an authentic empty is now worthless.

The binding problem

A ledger guarantees the record is tamper-proof — but not, by itself, that a token matches this bottle. We close that gap by design: every bottle is a single, owned title that cannot be copied into many, and it is retired the moment it is opened — so a copy has nothing to inherit and an authentic empty has nothing to refill.

§ Custody handshake

Closing the title-vs-bottle gap

Seller initiates transfer; title enters escrow; buyer pays in; seller ships. On receipt the buyer scans the public code and co-signs “received,” releasing payment and finalizing title. If the buyer never confirms, escrow refunds and title reverts — the physical handoff becomes part of the protocol.

§ Vaulting

Decoupling ownership from movement

For investment-grade wine, the bottle sits in a bonded warehouse for years and only the title circulates — trading pseudonymously and instantly. The vault is an audited custodian whose attestations are themselves signed on-chain. Likely the fastest path to real-world adoption.

Privacy is protection

Prove what you own
without exposing what you own.

Pseudonymous is not anonymous. We treat de-anonymization as an adversary from day one.

Baseline

Fresh address per bottle

No names on-chain. Provable ownership, private holder.

Stronger

Stealth addresses

Each transfer derives a one-time address, so a bottle's history can't be linked to a single party.

Strongest

Zero-knowledge

Prove “I hold a genuine, unopened bottle from this producer” without revealing which one — supporting verification, insurance and financing without disclosure.

Technology choices

Open trade-offs, not dogma

  • A public chain with privacy tooling (stealth / zk) best fits a neutral public good — pending foundation review.
  • A non-fungible, soulbound-until-transfer title with a burn primitive and producer-gated mint.
  • A simple code on every bottle — scan to verify, no special hardware required.
  • No protocol token. Reading and verification are free.
Governance

Root of trust is the hard part

  • A non-profit foundation stewards the protocol and the open data standard.
  • A consortium of producers, négociants, auction houses and warehouses governs — no single member can rewrite history.
  • Producer onboarding — admitting a château's signing key — must be rigorous, audited and revocable.

Want the full detail?

The whitepaper, concept doc, data model and threat model are openly published and iterated.