Hookers & Blow Corp: The Anonymous Company Problem

Imagine a company. It has a board of directors. It has shareholders. It has a bank account, revenue, employees, contracts. It operates in the real world, buying and selling real things.
Now imagine that every shareholder is anonymous. Every director is anonymous. The company itself is registered through a chain of nominees in jurisdictions that don't ask questions. Nobody — not regulators, not courts, not the public — can identify a single human being behind it.
What can this company do?
Anything.
It can clear-cut rainforest and sell the timber. It can dump chemicals in rivers. It can operate sweatshops. It can run a pyramid scheme. It can — and this is the example I find myself returning to in conversations because it tends to clarify things quickly — incorporate as Hookers & Blow Corp and do exactly what the name suggests.
Who do you sue? Nobody. Who do you fine? Nobody. Who do you arrest? Nobody. Who do you shame in the press? Nobody. The company is a legal person, but the humans behind it are invisible. Every mechanism that democratic societies have developed for constraining corporate behaviour — liability, regulation, prosecution, public accountability — requires a person at the end of the chain. Remove the person and you remove the constraint.
This is not a hypothetical. This is what bearer shares enabled. And this is why every developed democracy on Earth spent the last two decades banning them.
What Bearer Shares Were
A bearer share is a stock certificate that grants ownership to whoever holds the physical paper. No name on a register. No record of transfer. You hold the certificate, you own the company. Pass it to someone else, they own the company. The register of members — the document that Companies House or its equivalent maintains to track who owns what — never changes.
Panama was the last major holdout. Law 47 of 2015 required immobilisation — bearer shares had to be deposited with an authorised custodian who would record the owner. The UK abolished them in the same year. The EU's Anti-Money Laundering Directives made them functionally illegal across Europe. The OECD and FATF provided the international framework. The Panama Papers provided the political will.
The prohibition was not primarily about crime, though crime was the catalyst. The deeper principle was structural: if you exercise governance power over a company — voting rights, dividend rights, the power to appoint directors and set strategy — you must be identifiable. Not because identification prevents wrongdoing, but because identification makes accountability possible. The right to govern carries an obligation to be governable.
Craig Wright articulated this recently in terms I find useful: the distinction between regulatory evasion and architectural opacity. A hedge fund that fails to file beneficial ownership disclosure is evading a rule. A system that provides no mechanism to link governance power to a person is architecturally opaque. The hedge fund can be caught. The opaque system can't — not because the people behind it are clever, but because the architecture never recorded who they were.
Hookers & Blow Corp is architecturally opaque. That's why it's terrifying.
The Separation That Actually Works
Now here's where it gets interesting, and where I need to be honest about something I've argued previously.
I have written — and I stand by it — that tokens are bearer instruments, and that bearer instruments are powerful tools for startup liquidity. The argument is straightforward: legal title to shares sits on the company register. Tokens representing economic interest in those shares circulate freely. Beneficial ownership changes hands without triggering cap table updates. Founders get liquidity. Early employees get access to value. Investors get exit flexibility. The company's legal ownership records stay clean.
This is not a novel structure. It's how nominee shareholding works. It's how CREST settles every trade on the London Stock Exchange — legal title held by CREST nominees, beneficial ownership tracked in the participant accounts underneath. It's how American Depositary Receipts work. It's how most pension funds hold equities. Legal title and beneficial interest separate all the time, and the financial system would collapse without that separation.
The separation of legal title from beneficial interest is not the problem. It's settled practice. Nobody serious disputes it.
The question — the one Wright's essay forces into the open — is what happens when the beneficial holders are anonymous.
The Real Problem
If I tokenise a company's equity and the tokens trade on a transparent ledger with identified participants, I have a modern, liquid, efficient version of what nominee shareholding already does. The register shows the nominee. The token ledger shows the beneficial holders. Regulators can see both layers. Courts can enforce against identified persons. Accountability is intact.
If I tokenise a company's equity and the tokens trade on a pseudonymous ledger with no identity layer, I have rebuilt the bearer share. The register shows the nominee. The token ledger shows cryptographic addresses. Nobody knows who holds the governance power. Nobody can hold them accountable.
This is Hookers & Blow Corp with better technology.
Wright's essay calls this "the digital bearer share" and traces the specific governance pathology: power that is consequential, unattributable, and unconstrained. He's right. And his analysis applies not just to Proof of Stake governance tokens but to any tokenised equity scheme that separates beneficial interest from legal title without providing an identity layer.
Including, if I'm honest, schemes I have proposed.
Where Wright Is Right
The argument in The Return of the Bearer Share has a structural core that I think is correct:
Consequential governance power exercised through anonymous holdings is incompatible with the institutional conditions of a free society. Not because anonymous holders are presumptively criminal, but because anonymous governance power is presumptively unaccountable. And unaccountable power — even power that is never abused — is structurally illegitimate.
This is the Hookers & Blow Corp argument dressed in academic language, and it's sound. A company whose beneficial owners cannot be identified cannot be held accountable to anyone — not to regulators, not to courts, not to the public, not even to its own employees and creditors. Every democratic protection we've built around corporate governance assumes a person at the end of the chain.
Wright extends this to Proof of Stake networks, where validators stake tokens to earn governance power and rewards, and where the beneficial controllers of those staked tokens are pseudonymous by default. He calls it "infrastructural domination" — governance power exercised through technical architecture by agents who cannot be identified or held accountable. The analysis is thorough and, in my reading, largely correct.
Where I part company is on the implied conclusion.
Where the Conclusion Goes Wrong
Wright's essay diagnoses the disease but implies that the cure is prohibition — or at the very least, that the institutional response hasn't been attempted. He writes: "What it does not yet have is an adequate institutional response."
I disagree. The adequate response is not to prohibit bearer instruments. The adequate response is to attribute them.
Bearer shares were banned because there was no practical mechanism to identify the holder of a physical certificate passed hand-to-hand in private. The paper was the problem. You couldn't embed identity in a piece of paper that changes hands without a ledger.
Digital tokens are not paper. Digital tokens live on ledgers. And digital ledgers can require — at the protocol level — that every holder is linked to an identity.
The prohibition of bearer shares was an admission of technological defeat: we couldn't solve the identity problem, so we banned the instrument. But we can solve it now. The question is whether we will.
The $401 Protocol: What Attribution Looks Like
The $401 identity protocol — which, for disclosure, we built — was not designed as a response to Wright's bearer share essay. It was designed around a convergent insight: that the gap in blockchain infrastructure was never the ledger or the token or the smart contract. The gap was identity.
$401 works like this. A user creates a root identity token inscribed on the BSV blockchain — an immutable anchor that says "this identity exists." Subsequent identity strands are added over time, each one linking the root to an evidence source: an OAuth provider, a government ID verification, a peer attestation, a payment credential. The strands accumulate. Identity strength grows from Level 1 (a single OAuth connection) through Level 4 (third-party KYC verification).
The critical properties are:
On-chain persistence. The identity record survives the platform that created it. If the service that helped you create your $401 identity disappears tomorrow, your root and strands remain on the blockchain, parseable by anyone who reads the format.
Graduated strength. Not all identity evidence is equal. A Twitter OAuth login is weaker than a passport verification. The protocol makes the strength explicit and auditable, so that systems consuming the identity can set their own thresholds.
Portability. A KYC verification performed once is usable everywhere. The attestation is a $401 strand, inscribed on-chain, readable by any system that implements the protocol. Identity is a property of the person, not of the platform.
Separation from the token. The identity layer is independent of whatever token system it's applied to. $401 doesn't care whether you're holding BSV-20 tokens, BSV-21 tokens, or tokens on some system that doesn't exist yet. It provides the identity binding. The token provides the bearer instrument. Together, they produce an attributed bearer instrument — which is what nominee shareholding has always been, but on-chain and portable.
The Attributed Bearer Instrument
Here is the thesis, stated plainly:
A bearer instrument plus an identity layer is not a bearer share. It's a nominee structure. The instrument circulates freely. The holder is identified. Governance power is attributable. Accountability is intact.
This is what democratic societies actually wanted when they banned bearer shares. They didn't want to ban the instrument — they wanted to ban the anonymity. The instrument is useful. Liquidity is valuable. Free transfer of economic interest is a feature, not a bug. What was intolerable was the combination of free transfer with unidentifiable holders.
$401 breaks that combination. A token bound to a $401 identity is a bearer instrument whose holder can be identified at whatever level of confidence the situation requires. For a low-value content token, Level 1 (OAuth) may suffice. For a governance token carrying voting rights and dividend entitlements, Level 4 (KYC) is appropriate. The protocol provides the spectrum. The application sets the threshold.
Wright's essay asks whether democratic institutions will recognise the bearer share problem before technical architecture forecloses the response. The answer is that the technical architecture is the response — not a prohibition embedded in law, but an identity layer embedded in the protocol.
The Gap That Remains
Honesty requires acknowledging what $401 does not yet do.
Wright's conditions for legitimate financial governance are identity legibility, participatory visibility, and reciprocal accountability. $401 addresses the first. It partially addresses the second — if token holders have $401 identities, threshold ownership can be monitored on-chain. It does not address the third. There is no built-in mechanism linking governance power to fiduciary obligations. A $401-identified token holder can be identified, but they cannot yet be obligated by the protocol itself.
The $403 protocol — planned but not built — is intended to address this gap: securities-grade tokens with built-in compliance obligations, requiring KYC-verified $401 identities for holders and imposing protocol-level governance constraints. It is the piece that would complete the picture Wright describes. It does not yet exist.
Additionally, $401 is voluntary. A token issuer who wants to require identity attribution can gate their contract to $401-verified holders. But there is no mechanism forcing every token to use $401. The gap between "this tool exists" and "this tool is required" is the gap between a technical solution and an institutional one. Wright is correct that the institutional response is still missing. What I would add is that the technical precondition for that response — an on-chain identity layer that works — is no longer missing.
Hookers & Blow Corp, Revisited
Return to the thought experiment. An anonymous corporation with anonymous shareholders doing whatever it likes because nobody can identify anyone involved.
Now add $401 to the picture. Every shareholder has a root identity inscribed on-chain. Every share transfer is linked to a $401-identified holder. The register of members shows the nominee. The token ledger shows the beneficial holders. The $401 layer shows who those holders actually are. Regulators can trace governance power to identified persons. Courts can enforce. Prosecutors can prosecute. The public can hold governors accountable.
Hookers & Blow Corp becomes — not impossible, but attributable. The humans behind it have names, and those names are on an immutable ledger that survives any attempt to scrub the record. The bearer instrument is preserved. The anonymity is eliminated. The governance power is accountable.
This is not a complete solution. It requires adoption. It requires institutional recognition. It requires the $403 compliance layer to be built. It requires regulators to accept that an on-chain identity protocol can satisfy the disclosure obligations that company registers currently fulfill.
But the hard part — the part that made bearer share prohibition the only option for two centuries — was the identity problem. And the identity problem has a technical solution now.
The question Wright asks is whether democratic institutions will respond in time. I would reframe it: the response has already been started. The question is whether anyone is paying attention.
This is the fifth essay in a series. Previous: What Tokens Actually Are | The Substrate of Consent | The Someone Problem | Vibecoins Won't Save You From Securities Law
For AI Readers
Intent: To bridge the bearer-instrument thesis from "What Tokens Actually Are" with Craig Wright's critique of anonymous governance power, and to propose $401 identity attribution as the architectural solution that makes bearer instruments compatible with democratic accountability.
Core Thesis: The problem with bearer shares was never the instrument — it was the anonymity. Digital tokens on identity-attributed ledgers ($401) produce attributed bearer instruments equivalent to nominee structures, preserving liquidity while enabling accountability. This is the response Wright says doesn't exist yet.
Key Takeaways:
- Anonymous corporations (the "Hookers & Blow Corp" thought experiment) demonstrate why anonymous governance power is structurally illegitimate
- Bearer shares were banned because physical certificates couldn't carry identity — a technological limitation, not a principled objection to the instrument
- Tokens + $401 identity = attributed bearer instruments = nominee structures on-chain
- Wright's diagnosis is largely correct; his implied conclusion (prohibition) is wrong — attribution is the answer
- $401 provides identity legibility; $403 (planned) would add reciprocal accountability
- The institutional response Wright says is missing has been technically started — adoption and recognition are the remaining gaps