Global delivery from Hanoi, Vietnam ISO 9001:2015   ISO 27001:2013 hello@agiletech.vn (+84) 989 324 830

Blockchain in supply chain: what actually works after the hype

A crane-lifted shipping container wrapped in a chain of glass blocks with glowing seals, broken dull links on the dock below
Most of the chain broke. What survived is smaller, quieter, and actually useful.

In short

Blockchain in supply chain works in a narrow band of cases and fails in the broad one it was sold for. The flagship consortia, TradeLens, We.trade and B3i, all shut down because participants would not fund a shared ledger that mostly benefited a competitor who ran it. What survived are cases where the trust problem is real and structural: luxury goods authentication, pharmaceutical serialization under regulatory mandates, anchor-buyer food traceability where one powerful customer compels adoption, and cross-border trade documents. For everything else, a well-governed shared database with signed audit trails delivers the same guarantees at a fraction of the cost, and a hash-anchoring hybrid covers most cases that genuinely need tamper evidence.

Between 2017 and 2020, blockchain was going to fix the supply chain. Maersk and IBM built TradeLens to put global shipping on a ledger. A dozen European banks built We.trade for trade finance. The insurance industry built B3i. Analysts projected tens of billions in value, and every logistics conference had a blockchain track. By 2023, all three flagships had shut down, and the phrase had quietly disappeared from most vendor decks.

That collapse is the most useful dataset the industry has ever produced, because it separates what blockchain was sold for from what it is actually good at. The failures were not technical. The platforms worked. They failed on governance and incentives, and the survivors, which are real and growing, share a structure the failures lacked. Understanding that structure is worth more than any technology comparison.

This guide is the honest version of the assessment: what died and precisely why, the four use case families that survived, the ledger-versus-database decision stated without vendor gloss, a reference architecture for teams that genuinely need tamper-evident traceability, and a decision framework that routes your specific flow to the cheapest thing that solves it. It pairs with our supply chain implementation guide for the broader systems picture and our plain-language Web3 explainer for the underlying technology.

Key takeaways

  • The graveyard is the data: TradeLens, We.trade and B3i were the best-funded, best-connected blockchain supply chain projects ever attempted, and all three shut down for the same non-technical reason, participants would not pay to strengthen a platform a competitor controlled.
  • The survivors share one shape: either a regulator mandates the record (pharma serialization), a powerful anchor buyer compels it (retail food traceability), or the asset itself is valuable enough that provenance is the product (luxury authentication).
  • The honest technical question is never "can blockchain do this" but "who exactly do we not trust, and would they tamper with a signed, replicated database." If you cannot name the adversary, you do not need the ledger.
  • Hash anchoring is the underused middle path: keep operational data in an ordinary database, publish periodic cryptographic fingerprints to a public chain, and you get court-grade tamper evidence without consortium governance or per-transaction costs.
  • The blockchain layer is never the hard part. Capture at the physical edge, scanning, IoT sensors, supplier onboarding, data quality, consumes 80 percent of any traceability budget regardless of what stores the record.
  • Route the decision by trust shape: internal flows need workflow software, bilateral flows need signed APIs, multi-party flows with a compelling authority may justify a permissioned ledger, and consumer-facing provenance increasingly favors public-chain anchoring.

The promise, stated fairly

Five figures from different supply chain roles around a table sharing one glowing sealed ledger, each holding a key
One record no single party can quietly rewrite. Stated that plainly, the promise is real.

The pitch was coherent, which is why serious companies spent serious money on it. A global supply chain is a network of parties who do not fully trust each other: shippers, carriers, forwarders, customs agencies, banks, insurers, and buyers, each keeping private records that disagree with everyone else's. Reconciling those records consumes armies of clerks, and the gaps between them hide fraud, delay, and disputed liability. A shared, append-only ledger that every party writes to and none can retroactively edit would collapse that reconciliation work into a single source of truth.

The paper problem it targeted was real and enormous. A single international shipment can involve dozens of documents, bills of lading, letters of credit, certificates of origin, phytosanitary certificates, passed among parties by email and courier. Maersk's famous internal study tracked a container of avocados from Kenya to Rotterdam and found the paperwork cost roughly as much as the transport. Digitizing that flow onto a shared record that customs, banks, and carriers all accepted was the concrete, unglamorous value proposition underneath the hype.

Provenance was the second pillar. If every custody transfer of a product is written to an immutable record at the moment it happens, then the end buyer can verify the chain: this tuna was caught by this vessel on this date, this handbag left this factory, this pallet of lettuce passed through this distributor. Recalls that take weeks of phone calls become database queries. Counterfeits that depend on paperwork forgery become detectable. Ethical sourcing claims become auditable instead of aspirational.

Stated that way, the promise holds up. The failures that followed were not failures of the idea that shared, tamper-evident records are valuable. They were failures of a specific assumption buried inside it: that competing companies would jointly fund, govern, and feed a shared platform simply because the shared record was efficient. That assumption is where the graveyard begins.

The graveyard: what shut down and why

A foggy field of toppled chain-link monuments with dead lanterns, an archaeologist examining a hollow foundation, one still lit
The failures share a foundation problem: nobody needed the part that made it a blockchain.

TradeLens was the flagship. Launched by Maersk and IBM in 2018, it onboarded hundreds of organizations, processed data on tens of millions of containers, and had genuine traction with customs authorities. It shut down in early 2023. The stated reason was the inability to reach commercial viability, and the structural reason underneath was adoption asymmetry: TradeLens needed rival ocean carriers to feed their operational data into a platform half-owned by Maersk, their largest competitor. Some joined reluctantly and contributed minimally; most saw no reason to strengthen a rival's asset. Without full network data, the single source of truth was neither single nor complete, and customers would not pay for a partial one.

We.trade told the same story in trade finance. Built on IBM technology and owned by a consortium of major European banks, it aimed to digitize open-account trade for small and medium businesses. It entered liquidation in 2022 after the banks, which were each other's competitors, declined to keep funding a shared utility whose benefits accrued to the network rather than to any single balance sheet. B3i, the insurance industry's blockchain consortium, folded the same year for the same reason: shareholders would not put in more capital for infrastructure that helped everyone equally, which in competitive terms means it helped no one.

The pattern generalizes, and it is worth stating precisely because it is the single most important fact in this subject. Consortium blockchains have a cold-start problem that compounds a governance problem. The ledger is only valuable when most parties write to it, but each party's dominant strategy is to wait, contribute little, and let others build the network. And when the platform is operated by one participant, every contribution strengthens a competitor. Nothing about distributed ledger technology solves this, because it is not a technology problem. It is an incentive problem wearing a technology costume.

The honest lesson is narrower than "blockchain failed." Blockchain-as-neutral-shared-infrastructure among competing peers failed, repeatedly, at the highest funding levels the concept will likely ever enjoy. What did not fail, and what the next section covers, are deployments where the incentive problem was solved by something outside the technology: a regulator, a dominant buyer, or a brand whose product is trust itself.

The consortium era, by the numbers

3 Flagship consortia shut down in 2022 and 2023 TradeLens, We.trade and B3i: the best-funded attempts the concept will likely ever get.
300+ Organizations TradeLens onboarded before closing Adoption was real. Rival carriers withholding full data made the record permanently incomplete.
0 Failures attributed to the technology itself Every post-mortem points at incentives and governance. The ledgers worked as designed.

The need for full global industry collaboration has not been achieved. As a result, TradeLens has not reached the level of commercial viability necessary to continue.

Rotem HershkoHead of Business Platforms, A.P. Moller-Maersk, announcing the shutdown
The flagship consortia: lifespan in yearsBar chart of consortium lifespans. TradeLens ran about four and a half years from 2018 to early 2023, We.trade about five years to its 2022 liquidation, B3i about six years to its 2022 wind-down. Aura, the luxury authentication consortium launched in 2019, is still operating and growing, because its members share infrastructure costs without exposing competitive data to each other. 0 2 4 6 8years from launch to shutdown TradeLens (Maersk andIBM) 4.5 2018 to early 2023 We.trade (Europeanbanks) 5 2017 to 2022 liquidation B3i (insuranceconsortium) 6 2016 to 2022 wind-down Aura (luxury, stilloperating) 8 2019 to present, and growing The survivor: members share costs, not competitive data
The best-funded blockchain supply chain platforms ever built, measured from launch to shutdown announcement.

What survived, and the structure it shares

Three greenhouse domes each growing a chain plant from the same three-layer soil cross-section, a gardener watering one
Every survivor has the same anatomy: real databases below, a thin verification layer on top.

Luxury authentication is the clearest survivor. The Aura Blockchain Consortium, founded by LVMH, Prada and Cartier's parent Richemont, issues digital identities for tens of millions of luxury products, and it works where TradeLens did not for a structural reason: the members are not sharing operational data that exposes them to each other. Each brand writes provenance records for its own goods, the shared infrastructure is a cost split rather than a competitive risk, and the customer-facing benefit, proof that a resold handbag is genuine, directly protects each brand's pricing power. Provenance is not a compliance cost here. It is the product.

Pharmaceutical serialization survived because a regulator removed the adoption question. The US Drug Supply Chain Security Act and the EU Falsified Medicines Directive require unit-level tracing of prescription drugs through the distribution chain, with full DSCSA enforcement arriving through 2024 and 2025. When the law says every handoff must be verifiable, the cold-start problem disappears: everyone must participate or exit the market. Ledger-based and ledger-adjacent systems compete here on merit against centralized traceability hubs, and the interoperability requirements of thousands of trading partners give distributed approaches a genuine, if contested, case.

Anchor-buyer traceability is the third family. IBM Food Trust survives, in contrast to its sibling TradeLens, substantially because Walmart mandated it: leafy-greens suppliers were told to join and given deadlines, and a supplier's alternative to compliance was losing the account. The economics mirror the regulatory case, one powerful node absorbs the coordination cost and compels the network into existence. Recall speed improved from days of phone calls to seconds of queries, which is real value, though it is fair to note a Walmart-operated database with supplier write access would have delivered much of the same benefit.

The fourth family is cross-border trade documents, where the electronic bill of lading finally has legal footing: the UK Electronic Trade Documents Act of 2023 and the spreading UNCITRAL model law give digital possession of a trade document the same standing as paper. Platforms in this space use distributed-ledger techniques to guarantee that exactly one party holds the original at any moment, a singularity guarantee that is genuinely awkward for ordinary databases when no single operator is acceptable to all jurisdictions. It is the narrowest survivor, and arguably the most technically legitimate.

The survivor test: your use case needs at least one

  • A regulator mandates the recordPharma serialization under DSCSA and FMD. Adoption is compelled by law, so the cold-start problem never arises.
  • An anchor buyer compels the networkWalmart and food traceability. One dominant customer absorbs coordination costs and makes participation a condition of business.
  • Provenance is the product itselfLuxury authentication via Aura. The record directly protects resale value and brand equity, so every participant profits from writing to it.
  • No neutral operator is acceptableElectronic trade documents across jurisdictions. The singularity guarantee genuinely benefits from not having a single custodian.
  • Members share costs, not competitive dataAura brands write records about their own goods only. Nobody strengthens a rival by participating.
Who compels the record in each survivor caseSwimlane diagram of the four surviving use case families. Pharma serialization is compelled by DSCSA and FMD law, joined by every trading partner, records unit-level drug custody, and is verified by regulators. Food traceability is compelled by anchor buyer mandates like Walmart, joined by suppliers who want to keep the account, records lot-level custody, and is verified by the buyer during recalls. Luxury authentication is compelled by brand value itself, joined voluntarily by brands, records product identity, and is verified by customers at resale. Trade documents are enabled by electronic trade document law, joined by parties to each shipment, record possession of the original document, and are verified by banks, customs and courts. The force Who must join What is recorded Who verifies Pharmaserialization DSCSA and FMD law Every tradingpartner Unit-level custodyof drugs Regulators andauditors Foodtraceability Anchor buyermandate Suppliers who keepthe account Lot-level custodyevents The buyer, inrecalls Luxuryauthentication Brand value itself Brands,voluntarily Product identityand provenance Customers atresale Tradedocuments Electronic tradedocument law Parties to eachshipment Possession of theoriginal Banks, customs,courts
The four surviving use case families, and the outside force that solves the incentive problem the consortia never cracked.

The ledger versus the database, stated honestly

A steel vault with one guard and key beside a glass safe with many partial keys held by five figures, a level scale between
One is cheaper and faster. The other is harder to quietly rewrite. The scale is level for a reason.

Strip the branding away and a permissioned blockchain is a replicated, append-only database with a consensus protocol deciding write order, plus cryptographic signatures on entries. Every one of those properties is available separately and cheaply. An ordinary PostgreSQL database can be append-only by policy, replicated across parties by streaming, and cryptographically verifiable by signing entries and chaining hashes. The genuine question is never whether blockchain can hold supply chain data. It is whether the expensive part, decentralized consensus among mutually distrusting operators, is solving a problem you actually have.

The test that cuts through most meetings is naming the adversary. Who, specifically, do you believe would tamper with the record, and would a signed audit trail in a conventionally governed database fail to catch them? In internal flows, your warehouse to your stores, there is no adversary, and what looks like a trust problem is a data-quality problem that workflow software solves. In bilateral flows, you and one 3PL, a contract plus signed API logs settles disputes. The adversary answer only becomes interesting when many parties write to one record, none is acceptable as its custodian, and the record's integrity has legal or financial weight.

Cost asymmetry is the part vendor decks omit. A shared database with signed audit trails is a known quantity: ordinary engineers, ordinary hosting, ordinary operations. A permissioned ledger adds consensus infrastructure, node operations at every serious participant, key management for organizations that have never held signing keys, and a governance body to decide upgrades, membership and dispute rules. The governance body alone has killed more consortium projects than any outage. Teams consistently underestimate this layer because it does not appear in the architecture diagram.

There is a middle path that deserves more attention than it gets: hash anchoring. Operational data lives in an ordinary database, and on a schedule, hourly, daily, the system computes a cryptographic fingerprint of everything written since the last anchor and publishes that fingerprint to a public blockchain. The data stays private and fast; the anchor makes retroactive tampering provable by anyone, because rewriting history would break the published fingerprints. For most teams whose real requirement is "auditors and courts can trust this record," anchoring delivers it for a small fraction of consortium cost, with no governance body at all.

The vocabulary, without the mysticism

Permissioned ledger
A blockchain where a defined set of known organizations run the nodes and approve members. Hyperledger Fabric and enterprise Ethereum variants dominate. All the failed consortia used this model.
Hash anchoring
Publishing periodic cryptographic fingerprints of a private database to a public chain. Proves the history was not rewritten without exposing the data or requiring shared governance.
Singularity guarantee
Assurance that exactly one original of a document exists and one party possesses it. The core requirement of electronic bills of lading, and genuinely hard for ordinary databases without a trusted custodian.
Oracle problem
A ledger only guarantees the record was not altered after entry. If the scan, sensor or clerk that created the entry lied, the blockchain preserves the lie immutably.
Anchored database versus permissioned consortium ledgerComparison of the two record-layer choices, illustratively. The anchored database needs an ordinary backend team, one operating agreement, no per-party infrastructure, gives public tamper evidence through anchored hashes, and stays verifiable even if the operator shuts down. The permissioned ledger requires ledger specialists, a standing governance body and node operations at every serious participant, provides tamper evidence within the member set, and survives shutdown only if members keep nodes alive. Its genuine advantage is the single case where no custodian is trusted at all, where fully distributed writes are the requirement. Anchored database Permissioned ledger Engineering profile required Ordinary backend team Ledger specialists plusbackend Governance overhead One operating agreement Standing consortium body Per-party infrastructure None beyond API access Node operations and keycustody Tamper evidence Public, via anchored hashes Within the member set Survives operator shutdown Yes, anchors stayverifiable Only if members keep nodesalive No custodian trusted at all Anchor origin stillcentralized Fully distributed writes
What a team actually takes on with each record-layer choice, illustratively, for a mid-size multi-party traceability program.

A reference architecture for tamper-evident traceability

A four-story cutaway with sensor capture, database cabinets, a seal stamping floor, and a glass attic anchoring seals to a chain
Events live in databases. Only their fingerprints go up to the chain in the attic.

Whatever stores the record, serious traceability systems converge on the same layered shape, and the layers are worth walking because they show where the money actually goes. The bottom layer is capture: barcode and GS1 DataMatrix scanning at custody transfers, IoT sensors for condition data like temperature and humidity, EDI and API feeds from partners who will never install your app, and manual entry screens for the parties, small farms, small carriers, that have nothing else. This layer decides whether the record reflects reality, and it consumes most of the budget in every honest project accounting.

Above capture sits the integration and identity layer: an event pipeline that normalizes everything into a standard vocabulary, almost always EPCIS 2.0, the GS1 standard for supply chain events, plus master data services that give every product, location and party a stable identifier, and organization-level key management if entries are signed. This is unglamorous plumbing, and it is where projects succeed or die, because fifty suppliers with fifty data formats do not become one coherent event stream without sustained engineering. It is the layer AgileTech is most often hired to build, regardless of what sits above it.

The record layer is where the ledger decision finally lives, and the architecture is deliberately agnostic about it. The same EPCIS event stream can write to a conventional database with signed, hash-chained entries, to that same database plus a public-chain anchoring service, or to a permissioned ledger shared with partners. Because the choice is confined to one layer, it is reversible: more than one team has started on a consortium ledger and quietly migrated to anchored PostgreSQL when the consortium meetings outnumbered the transactions.

The top layer is where value becomes visible: recall tooling that traverses the custody graph in seconds, compliance reporting shaped for DSCSA or FMD auditors, consumer-facing verification pages behind a QR code, and partner portals with scoped views of shared events. A recurring failure mode is funding the record layer lavishly and this layer barely, which produces an immutable record nobody can act on. The record is the means. The recall query, the audit export and the verification page are the ends.

Traceability reference architectureArchitecture diagram in four tiers. The capture layer at the bottom holds barcode and DataMatrix scanning, IoT condition sensors, EDI and partner API feeds, and manual entry screens, and consumes most of the budget. Above it, the integration and identity layer holds the EPCIS 2.0 event pipeline, master data services and key management. The record layer above that is the swappable decision: a signed database, a hash anchoring service, or a permissioned ledger. The action layer on top holds recall queries, compliance exports, consumer QR verification and partner portals, where value becomes visible.Action layerWhere value isvisible Recall queries Complianceexports Consumer QRverification Partner portals queries and exports read the verified recordRecord layerThe swappabledecision Signed database Hash anchoring service Permissioned ledger normalized events written with signaturesIntegrationand identityWhere projectslive or die EPCIS 2.0 event pipeline Master data services Key management raw events normalized to EPCIS vocabularyCapturelayerMost of thebudget Barcode andDataMatrix scans IoT conditionsensors EDI and partnerAPIs Manual entryscreens
The layered shape every serious system converges on; the ledger decision is confined to one swappable layer.

Buying it: procurement, contracts and the questions that expose weak vendors

The vendor landscape sorts into four groups, and knowing which one is pitching you clarifies the meeting. Platform suites, the traceability modules inside SAP, Oracle and the big supply chain suites, sell blockchain as a checkbox feature and are best evaluated as traceability tools that happen to mention ledgers. Specialist traceability vendors sell the capture-to-recall pipeline and are the right conversation for food and pharma. Consortium platforms sell membership in a shared network, where the governance questions matter more than the product ones. And systems integrators sell the build, which is the honest framing for anything with unusual workflows.

Three questions expose weak pitches faster than any technical audit. First: "what happens to our data and our verification capability if you shut down," a question the TradeLens era made permanently legitimate, and the answer must include exportable data in a standard format, EPCIS, and verification that survives the vendor, which anchored hashes do and proprietary ledgers may not. Second: "who are the other participants, today, by name," because a network product without a network is a pilot. Third: "show me the recall query and the auditor export," which redirects the demo from ledger theater to the operational outputs you are actually buying.

Contract structure should mirror the architecture's reversibility. Pay for the capture and integration layers as owned assets, they are valuable under every future scenario, and treat the record layer as a swappable component with explicit exit rights: data export in EPCIS format, hash chains and anchoring receipts delivered to you, and no termination clause that turns your provenance history into hostage data. Per-transaction pricing on ledger writes deserves particular suspicion at supply chain volumes; a distribution operation emitting millions of events monthly can find the meter costing more than the infrastructure it meters.

Pilots deserve their own discipline, because this space is where pilots go to be press releases. A pilot that proves value looks like: one product line, one flow with a named pain, a baseline measured before the pilot, recall drill time, dispute resolution cost, counterfeit incident rate, and a pre-committed decision rule for scaling or stopping. A pilot that proves nothing looks like: a proof of concept on synthetic data, a joint announcement, and a quiet burial eighteen months later. The industry has run hundreds of the second kind. The first kind is rarer and is the only kind worth funding.

Procurement rules from the post-hype era

Do this

  • Own the capture and integration layersScanning, EPCIS pipelines and master data are valuable under every scenario, including abandoning the ledger entirely.
  • Demand vendor-independent verificationAnchored hashes on a public chain remain checkable if the vendor disappears. TradeLens customers learned why this clause matters.
  • Measure a baseline before the pilotRecall drill hours, dispute costs and counterfeit rates, captured first, are the only way the pilot can prove anything.
  • Ask for participants by nameA shared-network product is worth exactly its current network. Roadmap participants are not participants.

Not this

  • Buy the ledger before the scannersAn immutable record of unscanned reality is an expensive way to preserve guesses. Capture comes first, always.
  • Accept per-event pricing at volume blindlyMillions of monthly events turn a small meter into the largest line item. Model your event volume before signing.
  • Let governance arrive unbudgetedMembership rules, upgrade votes and dispute procedures killed more consortia than technology ever did. If nobody prices it, nobody has planned it.
  • Confuse a press release with adoptionThe graveyard is full of celebrated pilots. Scale decisions need pre-committed metrics, not announcements.

The decision framework: route by trust shape

Three trails from a mountain pass toward one campus, a partner village, and rival fortresses sharing a glass bridge, third cairn glowing
The technology choice follows the trust shape. Only the fortress gorge needs the glass bridge.

Every flow you might put on a ledger has a trust shape, and the shape, not the technology fashion, should route the decision. Shape one is internal: your factories, warehouses and stores, one legal entity end to end. There is no adversary, so there is no ledger case at all; what feels like a trust problem is fragmented systems and weak data capture, and the fix is integration and inventory infrastructure, not consensus protocols. A surprising share of blockchain inquiries dissolve at this step.

Shape two is bilateral: you and one counterparty, a 3PL, a contract manufacturer, a key supplier. Disputes here are settled by contracts plus evidence, and signed API logs with mutually held copies are evidence courts already understand. A shared ledger between two parties is a database with extra steps, since either party's refusal to accept the other as custodian is solved by simple mutual replication. Spend the money on interface quality and event completeness instead.

Shape three is multi-party with a compelling authority: a regulator mandates the record, or an anchor buyer compels the network, or an industry group with real teeth governs it. This is the survivor zone from earlier, and here the ledger conversation is legitimate, with the honest comparison being permissioned ledger versus authority-operated central hub. The deciding questions are whether participants will accept the authority as data custodian, and whether verification must outlive any single operator. Even here, anchored databases win a good share of honest evaluations.

Shape four is consumer-facing provenance: the end buyer, not a partner, is the verifier. Luxury resale, collectibles, certified-origin goods. Public verifiability is the requirement, which is why this shape increasingly lands on public-chain anchoring or public-chain-adjacent registries rather than private consortia: the customer scanning a QR code cannot be asked to trust a members-only ledger. This is the one shape where the public blockchain, the technology everyone means and nobody names in enterprise meetings, has a straightforwardly defensible role.

Route your flow by trust shapeDecision tree routing supply chain flows by trust shape. A single legal entity end to end needs workflow and inventory software with integration work, and no ledger. A bilateral flow with one counterparty needs mutually replicated signed API logs. A multi-party flow compelled by a regulator or anchor buyer leads to an authority-run hub if participants accept the authority as custodian, or a legitimate permissioned ledger evaluation if they do not. Consumer-verified provenance leads to public-chain anchoring or a public registry behind the QR code. Who writes to the record, and who must trust it? One legal entity Pain isreconciliation? Workflow andinventory softwareplus integration. Noledger case exists. One counterparty Contract settlesit? Signed API eventlogs, mutuallyreplicated. Courtsalready accept them. Compelled consortium Custodianaccepted? If yes, anauthority-run hub; ifno, evaluate apermissioned ledger. Consumer provenance Public proofneeded? Public-chainanchoring or a publicregistry behind theQR code.
The four-question routing from the framework, as one tree: name the adversary before naming the technology.

The honest conclusion

Blockchain in supply chain is neither the revolution of the 2018 keynotes nor the punchline of the 2023 retrospectives. It is a niche technology with a defensible core: multi-party records where no custodian is acceptable, provenance where verification must be public or must outlive every operator, and document singularity across jurisdictions. That core is real, growing, and much smaller than the market once believed. Everything outside it is better served by well-governed databases, signed audit trails, and the hash-anchoring hybrid that quietly gives most teams everything they actually wanted from the word "blockchain."

The deeper lesson of the consortium graveyard applies to any shared-infrastructure ambition, ledger or not: technology cannot manufacture the incentive to cooperate. TradeLens had world-class engineering and shut down anyway, because rival carriers rationally declined to feed a competitor's platform. Where a regulator, an anchor buyer or a brand-value flywheel supplies the incentive, shared records thrive, sometimes on ledgers. Where no such force exists, the whitepaper does not create one.

For most operations leaders reading this, the practical takeaway is comfortingly boring: your traceability problem is probably a capture and integration problem. Fund the scanners, the EPCIS pipeline, the master data and the recall tooling first, keep the record layer swappable, and add tamper evidence with anchoring if auditors or courts are in your future. If your flow genuinely matches a survivor shape, regulatory mandate, anchor buyer, provenance-as-product, then run the ledger evaluation with the procurement discipline above, and insist on exit rights the TradeLens era taught everyone to demand.

And if you are unsure which side of the line your flow falls on, the decision block below routes it in four questions. The technology choice at the end matters less than most meetings assume. The capture layer, the data discipline and the operational tooling around the record are where traceability projects are actually won, and they are the same work under every answer.

Your flow, routed

What is the trust shape of the flow you need to fix?

  • One legal entity end to end: your sites, your systems

    Workflow and inventory software plus integration work. No ledger.

    There is no adversary. The pain is fragmented capture and reconciliation, which consensus protocols do not address.

  • You and one counterparty, disputes settled by contract

    Signed API event logs, mutually replicated. No ledger.

    Courts already accept signed logs as evidence, and mutual copies remove the custodian objection at near-zero cost.

  • Many parties, and a regulator or anchor buyer compels the record

    Evaluate permissioned ledger against an authority-run hub, honestly.

    The compelling authority solves the cold-start and incentive problems that killed the consortium era. Either answer can win.

  • End consumers must verify provenance themselves

    Public-chain anchoring or a public registry behind the QR code.

    A customer cannot be asked to trust a members-only ledger. Public verifiability is the requirement, so the record must be publicly checkable.

Frequently asked questions

Is blockchain still used in supply chain management?

Yes, but in a much narrower band than the 2018 hype suggested. The surviving deployments cluster in four families: luxury goods authentication through the Aura consortium, pharmaceutical serialization under DSCSA and FMD mandates, anchor-buyer food traceability programs like the one Walmart compels, and electronic trade documents with new legal standing. The broad vision of shared ledgers among competing peers collapsed with TradeLens, We.trade and B3i in 2022 and 2023.

Why did TradeLens fail?

Incentives, not technology. TradeLens needed rival ocean carriers to feed operational data into a platform half-owned by Maersk, their largest competitor. Most contributed reluctantly or minimally, so the record was never complete enough for customers to pay for, and Maersk announced the shutdown in late 2022 citing the lack of full industry collaboration needed for commercial viability. Every major consortium of that era failed on the same governance and incentive structure.

What are the real benefits of blockchain in supply chain?

Where the use case fits, three: tamper-evident custody records that regulators, courts and customers can verify independently of any operator; recall traversal in seconds instead of days once capture is in place; and document singularity for instruments like bills of lading where exactly one original must exist. The honest caveat is that the first two are also achievable with signed databases and hash anchoring at far lower cost, so the ledger only earns its keep when no custodian is acceptable to all parties.

When is a shared database better than a blockchain for supply chain?

In most cases. If the flow is internal to one company, there is no adversary and workflow software solves it. If it is bilateral, signed API logs replicated to both parties settle disputes. Even multi-party flows usually work as a hub run by the regulator, anchor buyer or industry body, provided participants accept that custodian. The permissioned ledger case only opens when many parties write, none is acceptable as custodian, and the record carries legal or financial weight.

What is hash anchoring and why does it matter?

Hash anchoring keeps operational data in an ordinary database and periodically publishes a cryptographic fingerprint of the accumulated history to a public blockchain. Because rewriting past records would break the published fingerprints, tampering becomes provable by anyone, forever, without exposing the data itself. It delivers the tamper evidence most teams actually want from the word blockchain, without consortium governance, node operations or per-transaction fees, which is why it quietly wins many honest evaluations.

How much does a blockchain supply chain solution cost?

The record layer is the smaller line item; capture and integration dominate. Scanning hardware, supplier onboarding, EPCIS pipelines and master data typically consume most of the budget whatever stores the record. On top of that, an anchored database adds modest infrastructure, while a permissioned consortium adds node operations at each serious participant, key management, and a standing governance body whose meetings are a real recurring cost. Per-event pricing deserves scrutiny at volumes of millions of monthly events.

The blockchain question in supply chain is really a trust-shape question, and the winning layer is almost always capture and integration. To build the pipelines, records and recall tooling your operation needs, work with AgileTech, a supply chain engineering partner in Hanoi that gives you the honest record-layer answer and builds the layers that matter under every answer.

Consult Industry Specialists

Connect with us today to discuss your software development needs and discover how our tailored outsourcing services can propel your business forward.

Start a conversation
AgileTech Vietnam team at the office

Privacy choices

We use one category of strictly necessary first-party storage, which keeps the site working and remembers this choice; it is always active. Every other category is optional and stays off until you switch it on, wherever you are in the world. Two optional categories have something behind them today: Analytics, which is Google Analytics, and External content, which is the Google map of our Hanoi office on the Contact page. Neither runs until you allow it.

Our worldwide approach. We apply one standard to everyone: nothing outside strictly necessary storage runs until you allow it. That meets the EU and UK requirement for prior consent, Vietnam's Law 91/2025/QH15 on personal data protection, the notification and consent requirements of Singapore's PDPA, and US state privacy law. You can withdraw or change your choice at any time, as easily as you gave it, from Privacy choices in the footer.

Where you are connecting from. Our network tells us the country associated with your connection, and we use it to choose which consent policy to apply. We do not use it to work out your address, we do not put it in a cookie, and we never send your IP address to the page. Today every country receives the same strict policy, so it makes no difference to what you see. If your country cannot be determined, or you are using Tor, you get the strict policy too: an unknown location always means the more protective setting, never the weaker one.

If you are in the United States. We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We still honor an opt-out preference signal from your browser: if your browser sends Global Privacy Control, the optional categories stay off without you having to do anything.

Full detail, including the name and lifetime of the one cookie we set, is in the Cookie Policy.