NFT Real Estate Marketplace Development: A Technical Guide
• 13 min read
Introduction
Most guides to NFT real estate marketplace development describe the same project: minting an NFT for each house and listing it on a marketplace with a wallet attached. Almost none of them mention that in the United States the token nearly always represents a security, or that what gets tokenized is a share in a company that owns the property rather than the deed itself.
A founder could follow that advice and commission a build, then discover at launch that the product can't legally be sold to most of the people it was designed for.
Three facts shape a US real estate tokenization platform. The token is usually a security, so the SEC's rules on offerings and resale apply to it. The token represents an interest in a legal entity, typically an LLC, that holds title to the property.
And the investor checks the law requires, such as KYC (know your customer) and accreditation, have to be enforced inside the token's transfer logic, because a check that only runs at sign-up is bypassed the moment tokens move between wallets.
When a founder tells me they want to mint NFTs of houses, I start by asking what they're trying to achieve by tokenizing the property, because that answer decides the legal structure, and the legal structure decides the architecture. Until we know the business goal and the legal requirements, there's nothing sensible to build, and the right choices on users and budget follow from those two.
In this article:
- 1. Key takeaways
- 2. What are you actually tokenizing when you tokenize a house?
- 3. Why is a real estate token usually a security?
- 4. Which token standard should a real estate platform use?
- 5. How much of the build goes into compliance and identity?
- 6. Who is responsible for KYC, AML, and custody?
- 7. How do you secure a contract that can freeze and force-transfer tokens?
- 8. What does the marketplace layer need to do?
- 9. What order should you build in?
- 10. Frequently asked questions
- 11. Sources
- 12. Disclaimer
Key takeaways
- In the US, a fractional real estate token is usually a security. SEC staff confirmed in January 2026 that recording a security onchain doesn't change how federal securities law applies to it.
- An NFT doesn't transfer title to a house. Platforms tokenize membership interests in an LLC or special purpose vehicle that holds the deed.
- ERC-3643 and ERC-1400 are better starting points than ERC-721, because they build identity checks and transfer restrictions into the token.
- I'd expect around 30 to 40% of development effort to go into compliance, identity, smart-contract and related backend logic rather than the marketplace UI.
- Contracts with freeze, forced-transfer, and mint powers need an independent external audit before launch.
What are you actually tokenizing when you tokenize a house?
The misconception I correct most often is that minting an NFT means you've tokenized ownership of a house. An NFT is a record on a blockchain.
Legal title to US real property is recorded with the county where the property sits, and a token changing wallets doesn't update that record. A legal structure must establish the link between a token and a building, and the software can only enforce what that structure specifies.
The usual structure puts the property inside a company. An LLC or special purpose vehicle (SPV), meaning a company that exists only to hold one asset, owns the deed.
The LLC's membership interests are then represented as tokens, so a token holder owns a slice of the company that owns the building. Rent is paid to the LLC and distributed to members, while the LLC's operating agreement governs a decision to sell the property.
Propy's February 2022 sale in Gulfport, Florida, one of the first US home sales run as an NFT auction, used this model. CoinDesk reported that the NFT represented ownership of an LLC holding the 2,164-square-foot house, which sold for about $653,000 in ether.
What the buyer received was control of the company that holds the deed, which is why every design decision after this point starts from the question of what a token holder owns and who is allowed to hold one.
Why is a real estate token usually a security?
The test US courts apply comes from the Supreme Court's 1946 decision in SEC v. W.J. Howey Co. An investment contract, and therefore a security, exists when someone invests money in a common enterprise expecting profits from the efforts of others.
A fractional property token fits that description closely, since investors invest with the expectation of rent and appreciation, while a manager handles the work of finding tenants and maintaining the building.
The SEC has been direct that blockchain doesn't change this. In a July 2025 statement, Commissioner Hester Peirce wrote that "tokenized securities are still securities" and that blockchain "does not have magical abilities to transform the nature of the underlying asset."
In January 2026, three SEC divisions issued a joint staff statement on tokenized securities, stating that the format in which a security is issued, or whether its holders are recorded on-chain or off-chain, "does not affect application of the federal securities laws."
Most of the growth forecast for this market is in regulated products. Deloitte's Center for Financial Services projects that tokenized real estate will grow from under $0.3 trillion in 2024 to $4 trillion by 2035, at a 27% compound annual growth rate.
Of that total, Deloitte expects $2.39 trillion in tokenized loans and securitizations and $1 trillion in tokenized private real estate funds, and neither looks much like a single house sold as an NFT.
So the first line on your architecture diagram is an offering decision, made with securities counsel. Each common route compiles into different software:
- Regulation D, Rule 506(c) lets you advertise publicly but sell only to accredited investors, and you must take reasonable steps to verify their status. A March 2025 SEC staff no-action letter permits issuers to rely on minimum investments of $200,000 for individuals and $1 million for entities, backed by written representations, so your onboarding flow must capture and store that evidence.
- Regulation A Tier 2 allows up to $75 million in 12 months. It opens the offering to non-accredited investors within per-investor caps, at the cost of audited financial statements and ongoing reporting, so the platform has to track each investor's limit.
- Regulation Crowdfunding caps raises at $5 million in 12 months and requires an SEC-registered broker-dealer or funding portal, with resale restricted for a year.
Resale rules reach into the token too. Under the SEC's Rule 144 guidance, restricted securities purchased from a non-reporting issuer generally must be held for 1 year before public resale. That lockup becomes a condition your transfer logic checks on every move, alongside the holder's identity and eligibility.
Which token standard should a real estate platform use?
I don't choose a token standard before the legal and business model is settled, because the standard has to express rules the lawyers haven't finished writing. Once those rules exist, the choice usually narrows quickly.
| Standard | Status | Designed for | Compliance built in |
|---|---|---|---|
| ERC-721 | Final Ethereum standard | Unique items, one token per item | None, so restrictions have to be added by hand |
| ERC-1400 | Proposed in 2018, never finalized as an EIP | Security tokens with partitions and attached documents | Transfer checks with reason codes, controller-forced transfers |
| ERC-3643 (T-REX) | Final Ethereum standard, created 2021 | Regulated securities with onchain identity | Identity registry, compliance contract, freeze, forced transfer, recovery |
ERC-721 is the standard most NFT guides reach for, and it's a poor fit for fractional ownership. Every ERC-721 token is unique, which works for one token per property but not for 10,000 identical LLC shares, and the standard has no concept of who is allowed to hold a token.
ERC-3643 was written for this problem, and its identity registry links each wallet address to an identity contract, called ONCHAINID, and to the investor's country code of residence. A separate compliance contract governs the offering, such as investor caps or country restrictions, and a transfer succeeds only if the receiving wallet is verified and the compliance contract approves it.
ERC-1400 covers similar ground and adds partitions, which allow a single token to track different classes of the same security, although it never became a finalized Ethereum standard.
For a US fractional platform, ERC-3643 or ERC-1400 is generally the more relevant starting point, because both assume a transfer needs permission. The final decision still depends on what the token represents and who can hold it, so we make it together with the client's legal and compliance advisers.
How much of the build goes into compliance and identity?
Usually more than founders budget for. As a rough estimate, about 30-40% of the development effort will go into compliance, identity, smart contracts, and related backend logic rather than the marketplace UI. That figure moves with the regulatory model and with how much work third-party providers take on, but I wouldn't plan a regulated asset platform on the assumption that it will be small.
That layer typically includes:
- KYC and AML (anti-money laundering) checks at onboarding, with periodic rescreening
- accredited investor verification and per-investor limits
- linking each wallet to a verified identity and whitelisting it onchain
- transfer restrictions covering lockups, eligibility, and jurisdiction
- an auditable record of ownership and of every transaction
Each of those rules then has to be wired into the smart contracts and the platform. The marketplace is the part of the product people see, while the difficult work is ensuring the identity and transfer rules hold underneath it, including cases where the UI never shows, such as an investor whose KYC expires while they still hold tokens.
Lending platforms have the same shape, which I covered in our guide to P2P lending software development.
Who is responsible for KYC, AML, and custody?
This has to be settled before development starts, because the technical design follows from it. At Milo, we build the platform and integrate the services it needs, but we don't act as the KYC or AML provider or as a regulated custodian, and most platform teams shouldn't either.
Those roles sit with specialist firms and, depending on the structure, with a registered broker-dealer, funding portal, or transfer agent the platform works with.
For a US tokenized real estate platform, we'd typically look at established providers and connect them to the platform and the smart contracts:
- identity verification and KYC: Persona or Sumsub
- blockchain transaction monitoring: Chainalysis
- institutional custody and wallet infrastructure: Fireblocks or Coinbase
The exact choice depends on the client's regulatory requirements and business model, as well as where their investors live.
Sanctions screening applies whichever vendors you pick. OFAC's sanctions compliance guidance for the virtual currency industry, published in October 2021, states that sanctions obligations "apply equally to transactions involving virtual currencies and those involving traditional fiat currencies" and recommends geolocation tools and IP address blocking. In practice, you screen wallet addresses as well as people, and you do it on every transfer.
What founders underestimate most is how far compliance reaches beyond the sign-up flow. KYC results and investor eligibility have to feed the wallet whitelist, and the whitelist has to agree with transaction monitoring and the audit trail.
Founders also underestimate how long it takes to agree who is responsible for what between the platform and each of its regulated partners and providers. That agreement is a project phase with its own timeline, and skipping it only moves the cost closer to launch.
Key custody deserves its own line in the budget. Chainalysis found that private key compromises accounted for 43.8% of the roughly $2.2 billion stolen in crypto hacks in 2024, the largest share of any attack type.
ERC-3643 includes a recovery function for investors who lose access to their wallet, which helps, but it requires an operational process to verify someone's identity and approve the recovery, and attackers will try to exploit that process too.
How do you secure a contract that can freeze and force-transfer tokens?
Security tokens ship with powers ordinary tokens don't have. Under ERC-3643, an agent can freeze an investor's tokens or force a transfer, and can also recover tokens to a new wallet or change supply by minting and burning. Those functions exist for real reasons, such as a court order or a lost key, but each one directly changes who owns what, so each one is attack surface.
Our process for these contracts starts before any code is written, by defining exactly when each privileged function may be used and by whom. From there, we:
- review the contract logic against the platform and compliance requirements, so the onchain rules match what the business and its lawyers agreed
- check every access permission, including who holds the agent and owner roles and how those keys are stored
- test the transfer restrictions on every path that moves tokens, since a batch or delegated transfer that skips a check the single transfer runs is enough to break compliance
- test scenarios and edge cases, such as a forced transfer into a frozen wallet or a lockup expiring partway through a transaction
- recommend an independent external security audit before anything goes live
Small mistakes carry large consequences in this kind of system. An access permission set slightly too wide, or a transfer rule that a second code path can bypass, is enough to turn a compliant token into one that isn't, and an unrestricted mint function can dilute every holder at once.
Role design belongs in the audit scope as well. Agent powers held by a single wallet are a single point of failure, so a common safeguard is to put them behind a multisignature wallet, which needs several approvals before a transaction executes, and to separate roles so the key that can freeze tokens can't also mint them.
If the contract is upgradeable through a proxy, whoever controls upgrades can rewrite every rule, so that key needs the same protection.
The principle I work from is that once a smart contract controls ownership of a real asset, it can't be treated as just another piece of code. It needs independent security validation on top of our own testing before it goes live.
What does the marketplace layer need to do?
With the token and compliance layer in place, the marketplace looks more familiar. I'd scope it around these flows:
- Primary issuance, covering the property listing with its offering documents, investor subscriptions and payments, and the minting of tokens to verified wallets.
- Distributions, meaning rent paid from the LLC to token holders in proportion to their holdings, with the records needed for tax reporting.
- The ownership record must stay in step with the official securityholder file. The SEC's January 2026 staff statement notes that issuers can keep that master file on one or more crypto networks, but a named party, often a registered transfer agent, still answers for it.
- Secondary transfers, if the offering allows them, are limited to verified wallets and subject to lockups.
Secondary trading needs its own legal answer. Matching buyers and sellers of securities is regulated activity that generally involves a registered broker-dealer or an alternative trading system, so many platforms launch with primary issuance only and add trading through a licensed partner later. The general mechanics of two-sided platforms are covered in our online marketplace development guide, and the payment side in our payment API integration guide.
What order should you build in?
- Settle the legal structure and the offering exemption with securities counsel, and write down who is responsible for KYC, AML, custody, and the securityholder record.
- Choose the token standard and chain to fit those rules.
- Select and contract the identity, monitoring, and custody providers.
- Build and test the smart contracts, including every privileged role.
- Build the platform and the marketplace on top of it.
- Commission an independent audit and fix what it finds before launching to a small group of investors.
The order reflects how we approach any technology project at Milo. We work out the client's requirements and goals first and decide whether an existing solution can meet them before anyone writes custom code, because the technology should support the business idea rather than be the starting point.
In tokenized real estate, skipping that order is how a team ends up with a working marketplace for a product nobody can legally buy.
Frequently asked questions
Does an NFT give you legal ownership of a house?
No. Title to US real property is recorded with the county, and a token moving between wallets doesn't change that record. Real estate tokens normally represent membership interests in an LLC or SPV that holds the deed, so the holder owns part of the company that owns the property.
Is a real estate token a security in the US?
Usually, yes. A fractional property token generally meets the Supreme Court's Howey test for an investment contract, and SEC staff stated in January 2026 that recording a security onchain doesn't affect how federal securities law applies. The offering requires registration or an exemption, such as Regulation D, Regulation A, or Regulation Crowdfunding.
Which token standard is best for real estate tokenization?
For a US fractional-ownership platform, ERC-3643 or ERC-1400 is generally a better starting point than ERC-721, because both support identity checks and transfer restrictions. The final choice depends on what the token represents and who is allowed to hold it, so it should be made with your legal and compliance advisers.
How much of the budget goes into compliance?
Based on my project planning, about 30-40% of the development effort goes into compliance, identity, smart contracts, and related backend logic rather than the marketplace UI. The share varies with the regulatory model and with how much third-party providers handle.
Sources
- U.S. Securities and Exchange Commission, Divisions of Corporation Finance, Investment Management, and Trading and Markets, "Statement on Tokenized Securities" (January 28, 2026). https://www.sec.gov/newsroom/speeches-statements/corp-fin-statement-tokenized-securities-012826-statement-tokenized-securities. Cited for format neutrality and onchain master securityholder files.
- U.S. Securities and Exchange Commission, Commissioner Hester M. Peirce, "Enchanting, but Not Magical: A Statement on the Tokenization of Securities" (July 9, 2025). https://www.sec.gov/newsroom/speeches-statements/peirce-statement-tokenized-securities-070925. Cited verbatim.
- Supreme Court of the United States, SEC v. W.J. Howey Co., 328 U.S. 293 (1946). https://supreme.justia.com/cases/federal/us/328/293/. Cited for the investment contract test.
- U.S. Securities and Exchange Commission, "Regulation A" (current). https://www.sec.gov/resources-small-businesses/exempt-offerings/regulation. Cited for Tier 1 and Tier 2 limits and Tier 2 requirements.
- U.S. Securities and Exchange Commission, "Regulation Crowdfunding" (current). https://www.sec.gov/resources-small-businesses/exempt-offerings/regulation-crowdfunding. Cited for the $5 million cap, intermediary requirement, and resale restriction.
- U.S. Securities and Exchange Commission, "Revisions to Rules 144 and 145: A Small Entity Compliance Guide". https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/revisions-rules-144-145. Cited for restricted securities holding periods.
- Crowell & Moring, "SEC Issues No-Action Letter Clarifying Accredited Investor Verification Under Rule 506(c)" (March 2025). https://www.crowell.com/en/insights/client-alerts/sec-issues-no-action-letter-clarifying-accredited-investor-verification-under-rule-506c. Cited for the March 12, 2025 minimum investment thresholds.
- Ethereum Improvement Proposals, "ERC-3643: T-REX, Token for Regulated EXchanges" (Final, created 2021). https://eips.ethereum.org/EIPS/eip-3643. Cited for the identity registry, compliance contract, and agent functions.
- Ethereum EIPs GitHub, "ERC 1400: Security Token Standard," issue #1411 (opened September 13, 2018). https://github.com/ethereum/EIPs/issues/1411. Cited for ERC-1400's features and status.
- Ethereum Improvement Proposals, "ERC-721: Non-Fungible Token Standard". https://eips.ethereum.org/EIPS/eip-721. Cited for the standard's design.
- Office of Foreign Assets Control, U.S. Department of the Treasury, "Sanctions Compliance Guidance for the Virtual Currency Industry" (October 2021). https://ofac.treasury.gov/media/913571/download?inline=. Cited verbatim and for geolocation and IP blocking recommendations.
- Chainalysis, "$2.2 Billion Stolen in Crypto in 2024, but Hacked Volumes Stagnate" (2024 figures). https://www.chainalysis.com/blog/crypto-hacking-stolen-funds-2025/. Cited for total stolen and the private key compromise share.
- Deloitte Center for Financial Services, "Tokenized real estate" (April 24, 2025). https://www.deloitte.com/us/en/insights/industry/financial-services/financial-services-industry-predictions/2025/tokenized-real-estate.html. Cited for the 2024 baseline, 2035 projection, growth rate, and segment breakdown.
- CoinDesk, "NFT-Linked House Sells for $650K in Propy's First US Sale" (February 11, 2022). https://www.coindesk.com/business/2022/02/11/nft-linked-house-sells-for-650k-in-propys-first-us-sale. Cited for the LLC structure, price, and property details.
Disclaimer
This article is a technical guide for founders and CTOs commissioning software, written from an engineering perspective. It isn't legal, financial, or investment advice.
How securities and real estate law treat a specific platform depends on its structure and jurisdictions, so engage securities and real estate counsel before the architecture is fixed. Descriptions here are current as of September 2026.