How Counterfeiters Beat Tamper-Evident Labels (And What Actually Stops Them)
Tamper-evident labels are the standard. Almost every packaged product has one — a VOID seal, a heat-shrink band, a holographic sticker. And yet, the OECD estimates that counterfeit and pirated goods account for 2.5% of world trade, representing hundreds of billions of dollars annually. Much of it moves in packaging that looks completely legitimate.
The question worth asking: if tamper labels are everywhere, why is counterfeiting still at this scale?
The answer is that tamper labels were designed to stop a specific threat — retail-level tampering by an individual. Organised counterfeiting is a different problem. And organised counterfeiters have known how to work around tamper labels for years.
This piece covers exactly how they do it — and what technology actually stops them.
For a full breakdown of the technology, see our complete guide to tamper proof stickers.
Method 1: Copy the Label
The simplest bypass is reproduction. A tamper-evident label is a printed object. It has a visible design — a pattern, a colour, often a holographic effect or a VOID background. With access to the genuine label and commercial printing equipment, that design can be reproduced.
How reproduction works
Modern digital printing has made short-run security label reproduction significantly more accessible. The key elements counterfeiters reproduce:
VOID patterns: The VOID message is typically a printed or metalised layer. Screen printing can reproduce the visual. The label won't have the same adhesive interlayer mechanics — it may not VOID cleanly on removal — but if it's never removed, that doesn't matter.
Holographic effects: True optical variable devices (OVDs) require specialist embossing equipment that remains relatively difficult to access. Convincing-looking holographic approximations using standard rainbow foil or digital printing with gloss effects are more accessible. They don't shift colour in the same way under direct light, but in a retail environment with indirect lighting and a consumer who doesn't know what to look for, they can pass.
Colour, finish, size, and placement: These are the first things a consumer checks. If the reproduction matches on these, most consumers stop there.
What reproduction can't replicate
Precise adhesive interlayer mechanics are hard to reproduce exactly. A professionally made destructible (eggshell) label with precise interlayer bonding is genuinely difficult to fake because the material failure mode is engineered at a substrate level, not printed. This is why destructible labels remain more resistant than VOID labels against reproduction.
Method 2: The Refill Attack — When the Label Was Never a Problem
Reproduction involves creating a fake label. The refill attack is more elegant: it doesn't involve a fake label at all.
How the refill attack works
Genuine containers — premium bottles, jars, tubes — are collected after their original contents are consumed. Collection networks exist in markets across South and Southeast Asia, West Africa, and Latin America as organised operations. Containers are cleaned, inspected, and refilled with diluted, substituted, or counterfeit product.
A new tamper seal is then applied — either genuine label stock sourced through supply chain leakage (print vendor overruns, warehouse theft, distributor-level corruption), or a reproduced version.
The finished product enters trade. The container is 100% genuine. The weight, the smell, the initial product quality signal (before use) may be convincing. The tamper seal is intact.
Why this defeats tamper evidence entirely
The tamper seal was designed to detect interference with a sealed pack. The refill attacker is doing the sealing. There was never a seal to break. The mechanism that tamper labels rely on — irreversible evidence of opening — simply doesn't apply to an attack where the attacker is the one closing the pack.
Who this affects
The refill attack is most prevalent in high-value categories where the container is itself premium — luxury beauty and personal care (serums, creams, perfumes), spirits, specialty foods, motor oils and lubricants, agrochemicals. The higher the product value relative to the container cost, the better the economics of the refill operation.
Method 3: Source Genuine Label Stock from the Supply Chain
A reproduction that isn't quite right can fail under close inspection. Genuine label stock never fails that inspection — because it is genuine.
The supply chain leak
Security label stock travels a significant journey before reaching the finished pack. It is printed by a label converter, warehoused, transported to the packaging site, stored, and applied. Every point in that chain is a potential leak.
The most common sources: print vendor overruns (labels printed in excess of the confirmed order, either by design or error), warehouse theft at the converter or the brand's own facility, corrupt distributor or logistics partner, and excess label inventory from discontinued SKUs or pack redesigns that isn't securely destroyed.
Genuine label stock on a fake product is undetectable by visual inspection — because there is nothing wrong with the label. It is exactly what it should be.
What this means for brand protection
It means a brand's tamper label supply chain is itself a security perimeter. Brands that have not audited their label stock — production volumes, destruction records, waste reconciliation — may be unknowingly supplying their own counterfeiters.
Method 4: Exploit the Consumer Behaviour Gap
Even when a tamper label does show evidence of interference, it is only useful if the person holding the product notices and acts on it.
What the evidence says about consumer behaviour
Consumer tamper-evidence interaction research consistently shows that the majority of consumers do not actively inspect tamper seals before purchase or use. The seal registers as a trust signal on a subconscious level — "the seal is there, so the product is fine" — rather than triggering a deliberate check. A missing or clearly broken seal would likely be noticed. A subtly damaged or poorly reproduced seal often isn't.
The enforcement version of the same problem
Field enforcement teams face the same issue at scale. Without a positive verification mechanism — something that says "this pack is genuine" rather than "this seal appears intact" — enforcement relies on visual inspection and laboratory confirmation. Lab confirmation takes days to weeks. Product stays on shelf. The enforcement action is delayed.
What These Four Methods Have in Common
Every bypass method exploits the same fundamental characteristic of tamper-evident labels: they are reactive and visible.
Reactive, because they only provide information after something has happened — the label was removed, the seal was broken. They carry no positive confirmation of genuineness.
Visible, because any feature you can see, a counterfeiter can study, reproduce, or work around. The security value of a visible feature is directly proportional to how difficult it is to replicate — and that difficulty erodes over time as reproduction technology advances.
What Actually Stops Organised Counterfeiting
The methods that defeat tamper-label bypass share two characteristics: they are invisible and they provide positive verification rather than just evidence of interference.
Invisible cryptographic authentication
A cryptographic signature embedded in the pack artwork — not as a visible label, not as a separate component, but as part of the printed image itself — is invisible to the eye and therefore invisible to counterfeiters. There is nothing to photograph, study, or reproduce. The signature cannot be transferred from a genuine pack to a fake because it does not exist on a separable component.
Verification is done by smartphone camera. The camera reads the embedded signature and returns a result: genuine or not genuine. The result is based on a cryptographic verification process, not a visual comparison.
What this means for each bypass method:
Copy the label: There is nothing visible to copy.
Refill attack: A refilled genuine container still carries the original signature. But the brand's scan data shows whether the scan is consistent with the expected profile for that production batch and region — anomalies are flagged.
Genuine label stock sourced from the supply chain: An authentication signature is not part of the label stock. It is part of the artwork — generated per print run with a private key. Sourcing label stock grants no access to the signature.
Consumer behaviour gap: Verification is consumer-initiated through a scan, not dependent on visual inspection. The result is definitive, not a judgment call.
Serialisation: closing the provenance gap
Serialisation assigns a unique identifier to each unit at production. It tracks where that unit was made, when, for which market, and through which distribution route. A serial number that appears in an unexpected market, or that has been scanned an impossible number of times, generates an alert.
Serialisation does not by itself prevent a counterfeiter from copying a serial number onto a fake. But combined with invisible authentication — which verifies the physical pack, not just the credential — serialisation closes the remaining gap. The authentication verifies the pack is genuine; the serialisation verifies it is where it is supposed to be.
The Practical Decision
For brands facing retail-level interference or logistics tampering, tamper-evident labels remain appropriate. They are cost-effective, widely understood, and compliant with regulatory requirements in most categories.
For brands facing organised counterfeiting operations — manufactured fakes, refill attack, supply chain diversion — tamper labels are a necessary first layer and an insufficient one. The threat is operating at a level tamper evidence was never designed to address.
The gap is real, measurable, and solvable. The technology that closes it is already deployed at commercial scale.
FAQs
Can a product have both tamper evidence and authentication?
Yes, and for brands facing multiple threat types, both are appropriate. Tamper evidence addresses retail interference and regulatory compliance; authentication addresses manufactured counterfeiting and diversion. They solve different problems and coexist on the same pack without interference.
Is a QR code product authentication?
A standard QR code is not authentication — it is a link to a URL. Anyone can generate a QR code linking to any page, including a fake verification page. A serialised QR code with a unique code per pack gets closer, but serial numbers can be copied from genuine packs onto fakes. Cryptographic authentication embedded in the pack — not printed on its surface as a scannable code — is what makes verification forgery-proof.
Does pharmaceutical serialisation provide product authentication?
Serialisation under FMD and DSCSA verifies the serial number is valid and was assigned to a product of that type. It does not verify the physical pack is genuine — only that the credential on it is legitimate. A valid serial number can be copied onto a falsified pack. Physical authentication is a separate layer that addresses this gap.
How does invisible authentication work?
A cryptographic signature is generated using a private key and embedded in the pack artwork during the print process — not as a separate component but as part of the image. A smartphone camera reads the embedded signature and a server verifies it against the expected value generated by the corresponding public key. If the signature is valid, the pack is genuine. If not — because the pack is a fake without access to the private key — the verification fails. There is nothing on the surface to copy because the signature is not visible.
What is the cost difference between tamper evidence and authentication?
Tamper evidence costs per unit — label material, adhesive, application. At high volumes, standard VOID labels are very cost-effective. Authentication using embedded invisible signatures costs at the artwork level — it is an artwork change that applies to an entire print run, not a per-unit addition. At FMCG scale, this makes cryptographic authentication cost-competitive with physical label additions while providing significantly greater security.


