HomeGuides › COA Reuse and Theft, Explained (2026)
By TorontoHealth Editorial · Updated June 17, 2026

COA Reuse and Theft, Explained

The core idea: a Certificate of Analysis proves a test happened on some sample — not that it came from your vial, nor that the vendor showing it is the one who ordered it. That gap is exploited two ways: reuse and theft. A "real" PDF defeats neither.

Reuse

A supplier tests one good batch and gets a genuine COA. Then thousands of vials — many never tested — are sold against that single report. Every reseller buying from that supplier can show the same document, even though your specific vial was never analyzed. One test, an ocean of untested product riding on it.

Theft

A vendor downloads someone else's genuine COA — a competitor's, or their supplier's — and presents it as proof of their product. The document is authentic; it's just not theirs. Posting a real PDF only defeats forgery. It does nothing against a stolen-but-real report.

Why "the PDF is real" isn't enough

People check whether a COA looks legitimate and stop there. But authenticity is the floor, not the ceiling. The real questions are: whose sample was tested, and does the result tie to this vendor and this batch?

How to defeat both

Related: why two vendors share a COA · how to read a COA.

🧪 Run the free vendor check →
Related guides
How to read a peptide COA · How to spot a fake testing lab · Buying peptides in Canada · The Growth Guys discount code