We read 1,476 published peptide lab reports. Among those with a readable purity figure, 99.4% passed. That is not the reassuring finding it appears to be — and an independent 2026 analysis explains exactly why.
The grey-market peptide industry learned to speak the language of laboratories.
Product pages display chromatograms. Telegram sellers post QR-coded certificates. "Third-party tested" sits beside "99%+ purity" so consistently that the two phrases now function as a single visual signal for legitimacy. And much of the paperwork is genuinely scientific: real HPLC traces, real mass-spectrometry results, real lab identifiers, real verification codes.
The mistake is assuming a scientific-looking document answers a larger question than the assay was designed to answer.
In July 2026, CBS News bought a vial advertised as retatrutide for $95 from a Brooklyn bodega — no prescription, no age check. The seller's brand offered laboratory paperwork. When CBS checked, a manager at the laboratory named on the reports said the certificates were fake, and the purported retatrutide report appeared to contain data for tirzepatide instead. What made that striking was not that forged paperwork exists. It was that the market has become sophisticated enough for paperwork to be part of the product.
So we wanted to know what the legitimate paperwork says when you stop reading one certificate at a time and read the market in aggregate.
We assembled 1,476 published analytical reports attributed to Janoshik Analytical across 223 vendors, spanning February 2020 through 6 May 2026, plus 22 undated reports. It is, as far as we know, the largest assembled set of published peptide certificates anywhere.
It is not a random sample of what is sold. It is a record of what became public, and that distinction turns out to be the most important fact about it.
Only 786 reports — 53.3% — carried a readable numeric purity result. Among those, the median was 99.7% and the mean 99.33%. Ninety-five percent of readable values were at least 97.6%. Five were below 95%; one below 90%. At a 95% threshold, 99.4% passed.
There are two easy ways to misread that number, and both are wrong. The first is to conclude the grey market has achieved pharmaceutical-like consistency. The second is to conclude the laboratory results are meaningless. Neither follows. A purity result can be accurate and useful while the public collection of those results remains heavily selected.
Because every certificate in this dataset crossed a publication barrier. Someone ordered a test, received a result, and allowed it to become visible. A failed assay that was never posted is invisible to us. A bad batch retested until a better vial passed is invisible to us. So is every batch never tested at all.
That is survivorship bias with a marketing department. The 99.4% is a measurement of publication behaviour, not of product quality — and the mechanism is simple enough to state in a sentence: a vendor can test ten batches, publish the best one, and truthfully describe themselves as third-party tested.
*Figure 1. The PeptideAtlas corpus contains 1,476 published reports; only 786 carry a readable numeric purity value.*
The second finding surprised us more than the first, and we think it matters more for buyers.
Of 1,476 reports, 690 — 46.7% — contained no readable purity figure at all.
These are not missing documents; 1,470 have a COA image attached. Many are real analytical artefacts: identity confirmations, mass-spectrometry reports without quantitation, cropped images, low-resolution scans, or reports whose visible content simply never included a numeric purity value.
A certificate can create an impression of completeness while the underlying assay is narrow. A document can prove that a molecule of the expected mass was detected without establishing how much was present, how pure it was, whether the stated fill was accurate, whether endotoxin was controlled, or whether the vial being sold today came from the same batch.
Nearly half of the published certificates in this corpus do not provide a readable quantitative purity result. They may still contain useful identity or analytical information, but they cannot support the purity claim a reader may assume the document represents. A certificate is evidence only for the attributes it actually measures and reports.
*Figure 2. Purity is one attribute. It does not establish identity, fill accuracy, microbiological quality or provenance.*
The sharpest evidence for why purity is a weak proxy for quality does not come from our dataset. It comes from an independent 2026 preprint by Christopher Mendias and Tariq Awan of the Performance Medicine Institute, working from the publicly available Finnrick Analytics dataset.
The authors screened 6,487 peptide samples across 14 compounds and roughly 200 companies, tested between December 2024 and April 2026. Their median purity was 99.8% — almost exactly the picture our collection produces.
Then they asked a broader question, and the picture changed sharply. Under a permissive composite model — measured abundance between 90% and 110% of label claim, purity of at least 98%, and correct identity — 41.6% of samples failed at least one criterion. Under a stricter model closer to manufactured-product standards, 95% to 105% of label claim and at least 99.5% purity, 71.1% failed. Identity testing found 156 reports in which the stated peptide was not present at all. TB-500 passed just 7.5% of the time.
The endotoxin subset is the part every reader should remember. Data were available for only 243 samples — under 4% of the set, which is itself a finding about what this market bothers to measure — and 15% had measurable endotoxin. Purity did not predict endotoxin burden. The correlation was effectively zero: R² below 0.01.
That is the cleanest available statement of the problem. Chromatographic purity and overall product quality are not the same statistic, and one cannot be used to infer the other.
Two disciplines apply here and we hold to both. This is a preprint that had not completed peer review when we published, so its percentages should not be treated as settled epidemiology. And it is a separate dataset with different sampling, scope and criteria from ours — it is not a validation study of the PeptideAtlas corpus and must not be merged with it. What it provides is an independent analytical lesson that our own data cannot supply from the inside.
That distinction stopped being theoretical in spring 2026.
Community investigators reported that three independently submitted vials from a JEEP orange-cap T30 batch returned endotoxin estimates of roughly 1,350, 1,360 and a confirmed 2,306 endotoxin units per vial. The vials came from different donors in different countries. Buyers reported rashes and elevated heart rate.
For context, the commonly used USP bacterial-endotoxin limit for many parenteral drugs is expressed as 5 EU per kilogram of body weight per dose — about 350 EU for a 70kg patient. The reported vial values were several times that dose benchmark. This is community testing, not a regulator finding, and the comparison does not by itself establish how much endotoxin any individual user received in a single administration.
This is community evidence rather than a regulator finding, and it should be described that way. It also does not establish where contamination entered — endotoxin can be introduced through raw materials, water, equipment, handling, or fill-and-finish, and the vendor attributed the problem to raw-material procurement.
What it shows is simpler: a passing mass-and-purity result cannot rule out a class of failure the assay never tested for. Whatever a batch's purity result, that assay cannot answer the endotoxin question unless endotoxin was separately measured.
Endotoxin testing is available as a separate assay; it is not implied by a standard mass-and-purity result. If a certificate does not report endotoxin, that certificate provides no evidence that endotoxin was measured. There is no defensible way to infer microbiological quality from a purity number, and the Mendias–Awan result — essentially no correlation between purity and endotoxin in the tested subset — shows why.
The supply-chain context — why production provenance can disappear between synthesis, filling and retail — is the subject of our companion investigation, The Phantom Factories.
The market's language erases time. "Third-party tested" sounds like a standing property of a company, the way "licensed" or "accredited" might. Testing is nothing like that. It is an event: one sample, from one batch, at one moment, under one method.
Our dataset makes the gap visible. Seventy-five of 223 vendors — about a third — had exactly one published report. Only 117 had three or more; 45 had ten or more. The ten most heavily represented vendors accounted for 27.8% of all reports.
A vendor with one certificate from 2024 and a vendor with dozens of recent, product-specific certificates place the same badge on the same part of the homepage, in the same font.
The five results below 95% are instructive for a different reason. Four were human growth hormone — a recombinant 191-amino-acid protein rather than a short synthetic peptide, harder to manufacture, harder to stabilise and harder to assay. The fifth was an AOD-9604 result at 39.0%, the only catastrophic value in the entire collection, and one the vendor published itself.
Five results cannot establish a failure rate for either product class. But the pattern is a reminder that different molecules and production methods carry very different analytical challenges, and that a single market-wide purity badge flattens all of them.
*Figure 3. Published testing expanded rapidly from 2020 through May 2026.*
There is real progress in this dataset. Published reports rose from 4 in 2020 to 104 in 2023, 363 in 2024 and 660 in 2025, with 287 in the first five months of 2026 — roughly sixfold growth in three years. Buyers demanded evidence and vendors produced dramatically more of it. That norm is better than a market where nobody tests anything.
But the testing culture is splitting in two. Chainalysis reported in June 2026 that estimated independent testing spend per peptide buyer had fallen about 88%, to roughly $8, even as the market expanded — while crypto flows it attributed to laboratory testing rose sharply. That describes a market where vendors and wholesalers order more tests at scale while new retail buyers do less verification of their own.
The result is a peculiar trust architecture. Consumers see more laboratory evidence than ever, and more of it arrives through the party selling the product.
If certificates are this market's evidence, sample provenance is their hidden variable.
Janoshik is the market's de facto reference point for a practical reason: genuine reports carry a task number and key that can be checked against a public verification portal. That makes a verifiable report materially stronger than a screenshot. But the laboratory can only characterize the sample it receives. If a vendor chooses the vial, the test answers a question about that submitted vial — not a random unit purchased later from retail stock.
Finnrick uses a different model and now labels sample provenance explicitly. Its published records can include Public submissions, Vendor submissions made through its paid Launch program, and samples Finnrick purchased itself, including through mystery shopping. That distinction is useful because those categories answer different questions. A mystery-shopped unit provides stronger evidence about ordinary retail stock than a vendor-selected sample; a vendor submission can still provide useful batch data, but its provenance should remain visible rather than disappearing into a single vendor grade.
This is also why "independent testing" is not a binary property. Independence can refer to who owns the laboratory, who paid for the assay, who selected the vial, who knew the sample identity, and whether failures remain public. A strong evidence system makes those details inspectable.
FDA scientists made a related point in materials prepared for the July 2026 Pharmacy Compounding Advisory Committee meeting: the certificates they reviewed lacked information about individual impurities, aggregation, microbial bioburden and/or bacterial endotoxin. That is the regulatory version of the same lesson. A COA can be genuine and still be incomplete for the question a reader wants answered.
The strongest model is therefore not one laboratory or one badge. It is repeatable testing with disclosed sample provenance, batch linkage, multiple relevant assays, and a publication system that preserves failures as well as successes.
The most serious failure is not a low purity number. It is evidence detached from the product entirely.
The Brooklyn case is one version: a brand displaying reports that the named laboratory said were fake. A federal prosecution is another. In July 2026 the Department of Justice said the operators of Paradigm Peptides had represented products as safe, pure, tested, US-manufactured and FDA-approved when none of it was true; that material was imported from countries including China and India and not quality-tested before sale; and that products marketed as SARMs contained undisclosed testosterone. The owner was sentenced to 70 months in prison with a $5 million forfeiture. Among the conduct in the case: he forged laboratory certificates.
Certificate fraud in this market is not a forum rumour. It is prosecuted federal conduct with a prison term attached, handed down last month.
Which is why the verification portal matters more than the certificate. A genuine report resolves against the laboratory's public database using its task number. A JPEG resolves against nothing. That is the difference between evidence and graphic design — and it is a check many buyers may never run.
The lesson from 1,476 reports is not ignore COAs. It is to stop asking them to do work they cannot do.
A report worth relying on is independently verifiable through the issuing laboratory. It names the compound and the specific attributes measured. It is tied to a batch or lot. Its sample provenance is clear. It is recent, and repeated over time rather than standing alone. Failures are preserved rather than silently disappearing. And purity is evaluated alongside identity, measured amount and — where the product is injected — microbiological quality.
Translated into questions a reporter or a buyer can actually ask: Does the task number resolve? How many reports, over how long? Is there a readable purity figure? Does it report endotoxin, or does the certificate simply provide no evidence on that question? Does it cover this product, in this batch? Is it HGH, which is a different molecule with different manufacturing problems? And who is rating this vendor, and who pays the rater?
None of those elements turns an unapproved injectable into an approved medicine. They make the evidence legible. That distinction matters because this market's most successful rhetorical move has been converting a laboratory tested one thing about one vial into this brand is tested.
The 99.4% pass rate is a real result. It tells us that when vendors publish a readable purity number, they overwhelmingly publish a high one. That is useful information about the market's evidence ecosystem. It is not proof that 99.4% of grey-market vials are pure, much less safe.
If anything, the near-perfect number is what makes the dataset interesting. It shows how a market operating without conventional regulatory trust has built an elaborate substitute: certificates, QR codes, community testing, screenshots, reputation systems. Some of that infrastructure is valuable. Some of it is selective. Some of it can be forged. And almost all of it is narrower than the word quality.
PeptideAtlas collected 1,476 publicly accessible reports attributed to Janoshik Analytical from vendor websites and Janoshik's public verification system, then normalised vendor, substance, date and reported purity into a common schema. Purity is taken as reported; we re-ran no analyses. Vendor naming is imperfect because some reports identify a manufacturer, reseller or customer rather than the retail brand. Substance labels are the vendors' own — 1,476 reports carry 939 distinct substance strings, since "Tirzepatide," "Tirzepatide 30mg" and "Tirz 60mg" are three labels for one compound.
The dominant limitation is selection bias. This is a dataset of published reports. It cannot measure tests that were never published or products that were never tested, and it does not establish that any report corresponds to the vial a consumer received. For the pass rate, that is not a caveat on the finding — it is the finding.
Single laboratory: Janoshik's dominance makes the set internally coherent, which is what permits comparison across vendors, but it is one laboratory's methods, analytical uncertainties and reporting conventions.
The Mendias–Awan comparison comes from a separate dataset and a preprint that had not completed peer review when this report was prepared. The JEEP episode is attributed community evidence, included as an illustrative case and not a population estimate.
We are currently running an analysis to test whether shared task numbers, identical purity values at full precision, and duplicate certificate images can fingerprint common supply chains across nominally competing brands. We will publish the result, including a null result if that is what the data shows.
The full corpus, the codebook and the analysis script that generates every figure above are published on the dataset page. Anyone can re-run it.
Tier 1 — primary records
Tier 2 — published journalism and named research
Tier 3 — community evidence, attributed as such
PeptideAtlas is not affiliated with Janoshik Analytical, Finnrick Analytics, JEEP or any vendor named in this report. We do not sell peptides, testing, referrals or vendor placements, and we accept no vendor sponsorship. This is an investigation of public market evidence and is not medical, legal or purchasing advice. Peptides sold for research use are not approved for human use.
Related: The Phantom Factories, Grey-Market Peptide COA Corpus.