Imagine you're a museum curator worried about art theft. You could bolt paintings to the wall — or you could lace the canvas with an invisible UV-reactive dye that transfers to anything the painting touches: the thief's gloves, their bag, the walls of whatever basement they stash it in. MARCO does exactly this for protein generative models. It injects a structural watermark into the 3D conformations a model produces, and that watermark bleeds into any downstream model trained on those outputs. The committed claim: MARCO is the first radioactive watermarking framework purpose-built for protein generative models (PGMs). "Radioactive" means the watermark is not just present in the original model's outputs — it automatically transfers to pirate models trained on watermarked data. This is a dual-use defense: intellectual property protection against model extraction AND forensic traceability for biosecurity. No prior watermarking scheme targeted the specific geometry of protein structures. Architecturally, MARCO sits in the diffusion-model family. It attaches an auxiliary encoder-decoder to the reverse denoising process of a diffusion-based PGM. The original model's parameters stay frozen — the watermark is embedded iteratively during inference, not baked into model weights. This is a deliberate design choice: it means MARCO can be bolted onto existing PGMs without retraining them, trading some elegance for broad compatibility. The loss functions are protein-specific, targeting Cα-atom pairwise distances and backbone torsion angles (ψ, φ), which are the structural signatures biophysicists actually care about. An adversarial training loop with stochastic attack simulations hardens the watermark against removal attempts. On the ladder, this paper occupies genuinely new territory rather than competing against a named prior SOTA. Digital watermarking for images and text is mature, but protein structure watermarking had no established baseline. The authors claim superior fidelity and robustness, but the comparison is necessarily against adapted general-purpose watermarking methods rather than a direct PGM watermarking competitor. The absence of a named prior-art baseline is both the paper's strength (first mover) and its weakness (no strong adversary to validate against). Integrity is mixed. The validation is self-contained: the authors generate watermarked protein conformations, train pirate models on them, and check whether the watermark transfers. This is simulation-on-simulation — the paper is grading its own homework. Robustness is tested against stochastic attacks the authors designed, not against a red team or independent adversary. No pre-registration, no external benchmark suite for protein watermarking (because none exists yet). The biophysical fidelity metrics (Cα distances, torsion angles) are well-chosen but self-reported. The milestone question is where dual-use framing meets reality. For IP protection, the next number is adversarial robustness against real-world model extraction pipelines — not simulated attacks but actual distillation and fine-tuning pipelines used by model thieves. For biosecurity, the harder milestone is whether watermark traceability survives when a sophisticated actor deliberately tries to strip it before synthesizing a hazardous protein. The gap between "survives stochastic simulated attacks" and "survives a motivated nation-state adversary" is enormous and unquantified. The obvious experiment not run: adversarial removal by someone who knows exactly how MARCO works (white-box attack). The paper tests robustness against stochastic attacks, but a motivated attacker with knowledge of the encoder-decoder architecture and loss functions could mount targeted removal. The honest read: this is partly a compute/scope issue (red-teaming is expensive and open-ended) and partly a strategic omission — demonstrating vulnerability to white-box attacks in the introductory paper would undermine the narrative. Expect this in follow-up work, likely framed as "enhanced robustness."