There isn't any cryptographic basis to human retinas, though, to prove a scam is "real"; so, at the end of the day, this is just a centralized actor in the form of a hardware manufacturer that can forge as many retina scans as they want, with the only limit preventing any of us from doing the same being whatever DRM they can try to pile on their device.
On that note, is there anything we could use as a cryptographic basis? I'm guessing DNA would qualify. We could make everyone's addresses be derived from a content-address of our DNA.