21shares listed two new exchange-traded products on Euronext Amsterdam and Euronext Paris on 22 September 2026. One of them, ticker ZCASH, ISIN CH1608218801, is the first European ETP on Zcash. It charges a 2.5% annual management fee, and it is physically backed, which is the industry’s way of saying that somebody is genuinely holding the coins rather than selling you a synthetic return that tracks them. It follows Grayscale’s US spot Zcash ETF, ZCSH, on NYSE Arca. ZEC is trading around $1,526 and is up roughly 1,100% this year, so the demand is real and the product is a sensible response to it.
Jasmin Muelhaupt, Director of Financial Product Development at 21shares, described the asset as “combining Bitcoin’s capped supply with optional privacy and future-proof cryptography”. That is a fair description of Zcash. It is also, read slowly, the whole problem with putting Zcash inside a physically backed wrapper, and as far as I can find, not one piece of coverage asked the obvious follow-up.
TL;DR
- 21shares listed the first European Zcash ETP (ticker ZCASH) on Euronext Amsterdam and Paris on 22 September 2026, physically backed, 2.5% annual fee, following Grayscale’s US ZCSH.
- Zcash holdings can sit in transparent addresses, which anyone can count, or shielded addresses, which nobody outside can count. The press release says only that the assets are “held safely by established third-party custodians” and does not say which, or how the holdings are verified.
- There is no third option. Either the fund holds the asset in the mode that defeats the point of owning it, or the backing is unverifiable by the public for the life of the product.
- Zcash viewing keys do let a custodian show an auditor. That is disclosure to a nominated party, not proof to the market. For this asset, attestation is not a shortcut, it is the ceiling.
- Privacy is compatible with proving a computation and fatal to proving a holding. That is why a VRF proof survives shielding and a proof of reserves does not, and it is the difference between what Satoshie claims and what a custodian claims.
Physically backed by what, exactly, and where
Zcash gives a holder two places to keep coins. Transparent addresses behave like Bitcoin: balances and flows are public, and anybody with a block explorer can count them without asking permission. Shielded addresses do the thing Zcash was built to do, which is to hold value in a way that a third party cannot observe. The chain records that shielded value exists in aggregate. It does not record who has how much of it.
The 21shares announcement says the underlying cryptoassets are “held safely by established third-party custodians”. It does not name a custodian, and it says nothing about how the holdings are verified. For almost any other asset on almost any other ETP, that sentence is unremarkable boilerplate and I would not spend a paragraph on it. Custody arrangements live in the base prospectus, the administrator reconciles, the auditor signs, and in the background anyone sufficiently motivated can usually watch a wallet and check the number themselves. That last part is not a formal control. It is just the ambient fact that on a public chain, a large pile is countable.
For Zcash, that ambient fact is not a fact. It is a setting. And somebody chose it.
Follow both branches, because this is the part nobody wrote down.
If the ZEC backing this product sits in transparent addresses, then the holdings are countable, the product behaves like every other physically backed crypto ETP, and the largest pool of European Zcash is parked in permanent public view with a published size, a published ticker and a published creation and redemption process wrapped around it. The fund would be holding the asset in precisely the mode that makes the asset pointless, and advertising the address is not a neutral act when the asset’s entire user base selected it for the opposite property.
If the ZEC sits shielded, then the product is doing the honest thing by the asset, and the backing becomes something no investor, journalist, competitor or regulator can independently count at any point in the life of the product. Not because anybody is hiding anything. Because the cryptography is working as designed.
There is no third branch. The dial has two ends and the fund is somewhere on it. That position is a real decision with real consequences in both directions, it was taken by somebody at a custodian on a Tuesday, and it did not appear in the announcement, the coverage or the commentary.
Privacy and proof of holding are the same dial
This is the structural point, and it generalises well past one ETP.
An exchange-traded product’s core promise is that the thing is there. A privacy asset’s core promise is that nobody can tell what is where. These are not two properties that happen to be in tension. They are the same property measured from opposite sides. Every unit of confidentiality you add subtracts exactly one unit of external countability, because external countability is what confidentiality is defined as the absence of.
So “optional privacy” is precisely right, and the question it raises is optional for whom. On Zcash the option belongs to whoever controls the address. Inside an ETP, that is the custodian. You bought the exposure. Somebody else got the option, and they get to exercise it every day you hold the product, and you will not be told which way they exercised it.
That is a different complaint from the one this blog made about Robinhood’s AMC token, where the tokenholder got price exposure and the reserve kept the vote. This is not a right the holder lost. It is a capability the public lost, and it did not transfer to anybody. It was extinguished.
A viewing key is a disclosure, not a proof
The obvious rebuttal is that Zcash already solved this, and the rebuttal is half right, which is the most dangerous kind.
Zcash supports full viewing keys. A custodian can generate one for each shielded address and hand it to an auditor, who can then verify the balances and review the history without ever gaining spend authority. This is a genuinely good piece of cryptographic engineering and it is exactly how a regulated custodian should handle a shielded position. Anybody arguing that a Zcash ETP is unauditable is wrong.
But look at what that mechanism actually produces. A viewing key proves the balance to whoever holds the key. Everyone else receives a statement from a firm saying that another firm checked. That is an attestation, and an attestation is a relationship: it has a scope, a date, an engagement letter, a client who pays and a party who can decline to renew. It is not nothing. It is not a proof either.
This blog has made the attestation argument before, about Circle’s charter and Tether’s attestation, and the conclusion then was that an attestation is a choice and an issuer could always have done better. Here that conclusion does not hold, and the difference is worth naming. With a transparent asset, attestation is a shortcut that a lazy or secretive issuer takes instead of publishing something checkable. With a shielded asset, attestation is the ceiling. There is no better artefact available at any budget, to any auditor, with any amount of good faith, because the chain was deliberately built not to emit one. Selective disclosure to a nominated party is the maximum the design permits, and “we nominated a good auditor” is a governance claim, not a cryptographic one.
On-chain did not help here. It caused it.
I want to be honest about which side of this argument the technology landed on, because the lazy version of this post would blame a custodian or a regulator.
Nobody made this problem. It was not introduced by a bank, a wrapper, a broker or a European listing venue. The unverifiability of the backing is a property of the chain itself, engineered on purpose, at considerable cost, by people who were right to build it. Zcash is one of the few genuinely important pieces of cryptography this industry has produced, and financial privacy is a legitimate thing for an adult to want.
Which means “on-chain” was never a synonym for “checkable”, and this is the cleanest counterexample anybody has shipped. The asset is on-chain, permissionless, open source, capped and auditable in the formal sense. And the single question an ETP investor actually cares about, is the backing there, is the one question the chain is engineered to refuse to answer to a stranger.
A proof is not a balance
So why does any of this concern a gaming platform.
Because it separates two claims that crypto habitually welds together, and the seam is where almost every fairness argument in this industry quietly fails.
A balance claim is a statement about a pile: the coins exist, they are ours, they are enough. Verifying it requires observing the pile. Privacy destroys it. Confidentiality and proof of holding cannot coexist, and no amount of engineering changes that, because they are contradictory statements about the same fact.
A proof claim is a statement about a computation: this output was produced by this procedure from this input. Verifying it requires checking an equation, not inspecting anybody’s assets. A Chainlink VRF proof verifies against a public key and a request seed. It reveals nothing about who holds what, and it does not become weaker if every participant is anonymous. A stranger in 2030 can check it without the cooperation of the platform, the custodian, an auditor or the player.
Privacy is fatal to the first class of claim and completely indifferent to the second. That is the distinction, and once you have it, a lot of crypto marketing sorts itself. “Your funds are safe in segregated cold wallets” is a balance claim wearing a technical jacket, and it is exactly as strong as “held safely by established third-party custodians”, which is to say it depends entirely on who is saying it. “This draw resolved from a verified random word at this block” is a proof claim, and it depends on nobody.
What Satoshie actually claims, narrowly
The stake is escrowed on entry. The VRF coordinator is named in deployed code you can read before you commit anything. The coordinator verifies the randomness proof on-chain before the callback is permitted to run. The winner is computed inside that callback from the published formula, and the payout happens in the same transaction. Ticket counts are readable contract state, so your odds are arithmetic over a public number before you enter rather than a figure we print about ourselves afterwards.
Note what is absent from that list. There is no platform balance to attest to, because there is no credit relationship. You do not deposit with us and hold a number in our database. You take a position in a contract and the contract settles it. We are not asking you to believe a statement about a pile, which is convenient for us, because a statement about a pile is the thing that cannot be proved to a stranger and the thing that has ended most of the platforms this blog has written obituaries for.
Three honest limits
First, we are arguing from the easy side and we should say so. Satoshie is fully public on Base. Every entry, every draw and every payout is readable by anyone, which is the only reason our claims are checkable, and it is a real cost that we have written about before: public play feeds address clustering, screening vendors and, at the extreme, coercion. Zcash holders pay for a property we do not offer. We did not solve the trade-off in this post. We took the branch where it never arises.
Second, a VRF proof settles randomness and nothing else. It says nothing about our solvency, our runway or our prize funding, and where a prize is denominated in a stablecoin it inherits the issuer’s liability and the issuer’s reserves in full, which is the same off-chain claims problem one storey up. Our narrow guarantee is narrow on purpose and it does not expand because we wrote a confident blog post.
Third, this criticism reaches us too. The moment a player’s money sits anywhere other than in the contract, whether that is our front end, an exchange they cash out to or a custodian holding anything on their behalf, they are in exactly the position of a ZCASH holder: trusting a statement about a pile made by someone with an incentive. Our front end is an ordinary web application and it remains the least trustworthy thing we ship.
Three questions worth asking anyone
Is the claim I am being asked to accept a claim about a computation or a claim about a pile. If it is about a pile, who can count it, and do I need their permission. And if the honest answer is that a nominated third party counted it on a date and issued a letter, is that what I thought I was buying.
The ETP is a reasonable product and 21shares built it properly. The finding is not that anyone did anything wrong. The finding is that European investors can now buy, on a regulated venue, a physically backed product whose backing is the first in mainstream crypto that cannot be shown to them by anybody, ever, by design, and the launch materials did not mention it because nobody thought to ask.
A window you cannot see through is still a window. It is just not doing the one job you bought it for.
📷 Photo by Daniel McCullough on Unsplash


