The least glamorous blocker for tokenised securities is not privacy or settlement. It is custody, and on a shielded chain it looks nothing like custody anywhere else.

Start with the constraint everyone skips. A regulated fund usually cannot simply hold its own keys. Client assets have to sit under safekeeping arrangements, segregated, with someone accountable if they vanish. That obligation exists regardless of what the asset is issued on. No custody answer, no institutional allocation, no matter how elegant the chain.

On a transparent chain this is solved and boring. A custodian holds the keys, and anyone auditing can simply read the ledger to confirm the position exists. Verification is a lookup.

Dusk removes the lookup. Holdings are shielded, so an auditor staring at the chain sees commitments, not balances. The position is provably there and completely unreadable. Which means custody stops being about storing a key and becomes about controlling two separate powers that used to travel together.

The power to move an asset, and the power to see it.

Those split apart under shielded state. A custodian might hold spending authority while an auditor holds viewing rights for a defined scope and period. A regulator might get a third view that neither of them controls. Custody turns into permission engineering rather than key storage.

That is also a new failure mode. On a transparent chain, losing the ability to see your position is impossible. Here it is a real scenario, and it is not the same event as losing the funds.

Dusk partnering with Cordial Systems reads to me as an attempt at exactly this layer rather than a generic wallet integration.

@Dusk_Foundation is the viewing and disclosure model defined at protocol level, or is each custodian free to implement its own? Those give very different assurances to an auditor.

Curious what people here think proof of custody should look like when the ledger cannot be read.

@Dusk_Foundation $DUSK #dusk #RWA