Module D — The Honest Comparison

Question: On the criteria financial institutions actually use to select infrastructure, how does Ethereum compare to its realistic alternatives, and in which specific cases is Ethereum the wrong choice?

Full report — copy for an LLM

The 30-second answer

On the criteria that decide regulated-settlement procurement, Ethereum wins decisively on uptime, counterparty reachability, and India-available talent, and loses or ties on the ones that matter most for bank settlement: confidentiality, cost predictability, permissioning granularity, and legally recognised finality. The production record settles the public-versus-permissioned debate without argument: funds and stablecoins chose public Ethereum; every bank-run core-settlement venue with real volume chose a permissioned ledger, and said so, citing privacy. But the choice is three-way rather than two-way: multi-party securities and repo settlement went to Canton, while single-operator cash rails went to permissioned EVM chains, Kinexys included, and the middle option is usually left out of this debate. For India, Ethereum is the wrong answer wherever confidentiality of positions, a named legal settlement operator, or containment inside the RBI/SEBI perimeter is required, which describes nearly every domestic core-settlement use case. It is the right answer for cross-border reach, public-liquidity access and fund distribution, which sit today in GIFT City rather than the domestic perimeter.

The 5-minute summary

Where Ethereum genuinely wins. It has run since 2015 with no chain halt, against a competitor (Solana) that had eleven-plus outages through early 2024, a real and checkable advantage, and the reason liveness appears on institutional shortlists. It has the largest single pool of tokenised real-world assets by value, so it offers the most counterparty reachability. And India has abundant EVM/Solidity talent. These are real, and they are also not the criteria that decide most settlement procurements.

Where Ethereum loses, stated first and plainly. Confidentiality is the decisive loss. On Ethereum and its layer-2s, institutional tokenised assets settle on fully public ledgers: BlackRock's BUIDL holder list and every transfer are visible on a block explorer, and whitelisting controls who can transact, not what is visible. This is why Goldman, DTCC and HSBC built on the permissioned Canton Network instead, and said so on the record. JPMorgan is the instructive exception: it also rejected public Ethereum, but built Kinexys on a permissioned Ethereum-lineage chain rather than Canton, because a single-bank deposit rail has no cross-counterparty confidentiality problem to solve, since its clients are not each other's counterparties. It has since announced, but not yet shipped, JPM Coin natively on Canton. It is also why the highest-volume tokenised-settlement system in the world (Broadridge's repo platform, trillions per month) is permissioned, not public. Cost is low on average but volatile, and volatility is what a treasurer prices, not the average. Legal finality attaches to a named operator, which a leaderless public chain does not have.

The consortium graveyard cuts against the permissioned camp too, so do not overclaim in either direction. The failed projects (TradeLens, we.trade, Marco Polo, Contour, the Australian exchange rebuild) were overwhelmingly permissioned DLT that failed on governance and network effect, not public-chain projects. So "permissioned is obviously safer" is not supported by the failure record. Permissioned ledgers are not technically fragile; they are governance-fragile. The survivors had either a neutral foundation or a single credible operator, the lesson India's IBDIC consortium most needs.

Layer-2s reframe cost, not confidentiality. L2s cut fees by ninety percent or more, addressing Ethereum's weakest cost criterion, but they inherit the base layer's public transparency, and the privacy-focused L2s reached regulated production during 2026 only at the fund layer: tokenised money-market funds from Aberdeen, BlackRock, Fidelity International and State Street went live with a privacy wrapper on the TEE-based Silent Data L2 through the FCA-regulated Archax in February 2026, and no bank-run core-settlement venue has moved. So for the banks that chose Canton for privacy, L2s still do not change the decision; for the funds that chose public Ethereum for reach, they make it cheaper and now optionally confidential. Module E covers what moved and what did not. The bifurcation persists. What L2s do change is the migration path for the third option: because a permissioned EVM shares a language and a talent pool with public Ethereum and its L2s, an institution can move along that ladder without rebuilding, which is what JPMorgan did in putting JPM Coin on Base and a tokenised money-market fund on Ethereum while keeping its core private. Canton has had no equivalent ladder and is building one: Zenith, an EVM execution layer inside Canton announced in March 2026, runs unmodified Solidity that calls Daml contracts atomically, but it is not yet on Canton mainnet.

The reconciled reading, in three parts rather than two. Public Ethereum won the funds-and-stablecoin layer, where reach matters and holdings are already disclosed. Permissioned Canton won the multi-party bank-settlement layer (repo, collateral, depository settlement) where many counterparties settle one atomic transaction and each may see only its own leg, which is a genuine architectural win rather than vendor spin. Permissioned EVM chains won the single-operator cash layer, where the privacy boundary is simply the institution's own perimeter. For India that means Ethereum is the right tool for cross-border and fund distribution (via GIFT City); Canton-class architecture is right for confidential dealer-to-dealer bond and repo settlement; and a permissioned EVM is the lower-talent-risk answer for single-operator registers and rails, since India's developer pool is concentrated in EVM/Solidity while Daml skills are scarce in every market (a gap Zenith would narrow for new applications if it reaches mainnet). Collapsing that middle option is the most common error in this debate, and the one a well-briefed banker will catch. India tested the reading in September 2026 and it held: given a live mandate and a clean sheet, SEBI and the RBI built Demat 2.0 on a permissioned ledger owned by the depositories, settled in wholesale CBDC, for exactly the confidential multi-party securities case this module assigns away from public Ethereum. Canton's own long-term weaknesses belong in the same briefing. EthSystems, an Ethereum-aligned group, argues that Canton's rules change by a two-thirds Super Validator vote with no fork option, that a trade spanning several parties' nodes is only as available as all of them together, and that its privacy holds against other participants but rests on trust in whoever runs the nodes. Zenith answers the talent and tooling objections and none of these, so they stand whether or not it ships.

The full report

This is the module as originally researched. Its purpose is to be unfavourable to Ethereum wherever that is warranted, because the audience discards the whole body of research if it detects special pleading. The summary tiers above reflect the reconciliation pass. Several figures here (uptime logs, gas fees, some volume claims) sit at T4/T5 and are flagged as such; see the Reconciliation tab and Figure Ledger.

Overview

On the criteria institutions actually use, Ethereum wins decisively on only three (liveness/uptime, counterparty reachability, and India-available talent) and loses or ties on the criteria that decide most regulated-settlement procurements: confidentiality, cost predictability, permissioning granularity, and legally recognised settlement finality. On those, permissioned Canton has taken the high-value multi-party production book (Broadridge's Distributed Ledger Repo settled ~$7.5tn in June 2026 alone), while the single-operator cash rails went to permissioned EVM or bank-built chains (Kinexys, Citi). "Permissioned" is not one stack, and the comparison matrix below now carries all three.

Public production data resolves the permissioned-vs-public debate empirically. Funds and stablecoins overwhelmingly chose public Ethereum (~$17.5bn RWA value, ~50% chain share, Aug 2026, RWA.xyz), while every bank-operated core-settlement venue with real volume chose a permissioned ledger, citing sub-transaction privacy. Ethereum L2s reframe Ethereum's cost problem but do not touch its confidentiality problem.

Finding 1: Ethereum's only uncontested advantages are liveness, reach and talent

Ethereum mainnet has run since 30 July 2015 with no recorded chain halt through 15+ upgrades and a live proof-of-work-to-proof-of-stake switch (ethereumuptime.com, T5, corroborated by ethereum.org, T4). Solana had at least 11 partial or full outages between 2020 and early 2024 (Helius, T5), the last major halt ~5 hours on 6 February 2024. Ethereum's uptime is a genuine, checkable advantage. India analogue: NSDL/CDSL and RBI RTGS availability are already very high, so the marginal liveness gain for a domestic issuer is small; liveness is not the binding constraint, the ledger-as-register gap is.

Finding 2: Confidentiality is the criterion Ethereum loses on, and why banks chose Canton

On Ethereum mainnet and its L2s, institutional tokenised assets settle on fully public ledgers. BUIDL is a permissioned/whitelisted ERC-20 that gates who may hold or transfer, but balances, transfers, mints, redemptions and holder addresses are all publicly visible on Etherscan (contract 0x7712c34205737192402172409a8f7ccef8aa2aec, T1 on-chain). Whitelisting is access control, not confidentiality. The purpose-built Ethereum privacy layer that came closest, Aztec Connect, was WOUND DOWN (deposits disabled 31 Mar 2023). Its successor reached mainnet only in November 2025 and has no documented regulated-FI production deployment. EY's Nightfall exists (open-source ZK, Apr 2025, T1/T4) but has no confirmed named regulated-FI mainnet securities production use.

Canton provides protocol-level sub-transaction privacy (each party sees only its slice), which DTCC, Goldman's GS DAP and HSBC Orion cited as the explicit reason for choosing it over public Ethereum. Digital Asset CEO Yuval Rooz (Dec 2025, The Defiant, T3): institutions "can't have their positions visible to the entire world in real time." This is the single most decisive and best-evidenced finding in the module. India analogue: corporate-bond OTC block trades and repo positions, where a dealer's inventory visible in real time would move the market against them.

Revised September 2026. The two negatives in the paragraph above were overtaken. Aztec shipped private smart contracts on mainnet in July 2026; EY's Nightfall was integrated by Starknet for private institutional payments in February 2026; and a regulated deployment now exists at the fund layer, with Archax distributing tokenised money-market funds under a privacy wrapper on Silent Data since February 2026. The finding itself survives: no bank-run core-settlement venue has moved to a confidential public-chain rail, and Canton still holds that layer. See Module E and Reconciliation §1.12.

Revised September 2026. A qualification from the other side. EthSystems (Jan 2026, T4; formerly the Ethereum Foundation's institutional privacy task force, so an interested party) argues that permissioned privacy is enforced by operators and policy rather than by cryptography, and lapses if incentives, regulators or governance change. That holds for one boundary and not the other. Against other participants, Canton's privacy is the data model: a node that never receives a contract cannot disclose it. Against whoever operates the participant node hosting a party, and against the governance that sets the protocol's rules, it is a trust assumption, and a regulator that compels those parties reaches the data. A bank choosing between visibility to the whole market and visibility to a regulated operator usually accepts the second, so the finding stands. Canton's confidentiality is institutional, and should be described that way. See Finding 9 and Reconciliation §1.13.

Finding 3: Cost is low on average but volatile

Ethereum mainnet base fees fell to roughly 0.05–0.7 gwei through 2026 (avg ~$0.16–0.22/tx, Mar 2026; CoinLaw, T5), a ~95% drop since the Dencun upgrade (Mar 2024), but remain spiky; during the Oct 2025 flash drop, fees briefly hit ~15.9 gwei. L2s (Arbitrum ~$0.004–0.09, Base ~$0.02) are cheaper but add sequencer and bridge dependency. Permissioned ledgers have deterministic, contractually fixed operating costs with no public fee auction. India analogue: UPI runs at effectively zero marginal cost at 24.51bn transactions/month (Aug 2026, ₹29.82 lakh crore, NPCI, T3); a per-transaction fee auction is a non-starter for high-volume domestic retail rails.

Finding 4: The permissioned book is real, large, and concentrated in one application

Broadridge's Distributed Ledger Repo, a Canton-lineage permissioned platform, reported ~$7.3tn settled in January 2026, ~$8tn in March 2026, and ~$7.5tn in June 2026 (Broadridge press releases, NYSE:BR, T4/company; DLR data now on the Bloomberg Terminal via Kaiko, T2), while Module A cited ~$8.0tn for July 2026. RWA.xyz attributes ~$344.8bn represented asset value on Canton (12 May 2026, T2), but DefiLlama placed Canton public TVL at ~$961,000 (Jun 2026, T2): the value is institutionally controlled, not publicly liquid. Most Canton throughput is a single application (DLR repo), a market-structure artefact in which repeated overnight collateral cycles inflate gross volume, rather than diversified on-chain activity. India analogue: tri-party repo / CROMS/CCIL-settled G-sec repo, already centrally settled by CCIL, so a DLT repo layer adds little unless it enables intraday collateral mobility CCIL cannot.

Finding 5: The consortium graveyard implies permissioned networks fail on governance, not technology

Module A's graveyard, covering TradeLens (WOUND DOWN Q1 2023, neutral-governance failure), we.trade (2022, insufficient network effect), Marco Polo (2023, no product-market fit), Contour (late 2023) and ASX CHESS/Digital Asset Daml (scrapped Nov 2022, ~A$250m write-off), is overwhelmingly a graveyard of permissioned/consortium DLT rather than public-chain projects. R3 Corda's growth has plateaued; R3 announced a Solana partnership in 2025 to access public liquidity, a tacit admission that closed networks struggle for reach. The technology worked; the governance and liquidity did not. India analogue: IBBIC/IBDIC is structurally the same model, needing every rival to route trade-finance data through shared infrastructure, which is the same neutral-governance and network-effect problem, mitigated only if a genuinely neutral operator or regulator-utility model (the UPI/NPCI template) runs it rather than a bank-owned consortium.

Canton's governance has the same shape. Protocol changes pass by a two-thirds vote of Super Validators, the Canton Foundation is co-chaired by DTCC and Euroclear, and a dissenting participant has no fork to take (EthSystems, T4). The graveyard does not predict that Canton fails, because a neutral foundation and real volume are the survivor profile. It does mean Canton's resilience depends on a small set of regulated institutions staying aligned, and a regulator that pressures them changes the rules for every participant on the network.

Finding 6: Regulatory recognition favours the asset/issuer layer, and is chain-agnostic

Where regulators sanctioned tokenisation, they regulated the issuer and instrument, not the chain. The US GENIUS Act (18 Jul 2025, T1) regulates payment-stablecoin issuers; EU MiCA (full regime from 30 Dec 2024, T1) regulates EMTs/ARTs. Neither privileges Ethereum. DTCC received an SEC No-Action Letter (Dec 2025, T1) and chose Canton. In India, SEBI's DLT covenant system is IN PRODUCTION, the RBI's tokenised-CD pilot on UMI is LIMITED PILOT, and SEBI's Demat 2.0 corporate-bond pilot is LIMITED PILOT since 10 September 2026, all chain-agnostic or leaning permissioned/CBDC, none on public Ethereum. Revised September 2026: Demat 2.0 is the strongest Indian evidence this module has. Given a clean sheet and a live mandate, SEBI and the RBI chose a private permissioned ledger owned by the depositories, with the cash leg in wholesale CBDC and the depository record still authoritative. The criteria named in this module's comparison — confidentiality, permissioning granularity, an accountable operator, legally recognised finality — are exactly the ones that design satisfies and public Ethereum does not.

Finding 7: Talent in India favours EVM/Solidity, but not permissioned stacks

India onboarded 17% of the 39,148 new crypto developers globally in 2024, the most of any country (Electric Capital 2024 Developer Report, T2), and India's share of global Web3 developers rose to 15.2% (Hashed Emergent, Mar 2026, T3/T4). The skills concentrate in Solidity/EVM and Rust/Solana, a genuine Ethereum-family advantage. But Canton/Daml and Corda skills are scarce everywhere; the enterprise/permissioned end faces a shortage. Daml has roughly 200 contributors against thousands of monthly active Solidity developers (EthSystems, Jan 2026, T4). Canton's response is Zenith, which runs unmodified Solidity inside Canton and calls Daml contracts atomically through an external_call() primitive (Canton Network blog, Mar 2026, T4). It is not in production: mainnet was targeted for Q2 2026, and in July 2026 external_call() was scheduled for the Canton 3.6 upgrade, with pilots entering sandbox and no mainnet date given. If it ships, the Daml-scarcity argument weakens for new applications written in Solidity; the existing Daml estate, Broadridge DLR included, would still need Daml engineers.

Finding 8: Ethereum's base layer is durable; the bridges are the systemic weak point

Ethereum's base layer has never halted, but the multi-chain architecture institutions adopt to reach it is the single largest theft category. Chainalysis documented "$2 billion... stolen across 13 separate cross-chain bridge hacks," 69% of total funds stolen in 2022 to that point (Ronin ~$624m, Wormhole ~$320m, Nomad ~$190m, T2). BUIDL's own multi-chain design relies on Wormhole for cross-chain messaging, the same Wormhole that lost $326m in Feb 2022. Full-year 2025 theft exceeded $3.4bn (Chainalysis, T2). Permissioned ledgers with no public bridge and known participants have a materially smaller external attack surface.

Finding 9: The long-term case against Canton survives Zenith

The most complete published case against the permissioned path is EthSystems' "Public rails vs private ledgers" (Jan 2026, T4). It comes from an Ethereum-aligned group and reads as advocacy, but most of its claims are checkable. Canton's Zenith announcement (Mar 2026, T4) answers some of them.

EthSystems criticismAnswered by Zenith?
Daml lock-in: ~200 contributors, migration is a rewriteYes for new applications, once on mainnet: Solidity runs unmodified
Isolation from public DeFi and stablecoinsPartly: EVM contracts compose atomically with Daml inside Canton, but reaching Ethereum or Solana still runs through bridges (Chainlink, LayerZero), the trusted intermediary the critique names
Privacy enforced by operators, not cryptographyNo: Zenith keeps Canton's need-to-know privacy model
Consortium governance: two-thirds Super Validator vote, no forkNo: Zenith joins as one more Tier-1 Super Validator
A multi-party commit needs every party's node online, so failures correlateNo: Zenith settles through the same protocol
Breaking major-version migrations (2.x to 3.x)No: external_call() itself waits on the 3.6 upgrade
About two years of production recordNo

The arguments that survive are structural: who can read the data, who can change the rules, and whether one counterparty's outage takes a trade down with it. An application-layer change cannot reach any of them. They do not reverse Finding 2 or Finding 4, because banks chose Canton with these costs visible and Broadridge settles trillions a month on it. They are the terms of that choice, and a bank or Indian regulator evaluating Canton-class architecture should price them alongside the privacy case.

The comparison matrix

Each cell carries a source; institutional-usage status noted where relevant.

CriterionEthereum mainnetEthereum L2sSolanaPermissioned EVM (Besu / Quorum)Canton (permissioned)Corda / FabricConventional DB / UPI / CCIL
Settlement finalityProbabilistic, ~12.8 min (ethereum.org T4)Inherits L1 + up to ~7-day L1 withdrawalSub-second optimistic (T4)Deterministic, IBFT/QBFT or Raft; no reorgs (T4)Deterministic validator-set (T2)Deterministic notary (T4)Legally recognised: RTGS/CCIL under PSS Act (T1)
Throughput / costLow avg, volatile to 15+ gwei (T5)~$0.004-0.09, sequencer-dependent~$0.00025/tx (T5)Fixed infra cost; gas at zero, no fee auction (T4)Fixed contractual costFixed licence/opsUPI ~zero marginal, 24.51bn/mo (T3)
Privacy (production)None on base layer; whitelisting != confidentiality (T1)Same; no FI privacyPublic ledgerPairwise/small-group private state (Tessera, Besu privacy groups); does not compose across groups (T4)Sub-transaction privacy IN PRODUCTION (T3)Need-to-know channels (T4)Full (private DB); AA consent-based (T1)
PermissioningContract-level whitelist (T1)SameToken-levelNode- and account-level allowlists, native (T4)Native role-based via Daml (T2)NativeNative (closed)
GovernanceCredibly neutral, no operator (T4)Sequencer often single operatorFoundation-influencedSingle operator or consortium; a stack, not a shared networkCanton Foundation; DTCC/Euroclear co-chairs (T1); rule changes by two-thirds Super Validator vote, no fork (T4)Vendor/consortiumRegulator/utility
Vendor dependencyNone (client diversity)Rollup + bridge dependencyHistorically single clientLow; open-source clients, EVM-portableDigital Asset dependencyR3/IBM lock-in (T5)Vendor or in-house
Security recordBase never halted since 2015 (T5)Bridge risk: $2bn/13 hacks 2022 (T2)>=11 outages 2020-24 (T5)Kinexys live since 2020, >$3tn cumulative (T4)Smaller external surface, ~2-year record; commit needs every party's node online (T4)Long enterprise recordDecades of RTGS/depository ops
Liquidity / reachabilityLargest: ~$17.5bn RWA (T2)Arbitrum ~$0.85bn (T2)~$4.1bn, 97% tokenised-equity vol (T2/T3)Islanded; bilateral bridges only (Kinexys-DLR; JPM Coin on Base)~$344.8bn represented, ~$961k public TVL (T2)Not disclosedUniversal domestic reach
Talent (India)Abundant EVM (T3)Same poolGrowing Rust poolAbundant; same EVM pool (T3)Scarce (Daml, ~200 contributors, T4); Zenith EVM layer not yet on mainnetScarceAbundant
Regulatory recognitionIssuer-regulated, no chain blessing (T1)SameSameIssuer/operator-regulated; Kinexys and Citi CTS inside the banking perimeter (T1/T4)DTCC chose Canton (T1)CBDC pilotsRTGS/CCIL PSS-designated; SEBI DLT live (T1)

Why the permissioned-EVM column exists. The public-versus-Canton framing omits the option much of the production book actually runs on: a permissioned Ethereum-lineage chain. JPMorgan's Kinexys is Quorum-derived and Citi's platform is bank-built, so "banks chose Canton" is true of the securities and collateral layer and false of the cash layer. The mechanism behind that split is worth stating rather than asserting. Canton keeps no global state: each participant node holds only its own projection of a contract, and a global synchroniser proves atomicity across those projections without any node seeing the whole, so privacy is the data model. A permissioned EVM replicates global state across the permissioned set and adds privacy as private transaction groups, side databases shared pairwise or among a few parties, which means private state does not compose across groups and atomic delivery-versus-payment breaks as soon as one trade spans more than one group. That is precisely the shape of dealer-to-dealer repo and depository settlement, so Canton's win there is an engineering result rather than vendor spin; and it is why a permissioned EVM suffices where Kinexys sits, with one bank, one balance sheet, and clients rather than mutual counterparties. The same mechanism has an availability cost: a transaction commits only when every confirming participant responds, so a trade across five parties' nodes at 99% uptime each is available about 95% of the time, and one counterparty's outage stalls the whole trade (EthSystems, T4). Two caveats: the architectural cells above come from Besu/Quorum and Canton client documentation (T4) and should be cited to those docs, not to this table; and no named regulated-FI deployment of multi-party confidential securities settlement on a permissioned EVM was found, which is the reason Canton still holds that layer. Kinexys' current stack is UNVERIFIED: the Quorum lineage is documented for Onyx, but the November 2024 rebrand may have brought undisclosed changes, and Citi has never disclosed its technology.

Which L2s have real institutional usage

Arbitrum is IN PRODUCTION as an RWA venue (~$0.85bn, 10,713 holders, RWA.xyz T2) with a BUIDL share class; real but small. Base (Coinbase, OP Stack) is the largest L2 by activity and hosts JPMorgan's JPM Coin/Kinexys deposit token natively, a notable signal, though that is a permissioned deposit token rather than open DeFi. Optimism, ZKsync and Polygon carry BUIDL/BENJI share classes, mostly mirrored issuance driven by foundation fee subsidies rather than independent liquidity. The honest read: L2 institutional "usage" is overwhelmingly mirrored share classes, not distinct liquidity; only Base has a distinct institutional anchor.

Institutional volume, per chain

Solana's institutional volume is real but concentrated in tokenised equities trading (97% of cross-chain tokenised-equity volume, Q2 2026, T3), not settlement or credit. Avalanche's institutional-branded "Spruce" subnet is a permissioned testnet; the ~$1.7bn on Avalanche sits on the public C-Chain via BUIDL rather than the institutional subnet, so the value is not where the institutional branding is. Stellar's institutional volume is essentially one product (Franklin's BENJI), extreme concentration risk. Canton's trillions are ~90%+ one application (Broadridge DLR repo).

The cases against Ethereum

  1. Dealer-to-dealer bond and repo settlement where positions are market-sensitive. A public ledger exposes inventory; this is why Broadridge DLR runs on permissioned Canton. For India's OTC corporate-bond market, a permissioned ledger or CCIL system is correct.
  2. Core settlement needing a named legal operator with statutory finality. The PSS Act designates specific RBI systems; a leaderless chain has no operator to designate.
  3. High-volume domestic retail payments. UPI already clears 24.51bn/month at ~zero marginal cost with legal finality; a public chain is strictly worse.
  4. Consent-based data sharing for lending. The Account Aggregator framework already moves consented data; a blockchain removes the confidentiality the AA design provides.
  5. A bank-owned consortium onboarding competitors. The graveyard shows this fails on governance regardless of chain; a neutral utility is needed.
  6. When a conventional shared database suffices. For a single depository maintaining a register, a well-controlled database with audit logging already delivers the outcome.

Falsifiable conditions under which Ethereum would be the wrong long-term bet

Stated as checkable conditions, not vague risks: (1) a permissioned ledger captures >70% of tokenised-RWA value (not just repo throughput) by 2028; (2) production-grade confidential transactions do NOT ship and get regulator-sanctioned on any Ethereum L2 by end-2027; (3) a competing chain offers both sub-second deterministic finality and confidentiality in production while Ethereum's single-slot finality slips; (4) a major bridge failure causes a systemic loss in tokenised institutional assets; (5) regulators mandate that regulated securities settle only on operator-accountable systems with statutory finality. If none become true by ~2028, Ethereum's asset-layer position is durable; if two or more do, the long-term bet weakens materially.

A sixth condition runs the other way, falsifying the Canton case rather than the Ethereum one, and it belongs here because this module's central claim is that confidentiality is an architectural loss and not a temporary one: (6) if a named regulated financial institution puts multi-party confidential securities settlement into production on a permissioned EVM by end-2027, the privacy argument for Canton collapses from an architectural argument to a convenience one, because the thing Canton is said to do that an EVM cannot do (many counterparties, one atomic transaction, each seeing only its own leg) would have been done on an EVM. That would also make the permissioned-EVM option strictly dominant for India, which already wins on talent and migration optionality and would no longer lose on privacy. Check: any production deployment, not a pilot, on Besu/Quorum-lineage infrastructure settling a multi-party trade with per-party confidentiality, with a named institution and a named instrument. None was found today, and private transaction groups not composing across groups is the technical reason to expect this condition to stay unmet. Zenith does not meet it: Solidity running inside Canton is settled by Canton's protocol and privacy model, not by a permissioned EVM's private transaction groups.

These thresholds are an analyst framework, not sourced forecasts; never cite them as if predicted by a named source.

Module close

  1. Findings hardest to dismiss. BUIDL's holder list is public on Etherscan (checkable in one click, so whitelisting isn't confidentiality); Broadridge settled ~$7.5tn in June 2026 on permissioned Canton, not Ethereum; the consortium graveyard is overwhelmingly permissioned DLT; Ethereum has never halted since 2015 while Solana had 11+ outages (a conceded Ethereum advantage); cross-chain bridges leaked $2bn across 13 hacks in 2022.
  2. Strongest chart. RWA.xyz "Networks" table: distributed RWA value and holder count by chain, with Ethereum ~$17.5bn / 264k holders against Canton's ~$344.8bn represented but ~$961k public TVL. One chart captures the public-vs-permissioned bifurcation and the represented-vs-distributed distinction.
  3. Claims most likely to be challenged. "Ethereum has ~50% of RWA value" (RWA.xyz; disclose the 34%–65% range and the measure); "banks chose Canton for privacy" (Rooz on record, DTCC No-Action Letter, HSBC via Ledger Insights); "Ethereum has no production privacy" (Aztec Connect sunset, Aztec's Nov 2025 relaunch with no regulated-FI use, Nightfall's absence of a named deployment); "Canton's privacy is architectural" (true against other participants, trust-based against node operators and governance; EthSystems, Finding 2); "Canton has solved its developer problem" (Zenith is announced, not on mainnet).
  4. One-sentence summary. Public Ethereum has won the business of putting fund shares and stablecoins on-chain, but it has lost, and on today's technology cannot win, the business of confidential bank settlement, which has gone almost entirely to permissioned ledgers like Canton; for India, Ethereum is the right tool for cross-border and fund distribution and the wrong tool for confidential domestic bond and repo settlement.
  5. What this module could not establish. Primary confirmation of Kinexys/Citi volumes (needs filings or Bloomberg/Reuters); any named regulated-FI confidential-settlement deployment on an Ethereum L2; an India EVM-vs-permissioned talent split; the current stack behind Kinexys and Citi's platform (Quorum lineage is documented for Onyx, not for post-rebrand Kinexys, and Citi has disclosed nothing); and any named regulated-FI deployment of multi-party confidential securities settlement on a permissioned EVM, which is falsifiable condition 6; and when Zenith reaches Canton mainnet (external_call() scheduled for Canton 3.6, undated as of September 2026).