Yesterday a press release landed in my inbox announcing Zamanat's launch of a tokenized private credit fund on ZIGChain. The headline promised the "first instance of bringing GCC private credit into a regulated digital structure." One hundred million dollars in target size. Shariah-compliant. DIFC-registered. DFSA-supervised.
I read it twice, then opened the disclosure section. No smart contract audit. No token standard. No target yield. No borrower criteria. No default history. No team resumes beyond a single CEO name.
Code does not lie, but it often omits the context. Press releases omit more.
That asymmetry โ the precision of the regulatory wrapper versus the silence around the actual credit book โ is the entire story. Everything else is narrative architecture. So let me pull the structure apart the way I would any tokenized credit wrapper: not by what the issuer says it does, but by what the source code and the filing documents would need to contain to make the claims safe.
Context: what actually just went live
Zamanat is structuring a closed-ended exempt fund registered in the Dubai International Financial Centre and regulated by the Dubai Financial Services Authority. The vehicle is classified as a credit fund. Management sits with Truleum, which holds DFSA license F008013. Fund administration is handled by Apex Group. The blockchain layer โ issuance, whitelisting, and native ownership recording โ runs on ZIGChain. Disrupt.com, described as a MENA operator-led AI-native venture builder, is supporting and leading the raise. The target figure is "up to USD 100 million."
Investors receive ZM1 Investment Tokens. These are not utility tokens. They are not governance tokens. They represent fund equity โ beneficial ownership of a share of a private credit portfolio whose cash flows come from borrower interest and principal repayment.

There is one genuinely positive signal buried here. The yield source is real cash flow, not token emission. Private credit funds pay coupons from borrower repayments. There is no inflationary subsidy, no staking flywheel, no reflexive mechanism where new depositors fund old returns. On the narrow question of Ponzi architecture, this structure passes. That matters more than most RWA newsletters will admit, because a large fraction of the 2021โ2023 yield products failed precisely on this axis.

But passing the Ponzi test is the lowest bar in the room. It says nothing about whether the credit book is sound, whether the fund will actually capitalize, or whether you can exit.
The fund's stated mandate draws on two macro numbers the release leans on heavily: a $250 billion SME financing gap across the region, and projected Islamic finance assets reaching $9.7 trillion by 2029. Both are real datasets โ World Bank, LSEG, Kearney. Both describe the size of a market, not the size of this fund. A single $100 million vehicle against a $250 billion gap is 0.04%. That ratio is the honest measure of what this announcement actually moves.
Core: the settlement layer is not the risk layer
Here is the structural point the release never states plainly. ZIGChain is performing issuance and record-keeping. It is not performing custody, credit underwriting, or cash-flow distribution. The blockchain is the registry; traditional finance remains the balance sheet.
I spent four weeks in 2017 manually auditing Solidity contracts for three obscure ICOs, and the pattern from that period repeats here in a regulatory costume: the on-chain layer is the visible surface, and the actual value concentration sits off-chain, unexamined and unaudited by anyone outside the sponsor group.
When a private credit fund is wrapped in tokens, three things must be legible for the wrapper to be meaningful. First, the token standard and transfer restrictions. Second, the administrator and issuer permissions inside the contract. Third, the audit that certifies the contract behaves as described.
None of the three appear in the announcement.
On the token standard: an ERC-3643-style permissioned security token is the most probable architecture, because that is what DFSA professional-client whitelisting demands. ERC-3643 enforces transfer restrictions, identity binding, and eligibility at the contract level. That choice would be technically coherent. But probable is not disclosed. A reader cannot verify the standard, the upgradeability, or whether a single admin key can mint, freeze, or burn balances.
On permissions: permissioned security token implementations almost always carry a privileged issuer role. That role is necessary for compliance โ you must be able to block sanctioned addresses and reverse erroneous transfers to non-eligible holders. It is also a centralized capability. There is no way to evaluate the severity of that capability from the outside without the contract address and the verified source.

On audits: the release says nothing. For a $100 million vehicle, the absence of a named auditor is not a minor omission. It is a missing load-bearing wall.
The mechanical consequence of the structure is what makes the silence costly. An exempt fund in the DIFC is built for a limited set of professional investors. Closed-ended means no redemption mechanism: you cannot call your capital back before the fund's term matures. Secondary transfer exists only between whitelisted professional clients โ a pool small enough that real liquidity approaches zero. Assume a three-to-seven-year lock-up as the base case, not the pessimistic case.
So the honest technical description of ZM1 is this: a permissioned security token representing a long-duration, illiquid, privately-priced claim on an undisclosed credit portfolio, transferable only within a tiny whitelist, governed by a traditional fund structure where token holders almost certainly hold no voting rights. That is not a criticism of the design. It is what a closed-ended exempt credit fund is. The criticism is that the announcement markets it in the language of digital asset ownership, where people are conditioned to expect the opposite.
I reverse-engineered price-feed mechanisms across five lending platforms during the 2020 DeFi summer, and the lesson from that exercise holds across every wrapped-asset structure I have examined since. The failure mode of tokenized credit is never the token. It is the bridge between the token and the underlying credit event. In lending protocols, that bridge was the oracle. In a private credit fund, that bridge is the sponsor's underwriting process and the administrator's reporting. Neither is on-chain. Neither is audit-visible. Both determine whether you get paid.
Contrarian: compliance as camouflage
Here is where I diverge from the comfortable read of this announcement.
The consensus take is that Zamanat is a serious, regulation-first project, and that its DIFC/DFSA posture makes it more trustworthy than the offshore RWA shops. I think that reading is half right and dangerously incomplete.
Compliance is not a substitute for disclosure. It is a different axis.
The release leans hard on regulatory vocabulary โ DFSA-supervised, DIFC-registered, professional-client-only, license F008013 โ and every one of those phrases is accurate. But watch what the regulatory framing accomplishes rhetorically. It shifts the reader's evaluation from "can I assess the credit risk?" to "is this legitimately licensed?" Those are not the same question. A licensed vehicle can still hold a bad loan book. A regulated sponsor can still refuse to disclose a default rate. The license certifies process compliance. It does not certify asset quality, and it does not certify yield.
Three omissions sit at the center of that gap.
The first is the complete absence of borrower information. A private credit fund's entire risk profile is its credit book. Who borrows? What collateral? What sectors? What is the concentration? What is the historical default rate? None of it is disclosed. Without this, no yield figure can be interrogated, because yield is simply the price of the risk you are not being shown.
The second is team opacity. One CEO is named โ Umair Tariq โ with no educational background, no prior employer, no track record. For a fund targeting nine figures, this disclosure sits well below industry norm. The supporting parties are stronger: Apex Group carries institutional weight in fund administration, and Truleum's DFSA license is verifiable. But both are service providers, not sponsors taking credit risk. The credibility of the underlying sponsor remains unquantified.
The third is the "up to USD 100 million" construction itself. That phrasing almost always signals a target ceiling rather than a committed raise. First close could be a fraction of it. Which means the fund you are being asked to evaluate could be a fraction of the fund being announced.
There is a structural question underneath all three. Zamanat positions itself as the originator and structuring party, handing licensed management to Truleum and administration to Apex. That is a hub-and-spoke model with at least five moving parts: DFSA framework, Truleum, Apex, ZIGChain, and Disrupt.com. Every additional intermediary in a chain is a point where the chain can break โ and the sponsor is the party with the fewest verifiable credentials.
And one question the release never touches: why ZIGChain? Choosing a smaller ecosystem over Ethereum or a mature settlement layer is defensible on cost, but it raises a governance question the announcement should preempt. Is there a commercial or equity relationship between Zamanat, Disrupt.com, and ZIGChain? Undisclosed related-party arrangements are common in venture-builder originations. The release neither confirms nor denies. It simply omits.
Takeaway
What would change my assessment is not another press release. It is a specific set of artifacts. A published smart contract audit naming the firm. The token standard and admin permission structure. A target yield with the credit assumptions behind it. A borrower concentration breakdown. Full team backgrounds. And, most importantly, a first-close figure with regulatory confirmation.
Until those exist, ZM1 is a compliance wrapper around an unexamined credit book, and the wrapper is doing more narrative work than the asset ever will.
The RWA sector's next failure will not look like a DeFi exploit. It will look like a well-licensed fund that simply never disclosed the thing that mattered โ and by the time the lock-up expires, the disclosure will be a legal footnote no one read at entry.
Watch the first-close number. Watch for a named auditor. Watch whether a Shariah supervisory board is ever named, or whether "Shariah-compliant" stays a label without a scholar attached. Those three signals will tell you more about Zamanat's substance than the size of the market it claims to be bridging.
Silence, in a compliant fund, is still silence.