How can anyone be sure that there are no "phantom tokens"? Who is going to control the creation of these tokens? Is it all based on trust, are you serious? wtf
EDIT: zero knowledge proofs require a trusted setup. This allows the person who set up the system to create tokens at will if they didn't destroy the setup parameters.
this is why zero cash can't work.
It's the same problem with zero vert.