Researchers Outline ‘Shielded Bitcoin’ Privacy Layer That Would Leave Bitcoin’s Rules Untouched

Researchers Outline ‘Shielded Bitcoin’ Privacy Layer That Would Leave Bitcoin’s Rules Untouched

N
News Editor
2026-09-26 12:00:00
Researchers at cryptography firm [alloc] init have published a paper describing Shielded Bitcoin, a proposal that aims to bring Zcash-style privacy to bitcoin-denominated payments without changing Bitcoin’s consensus rules. The design would keep encrypted transfer data on the Bitcoin blockchain while moving proof verification to separate software that anyone could run. In practice, that means a Bitcoin transaction could still confirm on-chain even if the private payment embedded inside it failed Shielded Bitcoin’s own checks. The proposal is still early-stage. The 56-page specification does not explain how ordinary BTC would enter the system or how users would withdraw real bitcoin from it, leaving those mechanisms to a separate paper based on PIPEs. Critics, including Helius co-founder Mert Mumtaz, have argued that the design amounts to a synthetic ledger with major tradeoffs, citing a trusted setup, visible fee payments and the lack of an in-protocol way to move actual BTC in or out. [alloc] init also acknowledges several of those limits, including visible timing and fees, higher transaction costs and unfinished support for lightweight wallet verification. The paper arrives as privacy has become a more practical issue for crypto developers working on payroll, business payments and everyday spending. It also lands during a period of renewed attention on Zcash, whose shielded pools and private transaction activity have climbed sharply in recent months.

Researchers have proposed a system called Shielded Bitcoin that aims to add Zcash-style privacy to bitcoin payments without changing Bitcoin’s network rules. The design is still incomplete, though, and does not yet provide a finished mechanism for locking up real BTC and releasing it again on withdrawal.

The paper, published Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm [alloc] init, borrows the encrypted payment model used by Zcash. The stated goal is to hide payment amounts, senders and recipients while leaving Bitcoin’s base rules unchanged.

How the proposed system would work

Under the proposal, bitcoin-denominated value would be stored in encrypted records called notes. When a user spends one, the system would publish a marker showing that the note had been used, along with a mathematical proof that the sender owned the funds and had not created new ones. The amount, sender and recipient would stay hidden.

That is where the design departs from Zcash. Zcash verifies those proofs on its own blockchain. Shielded Bitcoin would instead publish the transfer data on Bitcoin and leave verification to separate software that anyone could run. As a result, a Bitcoin transaction could be confirmed on-chain even if the private payment recorded inside it failed Shielded Bitcoin’s own checks.

The paper also says encrypted transfer data would remain on Bitcoin, allowing users to reconstruct accepted payments from the public record with their wallet keys. Separate viewing keys would let them disclose transactions to an accountant or auditor without giving up the ability to spend their funds.

Why privacy is back in focus

Privacy has become a practical issue again in recent months as developers try to make cryptocurrencies more usable for payroll, business payments and everyday spending. Standard Bitcoin transactions permanently reveal amounts and addresses. Once an address is tied to a company or an individual, other payments connected to it become easier to trace.

Ethereum is reviewing a proposal for a shared private pool that would let users transfer ether and other tokens without publicly revealing payment details. Its authors have pointed to payroll, treasury management and donations as examples of use cases that are poorly served by fully public transactions.

Zcash remains the clearest comparison point. The network lets users choose between transparent payments, where addresses and amounts are public, and shielded payments, where those details are encrypted. According to CoinDesk calculations using ZecStats data, Zcash’s shielded pools held about 4.9 million ZEC on Friday, up 14% from July 30. That equals roughly 29% of issued coins and was worth about $7.8 billion after the rally.

Zcash recorded roughly 63,000 shielded transactions last week, its busiest week for private transfers since 2022 and the fourth-highest week on record. Across the network, reported transfer volume topped $23 billion, the largest weekly total since 2021 and the second-highest in its history.

Those figures have drawn both investor money and market attention. By early September, ZEC had gained more than 2,300% over the prior year and crossed $1,000. The rally extended above $1,600 on Wednesday.

The link between Bitcoin privacy research and Zcash predates this paper. Zerocoin was proposed in 2013 as a privacy extension for Bitcoin. Later Zerocash research evolved into Zcash, which launched as a separate cryptocurrency in 2016.

What the paper does not solve

The 56-page specification does not explain how ordinary BTC would enter the system or how it would be released when a user wanted to withdraw. The authors reserve those mechanisms for a separate paper using PIPEs, a technique designed to lock a Bitcoin signing key until specified conditions are met.

Their claim that users retain control of their funds applies to transfers inside the system. It explicitly does not cover deposits and withdrawals.

Those omissions have already drawn criticism from developers and Zcash supporters. Mert Mumtaz, co-founder of Helius, which provides infrastructure for Solana developers, and a Zcash proponent, described the proposal on X as 「a synthetic ledger with significant tradeoffs」.

He pointed to 「a trusted setup」 and 「no fee anonymization」, meaning the Bitcoin wallet paying to publish a private transfer could still be visible. He also criticized the lack of a deposit and withdrawal mechanism, writing that there was 「no in-protocol mechanism for getting actual BTC in or out (which means you are holding synthetics).」

「I respect that people are working on this and taking notes from zcash finally,」 he wrote, while adding that the proposal would require years of additional research and development.

Cypherpunk, a company that holds and mines Zcash, welcomed the research but said it did not see the design as competition for the existing network. 「Privacy works best when built into the base layer. Not requiring Bitcoin changing is this design's biggest selling point, and also its biggest drawback,」 the company wrote.

It added: 「More privacy on Bitcoin is good for everyone.」

Limits acknowledged by the authors

[alloc] init acknowledges several of the same constraints. The reference design in the paper requires a cryptographic setup whose security depends on at least one participant acting honestly. Transfer timing and fee payments would still be visible. An efficient way for lightweight wallets to verify reconstructed payment history is listed as future work.

Komarov estimated that a private transfer would take roughly 700 virtual bytes, compared with 100 to 200 for a standard Bitcoin transaction. At the same fee rate, miner fees would come out to about four times higher.

As of Friday, there was no launch date for the system.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.