Researchers have proposed a system called Shielded Bitcoin that aims to add Zcash-style privacy to bitcoin payments without changing Bitcoin’s network rules. The design is still incomplete, though, and does not yet provide a finished mechanism for locking up real BTC and releasing it again on withdrawal.
The paper, published Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm [alloc] init, borrows the encrypted payment model used by Zcash. The stated goal is to hide payment amounts, senders and recipients while leaving Bitcoin’s base rules unchanged.
How the proposed system would work
Under the proposal, bitcoin-denominated value would be stored in encrypted records called notes. When a user spends one, the system would publish a marker showing that the note had been used, along with a mathematical proof that the sender owned the funds and had not created new ones. The amount, sender and recipient would stay hidden.
That is where the design departs from Zcash. Zcash verifies those proofs on its own blockchain. Shielded Bitcoin would instead publish the transfer data on Bitcoin and leave verification to separate software that anyone could run. As a result, a Bitcoin transaction could be confirmed on-chain even if the private payment recorded inside it failed Shielded Bitcoin’s own checks.
The paper also says encrypted transfer data would remain on Bitcoin, allowing users to reconstruct accepted payments from the public record with their wallet keys. Separate viewing keys would let them disclose transactions to an accountant or auditor without giving up the ability to spend their funds.
Why privacy is back in focus
Privacy has become a practical issue again in recent months as developers try to make cryptocurrencies more usable for payroll, business payments and everyday spending. Standard Bitcoin transactions permanently reveal amounts and addresses. Once an address is tied to a company or an individual, other payments connected to it become easier to trace.
Ethereum is reviewing a proposal for a shared private pool that would let users transfer ether and other tokens without publicly revealing payment details. Its authors have pointed to payroll, treasury management and donations as examples of use cases that are poorly served by fully public transactions.
Zcash remains the clearest comparison point. The network lets users choose between transparent payments, where addresses and amounts are public, and shielded payments, where those details are encrypted. According to CoinDesk calculations using ZecStats data, Zcash’s shielded pools held about 4.9 million ZEC on Friday, up 14% from July 30. That equals roughly 29% of issued coins and was worth about $7.8 billion after the rally.
Zcash recorded roughly 63,000 shielded transactions last week, its busiest week for private transfers since 2022 and the fourth-highest week on record. Across the network, reported transfer volume topped $23 billion, the largest weekly total since 2021 and the second-highest in its history.
Those figures have drawn both investor money and market attention. By early September, ZEC had gained more than 2,300% over the prior year and crossed $1,000. The rally extended above $1,600 on Wednesday.
The link between Bitcoin privacy research and Zcash predates this paper. Zerocoin was proposed in 2013 as a privacy extension for Bitcoin. Later Zerocash research evolved into Zcash, which launched as a separate cryptocurrency in 2016.
What the paper does not solve
The 56-page specification does not explain how ordinary BTC would enter the system or how it would be released when a user wanted to withdraw. The authors reserve those mechanisms for a separate paper using PIPEs, a technique designed to lock a Bitcoin signing key until specified conditions are met.
Their claim that users retain control of their funds applies to transfers inside the system. It explicitly does not cover deposits and withdrawals.
Those omissions have already drawn criticism from developers and Zcash supporters. Mert Mumtaz, co-founder of Helius, which provides infrastructure for Solana developers, and a Zcash proponent, described the proposal on X as 「a synthetic ledger with significant tradeoffs」.
He pointed to 「a trusted setup」 and 「no fee anonymization」, meaning the Bitcoin wallet paying to publish a private transfer could still be visible. He also criticized the lack of a deposit and withdrawal mechanism, writing that there was 「no in-protocol mechanism for getting actual BTC in or out (which means you are holding synthetics).」
「I respect that people are working on this and taking notes from zcash finally,」 he wrote, while adding that the proposal would require years of additional research and development.
Cypherpunk, a company that holds and mines Zcash, welcomed the research but said it did not see the design as competition for the existing network. 「Privacy works best when built into the base layer. Not requiring Bitcoin changing is this design's biggest selling point, and also its biggest drawback,」 the company wrote.
It added: 「More privacy on Bitcoin is good for everyone.」
Limits acknowledged by the authors
[alloc] init acknowledges several of the same constraints. The reference design in the paper requires a cryptographic setup whose security depends on at least one participant acting honestly. Transfer timing and fee payments would still be visible. An efficient way for lightweight wallets to verify reconstructed payment history is listed as future work.
Komarov estimated that a private transfer would take roughly 700 virtual bytes, compared with 100 to 200 for a standard Bitcoin transaction. At the same fee rate, miner fees would come out to about four times higher.
As of Friday, there was no launch date for the system.

