Shielded Bitcoin paper proposes Zcash-style privacy on Bitcoin L1, but leaves peg mechanisms unresolved

Shielded Bitcoin paper proposes Zcash-style privacy on Bitcoin L1, but leaves peg mechanisms unresolved

N
News Editor
2026-09-28 09:09:19
A new paper from cryptography research group [[alloc] init] lays out "Shielded Bitcoin," a protocol that aims to enable private BTC transfers directly on Bitcoin’s base layer without a soft fork or a sidechain. Written by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin, the design borrows from Zcash’s shielded pool model, using encrypted notes, public nullifiers, and zero-knowledge proofs while treating Bitcoin as a data-availability layer through OP_RETURN-based envelopes. Indexers would watch the chain, replay transactions in block order, and discard invalid ones. The paper also highlights a key limitation: peg-in and peg-out, the mechanism for moving BTC into and out of the system, are explicitly left for future work. The proposal arrives as privacy assets and narratives are gaining traction. ZEC reached about $1,600 this week, with a roughly $26 billion market cap and ranking ninth among cryptocurrencies, while Grayscale’s Zcash ETF ZCSH has drawn more than $250 million in net inflows since its August 25 launch. The article also points to Citrea’s acquisition of privacy-focused Bitcoin wallet Crest, NEAR’s rollout of default confidential perpetuals and confidential limit orders, and broader concerns that AI-driven surveillance could make transparent blockchains more exposing over time. In that context, Shielded Bitcoin is being framed as an attempt to bring privacy demand back onto Bitcoin itself rather than leaving it to Ethereum, Monero, Solana, or Zcash.

A paper released Thursday by cryptography research group [[alloc] init] proposes a way to bring private BTC transfers to Bitcoin’s base layer without a soft fork or a sidechain. The paper, titled Shielded Bitcoin, was written by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin.

Shielded Bitcoin paper proposes Zcash-style privacy on Bitcoin L1, but leaves peg mechanisms unresolved 2

The design takes the core ingredients of Zcash’s shielded pool — encrypted notes, public nullifiers, and zero-knowledge proofs — and repackages them as a metaprotocol that publishes data directly to Bitcoin. In this setup, Bitcoin itself acts as the public chain where the data is recorded.

How the proposed system works

Under the proposal, value is held in the form of encrypted notes. Transfers are made by publishing a data envelope through OP_RETURN. Each envelope contains an encrypted note for the recipient as well as a proof that the sender controls the inputs and has not inflated supply.

Indexers would monitor Shielded Bitcoin transfers on the Bitcoin blockchain, replay every envelope in block order, and discard the invalid ones.

The article contrasts the design with Shielded CSV, the closest prior proposal. In Shielded Bitcoin, all data remains on-chain, which means wallets could recover funds using only a seed phrase.

The limitation is stated plainly in the abstract: peg-in and peg-out — in other words, how BTC enters and exits the system — are outside the scope of the paper.

Released into a strong privacy-trading cycle

The paper lands as privacy-related assets are seeing a sharp run.

ZEC reached about $1,600 this week, giving it a market capitalization of roughly $26 billion and putting it ninth among cryptocurrencies. The token is up about 90% over the past 30 days and about 2,500% over the past year.

Several catalysts are cited. Grayscale’s Zcash ETF, ZCSH, launched on Aug. 25 and has taken in more than $250 million in net inflows so far. On Sept. 16, Paradigm co-founder Matt Huang disclosed that the firm holds ZEC and called Zcash a “privacy complement” to Bitcoin. The piece adds that Multicoin made a similar move earlier this year.

Shielded Bitcoin is an attempt to bring that privacy function onto Bitcoin itself. As things stand, users who want private digital transactions still have to turn to chains such as Ethereum, Monero, Solana, or Zcash, according to the article.

Citrea, Crest, and NEAR add to the privacy push

The day before the paper was released, Bitcoin layer-2 project Citrea, backed by Galaxy Ventures, acquired privacy-focused Bitcoin wallet Crest. Citrea said the deal was meant to “bring Zcash-style privacy to Bitcoin.”

The same demand is showing up elsewhere. NEAR recently announced default confidential perpetual contracts and confidential limit orders. NEAR is up more than 150% over the past month.

The article says the narratives around Zcash and NEAR are reinforcing each other, and that the Zcash wallet ZODL has already become one of the largest referral sources on NEAR Intents.

Shielded Bitcoin paper proposes Zcash-style privacy on Bitcoin L1, but leaves peg mechanisms unresolved 3

The unresolved issue is still the bridge in and out

The article argues that Shielded Bitcoin gives Bitcoin maximalists who dismissed ZEC’s rally something concrete to point to, because the design is tightly aligned with the idea of Zcash as a “privacy complement” to Bitcoin while depending only on Bitcoin.

But the hardest part of the system may sit outside this paper. Peg-in and peg-out — the mechanism for locking and releasing real BTC — are deferred to a future PIPEs v2 paper. Here, PIPEs refers to Polynomial Inner Product Encryption, not the fundraising mechanism used in DATs.

The authors do not claim that the entry and exit mechanism will be trustless or censorship-resistant. The article treats that omission as central. Cross-chain bridges have long been one of the most heavily attacked parts of crypto, and it lists Ronin, Wormhole, Nomad, and KelpDAO as examples.

It also notes that new zero-knowledge circuits need real-world testing. Zcash’s own Orchard pool, the article says, carried a reliability bug through four years of professional audits before developers responded with the Ironwood upgrade.

OP_RETURN policy is part of the story too

The proposed design also relies on the looser OP_RETURN relay policy introduced in Bitcoin Core v30. The article notes that many maximalists strongly opposed that change last year.

Whatever architecture wins out, the piece argues that demand for privacy in crypto looks sturdier than it did in previous cycles, partly because the threat model is changing quickly.

AI surveillance is sharpening the privacy debate

To illustrate the point, the article points to Flock Safety, which operates about 120,000 AI-equipped license-plate cameras across the United States.

Critics, it says, are concerned less with any single camera than with the network effect: police can run algorithms across the system and mark movement patterns as “suspicious.” After reports that officers had abused the system, the company cut its default data retention period from 30 days to seven.

The article then compares that environment with transparent blockchains, which are global, permanent, and freely queryable by anyone. Address clustering on-chain has been effective for years. The missing link has been tying public addresses to real identities, and advances in AI may weaken that barrier.

Earlier this year, researchers at ETH Zurich and Anthropic showed that large-model agents could re-identify pseudonymous Hacker News users with high accuracy using personal-profile information alone.

The article says it is not a stretch to expect that future AI systems could reconstruct a person’s full on-chain history using nothing more than a transaction hash posted on X or a withdrawal from a KYC exchange. Blockchains do not forget.

Grayscale made a similar case for ZCSH

The article closes by noting that Grayscale made much the same argument when it launched ZCSH: as AI changes how financial activity is monitored, demand for real financial privacy is likely to rise. In that framing, private transactions are a response to surveillance becoming more automated and more permanent.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.