A team of cryptography researchers has proposed a new system called Shielded Bitcoin that would bring Zcash-style privacy to $BTC transfers without touching Bitcoin's core protocol. The white
A team of cryptography researchers has proposed a new system called Shielded Bitcoin that would bring Zcash-style privacy to $BTC transfers without touching Bitcoin's core protocol.
The white paper was authored by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of New York-based research firm [alloc] init. The proposal outlines a novel privacy metaprotocol on the Bitcoin base layer designed to enable shielded transactions without requiring operators, soft forks, or other changes to Bitcoin consensus.
How It Works
The proposal would conceal transaction amounts, senders, receivers, and links to previously spent funds using encrypted notes and zero-knowledge proofs. Instead of having miners enforce the privacy protocol, Shielded Bitcoin would use Bitcoin as a neutral publication and ordering layer.
The design explicitly draws from Zcash's architecture, using encrypted notes, public nullifiers that mark notes as spent, and zero-knowledge proofs that verify transactions are valid. Unlike Zcash, however, Shielded Bitcoin would not operate its own blockchain or consensus mechanism.
Programs called indexers scan Bitcoin for Shielded Bitcoin data, verify its cryptographic proofs, and reconstruct the private system's history. Invalid data can still land on-chain because Bitcoin does not understand the metaprotocol. Indexers simply ignore it. Anyone can rerun those checks using Bitcoin's published history, meaning no single indexer decides what is valid.
Wallets would generate separate spending and viewing keys, allowing users to transact privately while selectively disclosing transaction details.
Open Questions and Limitations
The proposal is not without gaps. Getting bitcoin in and back out of the shielded system is being left to a companion white paper based on [alloc] init's Bitcoin PIPEs v2 research and witness encryption. Witness encryption remains young technology. Komarov noted its ciphertexts have been reduced from roughly 300 terabytes to about 8 terabytes in a year, significant progress, but still far from practical. "It's still pretty experimental," Komarov said.
Developer Vadim Zavodil pointed out that the system starts with no established anonymity pool, meaning few early participants make it easier for outside observers to trace transaction relationships, a limitation the researchers themselves acknowledged. Pierre-Luc Dallaire-Demers, founder of Pauli Group, also noted the proposal lacks quantum resistance and expressed interest in working on a post-quantum version of the system.
Shikhelman was scheduled to present the research at BitDevs NYC on September 24 as [alloc] init sought feedback ahead of its companion white paper on entry and exit. Until that piece of the puzzle is solved, Shielded Bitcoin remains research rather than a usable privacy system.
Sources:Bitcoin.com News: Shielded Bitcoin Proposal Aims to Bring Privacy to Bitcoin L1CoinTelegraph: Researchers Propose Zcash-Style Bitcoin Privacy Without Soft ForkCrypto Times: Researchers Propose Shielded Bitcoin for Private L1 Transfers