Bitcoin researchers propose Shielded Bitcoin for private transfers

Bitcoin researchers propose Shielded Bitcoin for private transfers

Shielded Bitcoin would hide who sends what

Researchers have proposed a way to make Bitcoin payments private without changing Bitcoin's core rules. The proposal, called Shielded Bitcoin, appears in a paper dated Sept. 24 from [alloc] init researchers Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin.

The design is described as a metaprotocol, meaning a set of rules built on top of Bitcoin instead of a change to Bitcoin itself. It aims to hide transaction amounts, senders, recipients, and the links between transfers, and it would not require a soft fork, which is a change to Bitcoin's rules.

The researchers say the system would extend Bitcoin privacy beyond existing tools such as CoinJoin, PayJoin, and Silent Payments, which can make tracing harder or reduce address reuse but still leave amounts and other details visible.

Main points from the Sept. 24 paper

  • Shielded Bitcoin adapts techniques first used by Zcash: encrypted notes, public nullifiers, and zero-knowledge proofs.
  • Bitcoin would publish and order the private transaction data, but miners and nodes would not check the shielded state.
  • The current design publishes transfer data through OP_RETURN, a way of writing data into a Bitcoin transaction, though the researchers say other methods are possible.
  • Two pieces are still missing: peg-in and peg-out, the routes for moving regular BTC into and out of the shielded system.
  • Bitwise Europe head of research André Dragosch described the proposal as a "potential headwind for privacy coins."

How the researchers say the system would work

Under the proposal, users would hold BTC value as encrypted notes. To send funds, the sender would publish an envelope containing encrypted outputs, public nullifiers that mark earlier notes as spent, and a zero-knowledge proof, a way of proving something is true without revealing the details. The proof would show ownership and that value is conserved, while the amount and the identities of the parties stay hidden.

Bitcoin miners and nodes would not validate the private state. Instead, software that follows the Shielded Bitcoin rules would scan Bitcoin blocks and replay accepted transfer envelopes in the order they were recorded, building a shared note tree and a set of spent notes. Bitcoin would supply the timestamped history and ordering, while the metaprotocol would handle encrypted balances and transfer verification.

This differs from Zcash, where the network's consensus rules enforce shielded transaction validity directly. Shielded Bitcoin would leave Bitcoin consensus untouched and derive a separate private state from data anchored to the chain.

Some information would still be visible. Transaction timing, fees, input and output counts, and features of the Bitcoin transaction carrying the encrypted data could still give observers clues. The paper also describes viewing capabilities that would let users disclose transaction information selectively, without giving up control of their funds, creating a route for auditing or compliance where required.

The missing piece: getting BTC in and out

The design is incomplete at one critical boundary: moving ordinary BTC into and out of the shielded system. Peg-in and peg-out mechanisms sit outside the current specification. Those parts would need to lock Bitcoin on mainnet, represent that value inside the private note system, and later release the corresponding BTC when users exit.

[alloc] init expects those flows to rely on its PIPEs v2 work, but the detailed construction has not been published yet. That leaves open questions about whether entry and exit can be made trustless, private, and resistant to transaction linkage. A distinctive deposit amount, withdrawal amount, or timing pattern could still connect activity at either end of the system. Other deployment choices are also unresolved, including the final proof system, the publication format, and how light clients can verify the shielded state without replaying the full relevant Bitcoin history.

Bitwise flags pressure on privacy coins

Samuel Callahan, director of strategy and research at Bitcoin treasury company OranjeBTC, said the proposal fits a view that Bitcoin can gain features without competing with other blockchains one feature at a time. He said people still misunderstand what makes Bitcoin hard to displace, arguing that privacy, speed, and functionality can be built over time and that its strengths are decentralization, security, and credible monetary policy.

Dragosch of Bitwise framed the design differently, calling it a potential headwind for privacy coins. In that view, features once tied to separate networks could increasingly be reproduced around Bitcoin without changing its monetary rules or base-layer consensus.

What is confirmed

The paper exists, is dated Sept. 24, and lists Shikhelman, Komarov, and Moskvin of [alloc] init as its authors. The paper describes a metaprotocol that would hide transaction amounts, senders, recipients, and links between transfers, and it states that no soft fork or change to Bitcoin's consensus rules is required. It also states that peg-in and peg-out are outside the current specification and that the detailed PIPEs v2 construction has not been published.

The statements from Callahan and Dragosch are their opinions as reported, not confirmed outcomes. Shielded Bitcoin is a proposal, not a live feature on Bitcoin.

What is still unclear

It is not known whether entry into and exit from the system can be made trustless, private, and resistant to linkage between deposits and withdrawals. The final proof system, the publication format, and how light clients would verify shielded state are also undecided. The paper leaves open the possibility of publication methods other than OP_RETURN.

Why this matters for privacy coins

Privacy-focused cryptocurrencies are again drawing investor attention, which revives a long-running debate about whether dedicated privacy networks keep a lasting technological edge over Bitcoin. CryptoSlate reported that ZEC, the Zcash token, climbed above $1,600 this week as shielded activity accelerated. Whether Bitcoin-based privacy would reduce demand for privacy coins is a claim made by Bitwise, not a confirmed result.

Sources

Newisty Editorial Team
Written by

Newisty Editorial Team

Technology · Crypto · Digital Economy
View all posts

Newisty Editorial Team covers technology, cryptocurrency, digital products, online platforms, developer tools and the wider digital economy. Our content is researched from official sources, company announcements, public documentation, market data and other primary or reputable sources. Articles are reviewed and edited before publication for clarity, accuracy and useful context.

Comments (0)

Leave a comment
Your comment will appear publicly after submission.
No comments yet. Be the first to comment!