Researchers propose Shielded Bitcoin for private transfers without a soft fork
Alloc Init proposes private transfers on Bitcoin
Researchers at the cryptography research firm Alloc Init have proposed a way to bring Zcash-style private transfers to Bitcoin without a soft fork. A soft fork is a change to a blockchain network's rules.
The proposal is called Shielded Bitcoin. According to the paper, it would hide transaction amounts, senders, receivers and links to previously spent funds. The paper was published on Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin.
Key points from the Shielded Bitcoin paper
- The system would use encrypted notes and zero-knowledge proofs to keep transaction details private.
- Bitcoin would act as "a neutral publication and ordering layer", the researchers wrote, instead of having miners enforce the privacy protocol.
- Separate software, called indexers, would verify zero-knowledge proofs, check that funds have not been double-spent, and rebuild the state of the shielded system.
- The design draws on Zcash, but unlike Zcash it would not run its own blockchain or consensus mechanism.
Critics question a brand-new privacy pool
Developer Vadim Zavodil criticized the proposal on X. He argued that much of its privacy stack had already been implemented by Zcash, and questioned how much privacy a newly launched system could provide at first, because a new shielded pool would start without the anonymity set Zcash has accumulated over years of use.
"Privacy is a function of the crowd. Zcash has a real shielded pool built over years," he wrote. "A brand new metaprotocol starts at zero, so your first private transfer hides in a crowd of one."
In a companion post explaining the proposal, the researchers acknowledged a similar limitation. They said large deposits do not automatically create a large anonymity set, and that observers may still be able to narrow down relationships between transfers if a small number of actors create most notes, or if wallets show distinctive behavior.
Quantum resistance called into question
Pierre-Luc Dallaire-Demers, founder of the post-quantum cryptography firm Pauli Group, raised a separate issue. He described the construction as interesting but "not quantum resistant at all". He later said he was exploring what a fully post-quantum version could look like, assuming Bitcoin eventually adopts a post-quantum signature scheme.
A Zerocash co-author backs the direction
Zerocash co-author and StarkWare CEO Eli Ben-Sasson was more supportive of the proposal's direction. Responding to Alloc Init's announcement, he said the original intent behind the Zerocash paper, which preceded Zcash, was to bring privacy to Bitcoin.
Ben-Sasson said he had not yet read the Shielded Bitcoin paper, but that he would like to see the vision of privacy and scalability through zero-knowledge proofs materialize on Bitcoin's base layer.
What is confirmed and what is still unclear
Confirmed: Alloc Init published the Shielded Bitcoin proposal, and the design details above come from that paper and the researchers' companion post. The comments from Zavodil, Dallaire-Demers and Ben-Sasson were published publicly.
Still unclear: the supplied material does not say whether Shielded Bitcoin will be built, tested or adopted, and it gives no timeline. It also does not show the privacy and quantum-resistance concerns being resolved.
Why the proposal matters
The researchers present Shielded Bitcoin as a possible route to stronger privacy for Bitcoin users without changing the base protocol or requiring a soft fork. That would place privacy features in separate software rather than in Bitcoin's own rules.
Critics argue that privacy depends on how many people use a system, not only on the cryptography behind it. The researchers themselves noted that a small number of users or unusual wallet behavior could weaken the privacy of transfers.