A New York cryptography lab has proposed Zcash-style private transfers on Bitcoin without changing Bitcoin itself. Published on Thursday by [[alloc] init], Shielded Bitcoin would hide amounts and counterparties without a soft fork, separate blockchain, federation or trusted operator. Bitcoin would simply store and order encrypted data that it cannot understand, while outside software verifies the payments. There is one big catch. The researchers have not yet finished the mechanism for moving bitcoin into and out of the private system.
Key Takeaways
- The cryptography lab [[alloc] init] unveiled Shielded Bitcoin on Sept. 24, bringing the idea of private transfers to Bitcoin without a soft fork.
- Shielded Bitcoin transfers run about 700 vbytes, roughly 4 times the size of a typical BTC payment.
- [[alloc] init] still has work ahead, with a 2nd white paper set to explain how bitcoin gets in and back out.
Bitcoin’s transaction history is famously public. Send bitcoin (BTC) and the payment joins a ledger anyone can inspect, potentially forever. The New York lab [[alloc] init] is proposing a counterintuitive workaround. Leave Bitcoin’s rules alone and build privacy on top of them. Shielded Bitcoin uses encrypted notes and zero-knowledge (ZK) proofs to conceal amounts and counterparties, while Bitcoin acts almost like a public bulletin board.
The network records encrypted messages in the correct order without knowing what they mean. No soft fork is required, and there is no operator deciding which private transfers count. Bitcoin could end up carrying private payments that Bitcoin itself cannot read.
Bitcoin Becomes a Bulletin Board
The white paper, “Shielded Bitcoin: Private Transfers on the Bitcoin L1,” was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin. The researchers ask whether bitcoin can move privately using the network exactly as it exists today. Their answer is a metaprotocol whose rules are interpreted by independent software rather than Bitcoin consensus.
Programs called indexers scan Bitcoin for Shielded Bitcoin data, verify its cryptographic proofs and reconstruct the private system’s history. Invalid data can still land onchain because Bitcoin doesn’t understand the metaprotocol. Indexers simply ignore it. Anyone can rerun those checks using Bitcoin’s published history, meaning no particular indexer gets to decide what is valid. That is the fascinating part. Bitcoin keeps doing what it has always done, as another set of rules makes sense of selected data riding on top.
Alice Pays Bob Without Showing the Amount
Value inside Shielded Bitcoin lives in encrypted records called notes. If Alice pays Bob, she creates a note containing an amount and Bob’s receiving information, then encrypts it so Bob can identify it. Her bitcoin transaction publishes the encrypted note alongside a serial number called a nullifier and a zero-knowledge proof.
The proof establishes that Alice’s notes exist, she can spend them and the value going in equals the value coming out without revealing which notes were spent or their amounts. Indexers verify the proof and ensure each nullifier hasn’t previously appeared. Once used, that nullifier cannot be used again, preventing the same note from being spent twice. Bob’s wallet scans new encrypted notes until his viewing key opens one.
Onchain the public still sees that a shielded transfer happened, its timing, the number of notes involved, its fee and the bitcoin transaction carrying it. What disappears are the amount, shielded sender and recipient, and the connection to previously spent notes. A recognizable bitcoin address repeatedly paying transaction fees could still leak clues, and a small number of users would make the crowd easier to analyze.
Privacy also costs block space. Komarov told journalist Laura Shin in an interview that a shielded payload is about 700 vbytes compared with roughly 100 to 200 for a typical Bitcoin payment, making it around four times larger. Komarov called the added cost “not catastrophic.” More users, meanwhile, would strengthen the anonymity set by giving individual payments a larger crowd to disappear into.
The Biggest Problem Is the Door
Here’s the catch. The Sept. 24 white paper describes transfers after bitcoin is already inside the shielded system. Getting bitcoin in and back out is being left to a companion white paper based on [[alloc] init]’s Bitcoin PIPEs v2 research and witness encryption.
The planned system would cryptographically lock a BTC private key until someone produces the required proof, while the Bitcoin network ultimately sees an ordinary Schnorr spend. [[alloc] init] says it would never custody user funds, even at the boundary. But witness encryption is young technology. Komarov said its ciphertexts have been reduced from roughly 300 terabytes to about 8 terabytes in a year. That is enormous progress, but eight terabytes is still eight terabytes. “It’s still pretty experimental,” Komarov explained.
Entry and exit could also expose amounts and timing that help observers link outside Bitcoin activity with shielded transactions. The lab has run public break-it challenges since May, but there is no launch date. Until the door works, Shielded Bitcoin remains research rather than a usable privacy system.
Bitcoin and Zcash Communities Weigh In
The Zcash influence is obvious. Zcash already uses encrypted notes, nullifiers and zero-knowledge proofs, while Shielded Bitcoin borrows that architecture without creating another blockchain. Public company Cypherpunk called Shielded Bitcoin “a great step forward” and further remarked that more privacy on Bitcoin benefits everyone.
But Cypherpunk also argued the design isn’t yet a competition for the Zcash chain. The firm pointed to its trusted setup, lack of consensus enforcement and trustless light clients, an unfinished bridge, and Bitcoin L1 fees, while noting Zcash already has nearly 10 years in production and a shielded pool worth more than $7 billion. “Financial privacy isn’t zero-sum,” Cypherpunk concluded.
X reactions quickly became less diplomatic. Joe Burnett wrote “zcash to 0,” while Daniel Buchner, director of product and director of digital assets at Proof, shared his two cents saying:
“The amount of privacycoin stans having cope-induced seizures from the mere thought that the Bitcoin community is progressing down the path of private transactions, potentially Thanos snapping the narratives of one-off privacy chains, is approaching a decibel level where ear damage is becoming a concern.”
Sam Callahan, director of strategy and research at OranjeBTC, offered a broader argument. “People still misunderstand Bitcoin’s moat. Bitcoin doesn’t need to win every feature race. Privacy, speed, and functionality can be built over time. The moat is its decentralization, security, and credible monetary policy. And on those dimensions, nothing else comes close.”
The X account Rune brought the privacy-coin rivalry back to earth with a reference to the Bitget hack and monero (XMR), writing on X, “ZEC holders praying the Bitget hacker uses zcash to hide the trace… but for some reason hacker is using XMR.” Behind the trash talk is a real technical debate over whether the Bitcoin blockchain can acquire stronger privacy without changing its base rules.
Bitcoin Carries Secrets It Cannot Read
Unlike Satoshi’s white paper, Shielded Bitcoin is a specification, not a product. The peg remains unfinished, witness encryption is experimental, fees can leak information, wallets need to become practical and privacy improves only when enough users participate. The current Groth16 proof design also requires a one-time trusted setup.
Shikhelman was scheduled to present the research at BitDevs NYC on Sept. 24 as [[alloc] init] sought feedback ahead of its companion white paper on entry and exit. The next workaround will determine whether the private system described on paper can connect safely to actual bitcoin.
For now, the idea is wonderfully counterintuitive. [[alloc] init] wants Bitcoin to record private financial activity without changing Bitcoin or asking the network to understand what it is recording. If the unfinished pieces work, Bitcoin could preserve transactions forever while remaining blind to the amounts and counterparties that made those transactions worth hiding in the first place.
Author: Jamie Redman
Source: Bitcoin
Reviewed By: Editorial Team