Breaking
DEDAX rises thanks to hopes of relaxation in the Persian GulfCNAsian Games baseball rematch: Taiwan team vs. China team resultsFRVisit of Pope Leo XIV to France: speech at the Elysée and program of festivitiesDEFour injured after collision between tram and truck in DresdenARAmr Diab achieves a new Guinness record by topping the Arab Billboard for 69 weeks.DEStumbling block laying stop in Heidenau: criticism from Gunter DemnigRUUkraine lost the battle in the air due to the lack of specialists in the Armed Forces of Ukraine - Major KasyanovCRYPTO-TRList of crypto assets stolen in Bitget attack announcedFRThe Académie Goncourt removes Thélyson Orélien's novel from its selectionARSouth Africa is trying to break a world record for the largest number of people grilling food at the same timeDEDAX rises thanks to hopes of relaxation in the Persian GulfCNAsian Games baseball rematch: Taiwan team vs. China team resultsFRVisit of Pope Leo XIV to France: speech at the Elysée and program of festivitiesDEFour injured after collision between tram and truck in DresdenARAmr Diab achieves a new Guinness record by topping the Arab Billboard for 69 weeks.DEStumbling block laying stop in Heidenau: criticism from Gunter DemnigRUUkraine lost the battle in the air due to the lack of specialists in the Armed Forces of Ukraine - Major KasyanovCRYPTO-TRList of crypto assets stolen in Bitget attack announcedFRThe Académie Goncourt removes Thélyson Orélien's novel from its selectionARSouth Africa is trying to break a world record for the largest number of people grilling food at the same time
BackResearchers Publish Specification for Shielded Bitcoin Protocol
Researchers Publish Specification for Shielded Bitcoin Protocol
Tech
Decrypt1 hour agoTech2 min read

Researchers Publish Specification for Shielded Bitcoin Protocol

A new protocol proposal brings Zcash-style private transfers to the Bitcoin base layer without requiring consensus rule changes.

Quick Look

Researchers at [[alloc] init] published a 56-page paper detailing Shielded Bitcoin, a protocol enabling private transfers on Bitcoin's base layer using zero-knowledge proofs and encrypted notes.

AI-generated summary

Why It Matters

Researchers published a 56-page paper proposing a protocol for private transfers on the Bitcoin base layer without changing consensus rules.

Font size

In brief

Researchers at [[alloc] init] have published a specification for Shielded Bitcoin, a protocol for private transfers on the Bitcoin base layer.

The design borrows Zcash's encrypted notes and zero-knowledge proofs, and requires no changes to Bitcoin's consensus rules.

Mechanisms for moving BTC into and out of the shielded system are not covered and are due in a separate paper.

Researchers at Bitcoin cryptography developer [[alloc] init] have published a design for "ZCash-style" private transfers that would hide the sender, recipient and amount of a payment while running on the existing Bitcoin network.

The 56-page paper, dated September 24, 2026, is written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin.

The team has "put a lot of work into thinking carefully about the security of Shielded Bitcoin and about what information the protocol reveals," Shikhelman tweeted. Komarov called it "ZCash-style privacy on the Bitcoin L1 via PIPEs v2."

Scott Odell, chief operating officer of [[alloc] init], tweeted that the firm had been "cooking on this for quite a while," and described it as a contribution to making Bitcoin "private, without changing Bitcoin."

Value in Shielded Bitcoin is held as encrypted "notes," and each transfer carries a zero-knowledge proof that the sender controls the notes being spent and that inputs and outputs balance. A public marker called a nullifier lets software reject double spends without revealing which note was used.

Zcash enforces those rules through its own blockchain. Shielded Bitcoin publishes transfers as data on Bitcoin, which records them without checking them, while separate software called indexers verifies the proofs and rebuilds the shielded state.

The paper contrasts this with Shielded CSV, a 2025 Bitcoin proposal in which coin owners must keep their own transaction data, which generally cannot be recovered from the chain.

Timing, fees and the number of inputs and outputs remain public, the authors write. "Like Zcash and Monero, Shielded Bitcoin preserves the privacy of who paid whom and how much, not that a shielded transfer happened," the paper states.

Peg-in and peg-out

The paper covers only transfers inside the system. How BTC enters and leaves is left to a separate paper built on Bitcoin PIPEs v2, earlier [[alloc] init] research that encrypts a Bitcoin signing key so it can be recovered only with a valid proof, according to the firm's website.

The current version uses the Groth16 proof system, whose security depends on an honestly run trusted setup ceremony. It publishes each transfer in an OP_RETURN output, which comes to 625 vbytes for a transfer with two inputs and two outputs, according to the paper.

That relies on the larger OP_RETURN default in Bitcoin Core v30, a contested change that node operators can reverse, so relay depends on enough nodes and miners keeping it, the paper notes.

An appendix sketches an optional compliance layer in which a "Trust Authority" certifies approved deposits, letting institutions verify a note's origins without exposing the transfer graph. Notes without that evidence would remain valid.

Zcash, whose design Shielded Bitcoin borrows, now trades through regulated funds in the U.S. and Europe. Grayscale's Zcash ETF began trading on NYSE Arca on August 25, and 21Shares listed Europe's first Zcash exchange-traded product on Euronext Paris and Amsterdam on September 22.

What to Watch

AI outlook — possibilities, not facts

  • Publication of a separate paper detailing peg-in and peg-out mechanisms.

    Likely · Within months

Open Questions

  • How will the peg-in and peg-out mechanisms function?
  • Will node operators widely support larger OP_RETURN defaults?

Related Topics

This article was originally published by Decrypt.

Related Stories

Researchers propose Shielded Bitcoin to add Zcash-style privacy to Bitcoin without soft fork
Developing·

Researchers propose Shielded Bitcoin to add Zcash-style privacy to Bitcoin without soft fork

Researchers at Alloc Init proposed Shielded Bitcoin, a system to enable private Bitcoin transfers using encrypted notes and zero-knowledge proofs without requiring a protocol soft fork. The design leverages Bitcoin as a publication layer while relying on external indexers for validation, drawing both support and criticism over privacy limitations and quantum resistance.

Cointelegraph
2 min read
More on this topicshielded bitcoin