Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Researchers propose Zcash-style privacy for Bitcoin without soft fork
00

Researchers propose Zcash-style privacy for Bitcoin without soft fork

Sep 24, 2026

Researchers Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of cryptography firm [[alloc] init] have proposed Shielded Bitcoin, a metaprotocol designed to bring Zcash-style private transactions to the Bitcoin base layer. The system uses zero-knowledge proofs and encrypted notes to conceal transaction amounts and counterparty identities without requiring a soft fork or consensus changes. Instead, separate indexer software verifies transactions while Bitcoin acts as a neutral ordering layer. The design currently lacks a finalized pegging mechanism, which researchers plan to address in a future paper using PIPEs v2 witness encryption.

Core architecture of Shielded Bitcoin

  • ▪Researchers Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of cryptography firm [[alloc] init] published a 56-page whitepaper on September 24, 2026, proposing a novel privacy metaprotocol called Shielded Bitcoin
  • ▪The Shielded Bitcoin metaprotocol, proposed by [[alloc] init] researchers, enables private transactions directly on the Bitcoin base layer without requiring a soft fork, consensus changes, or a separate blockchain
  • ▪[[alloc] init]'s Shielded Bitcoin adapts Zcash's architecture, using encrypted notes, public nullifiers to prevent double-spending, and zero-knowledge proofs to conceal transaction amounts, senders, and recipients
  • ▪Under [[alloc] init]'s Shielded Bitcoin proposal, Bitcoin miners and nodes do not validate the shielded state, acting instead as a neutral publication and ordering layer while separate indexer software verifies transactions

Transaction size and data requirements

  • ▪The current implementation profile of [[alloc] init]'s Shielded Bitcoin uses the Groth16 proof system and publishes encrypted transfer data on-chain using Bitcoin's OP_RETURN output
  • ▪Misha Komarov stated that each Shielded Bitcoin transaction would carry an encrypted note of about 700 vbytes, making it roughly four times larger than a typical Bitcoin transaction and increasing miner fees by the same multiple
  • ▪[[alloc] init]'s Shielded Bitcoin whitepaper notes that publishing transfers via OP_RETURN requires 625 vbytes for a two-input, two-output transaction, relying on the larger default OP_RETURN size introduced in Bitcoin Core v30

Proposed pegging mechanism

  • ▪Misha Komarov stated on September 10, 2026, that [[alloc] init] had reduced the size of the witness encryption files used in its Bitcoin PIPEs scheme to approximately 8 terabytes, down from roughly 300 terabytes within the past year
  • ▪[[alloc] init]'s Shielded Bitcoin proposal does not yet define the peg-in and peg-out mechanisms for moving BTC into and out of the shielded system, leaving these details for a future paper
  • ▪The planned pegging mechanism for [[alloc] init]'s Shielded Bitcoin is intended to rely on [[alloc] init]'s PIPEs v2, a witness encryption scheme that locks a Bitcoin signing key without requiring a third-party custodian

Auditing and compliance

  • ▪[[alloc] init]'s Shielded Bitcoin proposal includes viewing capabilities that allow users to selectively disclose transaction information for auditing without surrendering control of their funds
  • ▪An appendix in [[alloc] init]'s Shielded Bitcoin whitepaper outlines an optional compliance layer where a Trust Authority certifies approved deposits, allowing institutions to verify a note's origins without exposing the transfer graph

Criticisms and privacy limitations

  • ▪[[alloc] init]'s Shielded Bitcoin whitepaper and blog post caution that transaction timing, fees, input and output counts, and distinctive wallet behaviors could still allow observers to narrow down relationships between transfers
  • ▪Developer Vadim Zavodil criticized [[alloc] init]'s Shielded Bitcoin proposal, arguing that a brand-new metaprotocol starts with an anonymity set of zero, unlike Zcash which has accumulated a large shielded pool over years of use

Debatable claims

  • ▪Bitcoin-based privacy protocols will make dedicated privacy coins obsolete
  • ▪Shielded Bitcoin's initial lack of an anonymity set undermines its privacy value
  • ▪Bitcoin privacy protocols should exclude optional compliance layers
  • ▪Implementing privacy via off-chain indexers is an acceptable compromise for Bitcoin

6 sources

Cointelegraph
Researchers Propose Zcash-Style Bitcoin Privacy Without Soft Fork
View source article
Decrypt
Researchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers - Decrypt
View source article
Bitcoin Magazine
[[alloc] Init] Releases Shielded Bitcoin Proposal For Private Bitcoin Transactions
View source article
Bankless
Alloc Init Proposes Zcash-Style Privacy for Bitcoin
View source article
CryptoSlate
Bitcoin researchers target privacy coins with Zcash-style shielded transfers
View source article

Featured stories

Foundry Launches Zcash Mining Pool, Reaches 30% Network Hashrate

Apr 13, 2026 · 2 sources

Story comments

Loading comments…

Related Projects

BitcoinZcash

Topics

Bitcoin protocol & upgradesZero-knowledge proofsPrivacy coinsBitcoin privacyBitcoin

Featured stories

Foundry Launches Zcash Mining Pool, Reaches 30% Network Hashrate

Apr 13, 2026 · 2 sources