Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,000▲ 0.18%ETH$2,689▲ 0.68%SOL$120.47▲ 3.89%TOTAL CRYPTO$2.89T▼ 2.30%S&P 5007,743.41▲ 0.86%NASDAQ27,068.72▲ 3.51%DOW51,828.62▼ 3.26%GOLD4,321.20▼ 7.95%WTI92.41▲ 12.20%BRENT97.44▲ 10.00%EUR/USD1.1400▼ 2.30%USD/JPY157.19▼ 1.23%DXY101.04▲ 2.14%
Crypto

Researchers Propose Shielded Bitcoin Using Zcash Privacy Tech

A new paper borrows Zcash's encrypted payment design to hide bitcoin amounts and counterparties without changing network rules, though key gaps remain unsolved.

Pexels – Leeloo The First

A group of researchers has proposed a design for private bitcoin payments that borrows Zcash’s encrypted transaction model while leaving Bitcoin’s consensus rules untouched, according to a paper published Thursday. The 56-page specification, called Shielded Bitcoin, describes how bitcoin-denominated transfers could hide amounts, senders and recipients, but leaves the hardest problem unsolved: how actual bitcoin enters and leaves the system.

The paper comes from Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm alloc init. It lands amid renewed interest in privacy coins, with Zcash’s shielded pools holding about 4.9 million ZEC as of Friday, up 14 percent from July 30, roughly 29 percent of all issued coins and worth about $7.8 billion after a year in which ZEC gained more than 2,300 percent and crossed $1,600 on Wednesday.

How the design works

Zcash lets users choose between transparent payments, whose addresses and amounts are public, and shielded payments that encrypt those details. Its blockchain verifies the zero-knowledge proofs attached to shielded transactions as part of consensus.

Shielded Bitcoin takes a different route. Encrypted transfer records, called notes, would be published inside ordinary Bitcoin transactions. Spending a note publishes a marker showing it has been used, along with a mathematical proof that the sender owned the funds and did not create new ones. The amount, sender and recipient stay hidden. Because Bitcoin’s own validators do not check those proofs, verification falls to separate software that anyone can run and reconstruct from the public record using wallet keys.

That split creates the design’s central weakness. A Bitcoin transaction can be confirmed even if the private payment recorded inside it fails Shielded Bitcoin’s own checks. In practice that means the system’s guarantees are only as good as the off-chain software verifying them, a departure from how Bitcoin normally settles value. Separate viewing keys would let users disclose transactions to an accountant or auditor without handing over spending control, a feature aimed at compliance-sensitive users.

What is missing

The specification does not explain how ordinary BTC would be locked into the system or released on withdrawal. The authors reserve those mechanisms for a follow-up paper using PIPEs, a technique designed to hold a Bitcoin signing key until specified conditions are met. Their claim that users retain control of funds covers transfers inside the system and explicitly excludes deposits and withdrawals.

Critics were quick to point at the gap. One reviewer wrote that with no in-protocol mechanism for getting actual BTC in or out, users would effectively be holding synthetics. The reference design also depends on a trusted cryptographic setup whose security requires at least one participant to have acted honestly during generation, a known sore point in zero-knowledge systems.

Costs are higher too. Komarov estimated a private transfer at roughly 700 virtual bytes against 100 to 200 for an ordinary bitcoin transaction, putting miner fees at about four times the equivalent rate. Transfer timing and fee payments remain visible, so outside observers can still correlate activity even when amounts are hidden. There is no launch date.

Why privacy is back on the agenda

The proposal arrives as on-chain privacy has become both a market story and a policy story. Zcash recorded roughly 63,000 shielded transactions last week, its busiest week for private transfers since 2022 and fourth-highest on record, with reported transfer volume above $23 billion, the largest weekly total since 2021.

Regulators have moved the other way. European Union rules under MiCA require transfers involving identified parties to carry sender and recipient data, and several exchanges have delisted privacy coins outright. Bitcoin developers have debated privacy upgrades for a decade, from CoinJoin mixing to taproot’s script privacy, none of which conceal amounts.

The connection to Bitcoin goes back further than this week. Zerocoin was proposed as a Bitcoin privacy extension in 2013, and the follow-on Zerocash research became Zcash, which launched as a separate chain in 2016. Shielded Bitcoin is in effect a return of that lineage to its original host, made plausible by years of work on proof verification outside consensus.

The hard part is still the bridge

Privacy researchers have generally agreed that encrypted payments inside Bitcoin are feasible on paper. The unsolved problem is custody of the underlying coins without introducing a trusted party, which is exactly the problem PIPEs are meant to address and exactly what this paper defers. Until that follow-up lands, Shielded Bitcoin remains a specification, not a deployable protocol.

Even a complete design would face practical hurdles. Wallet support, fee market dynamics for larger transactions, and the political sensitivity of built-in privacy on Bitcoin’s base layer all sit between the paper and any production system. Bitcoin’s improvement process moves slowly by design, and anything touching consensus-adjacent behavior tends to take years.

For now the paper’s contribution is to show the shape of a possible design rather than a shipping one. The authors acknowledge the limits themselves, listing lightweight wallet verification and fee anonymization as future work alongside the deposit and withdrawal mechanisms.

The market context matters for how the paper is received. ZEC’s rally has drawn speculative capital into privacy assets at a moment when Bitcoin itself is consolidating near $84,000 under pressure from rising Treasury yields. Research that links the two narratives tends to travel quickly through trading desks even when, as here, the authors caution that the system is nowhere near deployment.

SourcesCoinDesk (Sept 26); Shielded Bitcoin paper, alloc init; ZecStats data via CoinDesk
Share: X