Researchers at cryptography firm alloc init proposed Shielded Bitcoin, Zcash-style privacy for BTC that stores encrypted transfers on-chain without a soft fork.
A group of researchers published a paper on Thursday describing a way to make bitcoin payments private without changing a single rule of the network. The system, called Shielded Bitcoin, borrows the encrypted payment design of Zcash and uses the Bitcoin blockchain as a public noticeboard for coded transfers rather than as the enforcer of payment rules.
The paper comes from Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm alloc init. It lands as privacy has moved back to the center of crypto conversation. Zcash, the most prominent privacy coin, has rallied more than 2,300 percent over the past year, crossed $1,000 in early September and pushed above $1,600 this week. Its shielded pools now hold about 4.9 million ZEC, roughly 29 percent of all issued coins, worth about $7.8 billion.
The timing is not accidental. Zcash recorded roughly 63,000 shielded transactions last week, its busiest week for private transfers since 2022 and the fourth-highest on record. Reported transfer volume across the network exceeded $23 billion, the largest weekly total since 2021. Money and attention are flowing toward privacy at exactly the moment Bitcoin researchers are asking whether the oldest chain can get some of it without a protocol war.
How the design works
Under Bitcoin’s current rules, every node checks every transaction against one shared rulebook. A payment that breaks the rules never makes it into a block, so a confirmation doubles as proof the network agreed the money was real and the sender owned it. The downside is total transparency: amounts and addresses sit on a public ledger forever, and once an address is linked to a person or company, their whole financial history becomes traceable.
Zcash solves this inside its own chain. Money is held in encrypted records called notes, like sealed envelopes only the owner can open. Spending a note publishes a nullifier, a unique tag marking the envelope as used without revealing which one. If the same tag appears twice, the second spend is rejected. Each transaction carries a zero-knowledge proof that the rules were followed without showing any details. A confirmed Zcash transaction has already passed the privacy rules.
Shielded Bitcoin keeps the notes and the proofs but changes who does the checking. Encrypted transfer data is written onto the Bitcoin blockchain as ordinary data, something Bitcoin already permits. Bitcoin records it, orders it and checks nothing. Separate software, which anyone can run, reads the chain, picks out shielded transactions, verifies the proofs and ignores anything invalid. Users can reconstruct accepted payments from the public record with their wallet keys, and separate viewing keys let them disclose transactions to an accountant or auditor without handing over spending power.
The paper describes this as Bitcoin serving as a noticeboard that pins up whatever it is given, in the order it arrives. Shielded Bitcoin pins up coded messages. Anyone with the right decoder can work out which messages are valid and who owns what. Everyone else sees only gibberish.
The missing piece and the catches
The biggest gap is getting money in and out. The paper explains how private transfers work once bitcoin is already inside the system, but not how real BTC would be locked up on entry or released on exit. Without that, the system moves a representation of bitcoin rather than the real thing. The firm says a second paper will address it with PIPEs, its technique for locking bitcoin in a vault that only a valid proof can open.
Other weaknesses are spelled out in the paper itself. The design needs a trusted setup, a one-off ceremony that generates cryptographic keys whose secret material must be destroyed; anyone who kept a copy could mint money undetected. Fees paid to Bitcoin remain visible, leaking some information. Each shielded transaction takes about four times the space of a normal payment, so it costs more to send. And privacy depends on scale: hiding among ten users protects far less than hiding among ten million. The system only becomes genuinely private if many people use it.
Critics have also pointed out a structural quirk. Because Bitcoin validates nothing, a Bitcoin transaction can be confirmed while the private payment recorded inside it fails Shielded Bitcoin’s own checks. Users would need to run or trust the separate verification software to know their payment actually settled, a responsibility Bitcoin itself never imposes today.
Why not just fork Bitcoin
The obvious alternative, building privacy into Bitcoin itself, would require a soft fork and broad agreement across a famously cautious community. Such changes can take years or never happen; past attempts to add privacy features to Bitcoin have stalled for years over both technical and political concerns. Shielded Bitcoin’s appeal is precisely that it sidesteps that fight. Its weakness is the flip side: without changing the rules, Bitcoin cannot guarantee any of it.
There is no launch date and no product. The paper is a detailed blueprint, and its hardest component, the bridge to real bitcoin, is not yet published. Still, it adds to a growing list of Bitcoin privacy research arriving as developers try to make crypto practical for payroll and business payments, where exposed amounts and addresses are a real commercial problem.
The connection between the two chains runs deeper than this week’s paper. Zcash grew out of the Zerocash research project, which itself built on earlier work on Bitcoin-adjacent privacy. Shielded Bitcoin is, in a sense, the research coming home: Zcash-style cryptography pointed back at the chain it originally tried to upgrade.
Whether anyone builds it is another question. The design asks users to accept higher fees, a trusted ceremony and reliance on off-chain software in exchange for privacy that Bitcoin’s own consensus does not enforce. That is a real trade, not a free upgrade. But as Zcash’s rally shows, demand for private payments is no longer theoretical, and the first credible way to bring it to Bitcoin without a fork is now on the table.
