Researchers at cryptography firm Alloc Init have proposed a method for bringing Zcash-style private transfers to Bitcoin without consensus changes to the underlying protocol.
The proposal, called Shielded Bitcoin, would conceal transaction amounts, senders, receivers, and links to previously spent funds using encrypted notes and zero-knowledge proofs. The paper was published by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin.
Technical Approach
Rather than requiring miners to enforce privacy rules, Shielded Bitcoin would use Bitcoin as a neutral publication and ordering layer. Separate software called indexers would verify zero-knowledge proofs, prevent double-spending, and maintain the state of the shielded system.
The design draws explicitly from Zcash's architecture, utilizing encrypted notes, public nullifiers that mark spent notes, and zero-knowledge proofs validating transactions. Unlike Zcash, Shielded Bitcoin would not operate its own blockchain or consensus mechanism.
Mixed Reception
The proposal has drawn both criticism and support from the cryptocurrency community. Developer Vadim Zavodil raised concerns about the anonymity set available to a newly launched system, noting that a brand new shielded pool would start without the privacy protections Zcash has accumulated over years of use.
The Shielded Bitcoin researchers acknowledged this limitation in accompanying materials, noting that large deposits do not automatically create a large anonymity set and that observers may still trace relationships between transfers if a small number of actors create most notes.
Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group, raised concerns about quantum resistance, though he indicated interest in exploring what a fully post-quantum version could entail.
Eli Ben-Sasson, co-author of the original Zerocash paper and CEO of StarkWare, expressed support for the proposal's direction, noting that the original vision behind Zerocash was to bring privacy to Bitcoin.


