Researchers propose Zcash-style Bitcoin privacy without soft fork
A metaprotocol called Shielded Bitcoin would hide transaction details using zero-knowledge proofs, without changing Bitcoin's consensus rules.
The short answer
Researchers at Alloc Init published a design for Shielded Bitcoin, which would hide transaction amounts, senders and receivers using encrypted notes and zero-knowledge proofs. The system would publish transfers on Bitcoin but have separate software verify them, avoiding the need for protocol changes.
What happened
Researchers at Alloc Init published a design for Shielded Bitcoin, a system that would hide transaction amounts, senders and receivers on Bitcoin's base layer. The 56-page paper, written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, borrows the encrypted-note approach from Zcash but builds it directly on Bitcoin without requiring a soft fork.
The system works by holding value in encrypted notes. When a user sends Bitcoin, their wallet publishes encrypted notes alongside a zero-knowledge proof that proves the sender controls the notes being spent and that amounts balance. Bitcoin records these transfers as data without verifying them, while separate software called indexers reads the transfers, verifies the proofs and tracks nullifiers, unique identifiers that prevent the same note from being double-spent.
Each transfer takes up 625 vbytes of block space with two inputs and two outputs. The current design uses the Groth16 proof system and relies on Bitcoin's OP_RETURN output format. Timing, fees and the number of inputs and outputs remain visible on the blockchain.
Why it matters
Bitcoin's ledger is public, making it possible to examine transaction amounts and trace links between wallets. Shielded Bitcoin would provide privacy comparable to Zcash by hiding who paid whom and how much, without requiring miners to enforce new consensus rules. Instead, the system uses Bitcoin as a publication layer while indexers handle verification, meaning no single party controls the ledger.
The proposal arrives as privacy tools gain institutional acceptance. Grayscale's Zcash ETF began trading on NYSE Arca on August 25, and 21Shares listed Europe's first Zcash exchange-traded product on Euronext Paris and Amsterdam on September 22. ZEC was trading at $1,592 on September 25, up 4% over the past 24 hours.
What is still unclear
- Developer Vadim Zavodil raised concerns about initial anonymity. He argued that a new shielded pool would start without the anonymity set Zcash has accumulated over years, meaning a user's first private transfer would hide in a crowd of one.
- Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group, said the construction is interesting but not quantum resistant. He said he was exploring what a fully post-quantum version could look like.
- Observers may still narrow down relationships between transfers if a small number of actors create most notes or wallets exhibit distinctive behavior. Transaction patterns and repeated publication fees could help identify links over time.
Questions readers ask
How does Shielded Bitcoin hide transaction details without a soft fork?
It publishes transfers as data on Bitcoin alongside zero-knowledge proofs. Separate indexer software verifies the proofs and tracks nullifiers to prevent double-spending, without requiring Bitcoin's consensus rules to change.
What information remains visible on the blockchain?
Timing, fees and the number of inputs and outputs stay public. Like Zcash, the system hides who paid whom and how much, but observers can still see that a shielded transfer happened.
What is the main criticism of Shielded Bitcoin's privacy?
A new system would start with zero anonymity set, meaning early transactions could be easier to trace. Observers may also narrow down relationships through transaction patterns and distinctive wallet behavior.
Is Shielded Bitcoin resistant to quantum computing attacks?
No. The current design is not quantum resistant, though researchers are exploring what a post-quantum version could look like if Bitcoin adopts a post-quantum signature scheme.
Sources
- 1 CointelegraphResearchers propose Zcash-style private Bitcoin transfers without a soft fork · 25 Sep, 04:41 UTC
- 2 DecryptResearchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers · 25 Sep, 09:50 UTC
- 3 CoinDeskBitcoin could soon get Zcash-style 'shielded' privacy without changing its rules · 26 Sep, 12:00 UTC
- 4 CryptoPotatoResearchers Propose Zcash-Style Privacy for Bitcoin Without a Soft Fork · 26 Sep, 21:44 UTC