Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
Bitcoin could soon get Zcash-style 'shielded' privacy without changing its rules
Researchers have mapped out private bitcoin-denominated transfers that run alongside Bitcoin, but the system still lacks a finished way to lock up real BTC and release it again.
Researchers proposed Shielded Bitcoin, a system modeled on Zcash that could conceal payment amounts, senders and recipients without changing Bitcoin’s network rules. The proposal would store encrypted transfers on Bitcoin but rely on separate software to verify them, meaning a Bitcoin transaction could be confirmed even if the private payment failed its own checks. The research remains preliminary, with no launch date or mechanism for depositing and withdrawing bitcoin, while critics also cite visible fees, higher transaction costs and reliance on a trusted cryptographic setup.
A group of researchers floated a way to make bitcoin payments more private without changing the network’s rules, as privacy-focused cryptocurrencies led by Zcash attract renewed investor interest.
The Shielded Bitcoin paper, published on Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm [alloc] init, borrows the encrypted payment design used by Zcash.
Inside the proposed system, bitcoin-denominated value would be held in encrypted records called notes. Spending one would publish a marker showing it had been used, along with a mathematical proof that the sender owned the funds and had not created new ones. The amount, sender and recipient would remain hidden.
Zcash’s blockchain checks those proofs itself. Shielded Bitcoin would publish the transfer data on Bitcoin and leave the checks to separate software that anyone could run. A Bitcoin transaction could therefore be confirmed while the private payment recorded inside it failed Shielded Bitcoin’s checks.
Privacy has become a practical concern in recent months as developers try to make cryptocurrencies useful for payroll, business payments and everyday spending. Ordinary bitcoin transactions permanently expose amounts and addresses, but once an address is linked to a company or person, other payments associated with it become easier to follow.
Ethereum is also reviewing a proposal for a shared private pool that would let people transfer ether and other tokens without publicly revealing payment details. Its authors cite payroll, treasury management and donations among the uses poorly served by fully public transactions.
How Zcash works
Zcash lets users choose between transparent payments, whose addresses and amounts are public, and shielded payments that encrypt those details. Its shielded pools held about 4.9 million ZEC on Friday, up 14% from July 30, according to CoinDesk calculations using ZecStats data. That represents roughly 29% of issued coins, worth about $7.8 billion following the rally.
Zcash recorded roughly 63,000 shielded transactions last week, its busiest week for private transfers since 2022 and fourth-highest on record. Across the network, reported transfer volume exceeded $23 billion, the largest weekly total since 2021 and second-highest in its history.
Zcash has attracted both investor money and attention amid those metrics. By early September, ZEC had gained more than 2,300% over the preceding year and crossed $1,000. It extended the rally above $1,600 on Wednesday.
The connection to Zcash goes back further than Thursday’s paper. Zerocoin was proposed as a privacy extension to Bitcoin in 2013, the subsequent Zerocash research developed into Zcash, which launched as a separate cryptocurrency in 2016.
Shielded Bitcoin would keep the encrypted transfer data on Bitcoin so users could reconstruct accepted payments from the public record using their wallet keys. Separate viewing keys would allow them to disclose transactions to an accountant or auditor without handing over permission to spend their funds.
Unanswered questions
The 56-page specification does not explain how ordinary BTC would enter that system or be released when someone wanted to withdraw. The authors reserve those mechanisms for a separate paper using PIPEs, a technique designed to lock a Bitcoin signing key until specified conditions are met. Their claim that users retain control of their funds covers transfers inside the system and explicitly excludes deposits and withdrawals.
Meanwhile, the omissions have drawn criticism from developers and Zcash supporters.
Mert Mumtaz, cofounder of Helius, which provides infrastructure for Solana developers, and a Zcash proponent, described the proposal on X as “a synthetic ledger with significant tradeoffs.”
He pointed to “a trusted setup” and “no fee anonymization,” meaning the Bitcoin wallet paying to publish a private transfer could still be visible. He also criticized the absence of a deposit and withdrawal mechanism, writing that there was “no in-protocol mechanism for getting actual BTC in or out (which means you are holding synthetics).”
“I respect that people are working on this and taking notes from zcash finally,” he wrote, adding that the proposal would require years of additional research and development.
Cypherpunk, a company that holds and mines Zcash, welcomed the research but did not perceive it as competition for the existing network. “Privacy works best when built into the base layer. Not requiring Bitcoin changing is this design's biggest selling point, and also its biggest drawback,” the company wrote.
“More privacy on Bitcoin is good for everyone,” it added.=
Meanwhile, [alloc] init acknowledges several of those limits. Their reference design used in the paper requires a cryptographic setup whose security depends on at least one participant acting honestly. Transfer timing and fee payments remain visible, while an efficient way for lightweight wallets to verify the reconstructed payment history is listed as future work.
Komarov estimated a private transfer at roughly 700 virtual bytes, against 100 to 200 for an ordinary bitcoin transaction, putting miner fees at about four times as much at an equivalent fee rate.
There is no launch date for the system as of Friday.
Read More: Zcash seals $1.7 billion shielded pool as Ironwood upgrade activates
1XRP Ledger’s Batch upgrade slips to Oct. 9 after validator support resets20 minutes ago 2U.S. SEC's steadiest crypto advocate, Hester Peirce, to depart next week6 hours ago 3Another appeals court rules against prediction market provider Kalshi, says sports contracts are subject to state regulations7 hours ago 4Blockchain Association sees leadership shift shortly after crypto Clarity Act fizzles8 hours ago 5Circle and Tether step in to freeze hacker wallet after massive Bitget crypto heist14 hours ago 6Tokenization is moving faster than Washington14 hours ago 7Tether confirms minimal EQIBank exposure following $89M US asset seizure14 hours ago 8Strategy proposes daily dividends to bring STRC back toward $10014 hours ago 9Bond volatility surges while bitcoin and Wall Street stay calm16 hours ago 10Bitcoin holders are cashing out, just not the way they did at prior market tops17 hours ago
The Definitive Stablecoin Landscape Series: Asia Pacific
The Definitive Stablecoin Landscape Series: Asia Pacific
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
Why it matters:
As stablecoins move into regulated finance, APAC is becoming a key proving ground. This report maps the region’s rules, use cases, and RLUSD’s role.
XRP Ledger’s Batch upgrade slips to Oct. 9 after validator support resets
Live updates: Oil back on the rise as Iran denies report of deal talks
EU financial watchdogs warn quantum computing poses imminent threat to blockchain encryption
GoTyche