0x428d47bd428d…428d47c0

ConfirmedInfrastructure608 vB63 sat/vB3 min decode

Shielded Bitcoin Paper Proposes Zcash-Style Privacy Without Fork

Researchers publish 56-page Shielded Bitcoin paper on September 24, 2026, hiding sender, recipient, and value on Bitcoin L1 without consensus changes. Peg-in mechanics deferred to a follow-up built on PIPEs v2.

Researchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers
WitnessResearchers Publish 'Zcash-Style' Design for Private Bitcoin TransfersAI-generated

Outputs

  1. 56-page paper dated September 24, 2026, authored by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin

  2. Protocol uses zero-knowledge proofs and encrypted notes; requires no Bitcoin consensus changes

  3. Each transfer with two inputs and two outputs weighs 625 vbytes in OP_RETURN, depending on Bitcoin Core v30's larger default

  4. Peg-in and peg-out mechanisms deferred to follow-up paper using Bitcoin PIPEs v2

  5. ZEC traded at $1,592 on September 25, up 4% over 24 hours, per CoinGecko

A 56-page research paper dated September 24, 2026, lays out a protocol called Shielded Bitcoin that would hide the sender, recipient, and value of each transaction while running on Bitcoin's existing base layer, according to Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of a Bitcoin cryptography research firm. The design borrows Zcash's encrypted notes and zero-knowledge proofs and, crucially, requires no consensus changes to Bitcoin.

What does the protocol actually do?

Shielded Bitcoin holds value as encrypted "notes." Each transfer carries a zero-knowledge proof that the sender controls the notes being spent and that inputs and outputs balance. A public marker called a nullifier lets software reject double spends without revealing which note was consumed.

Zcash enforces those rules on its own blockchain. Shielded Bitcoin instead publishes transfers as data on Bitcoin, which records them without validating the underlying proofs. Separate software called indexers then verifies the proofs and rebuilds the shielded state off-chain.

"Like Zcash and Monero, Shielded Bitcoin preserves the privacy of who paid whom and how much, not that a shielded transfer happened," the paper states.

What's still missing from the spec?

Mechanisms for moving BTC into and out of the shielded system remain unspecified. The authors defer peg-in and peg-out design to a follow-up paper built on Bitcoin PIPEs v2, earlier work from the same firm that encrypts a Bitcoin signing key so it can only be recovered against a valid zero-knowledge proof.

Shikhelman said the team "put a lot of work into thinking carefully about the security of Shielded Bitcoin and about what information the protocol reveals." Komarov characterized the project as "ZCash-style privacy on the Bitcoin L1 via PIPEs v2."

Scott Odell, chief operating officer of the firm, said the team had been working on the design for some time and described it as a contribution toward making Bitcoin private, without changing Bitcoin.

What are the technical trade-offs?

Several design choices surface in the paper:

  • Timing, fees, and the number of inputs and outputs remain public on-chain.
  • The system relies on the Groth16 proof system, whose security depends on an honestly run trusted setup ceremony.
  • A transfer with two inputs and two outputs occupies 625 vbytes inside an OP_RETURN output.
  • That payload size requires the larger OP_RETURN default introduced in Bitcoin Core v30, a contested change that node operators can still reverse.
  • Relay of shielded transfers therefore depends on enough nodes and miners continuing to accept the larger carrier output.

The authors contrast this with Shielded CSV, a 2025 Bitcoin proposal in which users must keep their own transaction data outside the chain.

Is there a compliance path?

An appendix sketches an optional "Trust Authority" that certifies approved deposits. Institutions could verify a note's provenance without seeing the wider transfer graph. Notes without Trust Authority evidence remain valid, preserving permissionless use alongside the regulated one.

Where does Zcash sit right now?

The viability of a Bitcoin analog will hinge in part on how the privacy-native asset it borrows from trades in regulated markets. ZEC stood at $1,592 on September 25, up 4% over 24 hours, with a seven-day high of $1,658.86, according to CoinGecko.

Grayscale's Zcash ETF began trading on NYSE Arca on August 25, and 21Shares listed Europe's first Zcash ETP on Euronext Paris and Amsterdam on September 22. Adoption of the Bitcoin design now turns on whether the follow-up peg-in paper and a critical mass of indexers arrive before node operators move to roll back the Bitcoin Core v30 OP_RETURN default that the protocol currently requires.

via allocinit.xyz (Original)

More from Marcus Bennett

Marcus Bennett

Show full bio

Senior reporter covering business strategy at Mempool Brief.

413 articles