Shielded Bitcoin Proposal Aims to Bring Privacy to Bitcoin L1 Without Changing Its Rules
Key Takeaways
- •Shielded Bitcoin, proposed by the [[alloc] init] research lab in a Sept. 24 white paper by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin, would enable private transfers on Bitcoin's base layer using encrypted notes, nullifiers, and zero-knowledge proofs without any soft fork.
- •Independent indexers rather than Bitcoin consensus validate the metaprotocol, allowing anyone to recheck validity against the public blockchain while the network itself cannot interpret shielded payments.
- •A shielded payload occupies about 700 vbytes compared with roughly 100 to 200 vbytes for a typical bitcoin payment, meaning users bear roughly four times the block space cost at the point of transfer.
- •Getting bitcoin into and out of the shielded system remains unsolved and is deferred to a white paper, as witness encryption—despite ciphertexts shrinking from roughly 300 terabytes to 8 terabytes in a year—is still experimental.
- •Cypherpunk praised the proposal as a step forward but cited its trusted setup, lack of consensus enforcement and trustless light clients, and unfinished bridge, arguing it is not yet a rival to Zcash, which has nearly 10 years in production and a shielded pool exceeding $7 billion.

Bitcoin's transaction history is famously public. When someone sends bitcoin ($BTC), the payment lands on a ledger that anyone can inspect, potentially forever. The New York research lab [[alloc] init] has proposed a counterintuitive answer to that exposure: leave Bitcoin's rules untouched and build privacy on top of them.
The proposal, called Shielded Bitcoin, uses encrypted notes and zero-knowledge (ZK) proofs to conceal amounts and counterparties, while Bitcoin functions almost like a public bulletin board. The network records encrypted messages in the correct order without knowing what they mean. No soft fork is required, and no operator decides which private transfers count. In effect, Bitcoin could end up carrying private payments that Bitcoin itself cannot read. Whether that separation from consensus is a strength or a weakness is precisely what the debate around the proposal is about.
Bitcoin Becomes a Bulletin Board
The white paper, "Shielded Bitcoin: Private Transfers on the Bitcoin L1," was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin. The researchers set out to determine whether bitcoin can move privately using the network exactly as it exists today. Their answer is a metaprotocol whose rules are interpreted by independent software rather than by Bitcoin consensus.
Programs called indexers scan Bitcoin for Shielded Bitcoin data, verify its cryptographic proofs and reconstruct the private system's history. Invalid data can still land onchain, because Bitcoin does not understand the metaprotocol; indexers simply ignore it. Anyone can rerun those checks against Bitcoin's published history, meaning no single indexer gets to decide what is valid. That is the fascinating part of the design. Bitcoin keeps doing what it has always done, while another set of rules makes sense of selected data riding on top.
Alice Pays Bob Without Showing the Amount
Value inside Shielded Bitcoin lives in encrypted records called notes. If Alice pays Bob, she creates a note containing an amount and Bob's receiving information, then encrypts it so that only Bob can identify it. Her bitcoin transaction publishes the encrypted note alongside a serial number called a nullifier and a zero-knowledge proof.
The proof establishes that Alice's notes exist, that she is entitled to spend them and that the value going in equals the value coming out — without revealing which notes were spent or their amounts. Indexers verify the proof and confirm that each nullifier has not previously appeared. Once used, a nullifier cannot be used again, preventing the same note from being spent twice. Bob's wallet scans new encrypted notes until his viewing key opens one.
Onchain, the public still sees that a shielded transfer occurred, its timing, the number of notes involved, its fee and the bitcoin transaction carrying it. What disappears are the amount, the shielded sender and recipient, and the link to previously spent notes. Even so, a recognizable bitcoin address repeatedly paying transaction fees could still leak clues, and a small number of users would make the crowd easier to analyze.
Privacy also costs block space. Komarov told journalist Laura Shin in an interview that a shielded payload runs about 700 vbytes, compared with roughly 100 to 200 vbytes for a typical Bitcoin payment — around four times larger. Because Bitcoin fees scale with transaction size, that overhead is paid directly at the point of transfer. Komarov described the added cost as "not catastrophic." More users, meanwhile, would strengthen the anonymity set by giving individual payments a larger crowd to disappear into.
The Biggest Problem Is the Door
There is a catch. The Sept. 24 white paper describes transfers only after bitcoin is already inside the shielded system. Getting bitcoin in and back out is being left to a companion white paper based on [[alloc] init]'s Bitcoin PIPEs v2 research and witness encryption.
The planned system would cryptographically lock a $BTC private key until someone produces the required proof, while the Bitcoin network ultimately sees an ordinary Schnorr spend. [[alloc] init] says it would never custody user funds, even at the boundary. But witness encryption is young technology. Komarov said its ciphertexts have shrunk from roughly 300 terabytes to about 8 terabytes in a year. That is enormous progress, but eight terabytes is still eight terabytes. "It's still pretty experimental," Komarov explained.
Entry and exit could also expose amounts and timing that help observers link outside Bitcoin activity with shielded transactions. The lab has run public break-it challenges since May, but there is no launch date. Until the door, Shielded Bitcoin remains research rather than a usable privacy system.
Bitcoin and Zcash Communities Weigh In
The Zcash influence is obvious. Zcash already uses encrypted notes, nullifiers and zero-knowledge proofs, and Shielded borrows that architecture without creating another blockchain. The public company Cypherpunk called Shielded Bitcoin "a great step forward," adding that more privacy on Bitcoin benefits everyone.
Cypherpunk also argued, however, that the design is not yet a competition for the Zcash chain. The firm pointed to Shielded Bitcoin's trusted setup, its lack of consensus enforcement and trustless light clients, an unfinished bridge and Bitcoin L1 fees, while noting that Zcash already has nearly 10 years in production and a shielded pool worth more than $7 billion. "Financial privacy isn't zero-sum," Cypherpunk concluded.
X reactions quickly became less diplomatic. Joe Burnett wrote "zcash to 0," while Daniel Buchner, director of product and director of digital assets at Proof, offered a sharper take: "The amount of privacycoin stans having cope-induced seizures from the mere thought that the Bitcoin community is progressing down the path of private transactions, potentially Thanos snapping the narratives of one-off privacy chains, is approaching a decibel level where ear damage is becoming a concern."
Sam Callahan, director of strategy and research at OranjeBTC, framed a broader argument. "People still misunderstand Bitcoin's moat. Bitcoin doesn't need to win every feature race. Privacy, speed, and functionality can be built over time. The moat is its decentralization, security, and credible monetary policy. And on those dimensions, nothing else comes close."
The X account Rune brought the privacy-coin rivalry back to earth with a reference to the Bitget hack and monero ($XMR), a privacy-focused cryptocurrency, writing on X: "ZEC holders praying the Bitget hacker uses zcash to hide the trace… but for some reason hacker is using $XMR." Behind the trash talk sits a genuine technical debate over whether the Bitcoin blockchain can acquire stronger privacy without changing its base rules.
Bitcoin Carries Secrets It Cannot Read
Unlike Satoshi's white paper, Shielded Bitcoin is a specification, not a product. The peg remains unfinished, witness encryption is experimental, fees can leak information, wallets must become practical, and privacy improves only when enough users participate. The current Groth16 proof design also requires a one-time trusted setup, a parameter-generation event whose participants must be trusted to have discarded their secret material.
Shikhelman was scheduled to present the research at BitDevs NYC on Sept. 24 as [[alloc] init] sought feedback ahead of its companion white paper on entry and exit. That next workaround will determine whether the private system described on paper can connect safely to actual bitcoin — the milestone to watch, alongside the lab's ongoing break-it challenges.
For now, the idea remains wonderfully counterintuitive. [[alloc] init] wants Bitcoin to record private financial activity without changing Bitcoin or asking the network to understand what it is recording. If the unfinished pieces work, Bitcoin could preserve transactions forever while remaining blind to the amounts and counterparties that made those transactions worth hiding in the first place.
Source: CryptoNewsNet; original coverage at News.Bitcoin.com.