NewsCryptoResearchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers

Researchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers

Author: Decrypt·

Key Takeaways

  • •[[alloc] init] published a 56-page specification for Shielded Bitcoin on September 24, 2026, enabling private payments on Bitcoin's base layer without altering consensus rules.
  • •The protocol conceals senders, recipients and amounts using Zcash-style encrypted notes and zero-knowledge proofs, with Bitcoin recording transfers as unchecked data that independent indexers verify and rebuild.
  • •Unlike the 2025 Shielded CSV proposal, Shielded Bitcoin stores transfer data on Bitcoin itself, sparing holders from permanently losing funds if they misplace their own transaction records.
  • •The current implementation depends on the Groth16 proof system's trusted setup ceremony and on Bitcoin Core v30's larger OP_RETURN default, a contested change node operators can reverse.
  • •An optional 'Trust Authority' compliance layer would let institutions verify note origins without exposing the transfer graph, arriving as Zcash attracts regulated products including Grayscale's NYSE Arca ETF and 21Shares' European ETP.
Researchers Publish 'Zcash-Style' Design for Private Bitcoin Transfers

Researchers at Bitcoin cryptography developer [[alloc] init] have published a specification for Shielded Bitcoin, a protocol for private transfers on the Bitcoin base layer that requires no changes to the network's consensus rules. That constraint is notable: changing Bitcoin's consensus rules has historically required broad coordination among node operators, miners and developers.

The design, laid out in a 56-page paper dated September 24, 2026, borrows Zcash's encrypted notes and zero-knowledge proofs to hide the sender, recipient and amount of a payment while running on the existing Bitcoin network. It was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin.

The team has "put a lot of work into thinking carefully about the security of Shielded Bitcoin and about what information the protocol reveals," Shikhelman tweeted.

Komarov called the work "ZCash-style privacy on the Bitcoin1 via PIPEs v2" in a post on X.

ZCash-style privacy on the Bitcoin L1 via PIPEs v2. — Misha Komarov (@nemothenoone) September 24, 2026

Scott Odell, chief operating officer of [[alloc] init], tweeted that the firm had been "cooking on this for quite a while," describing the design as a contribution to making Bitcoin "private, without changing Bitcoin."

Under the proposal, value in Shielded Bitcoin is held as encrypted "notes." Each transfer carries a zero-knowledge proof that the sender controls the notes being spent and that inputs and outputs balance. A public marker called a nullifier lets software reject double spends without revealing which note was used.

Zcash enforces those rules through its own blockchain. Shielded Bitcoin instead publishes transfers as data on Bitcoin, which records them without checking them, while separate software called indexers verifies the proofs and rebuilds the shielded state.

The paper contrasts this approach with Shielded CSV, a 2025 Bitcoin proposal in which coin owners must keep their own transaction data, which generally cannot be recovered from the chain — putting the burden of safekeeping, and the risk of permanent loss, on individual holders.

Timing, fees and the number of inputs and outputs remain public, the authors write. "Like Zcash and Monero, Shielded Bitcoin preserves the privacy of who paid whom and how much, not that a shielded transfer happened," the paper states.

Peg-in and peg-out

The paper covers only transfers inside the system. How BTC enters and leaves is left to a separate paper built on Bitcoin PIPEs v2, earlier [[alloc] init] research that encrypts a Bitcoin signing key so it can be recovered only with a valid proof, according to the firm's website.

The current version uses the Groth16 proof system, whose security depends on an honestly run trusted setup ceremony. Trusted setups have long been a focal point of scrutiny in zero-knowledge systems, since anyone holding the ceremony's secret material could forge proofs. It publishes each transfer in an OP_RETURN output, which comes to 625 vbytes for a transfer with two inputs and two outputs, according to the paper.

That relies on the larger OP_RETURN default in Bitcoin Core v30, a contested change that node operators can reverse, so relay depends on enough nodes and miners keeping it, the paper notes.

An appendix sketches an optional compliance layer in which a "Trust Authority" certifies approved deposits, letting institutions verify a note's origins without exposing the transfer graph. Notes without that evidence would remain valid.

Zcash, whose design Shielded Bitcoin borrows, now trades through regulated funds in the U.S. and Europe. Grayscale's Zcash ETF began trading on NYSE Arca on August 25, and 21Shares listed Europe's first Zcash exchange-traded product on Euronext Paris and Amsterdam on September 22. The result is a regulated-market footprint for the very zero-knowledge design Shielded Bitcoin ports to the base layer.

ZEC was trading at $1,592 on September 25, up 4% over the past 24 hours, with a seven-day high of $1,658.86, per CoinGecko.