BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Researchers Propose Shielded Bitcoin for Zcash-Style Private Transfers

Researchers at Bitcoin cryptography firm Alloc Init published a 56-page paper on September 24 proposing Shielded Bitcoin, a design for Zcash-style private transfers on the Bitcoin base layer

AnonymousCryptoCompass newsroom
September 27, 2026
2 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.
bitcoin main

Researchers at Bitcoin cryptography firm Alloc Init published a 56-page paper on September 24 proposing Shielded Bitcoin, a design for Zcash-style private transfers on the Bitcoin base layer that needs no soft fork or consensus change. The specification, authored by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, would hide the sender, recipient and amount of a payment while Bitcoin records and orders the data without validating it.

How the design borrows Zcash’s privacy model

Shielded Bitcoin holds value in encrypted notes, and each transfer carries a zero-knowledge proof that the sender controls the notes being spent and that inputs and outputs balance. A public marker called a nullifier lets software reject double spends without revealing which note was used. Unlike Zcash, which enforces those rules through its own blockchain, the proposal treats Bitcoin as a “neutral publication and ordering layer”: separate software called indexers verifies the proofs and rebuilds the shielded state. “Like Zcash and Monero, Shielded Bitcoin preserves the privacy of who paid whom and how much, not that a shielded transfer happened,” the paper states.

The unfinished parts: deposits, withdrawals and cost

The paper covers only transfers inside the system. How BTC enters and leaves is left to a separate paper built on Bitcoin PIPEs v2, earlier Alloc Init research that encrypts a Bitcoin signing key so it can be recovered only with a valid proof. The current design uses the Groth16 proof system, whose security rests on a trusted setup ceremony, and publishes each transfer in an OP_RETURN output of roughly 625 vbytes for two inputs and two outputs. Komarov estimates a private transfer at about 700 vbytes, roughly four times the miner fees of a standard Bitcoin transaction. The proposal joins a wider effort to add Zcash-style privacy to Bitcoin, including Citrea’s acquisition of privacy builder Crest.

Reaction and the state of privacy coins

The paper lands amid a privacy-coin revival. Zcash’s shielded pools held about 4.9 million ZEC as of Friday, roughly 29 percent of issued coins and worth about $7.8 billion, and 21Shares listed Europe’s first Zcash ETP in late September. Some developers were skeptical: Vadim Zavodil argued that a new shielded pool “starts at zero,” while Zerocash co-author Eli Ben-Sasson welcomed the direction, noting the original goal of Zerocash was to bring privacy to Bitcoin.