Researchers at cryptography firm Alloc Init have proposed a system to bring Zcash-style private transfers to Bitcoin without requiring a soft fork. The proposal, called Shielded Bitcoin, conceals transaction amounts, senders, receivers and links to previously spent funds using encrypted notes and zero-knowledge proofs.
The paper, published Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, outlines a method for stronger privacy on Bitcoin that avoids consensus changes to the base protocol. Rather than having miners enforce the privacy layer, the researchers wrote that the system would treat Bitcoin as "a neutral publication and ordering layer." Separate software, called indexers, would verify zero-knowledge proofs, confirm funds have not been double-spent and reconstruct the state of the shielded system.
Shielded Bitcoin draws directly from Zcash's architecture, the researchers said. It similarly uses encrypted notes, public nullifiers that mark notes as spent, and zero-knowledge proofs that demonstrate transaction validity. Unlike Zcash, however, the system would not operate its own blockchain or consensus mechanism.
The proposal has drawn mixed reactions within the privacy community. Developer Vadim Zavodil criticized the design on X, arguing that much of its privacy stack had already been implemented by Zcash and questioning how much utility a newly launched system could initially provide. "Privacy is a function of the crowd. Zcash has a real shielded pool built over years," he wrote. "A brand new metaprotocol starts at zero, so your first private transfer hides in a crowd of one."
In a companion post, the Shielded Bitcoin researchers acknowledged the limitation, noting that large deposits do not automatically create a large anonymity set. They added that observers may still be able to narrow relationships between transfers if a small number of actors create most notes, or if wallets exhibit distinctive behavior.
Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group, raised a separate concern, calling the construction interesting but "not quantum resistant at all." He later said he was exploring what a fully post-quantum version could look like, assuming Bitcoin eventually adopts a post-quantum signature scheme.
Zerocash co-author and StarkWare CEO Eli Ben-Sasson was more supportive of the proposal's direction. He said the original intent behind the Zerocash paper, which preceded Zcash, was to bring privacy to Bitcoin. While Ben-Sasson noted he had not yet read the Shielded Bitcoin paper in full, he expressed interest in seeing the vision of privacy and scalability through zero-knowledge proofs materialize on Bitcoin's base layer.
The announcement comes days after reports that Zcash's November upgrade could freeze funds in its legacy Sprout pool.












