Researchers have outlined a system that could enable private bitcoin-denominated transfers alongside the Bitcoin network, although a complete mechanism for depositing and withdrawing actual BTC has not yet been developed.
A team of researchers has proposed a method for improving Bitcoin transaction privacy without modifying the network’s underlying rules, as privacy-focused cryptocurrencies such as Zcash receive renewed attention from investors.
The proposal, called Shielded Bitcoin, was published Thursday by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of cryptography firm [alloc] init. The design takes inspiration from the encrypted payment system used by Zcash.
Under the proposed model, bitcoin-denominated funds would be represented by encrypted records known as notes. To spend a note, a user would publish a marker indicating that the funds had been used, together with a cryptographic proof showing ownership and confirming that no additional funds had been created. Details such as the transaction amount, sender, and recipient would remain private.
Zcash verifies these proofs directly on its blockchain. Shielded Bitcoin would instead place the relevant transfer information on Bitcoin while relying on separate software to perform the verification. This means a Bitcoin transaction could be accepted by the network even if the private payment embedded within it failed the Shielded Bitcoin verification process.
The demand for transaction privacy has gained practical importance as cryptocurrency developers explore applications involving payroll, corporate payments, and everyday purchases. Standard Bitcoin transactions permanently expose wallet addresses and transferred amounts. Once an address becomes connected to an individual or business, other transactions associated with that address can become easier to trace.
Ethereum developers are considering a similar concept through a proposal for a shared private pool that could allow users to transfer ether and other tokens without publicly exposing payment information. The proposal identifies payroll, treasury operations, and donations as examples of activities that can be difficult to conduct privately on fully transparent blockchains.
How Zcash Works
Zcash provides users with a choice between transparent transactions, where addresses and amounts remain publicly visible, and shielded transactions, which encrypt those details.
According to CoinDesk calculations based on ZecStats data, Zcash’s shielded pools contained around 4.9 million ZEC on Friday, representing a 14% increase from July 30. The amount accounts for approximately 29% of all issued ZEC and was worth about $7.8 billion following the recent price increase.
The network processed around 63,000 shielded transactions last week, marking its busiest week for private transfers since 2022 and its fourth-highest weekly total on record. Overall reported transfer volume surpassed $23 billion, making it the largest weekly figure since 2021 and the second-highest in Zcash’s history.
Those figures have also drawn increased investor attention to Zcash. By early September, ZEC had risen more than 2,300% over the previous year and surpassed $1,000. The token continued higher, moving above $1,600 on Wednesday.
The relationship between Bitcoin and Zcash privacy research dates back more than a decade. Zerocoin was introduced in 2013 as a potential privacy extension for Bitcoin. The research later evolved into Zerocash, which eventually became Zcash, launched as an independent cryptocurrency in 2016.
Shielded Bitcoin would store encrypted transaction information on the Bitcoin blockchain, allowing users to reconstruct valid private payments from the public record using their wallet keys. Separate viewing keys could also allow users to provide transaction information to accountants or auditors without giving those parties the ability to spend the underlying funds.
Remaining Questions
The 56-page proposal does not yet explain how regular BTC would be deposited into the system or withdrawn from it. The researchers have reserved those mechanisms for a separate paper based on PIPEs, a technology intended to keep a Bitcoin signing key locked until predefined conditions are satisfied.
The authors’ statement that users maintain control over their funds applies to transfers conducted within the proposed system and specifically does not cover deposits or withdrawals.
Those omissions have prompted criticism from some developers and members of the Zcash community.
Mert Mumtaz, co-founder of Helius and a supporter of Zcash, described the proposal on X as a “synthetic ledger with significant tradeoffs.” He highlighted the requirement for a trusted setup and the lack of fee anonymization, arguing that the Bitcoin wallet used to publish a private transfer could remain identifiable.
Mumtaz also pointed to the absence of an established deposit and withdrawal mechanism, arguing that without a protocol-level method for moving real BTC into and out of the system, users would effectively be dealing with synthetic bitcoin.
He nevertheless acknowledged the research effort, saying he respected the work and the use of ideas developed through Zcash research. He added that the proposal would likely require years of additional research and development.
Cypherpunk, a company involved in holding and mining Zcash, also welcomed the research while saying it did not view the proposal as a direct competitor to Zcash. The company argued that privacy is most effective when incorporated at the base layer, while noting that avoiding changes to Bitcoin’s protocol is both one of the design’s main advantages and a significant limitation.
The company also said that greater privacy on Bitcoin could benefit the broader cryptocurrency ecosystem.
The researchers at [alloc] init recognize several of the system’s current limitations. Their reference implementation relies on a cryptographic setup whose security requires at least one participant to behave honestly. Transaction timing and fee payments would remain visible, while developing an efficient method for lightweight wallets to verify reconstructed payment histories remains future work.
Komarov estimated that a private transfer would occupy roughly 700 virtual bytes, compared with around 100 to 200 virtual bytes for a standard Bitcoin transaction. At the same fee rate, that would make the miner fee approximately four times higher.
As of Friday, the researchers had not announced a launch date for the proposed system.

More Stories
Bitget Hacker Moves $83M in Stolen XRP Beyond Ripple’s Freeze Reach
SEC Commissioner Hester Peirce to Leave Agency Next Week
Kalshi Faces Another Appeals Court Loss Over State Regulation of Sports Contracts