Researchers propose Zcash-style private Bitcoin transfers without soft fork
Alloc Init researchers have proposed Shielded Bitcoin, a system that would hide transaction details using zero-knowledge proofs while leaving Bitcoin's consensus rules unchanged.

Key points
- Alloc Init researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin published the Shielded Bitcoin paper on Thursday.
- The design uses encrypted notes, public nullifiers and zero-knowledge proofs, drawing on Zcash's architecture.
- Bitcoin would act as a neutral publication and ordering layer, with separate indexers verifying proofs and checking for double-spends.
- Developer Vadim Zavodil argued a new shielded pool would start with no anonymity set, unlike Zcash's pool built over years.
- Pauli Group founder Pierre-Luc Dallaire-Demers said the construction is not quantum resistant at all.
Researchers at the cryptography firm Alloc Init have proposed a way to bring Zcash-style private transfers to Bitcoin without a soft fork. The proposal, called Shielded Bitcoin, would hide transaction amounts, senders, receivers and links to previously spent funds. The paper was published on Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, according to CoinTelegraph.
The design offers a possible route to stronger privacy for Bitcoin users without changing the base protocol's consensus rules. Rather than having miners enforce the privacy protocol, Shielded Bitcoin would treat Bitcoin as what the researchers called a neutral publication and ordering layer. Separate software known as indexers would verify zero-knowledge proofs, check that funds have not been double-spent, and rebuild the state of the shielded system.
The construction explicitly borrows from Zcash's architecture. The researchers said it similarly relies on encrypted notes, public nullifiers that mark notes as spent, and zero-knowledge proofs that show transactions are valid. Unlike Zcash, Shielded Bitcoin would not run its own blockchain or consensus mechanism.
Privacy without a soft fork
The proposal drew mixed reactions. Developer Vadim Zavodil criticised it on X, arguing that much of its privacy stack had already been implemented by Zcash. He questioned how much privacy a newly launched system could offer at first, saying a new shielded pool would begin without the anonymity set Zcash has accumulated over years of use. He wrote that privacy is a function of the crowd, adding that a brand new metaprotocol starts at zero.
In a companion post, the Shielded Bitcoin researchers acknowledged a similar limitation. They said large deposits do not automatically create a large anonymity set. Observers may still be able to narrow down relationships between transfers if a small number of actors create most notes, or if wallets show distinctive behaviour.
Pierre-Luc Dallaire-Demers, founder of the post-quantum cryptography firm Pauli Group, raised a separate concern. He described the construction as interesting but not quantum resistant at all. He later said he was exploring what a fully post-quantum version could look like, assuming Bitcoin eventually adopts a post-quantum signature scheme.
Zcash-style design
Zerocash co-author and StarkWare chief executive Eli Ben-Sasson was more supportive of the direction. He said the original intent behind the Zerocash paper, which preceded Zcash, was to bring privacy to Bitcoin. Ben-Sasson said he had not yet read the Shielded Bitcoin paper, but would like to see privacy and scalability through zero-knowledge proofs materialise on Bitcoin's base layer.