Researchers publish plan for Zcash-style privacy on Bitcoin
A 56-page paper from [alloc] init proposes hiding sender, recipient and amount on Bitcoin without changing consensus rules, though fees would be about four times higher.
Key points
- The paper, dated 24 September 2026, is by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of [alloc] init.
- A private transfer would weigh about 700 vBytes, against 100 to 200 for an ordinary transaction.
- Zcash shielded pools hold 4.9 million ZEC, about 29% of issued supply, up from 7.6% five years ago.
- Zcash saw about 63,000 shielded transactions last week, its best week since 2022, with over $23 billion transferred.
- How BTC enters and exits the system is left to a later paper built on PIPEs v2.
Researchers at the Bitcoin cryptography firm [alloc] init have published a 56-page paper proposing a way to hide the sender, recipient and amount of a Bitcoin transaction without changing Bitcoin's consensus rules. The paper, titled Shielded Bitcoin, is dated 24 September 2026 and was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, according to Cointribune.
The design borrows Zcash's encrypted notes, public nullifiers that mark a note as spent, and zero-knowledge proofs that show a transfer is valid. Unlike Zcash, Shielded Bitcoin would not run its own blockchain or consensus mechanism. Bitcoin would act as what the researchers call a neutral publication and ordering layer, while separate software called indexers verifies the proofs, checks for double spends and rebuilds the shielded state.
Value inside the system would sit in encrypted notes. Spending one publishes a marker proving it was used, alongside a mathematical proof that the spender controlled the funds. Bitcoin keeps its role as a settlement and ordering layer but gives up verifying anything about the private payment itself, so a Bitcoin confirmation would no longer guarantee that the private payment it carries is valid.
A privacy plan without forks
The paper leaves one central question open: how real BTC enters or exits the system. That mechanism is deferred to a separate paper built on PIPEs v2, earlier [alloc] init research that encrypts a Bitcoin signing key so it can be recovered only with a valid proof, according to Decrypt. Until that design appears, the proposal covers only transfers already inside the pool.
Cost and timing would remain visible. A private transfer would weigh roughly 700 vBytes, against 100 to 200 for an ordinary transaction, meaning it would cost about four times more. The current version uses the Groth16 proof system, whose security depends on an honestly run trusted setup ceremony, and publishes each transfer in an OP_RETURN output, relying on the larger OP_RETURN default in Bitcoin Core v30 that node operators can reverse.
Developers gave mixed reactions. Vadim Zavodil criticised the proposal on X, arguing much of its privacy stack had already been implemented by Zcash, and questioned how much privacy a new system could offer at launch. Pierre-Luc Dallaire-Demers of Pauli Group called the construction interesting but not quantum resistant, while Zerocash co-author Eli Ben-Sasson was more supportive, saying he had not yet read the paper but wanted to see privacy and scalability through zero-knowledge proofs on Bitcoin's base layer.
Notes, proofs and indexers
The timing is notable. Zcash's shielded pools hold 4.9 million ZEC, about 29% of issued supply, up from 7.6% five years ago and 23.3% a year ago, and recorded about 63,000 shielded transactions last week, its best week since 2022, with more than $23 billion transferred. For Bitcoin users the tradeoff is cost and a weaker guarantee than a consensus-enforced design, since they would rely on indexer software rather than miners to confirm a payment is valid.