Researchers at Alloc Init have proposed a way to hide who sends Bitcoin (BTC), who receives it and how much moves, borrowing Zcash (ZEC) cryptography and skipping a soft fork.
Key Points:
- Alloc Init's Shielded Bitcoin would use encrypted notes and zero-knowledge proofs to hide transfer details on Bitcoin.
- Indexers, not miners, would check the proofs, so Bitcoin's consensus rules would stay the same.
- Critics point to a thin anonymity set at launch and a lack of quantum resistance.
Shielded Bitcoin Design
Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin released the paper, called Shielded Bitcoin, on Thursday. It uses encrypted notes, public nullifiers and zero-knowledge proofs to conceal amounts, senders, receivers and links to previously spent coins. Unlike Zcash, the system would not run its own blockchain or consensus mechanism.
Miners would play no role in enforcing the rules, since transactions would sit on Bitcoin as plain data while separate software called indexers checks proofs, rejects double-spends and rebuilds the system's state. A user who deposits 1 BTC would get a private note of equal value, and sending 0.2 BTC would split that note into two new encrypted ones.
The design still lacks a finished peg for moving coins in and out, and the authors do not claim those steps will be private. The team plans to build that piece with PIPEs v2, a witness encryption scheme, and has promised a separate paper on it. One technical review rated its privacy properties on par with Zcash's shielded pools.
Also Read: Could Tokenized Stocks Land On XRPL? The SEC Order Raises The Question
Zavodil, Ben-Sasson React
Developer Vadim Zavodil criticized the plan, arguing that Zcash had already built most of this privacy stack and that a new pool lacks the anonymity set Zcash has gathered over years. "A brand new metaprotocol starts at zero, so your first private transfer hides in a crowd of one," he wrote.
The researchers conceded a similar point in a companion post, writing that large deposits do not automatically create a large anonymity set. Observers could still link transfers if a few actors create most notes or wallets behave in distinctive ways. Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group, raised another concern, calling the construction interesting but "not quantum resistant at all."
Eli Ben-Sasson, CEO of StarkWare, struck a warmer tone, saying the original aim of the 2014 Zerocash paper he co-wrote was to bring privacy to Bitcoin. He had not yet read the new proposal but said he wants to see privacy and scalability through zero-knowledge proofs reach Bitcoin's base layer.
Zcash, which grew out of that research, is heading into its own overhaul. Its NU7 upgrade would cut target block time from 75 seconds to 25 seconds and halt spending from the legacy Sprout shielded pool. Testnet activation is set for Oct. 6, and developers expect to decide on Oct. 20 whether to go ahead with a Nov. 5 mainnet launch.
Read Next: Ethereum Could Gain New Demand From AI Payments, BlackRock Says

