News

Shielded Bitcoin Privacy Proposal Brings Zcash-Style Secrecy to BTC

Liam Tremblay 5 min read
Shielded Bitcoin privacy proposal shown as a gold bitcoin in a glass shield beside encrypted notes and blockchain blocks

Every bitcoin payment you’ve ever made sits on a public ledger forever. Now a new Shielded Bitcoin privacy proposal wants to change that without touching Bitcoin’s rules at all. Researchers at [alloc] init published it this week, promising private transfers with no soft fork, operator or custodian. It’s the most interesting Bitcoin privacy idea I’ve read in years, but it’s still missing its most important piece.

That missing piece is the peg, the mechanism that moves real BTC in and out of the system. Until it exists, this is a clever blueprint rather than a working product. Still, the blueprint deserves attention, because it tackles a problem Bitcoin has dodged since 2009.

What the Shielded Bitcoin Privacy Proposal Actually Does

Clara Shikhelman, Misha Komarov and Aleksei Moskvin wrote the paper. Their Shielded Bitcoin privacy proposal works as a metaprotocol, so it rides on top of Bitcoin instead of changing it. That matters, because rewriting Bitcoin’s rules is painfully slow, as the long fight over quantum computing risk keeps proving. Here, nobody has to convince miners or node operators to upgrade anything.

Instead, each private transaction is just a blob of data with a short prefix, something like “shbtc:”. Users tuck it into a normal Bitcoin transaction through OP_RETURN or the witness field. Bitcoin itself doesn’t check that data or enforce any rules on it. So a separate program called an indexer reads the chain, validates each blob and quietly ignores anything invalid.

Honestly, the setup sounds a lot like how Runes and other token metaprotocols already work. Anyone can run it with a Bitcoin node, an indexer and their own keys. There’s no coordinator to trust and no off-chain server holding your recovery data. That self-custody design is exactly why I think this idea beats most privacy pitches.

How Notes and Nullifiers Hide the Money Trail

Under the hood, the design borrows heavily from Zcash. Coins become encrypted notes rather than visible outputs. Say you deposit 1 BTC and later send 0.2 BTC to a friend. The system then swaps your original note for two new encrypted ones: 0.2 BTC for them, 0.8 BTC for you.

Spending works differently too. Rather than deleting spent coins, indexers keep a list of nullifiers that mark a note as used without revealing which note it was. Each transaction also carries a zero-knowledge proof. In short, that proof confirms the note exists, the spender owns it and nobody created coins out of thin air.

Wallets feel familiar as well. Each one derives a master secret key, much like a standard HD wallet, and splits it into separate keys for spending, viewing and receiving. As a result, you could in principle share a viewing key without handing over spending power.

Why the Shielded Bitcoin Privacy Proposal Matters for Everyday Holders

Most people still assume bitcoin is anonymous, but it isn’t. Every address, amount and hop is public, and analytics firms map those flows for a living. Even Bank of Canada researchers have made the case for privacy as a public good in digital payments. So this isn’t only a cypherpunk worry.

Coinjoins have been Bitcoin’s main answer so far, but they come with real drawbacks. Users need to coordinate, estimate how private they actually are and sometimes remix coins again. By contrast, a technical review from Bitcoin Magazine says Shielded Bitcoin avoids all of that and matches Zcash’s shielded pools on privacy. If that holds up, it’s a genuine upgrade for anyone who values discretion.

The Peg Is the Part Nobody Has Built Yet

Here’s the catch. Moving real BTC into the system depends on a peg built with PIPEs v2, a witness encryption scheme. Put simply, it locks a private key behind a puzzle that only a valid zero-knowledge proof can open. According to the team, a paper covering this part is still in progress.

Pegs are also where Bitcoin side systems tend to break. Blockstream’s sidechain recently lost roughly $320 million worth of bitcoin to an inflation bug, and about $46 million still hasn’t come back. That system relies on a federation, whereas PIPEs promise a peg with no custodian at all. It’s a bold claim, and I’d want outside reviewers to attack it hard before anyone trusts it with serious money.

Canadian Rules Could Shape the Shielded Bitcoin Privacy Proposal

For Canadians, privacy tools collide with compliance fast. Registered platforms must follow FINTRAC’s travel rule, which attaches sender and recipient details to covered transfers, generally those of $1,000 or more. Self-hosted wallets largely sit outside that rule. However, exchanges still sit at every on-ramp and off-ramp.

This is where the Shielded Bitcoin privacy proposal gets tricky. The authors admit that entering and leaving the system carries its own privacy risks, and they’ve promised details in a future paper. My guess is that Canadian exchanges will treat coins fresh from a shielded pool with extra scrutiny. Anyone wondering how those obligations fit together can start with our guide to crypto regulations in Canada.

What the Shielded Bitcoin Privacy Proposal Still Needs

Right now, three things stand between this Shielded Bitcoin privacy proposal and real-world use. First, the peg paper has to land. Next, independent cryptographers need to pick it apart. Finally, developers have to ship indexers and wallets that ordinary people will actually use.

Each step could take months, if not years. After all, fresh code always hides surprises, and privacy code hides them better than most. Even so, I like this Shielded Bitcoin privacy proposal more than most, because it needs no fork and no middleman.

If financial privacy matters to you, keep an eye out for the peg design when it lands. Read it, see what independent reviewers say, and then decide whether shielded bitcoin deserves a place in your own setup.