ZEC climbed above $1,600 this week because investors decided privacy is worth paying for. Now a team of Bitcoin researchers says you may not need to leave BTC to get it.
A Sept. 24 paper from [[alloc] init] researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin introduces Shielded Bitcoin. It’s a metaprotocol meant to hide transaction amounts, senders, recipients and the links between transfers, while still publishing its protocol data through Bitcoin mainnet.
The catch that makes it interesting is what it doesn’t ask for. There’s no soft fork and no change to Bitcoin’s consensus rules. The privacy logic sits above the network entirely, which means nobody has to wait for an upgrade that may never come.
Zcash’s playbook, minus the separate chain
The design borrows techniques Zcash pioneered: encrypted notes, public nullifiers and zero-knowledge proofs. But it doesn’t spin up a new blockchain. Bitcoin acts as the publication and ordering layer, and participants rebuild the private transaction state from what’s recorded there.
Here’s how a transfer would work. You’d hold BTC-denominated value as encrypted notes. When you send funds, you publish an envelope containing encrypted outputs, public nullifiers that mark your old notes as spent, and a zero-knowledge proof showing you own the funds and that value was conserved.
The amount and the identities on both sides stay hidden.
Miners and nodes wouldn’t validate any of this. Software following the Shielded Bitcoin rules would scan BTC blocks, replay the accepted transfer envelopes in the order they were recorded and arrive at a shared note tree and spent-note set. Bitcoin supplies the timestamped history and ordering. The metaprotocol handles encrypted balances and checks that transfers are valid.
That’s a real architectural split from Zcash, where the network’s own consensus rules enforce shielded transaction validity. Shielded Bitcoin leaves BTC consensus alone and derives a separate private state from data anchored to the chain.
The current implementation profile uses OP_RETURN to publish the encrypted transfer data. The researchers leave the door open to other publication methods.
Further than CoinJoin ever went
Bitcoin users already have privacy tools. CoinJoin, PayJoin and Silent Payments can make tracing harder or cut down address reuse. None of them hide the amount, and other transaction details stay in the open too.
Shielded Bitcoin would go further. It still isn’t invisible. Transaction timing, fees, input and output counts and the characteristics of the Bitcoin transaction carrying the encrypted data could all give observers something to work with. If you’re assuming perfect cover, don’t.
The paper also includes viewing capabilities. Those could let users selectively disclose transaction information without handing over control of their funds, which gives auditors or compliance teams a way in where it’s required.
The hard part is still missing
Here’s the part skeptics should circle. The spec doesn’t cover how ordinary BTC gets into or out of the shielded system.
Peg-in and peg-out mechanisms sit outside the current specification. They’d need to lock Bitcoin on mainnet, represent that value inside the private note system and later release the matching BTC when a user exits. [[alloc] init] expects those flows to rely on its PIPEs v2 work, but the researchers haven’t published the detailed construction yet.
That’s not a footnote. Whether entry and exit can be trustless, private and resistant to linkage is still an open question. A distinctive deposit amount, withdrawal amount or timing pattern could tie your activity together at either end, no matter how well the middle is hidden.
Other choices are unsettled too: the final proof system, the publication format and how light clients could verify shielded state without replaying the full relevant Bitcoin history.
Bitcoin maximalists see a moat, not a race
Sam Callahan, director of strategy and research at Bitcoin treasury company OranjeBTC, said the work fits a broader view that Bitcoin can pick up functionality over time without competing with other chains feature by feature.
“People still misunderstand Bitcoin’s moat. Bitcoin doesn’t need to win every feature race. Privacy, speed, and functionality can be built over time. The moat is its decentralization, security, and credible monetary policy,” Callahan said. “And on those dimensions, nothing else comes close.”
André Dragosch, Bitwise Europe Head of Research, called Shielded Bitcoin a “potential headwind for privacy coins.” The risk he’s pointing at is simple: features once tied to separate networks could increasingly be rebuilt around Bitcoin without touching its monetary rules or base-layer consensus.
Why Zcash holders should pay attention
The timing matters. Privacy-focused cryptocurrencies are drawing investor attention again, reopening an old argument over whether dedicated privacy networks hold a lasting technical edge over Bitcoin.
For Zcash, privacy is the whole reason for its recent revaluation. ZEC climbed above $1,600 this week as shielded activity picked up and investors came back to the idea that Zcash offers native transactions that hide senders, recipients and amounts.
And usage has tracked the price. Weekly shielded transactions recently reached 62,379, the highest since 2022. Nearly 5 million ZEC sat in shielded pools this month. The network settled more than $23 billion in transfer volume last week, its strongest weekly total since 2021.
Shielded Bitcoin pushes on that story because it’s chasing similar confidentiality while keeping BTC as the underlying asset. Bitcoin, for its part, is up 0.07% over the past 24 hours and holds the No. 1 spot by market cap.
If you’re weighing a move into a privacy coin today, the paper doesn’t change the math yet. Nothing you can use exists until [[alloc] init] publishes the PIPEs v2 peg-in and peg-out design, and that’s the one document worth waiting for. If it works as designed, you’d have a way to get stronger privacy without leaving BTC.