{"id":78633,"date":"2026-09-25T03:59:16","date_gmt":"2026-09-25T03:59:16","guid":{"rendered":"https:\/\/crowdfundjunction.com\/blog\/shielded-bitcoin-proposal-aims-to-bring-privacy-to-bitcoin-l1\/"},"modified":"2026-09-25T03:59:16","modified_gmt":"2026-09-25T03:59:16","slug":"shielded-bitcoin-proposal-aims-to-bring-privacy-to-bitcoin-l1","status":"publish","type":"post","link":"https:\/\/crowdfundjunction.com\/blog\/shielded-bitcoin-proposal-aims-to-bring-privacy-to-bitcoin-l1\/","title":{"rendered":"Shielded Bitcoin Proposal Aims to Bring Privacy to Bitcoin L1"},"content":{"rendered":"<p><b>(Originally posted on : Bitcoin News )<\/b><br \/>\n<\/p>\n<div>\n<div class=\"@container mb-[25px] rounded-sm overflow-clip py-0.5 pr-0.5 pl-2.5 bg-success-100\">\n<div class=\"flex flex-col gap-m overflow-clip rounded-[6px] !bg-success-10 p-3 @[420px]:p-m\">\n<h2 class=\"m-0 flex items-center gap-s text-[19px] !text-[#1c1c1c] md:text-[20px]\"><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"16\" height=\"10\" viewbox=\"0 0 16 10\" fill=\"none\" class=\"shrink-0 text-success-100\" aria-hidden=\"true\"><path d=\"M1 1.5h14\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><path d=\"M1 8.5h10\" stroke=\"currentColor\" stroke-width=\"2.5\" stroke-linecap=\"round\"\/><\/svg><span>Key Takeaways<\/span><\/h2>\n<ul class=\"m-0 flex list-none flex-col gap-m pl-0\">\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">The cryptography lab [[alloc] init] unveiled Shielded Bitcoin on Sept. 24, bringing the idea of private transfers to Bitcoin without a soft fork.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">Shielded Bitcoin transfers run about 700 vbytes, roughly 4 times the size of a typical BTC payment.<\/span><\/li>\n<li class=\"m-0 flex items-start gap-s !text-[#434248]\"><span class=\"mt-2 size-2 shrink-0 rounded-full bg-success-100\" aria-hidden=\"true\"\/><span class=\"text-body\">[[alloc] init] still has work ahead, with a 2nd white paper set to explain how bitcoin gets in and back out.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>Bitcoin\u2019s transaction history is famously public. Send bitcoin (BTC) and the payment joins a ledger anyone can inspect, potentially forever. The New York lab [[alloc] init] is proposing a counterintuitive workaround. Leave Bitcoin\u2019s rules alone and build privacy on top of them. Shielded Bitcoin uses encrypted notes and <a href=\"https:\/\/news.bitcoin.com\/zk-proofs-2025-predictions-another-breakthrough-year-projected-expert-sees-100x-improvement\/\">zero-knowledge (ZK) proofs<\/a> to conceal amounts and counterparties, while Bitcoin acts almost like a public bulletin board.<\/p>\n<p>The network records encrypted messages in the correct order without knowing what they mean. No soft fork is required, and there is no operator deciding which private transfers count. Bitcoin could end up carrying private payments that Bitcoin itself cannot read.<\/p>\n<h2>Bitcoin Becomes a Bulletin Board<\/h2>\n<p>The white paper, \u201c<a href=\"https:\/\/allocinit.notion.site\/Shielded-Bitcoin-Private-Transfers-on-Bitcoin-L1-3e436974087f80f586acf2462bc547a5\" target=\"_blank\" rel=\"noopener noreferrer\">Shielded Bitcoin: Private Transfers on the Bitcoin L1<\/a>,\u201d was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin. The researchers ask whether bitcoin can move privately using the network exactly as it exists today. Their answer is a metaprotocol whose rules are interpreted by independent software rather than Bitcoin consensus.<\/p>\n<p>Programs called indexers scan Bitcoin for Shielded Bitcoin data, verify its cryptographic proofs and reconstruct the private system\u2019s history. Invalid data can still land onchain because Bitcoin doesn\u2019t understand the metaprotocol. Indexers simply ignore it. Anyone can rerun those checks using Bitcoin\u2019s published history, meaning no particular indexer gets to decide what is valid. That is the fascinating part. Bitcoin keeps doing what it has always done, as another set of rules makes sense of selected data riding on top.<\/p>\n<h2>Alice Pays Bob Without Showing the Amount<\/h2>\n<p>Value inside Shielded Bitcoin lives in encrypted records called notes. <a href=\"https:\/\/news.bitcoin.com\/meet-alice-bob-the-foundation-of-bitcoins-cryptography\/\">If Alice pays Bob<\/a>, she creates a note containing an amount and Bob\u2019s receiving information, then encrypts it so Bob can identify it. Her bitcoin transaction publishes the encrypted note alongside a serial number called a nullifier and a zero-knowledge proof.<\/p>\n<p>The proof establishes that Alice\u2019s notes exist, she can spend them and the value going in equals the value coming out without revealing which notes were spent or their amounts. Indexers verify the proof and ensure each nullifier hasn\u2019t previously appeared. Once used, that nullifier cannot be used again, preventing the same note from being spent twice. Bob\u2019s wallet scans new encrypted notes until his viewing key opens one.<\/p>\n<p>Onchain the public still sees that a shielded transfer happened, its timing, the number of notes involved, its fee and the bitcoin transaction carrying it. What disappears are the amount, shielded sender and recipient, and the connection to previously spent notes. A <a href=\"https:\/\/news.bitcoin.com\/a-beginners-guide-to-bitcoin-address-evolution\/\">recognizable bitcoin address<\/a> repeatedly paying transaction fees could still leak clues, and a small number of users would make the crowd easier to analyze.<\/p>\n<p>Privacy also costs block space. Komarov <a href=\"https:\/\/x.com\/laurashin\/status\/2103187450872918251?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">told journalist Laura Shin in an interview<\/a> that a shielded payload is about 700 vbytes compared with roughly 100 to 200 for a typical Bitcoin payment, making it around four times larger. Komarov called the added cost \u201cnot catastrophic.\u201d More users, meanwhile, would strengthen the anonymity set by giving individual payments a larger crowd to disappear into.<\/p>\n<h2>The Biggest Problem Is the Door<\/h2>\n<p>Here\u2019s the catch. The Sept. 24 white paper describes transfers after bitcoin is already inside the shielded system. Getting bitcoin in and back out is being left to a companion white paper based on <a href=\"https:\/\/x.com\/allocinitxyz\/status\/2098161814215528623?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">[[alloc] init]\u2019s Bitcoin PIPEs v2 research<\/a> and witness encryption.<\/p>\n<p>The planned system would cryptographically lock a BTC private key until someone produces the required proof, while the Bitcoin network ultimately sees an ordinary Schnorr spend. [[alloc] init] says it would never custody user funds, even at the boundary. But witness encryption is young technology. Komarov said its ciphertexts have been reduced from roughly 300 terabytes to about 8 terabytes in a year. That is enormous progress, but eight terabytes is still eight terabytes. \u201cIt\u2019s still pretty experimental,\u201d Komarov explained.<\/p>\n<p>Entry and exit could also expose amounts and timing that help observers link outside Bitcoin activity with shielded transactions. The lab has run public break-it challenges since May, but there is no launch date. Until the door works, Shielded Bitcoin remains research rather than a usable privacy system.<\/p>\n<h2>Bitcoin and Zcash Communities Weigh In<\/h2>\n<p>The Zcash influence is obvious. Zcash already uses encrypted notes, nullifiers and zero-knowledge proofs, while Shielded Bitcoin borrows that architecture without creating another blockchain. Public company Cypherpunk called Shielded Bitcoin \u201ca great step forward\u201d and further remarked that more privacy on Bitcoin benefits everyone.<\/p>\n<p>But Cypherpunk also <a href=\"https:\/\/x.com\/cypherpunk\/status\/2103193374261920255?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">argued the design isn\u2019t yet a competition<\/a> for the Zcash chain. The firm pointed to its trusted setup, lack of consensus enforcement and trustless light clients, an unfinished bridge, and Bitcoin L1 fees, while noting Zcash already has nearly 10 years in production and a shielded pool worth more than $7 billion. \u201cFinancial privacy isn\u2019t zero-sum,\u201d Cypherpunk concluded.<\/p>\n<p>X reactions quickly became less diplomatic. <a href=\"https:\/\/x.com\/IIICapital\/status\/2103163061846892692?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">Joe Burnett wrote<\/a> \u201czcash to 0,\u201d while Daniel Buchner, director of product and director of digital assets at Proof, <a href=\"https:\/\/x.com\/csuwildcat\/status\/2103215291928805516?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">shared his two cents saying:<\/a><\/p>\n<blockquote>\n<p>\u201cThe amount of privacycoin stans having cope-induced seizures from the mere thought that the Bitcoin community is progressing down the path of private transactions, potentially Thanos snapping the narratives of one-off privacy chains, is approaching a decibel level where ear damage is becoming a concern.\u201d<\/p>\n<\/blockquote>\n<p>Sam Callahan, director of strategy and research at OranjeBTC, <a href=\"https:\/\/x.com\/samcallah\/status\/2103161378676891682?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">offered a broader argument<\/a>. \u201cPeople still misunderstand Bitcoin\u2019s moat. Bitcoin doesn\u2019t need to win every feature race. Privacy, speed, and functionality can be built over time. The moat is its decentralization, security, and credible monetary policy. And on those dimensions, nothing else comes close.\u201d<\/p>\n<p>The X account Rune brought the privacy-coin <a href=\"https:\/\/x.com\/RuneCrypto_\/status\/2103241519784198583?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">rivalry back to earth<\/a> with a reference to the Bitget hack and monero (XMR), <a href=\"https:\/\/x.com\/RuneCrypto_\/status\/2103241519784198583?s=20\" target=\"_blank\" rel=\"noopener noreferrer\">writing on X<\/a>, \u201cZEC holders praying the Bitget hacker uses zcash to hide the trace\u2026 but for some reason hacker is using XMR.\u201d Behind the trash talk is a real technical debate over whether the Bitcoin blockchain can acquire stronger privacy without changing its base rules.<\/p>\n<h2>Bitcoin Carries Secrets It Cannot Read<\/h2>\n<p><a href=\"https:\/\/www.bitcoin.com\/bitcoin.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Unlike Satoshi\u2019s white paper,<\/a> Shielded Bitcoin is a specification, not a product. The peg remains unfinished, witness encryption is experimental, fees can leak information, wallets need to become practical and privacy improves only when enough users participate. The current Groth16 proof design also requires a one-time trusted setup.<\/p>\n<p>Shikhelman was scheduled to present the research at BitDevs NYC on Sept. 24 as [[alloc] init] sought feedback ahead of its companion white paper on entry and exit. The next workaround will determine whether the private system described on paper can connect safely to actual bitcoin.<\/p>\n<p>For now, the idea is wonderfully counterintuitive. [[alloc] init] wants Bitcoin to record private financial activity without changing Bitcoin or asking the network to understand what it is recording. If the unfinished pieces work, Bitcoin could preserve transactions forever while remaining blind to the amounts and counterparties that made those transactions worth hiding in the first place.<\/p>\n<\/p><\/div>\n<p><a href=\"https:\/\/news.bitcoin.com\/featured\/shielded-bitcoin-proposal-aims-to-bring-privacy-to-bitcoin-l1\/\">Source link <\/a><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>(Originally posted on : Bitcoin News ) Key Takeaways The cryptography lab [[alloc] init] unveiled Shielded Bitcoin on Sept. 24, bringing the idea of private transfers to Bitcoin without a soft fork. Shielded Bitcoin transfers run about 700 vbytes, roughly 4 times the size of a typical BTC payment. [[alloc] init] still has work ahead, [&hellip;]<\/p>\n","protected":false},"author":19,"featured_media":78634,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[32],"tags":[],"_links":{"self":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78633"}],"collection":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/users\/19"}],"replies":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/comments?post=78633"}],"version-history":[{"count":0,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/posts\/78633\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media\/78634"}],"wp:attachment":[{"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/media?parent=78633"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/categories?post=78633"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/crowdfundjunction.com\/blog\/wp-json\/wp\/v2\/tags?post=78633"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}