Researchers Propose “Shielded Bitcoin” to Bring Zcash-Style Privacy to BTC

Changelly
Coinbase


  • [alloc] init researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin released the 56-page Shielded Bitcoin paper on 24 September.
  • Transfers would be published on Bitcoin, while separate indexer software verifies the zero-knowledge proofs and rebuilds the private ledger.
  • The design relies on a trusted setup and leaves deposits and withdrawals of real Bitcoin to a separate paper.

Researchers at cryptography firm [alloc] init published a design for private Bitcoin transfers that would hide amounts, senders and receivers without any change to Bitcoin’s consensus rules.

Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin wrote the 56-page paper, titled “Shielded Bitcoin”. Shikhelman, the firm’s head of protocol research, was scheduled to present it at a BitDevs meetup in New York the same evening.

The design borrows from Zcash. Like Zcash, it holds value in encrypted records called notes. Spending a note publishes a public marker, called a nullifier, which stops the same note from being spent twice. Each spend also carries a zero-knowledge proof that the transfer is valid, without revealing its contents.

Read more: BlackRock Says AI Agents Could Accelerate Digital Asset Adoption

okex

Indexers Check the Proofs

Unlike Zcash, Shielded Bitcoin has no blockchain of its own. Zcash builds the checks on shielded transfers into its own consensus rules. Here, each transfer is published on Bitcoin, which only records and orders the data.

Separate software called indexers then replays those transfers in Bitcoin’s order and verifies the proofs. The authors say any two correct indexers reading the same Bitcoin history reach the same private ledger without coordinating.

“Peg-in and peg-out, the mechanisms by which value enters and exits the shielded transfer system, belong to the broader system and fall outside the scope of this paper.”

The authors plan to handle that step with PIPEs v2, a separate [alloc] init design that uses witness encryption to lock Bitcoin signing keys behind set conditions. The Shielded Bitcoin paper sets no launch date.

Setup, Fees and Relay Limits

The paper’s security claims hold only if its proof system’s setup is generated honestly. Its reference profile uses Groth16 proofs, which need a trusted setup ceremony.

Even with the proofs, transfer timing, fees and the number of notes going in and out remain visible on Bitcoin, the authors state. A transfer with two inputs and two outputs produces a 610-byte envelope, including a 192-byte proof. The paper carries it in a single OP_RETURN output of 625 virtual bytes.

That carrier depends on Bitcoin Core’s decision to lift its OP_RETURN data cap in version 30.0. Node operators can still restore that cap on their own machines. 

The paper lists tighter relay or mining policy around large data outputs as a deployment risk. A soft-fork proposal last October, BIP-444, sought to cap OP_RETURN data at 83 bytes.

For regulated institutions, the paper sketches an optional layer in which a trust authority certifies approved deposits and recipient addresses. Its wallet design also lets holders give auditors read-only viewing keys, which carry no power to spend.

Read more: Australia’s 40-Year Economic Outlook Puts AI at the Center of Growth, Omits Crypto



Source link

Changelly

Be the first to comment

Leave a Reply

Your email address will not be published.


*