A team of cryptographers has unveiled a design for a privacy-focused metaprotocol that could allow fully shielded Bitcoin transfers while leaving the underlying consensus untouched.
Proposal overview
The initiative, authored by Clara Shikhelman, Misha Komarov and Aleksei Moskvin, describes a protocol that operates as a separate layer on top of the Bitcoin blockchain. Rather than altering the network’s rules, it introduces a new transaction format that can be recorded in any standard Bitcoin transaction – for example via OP_RETURN or the witness field – and is identified by a distinct prefix such as “shbtc:”. Validation of these entries is performed off-chain by a dedicated indexer that watches the chain, discarding malformed records while maintaining a view of the system’s state.
Transaction mechanics
Within the protocol, the analogue of a UTXO is called a “note”. When a note is spent, the sender publishes a nullifier, an encrypted proof that the note has been consumed without revealing which note it was. The indexer aggregates nullifiers into a growing set; any repeat indicates a double-spend attempt. To prove legitimacy, each transaction must contain a zero-knowledge proof that:
- the referenced note appears in the global note merkle tree,
- the spender possesses the appropriate spend key,
- the nullifier is derived correctly, and
- no new coins are created.
Key material is derived from a master secret in a hierarchy similar to Bitcoin’s HD wallets. A user’s receiving address is generated by combining a diversifier with a view key, while separate keys handle spending, nullifying and decryption of incoming notes. Encryption of note outputs uses an ephemeral key pair shared between sender and recipient, ensuring that only the intended party can recover the value, diversifier and seed data.
Privacy guarantees
Because the protocol hides amounts, recipients and the link between inputs and outputs, its privacy level is comparable to Zcash’s shielded pools. No coin-join style mixing or periodic re-randomization is required; the zero-knowledge proof alone enforces that each nullifier corresponds to a valid, previously created note. The design also avoids any need for a coordinating service or custodial entity, relying solely on the user’s node and the public indexer.
Pegging mechanism
Moving Bitcoin into the shielded layer uses a construct called PIPEs (Programmable Incentive-based Privacy Envelopes). Version 2 of PIPEs employs witness encryption: a private key is encrypted under a condition that can only be satisfied by presenting a zero-knowledge proof that a specific on-chain transaction has occurred. This enables deposits and withdrawals without any operator or federation, as the funds are released only when the required proof is generated.
Current status
The researchers have released a whitepaper and an accompanying blog post outlining the architecture. Development of the PIPEs-based peg is still in progress, with a detailed technical paper slated for near-future publication. No implementation has yet been deployed on mainnet, and the design remains a proposal pending community review.
Why it matters
If adopted, Shielded Bitcoin could provide strong transaction privacy on the world’s largest blockchain without the need for hard forks or trusted intermediaries. By leveraging existing Bitcoin infrastructure and a passive indexing model, the protocol aims to lower the barrier to privacy-enhancing features while preserving the network’s security guarantees. The success of the PIPEs peg would also demonstrate a novel way to move assets into a privacy layer without custodial risk, potentially influencing future privacy solutions across the cryptocurrency ecosystem.




