Researchers have released a specification for a privacy layer called Shielded Bitcoin that aims to hide transaction details on the base layer. The design borrows concepts from Zcash but requires no alteration to Bitcoin's consensus rules.
Overview
The 56-page paper was dated September 24, 2026 and authored by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of the cryptography group [[alloc] init]. Scott Odell, the group’s chief operating officer, said the work had been in development for a while and represents a way to make Bitcoin more private without changing its core rules. The authors stressed that they examined what information the protocol might leak and sought to minimise any disclosure.
Technical Design
Funds are stored as encrypted notes, and each transfer includes a proof that verifies the sender’s control of those notes and that the total value in equals the total value out. A public nullifier lets software detect double spends without revealing which note was used. The protocol records each transfer as data in an OP_RETURN output on the Bitcoin blockchain; the chain itself does not validate the proof, while separate indexer software checks the zero-knowledge evidence and reconstructs the shielded state. The current implementation uses the Groth16 proof system, which depends on an honestly run trusted-setup ceremony. A typical transfer with two inputs and two outputs occupies about 625 vbytes, relying on the enlarged OP_RETURN limit introduced in Bitcoin Core v30, a change that node operators can opt out of. The paper leaves peg-in and peg-out mechanisms to a follow-up work based on earlier PIPEs v2 research that encrypts a signing key recoverable only with a valid proof. An appendix sketches an optional compliance layer where a trusted authority can certify approved deposits, allowing institutions to verify a note’s origin without exposing the full transfer graph; notes lacking such certification remain usable.
Why it matters
Unlike a 2025 proposal called Shielded CSV, which required users to keep their own transaction data, Shielded Bitcoin moves the verification burden to external indexers while keeping the base layer unchanged. The approach conceals the sender, recipient and amount, similar to Zcash and Monero, but leaves timing, fees and the number of inputs and outputs visible on chain. This distinction means observers can still see that a shielded transfer occurred, though not the details of the exchange. The research arrives as Zcash gains broader regulated exposure, with a Grayscale ETF trading on NYSE Arca since August 25 and a 21Shares product listed on Euronext Paris and Amsterdam on September 22, and ZEC trading around $1,592 on September 25. If adopted, the design could offer Bitcoin users a strong privacy option without necessitating a consensus fork or new token.




