Zcash-Style Privacy Could Come to Bitcoin Without Altering Its Base Protocol

Researchers have outlined a proposal that could bring private Bitcoin payments to users without requiring changes to Bitcoin’s existing rules. The design, however, still lacks a finalized method for moving real BTC into the system and withdrawing it later.

The proposal comes as privacy-focused cryptocurrencies such as Zcash see renewed interest from investors. The research, titled Shielded Bitcoin, was published Thursday by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of cryptography firm [alloc] init.

The proposed system takes inspiration from Zcash’s encrypted payment architecture. Bitcoin-denominated funds would be represented by encrypted records known as notes. When users spend those notes, they would publish a marker showing that the funds had already been used, along with a cryptographic proof demonstrating ownership and confirming that no additional funds were created.

Details including the payment amount, sender and recipient would remain concealed.

The approach differs from Zcash in how the proofs would be verified. Zcash performs that verification directly on its blockchain, while Shielded Bitcoin would publish the encrypted transfer information on Bitcoin and rely on independent software to validate the private payment. Consequently, Bitcoin could accept the transaction containing the payment even if the corresponding Shielded Bitcoin verification failed.

The research comes as transaction privacy becomes increasingly relevant for cryptocurrency use cases such as business payments, payroll and everyday purchases. Standard Bitcoin transactions permanently expose wallet addresses and payment amounts. Once an address is linked to an individual or organization, activity connected to that address can become easier to track.

Ethereum is exploring a comparable privacy concept through a proposal for a shared private pool. The system would allow users to transfer ether and other tokens without publicly disclosing transaction details, with payroll, treasury management and donations among the proposed applications.

Zcash’s Privacy Approach

Zcash allows users to make either transparent transactions, where addresses and amounts are publicly visible, or shielded transactions, which hide those details.

CoinDesk calculations using ZecStats data showed that approximately 4.9 million ZEC were held in shielded pools on Friday. That figure was 14% higher than on July 30 and represented about 29% of Zcash’s issued supply. Following ZEC’s recent rally, those holdings were worth roughly $7.8 billion.

Zcash processed around 63,000 shielded transactions last week, making it the network’s busiest week for private transfers since 2022 and its fourth-highest weekly total. Total reported transfer volume exceeded $23 billion, the highest weekly figure since 2021 and the second-largest in the network’s history.

The increase in privacy activity has coincided with significant market attention toward Zcash. ZEC had climbed more than 2,300% over the previous year by early September and passed the $1,000 level. The cryptocurrency continued rising and traded above $1,600 on Wednesday.

The technology connecting Bitcoin privacy research to Zcash has roots dating back to 2013. Zerocoin was initially proposed as a privacy extension for Bitcoin. Later research led to Zerocash, which eventually became the foundation for Zcash when the separate cryptocurrency launched in 2016.

Shielded Bitcoin would store encrypted payment information on the Bitcoin blockchain. Wallet users could use their keys to reconstruct valid private transactions from the public record. Separate viewing keys could also let users disclose transaction information to auditors or accountants without giving them the ability to spend the funds.

Open Questions Around BTC

The proposal’s biggest unresolved issue is how users would deposit ordinary BTC into the system and withdraw it afterward. The 56-page paper leaves those mechanisms for future research involving PIPEs, a technology intended to lock a Bitcoin signing key until specific conditions have been satisfied.

The researchers’ statement that users retain control of their funds applies to transfers made within the system and specifically excludes the deposit and withdrawal process.

These missing components have prompted criticism from some developers and Zcash supporters.

Mert Mumtaz, co-founder of Helius and a Zcash supporter, characterized the proposal on X as a synthetic ledger with significant tradeoffs. He cited its trusted-setup requirement and the absence of fee anonymization, which could still expose the Bitcoin wallet used to publish a private transfer.

Mumtaz also highlighted the lack of a protocol-level mechanism for moving actual BTC into and out of the system. Without such functionality, he argued, users would effectively be dealing with synthetic representations of Bitcoin.

He nevertheless acknowledged the research and its adoption of concepts developed through Zcash. He said the system would require substantial additional research and development.

Cypherpunk, a company that holds and mines Zcash, also welcomed the research while saying it did not view the proposal as direct competition for Zcash. The company said privacy is strongest when it is integrated into the base layer, while noting that avoiding changes to Bitcoin is both one of Shielded Bitcoin’s principal advantages and one of its biggest limitations.

Cypherpunk added that increasing Bitcoin’s privacy could benefit the wider cryptocurrency ecosystem.

The [alloc] init researchers also acknowledge several limitations. Their reference design requires a cryptographic setup in which the system’s security depends on at least one participant behaving honestly. Transaction timing and fee payments would remain visible, and an efficient method for lightweight wallets to verify reconstructed payment histories has yet to be developed.

Komarov estimates that a private payment would consume roughly 700 virtual bytes, compared with about 100 to 200 virtual bytes for a conventional Bitcoin transaction. At the same fee rate, the larger size could make the miner fee approximately four times higher.

No launch date had been announced for the proposed system as of Friday.