Researchers Unveil “Shielded Bitcoin”: Zcash-Style Privacy on Bitcoin’s Base Layer Without a Fork

A new Shielded Bitcoin spec brings Zcash-style private transfers to Bitcoin L1 via zero-knowledge proofs—no consensus changes—relying on indexers and OP_RETURN policy.

Bitcoin
Cryptocurrency
Regulations
Economy
Because Bitcoin
Because Bitcoin

Because Bitcoin

September 25, 2026

Bitcoin has long traded scalability for auditability. A new 56-page specification for “Shielded Bitcoin” argues you can add Zcash-grade privacy to Bitcoin’s base layer without touching consensus—if you’re willing to move validation off-chain and depend on mempool policy that isn’t guaranteed.

Authored by Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin and dated September 24, 2026, the design borrows Zcash’s encrypted note model and zero-knowledge proofs. Value lives in encrypted “notes,” and each transfer includes a proof that the spender controls the notes and that inputs equal outputs. A publicly visible nullifier prevents double-spends while keeping the spent note opaque. The network sees that something happened; it does not learn who paid whom or how much. Timing, fees, and the count of inputs/outputs remain observable.

Here’s the critical shift: Bitcoin simply records the data. Independent indexers verify the proofs and reconstruct the shielded state. That externalization of rule enforcement is the bet. It avoids consensus changes and lets the system run on today’s Bitcoin, but it trades protocol-native guarantees for an ecosystem of verifiers that users must trust to be available, correct, and diverse enough to withstand censorship or capture.

Mechanically, each transfer is embedded in an OP_RETURN output—about 625 vbytes for a typical two-input, two-output shielded transfer, per the paper. That size assumes the larger OP_RETURN default in Bitcoin Core v30. Because that default is a relay-policy choice and has been contested, nodes and miners could tighten it. The design implicitly relies on enough infrastructure choosing to forward these transactions; if policy drifts, throughput and reliability could suffer.

The current construction uses Groth16, a fast proof system with a trusted setup. Many practitioners accept the performance trade-off in exchange for compact proofs, but the ceremony introduces a social trust surface. The authors also contrast their approach with 2025’s “Shielded CSV,” where users must retain their own transaction data—information that generally cannot be reconstructed from the chain—raising long-term recoverability and UX concerns.

Two areas are intentionally deferred. The spec covers only transfers inside the shielded domain. How native BTC moves in and out is slated for a separate paper building on Bitcoin PIPEs v2—prior work from the same team that encrypts a Bitcoin signing key so it can be recovered only alongside a valid proof. That peg-in/peg-out path will determine actual usability: exchange integrations, wallet flows, and compliance workflows often hinge on it.

Speaking publicly, the authors emphasized careful scrutiny of what metadata the protocol leaks. Komarov framed the effort as Zcash-like privacy on Bitcoin L1 via PIPEs v2, and the team’s COO said they had been working toward “Bitcoin privacy without changing Bitcoin” for some time. An appendix proposes an optional compliance layer: a “Trust Authority” can certify approved deposits so institutions can verify a note’s provenance without revealing the transfer graph. Crucially, uncertified notes would still be valid, preserving neutrality while offering an on-ramp for regulated participants.

Market context matters. Zcash—whose primitives underpin this design—now sees regulated access in the U.S. and Europe. Grayscale’s Zcash ETF began trading on NYSE Arca on August 25, and 21Shares listed Europe’s first Zcash ETP on Euronext Paris and Amsterdam on September 22. On September 25, ZEC changed hands around $1,592, up 4% on the day, with a seven-day peak of $1,658.86, per CoinGecko.

My read: the architecture is elegant precisely because it refuses to ask Bitcoin to change. The pressure point becomes coordination—relay policy for OP_RETURN and a robust, permissionless indexer market. If those two layers harden, Shielded Bitcoin could offer pragmatic, ZK-powered privacy to BTC natives. If they don’t, the system risks being brittle at the edges. The forthcoming peg design will be the moment of truth.