skip to content

‘Shielded Bitcoin' Paper Proposes Private BTC Transfers

🔐 ‘Shielded Bitcoin' Paper Proposes Private BTC Transfers - thumbnail

This article originally appeared in Galaxy Research's weekly newsletter. Subscribe to get timely insights delivered to your inbox every Friday morning.

On Thursday, Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin, researchers at cryptography R&D firm [[alloc] init], published Shielded Bitcoin. It is a protocol for private BTC transfers directly on the Bitcoin L1, with no soft fork or sidechain. In short, it takes Zcash’s shielded pool design (encrypted notes, public nullifiers, and zero-knowledge proofs) and runs it as a metaprotocol that uses Bitcoin only to publish data.

Value is held as “encrypted notes.” Transfers are data envelopes posted via OP_RETURN. The envelope carries encrypted notes for recipients and a proof that the sender owns the inputs and didn’t inflate the supply. Indexers watch Bitcoin for Shielded Bitcoin transfers to replay every envelope in block order and discard invalid ones.

Unlike Shielded CSV, the closest prior proposal, all data would live onchain, so a wallet could recover its funds from its seed alone. The abstract explicitly noted that peg-in and peg-out (the way BTC enters the system) are outside the paper’s scope.

The paper lands in the middle of perhaps the strongest privacy trade in the history of crypto.

The paper lands in the middle of perhaps the strongest privacy trade in the history of crypto. Zcash (ZEC) topped $1,600 this week and now ranks No. 9 by market cap among cryptocurrencies at ~$26 billion. It is up ~90% in 30 days and ~2,500% over the past year. The rally has several catalysts. Grayscale’s Zcash ETF (ZCSH) began trading on Aug. 25 and has since drawn more than $250 million in net inflows. On Sept. 16, Paradigm co-founder Matt Huang disclosed that the firm holds ZEC and called Zcash a private complement to Bitcoin. This is yet another crypto fund coming out to the market and validating ZEC as a clear expression of the privacy trade (Multicoin did this earlier this year). Shielded Bitcoin is an attempt to bring that privacy to Bitcoin itself. As it stands, users have to use other blockchains like Ethereum, Monero, Solana, or Zcash to achieve private digital transactions.

The day before the paper came out, Citrea, a Bitcoin L2 backed by Galaxy Ventures, acquired Crest, a private Bitcoin wallet. Citrea called this acquisition an attempt to “bring Zcash-style privacy to Bitcoin.”

This comes on the heels of NEAR pursuing the same demand for privacy. It recently announced confidential perps by default and confidential limit orders. NEAR is also +150% in the past month. The Zcash and NEAR narratives reinforce each other as well. The Zcash wallet ZODL is among the largest referral sources on NEAR Intents.

Our take

For most of this year and last year, Bitcoin maximalists scoffed at ZEC’s run. The common view among this group has been that it’s a “coordinated pump heading for a rug.” Maxis have been saying this since $200-$300, and the token has proceeded to 5x since then. Shielded Bitcoin gives that camp something to lean on. It’s a clever design and is a direct shot at the “private complement to Bitcoin” thesis now priced into ZEC, because it relies only on Bitcoin.

Likely the hardest part of the design isn’t in the paper, though. Peg-in and peg-out, the mechanisms that lock and release real BTC, are deferred to a future PIPEs v2 paper. (That’s PIPEs as in Polynomial Inner Product Encryption, not the mechanism DATs used to raise money.) The authors explicitly decline to claim that entry and exit are trustless or censorship-resistant, which really matters. Bridges have repeatedly been the most exploited component in crypto: Ronin, Wormhole, Nomad, KelpDAO, just to name a few. Novel ZK circuits also need to be battle tested; Zcash’s own Orchard Pool carried a soundness bug for four years through professional audits (which developers have since responded to with the Ironwood upgrade).

The design of Shielded Bitcoin also leans on Bitcoin Core v30’s looser OP_RETURN relay policy, the same change many maximalists fought hard against last year. Whichever architecture wins, the demand side of privacy in crypto looks more durable than in past cycles. This is partly due to the rapidly changing threat model.

Flock Safety is probably the clearest real-world example of privacy concerns. The company runs about 120,000 AI-enabled license-plate cameras across the U.S.

Gadsden Flag (Flock Camera Edition)
The privacy trade is a response to surveillance getting more automated and permanent. (Image: Rep. Thomas Massie, via Wikimedia Commons)

Critics argue the danger is in the network, since police can run algorithms across it to flag movement patterns as “suspicious”. After reports of officers abusing the system, the company cut its default data retention from 30 days to seven.

Transparent blockchains are global, permanent, and free for anyone to query. Clustering addresses onchain has been a mature capability for years. The bottleneck has always been linking an onchain public address to a real person’s identity, and AI advancements will likely remove this obstacle.

Earlier this year, researchers from ETH Zurich and Anthropic showed that LLM agents can re-identify pseudonymous Hacker News users with high precision from their profiles alone.

It’s not unreasonable to expect a future in which AI can use a tweeted transaction hash or one withdrawal from a KYC’d exchange to identify an individual's entire history of onchain activity. The blockchain never forgets.

Grayscale made this same argument when it launched ZCSH: as AI changes how financial activity can be monitored, demand for true financial privacy should only grow. The privacy trade is a response to surveillance getting more automated and permanent. We’ll be watching it closely.

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.