Shielded Bitcoin Proposes Private Transfers on Bitcoin Without a Soft Fork

Researchers have presented the Shielded Bitcoin metaprotocol, which aims to enable more confidential transfers on Bitcoin L1 without changing consensus. The proposal does not yet include specifications for native BTC entry and exit.

The Shielded Bitcoin proposal was presented on September 24, 2026, by researchers Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin. It is a metaprotocol that aims to enable more private transfers on Bitcoin’s first layer without requiring a soft fork or any other change to the network’s consensus rules.

The paper describes a mechanism similar to shielded transactions known, for example, from Zcash. However, this is neither an activated feature of the Bitcoin protocol nor a complete system ready for everyday users. A substantial part of the proposal—the entry of native BTC into this layer and its exit back to Bitcoin—has not yet been published.

What the Shielded Bitcoin Proposal Uses

The foundation consists of encrypted data records known as “notes,” nullifiers, and zero-knowledge proofs. Nullifiers are intended to prevent double spending, while zero-knowledge proofs make it possible to verify that rules have been satisfied without revealing sensitive information that the transaction would otherwise disclose.

Under this architecture, the Bitcoin blockchain would be used to publish and order data. However, Bitcoin consensus would not verify the metaprotocol’s rules themselves. That task would be performed by independent indexers that monitor data stored in Bitcoin transactions and evaluate it according to the Shielded Bitcoin rules.

The proposed transfer is intended to hide the amount transferred, the recipient, and links to previously spent notes. However, it is not completely invisible. The existence and timing of the transfer, its structure, the fee, and the Bitcoin transaction carrying the relevant data would remain public.

Without Consensus Changes, but Also Without a Finished BTC Connection

An advantage of the proposed model is that internal transfers within the shielded layer do not require a soft fork.

However, the published specification does not address the peg-in and peg-out mechanism—that is, how native BTC would enter the system and subsequently be returned. The authors defer this topic to a separate paper intended to work with PIPEs. Without these rules, it is not possible to claim that users can already move native BTC into and out of such a layer with known trust or censorship-resistance properties.

For practical use, it will also be important to determine how Bitcoin transactions containing metaprotocol data will be relayed across the network, what their costs will be, and whether they will be compatible with the relay policies of nodes and miners.

Cryptographic and Privacy Limitations

The reference profile uses the Groth16 proof system. It requires a trusted one-time setup: the security assumption is that at least one participant in the process acted honestly.

The proposal also does not automatically guarantee practical anonymity for all users. Its scope would depend on system usage, the size of the anonymity set, metadata, and wallet behavior. The authors acknowledge that inferences may be drawn from available data. Hiding amounts and recipients therefore does not mean eliminating all traceable information.

Technically, the key point is that Shielded Bitcoin attempts to add Zcash-like confidentiality on top of the existing Bitcoin layer without changing its consensus. At the same time, it shifts important verification to the metaprotocol’s rules and indexers rather than Bitcoin’s own network rules.

What to Watch Next

  • a separate specification for the peg-in and peg-out mechanism through PIPEs;
  • independent cryptographic review, implementation, a testnet, and security audits;
  • data publication costs and compatibility with Bitcoin node and miner policies;
  • practical metadata leaks, growth of the anonymity set, and responses from wallets and exchanges.

For now, this is a new proposal. It would therefore be premature to claim that Bitcoin will soon gain this functionality.

Sources

Verified and updated: September 26, 2026 06:23

Sharing