Shielded Bitcoin: Researchers Propose Private Transfers Without Soft Fork
Researchers at Alloc Init have proposed a system to bring Zcash-style private transfers to Bitcoin without requiring a soft fork. The proposal, called Shielded Bitcoin, would conceal transaction amounts, senders, receivers, and links to previously spent funds using encrypted notes and zero-knowledge proofs.
The proposal draws from Zcash's architecture, using similar techniques such as public nullifiers that mark notes as spent and zero-knowledge proofs that show transactions are valid. However, unlike Zcash, Shielded Bitcoin would not operate its own blockchain or consensus mechanism.
Indexers would verify zero-knowledge proofs, check that funds haven't been double-spent, and reconstruct the state of the shielded system. The researchers acknowledge a limitation in the proposal: a new shielded pool would start without the anonymity set Zcash has accumulated over years of use.
The proposal has received mixed reactions from the community. Developer Vadim Zavodil criticized the idea, saying that much of its privacy stack had already been implemented by Zcash and questioning how much privacy a newly launched system could initially provide. Pierre-Luc Dallaire-Demers raised another issue, describing the construction as not quantum-resistant at all.
However, Zerocash co-author Eli Ben-Sasson was more supportive of the proposal's direction, saying that the original intent behind the Zerocash paper was to bring privacy to Bitcoin.