A proposal published on September 24 aims to transfer bitcoin while hiding amounts, recipients, and links between payments, without a soft fork and without changing Bitcoin's consensus rules.
It's called Shielded Bitcoin. The authors are Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of Alloc Init. The system borrows Zcash's structure, but reconstructs its own state from Bitcoin's history: a "metaprotocol" applied to data already published on the chain.
Value circulates in the form of "notes." A note contains satoshis and data that lets the recipient recognize and spend it.
To prevent double-spending, each spent note produces a nullifier. This is a cryptographic marker published only once. If it reappears, the transaction is rejected. An observer sees the nullifier but cannot directly link it back to the note it derives from.
Compared to CoinJoin, PayJoin, and Silent Payments, here even the amounts are meant to stay hidden.
The project also separates spending keys from viewing keys. A reviewer can be given visibility into payments without handing over the funds. But a viewing key doesn't prove the balance, nor does it prove that the entire history has been shown.
The hardest part remains: getting real bitcoin in and out of the private system. Alloc Init points to PIPEs v2 and witness encryption. A UTXO's key would only be recovered by presenting a valid proof; spending would then happen with a normal Schnorr signature.
naddr1qq3k...
It's called Shielded Bitcoin. The authors are Clara Shikhelman, Mikhail Komarov, and Aleksei Moskvin of Alloc Init. The system borrows Zcash's structure, but reconstructs its own state from Bitcoin's history: a "metaprotocol" applied to data already published on the chain.
Value circulates in the form of "notes." A note contains satoshis and data that lets the recipient recognize and spend it.
To prevent double-spending, each spent note produces a nullifier. This is a cryptographic marker published only once. If it reappears, the transaction is rejected. An observer sees the nullifier but cannot directly link it back to the note it derives from.
Compared to CoinJoin, PayJoin, and Silent Payments, here even the amounts are meant to stay hidden.
The project also separates spending keys from viewing keys. A reviewer can be given visibility into payments without handing over the funds. But a viewing key doesn't prove the balance, nor does it prove that the entire history has been shown.
The hardest part remains: getting real bitcoin in and out of the private system. Alloc Init points to PIPEs v2 and witness encryption. A UTXO's key would only be recovered by presenting a valid proof; spending would then happen with a normal Schnorr signature.
naddr1qq3k...
11❤️1
