https://www.allocinit.xyz/uploads/shielded-bitcoin.pdfThe paper does not specify the *peg-in / peg-out* process. That's pretty important since we saw what happened with liquid.
"The peg-in and peg-out constructions are not specified here. As discussed in Section 20.4, the expected direction for Shielded Bitcoin is to use PIPE-based boundary transitions: ordinary Bitcoin liquidity is committed on L1, while entry, exit, and unlock rules are represented as Bitcoin-anchored metaprotocol transitions rather than as changes to Bitcoin consensus. Federated or multisignature custody, BitVM-style bridges, and future covenant- or vault-based constructions remain useful comparison points, but the intended architecture is PIPE-based. The trust, liveness, censorship-resistance, and privacy properties of entry and exit therefore belong to the boundary protocol, not to the transfer proof."
And then... the money shot :
"*Opt-in KYC* and Certified-Recipient Lineage
A future deployment could let wallets attach an encrypted lineage attestation to an output created for
a Trust-Authority-certified payment address. Without revealing earlier addresses or the transfer graph,
the proof would show that each lineage root came from an authenticated peg-in whose actual Bitcoin
inputs were approved, that every later preserving transfer consumed only notes carrying the same claim, and that each claim-preserving transfer output used the certified PaymentAddress. An institution could verify this evidence locally and bind it to a fresh operation challenge. Bitcoin consensus and base replay would not interpret it, and notes without the evidence would remain valid. This direction is discussed further in Appendix D."
I love when cryptographers and cypherpunks talk about "opt-in" KYC. That makes me all fuzzy inside. /sarc
They have to work really hard to recycle that zcash stuff.
https://kosher.cash/