Overview
- The 56‑page Shielded Bitcoin specification, published Sept. 24 by [alloc] init researchers Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin, outlines a metaprotocol that embeds encrypted notes, public nullifiers and ZK proofs as data on Bitcoin.
- Under the design, separate indexers—not Bitcoin nodes or miners—would scan blocks, verify proofs and rebuild a private note state so Bitcoin consensus and block validation remain unchanged.
- Key practical gaps remain: the paper defers peg‑in/peg‑out mechanics to a follow‑on PIPEs paper, the reference design currently needs roughly 330 terabytes of on‑disk state with a stated target of about 100 gigabytes, and it uses Groth16 which requires a trusted setup.
- Experts reacted with cautious interest: some ZK pioneers praised the direction while others warned the cryptography is experimental and pointed to remaining privacy leaks such as visible fees, timing and input/output counts.
- If developed and vetted, the proposal could give Bitcoin users stronger private payment options and pressure standalone privacy coins, but it faces major engineering, cryptographic review and regulatory questions before real‑world use.