Shielded Bitcoin: A Proposal for Private Onchain BTC Transfers
Summary
The article describes Shielded Bitcoin, a proposed protocol for private BTC transfers on Bitcoin’s base layer without a soft fork or sidechain. It adapts a shielded-pool approach: value is represented by encrypted notes, while transfers publish encrypted recipient data and zero-knowledge proofs through OP_RETURN. Indexers replay the published envelopes in block order and reject invalid transfers. The article says the design keeps its data onchain, allowing wallet recovery from a seed, and distinguishes it from an earlier proposal that stored some data elsewhere.
A central limitation is that the paper leaves peg-in and peg-out—the mechanisms for entering and exiting the system with BTC—to future work. The article therefore does not establish that these transfers would be trustless or censorship-resistant. It also flags the need to test novel zero-knowledge circuits and notes reliance on Bitcoin Core’s OP_RETURN relay policy. Broader claims about demand for privacy are contextual arguments, supported by market developments and concerns about automated identity discovery, rather than evidence that the protocol is secure or adopted.
Key ideas
- Shielded Bitcoin proposes private BTC transfers using encrypted notes and zero-knowledge proofs published on Bitcoin.
- The design uses Bitcoin as a data layer and relies on indexers to replay and validate transfer envelopes.
- Onchain data is intended to let users recover funds from a wallet seed.
- The proposal leaves BTC entry and exit mechanisms outside its scope, so their trust and censorship properties remain unresolved.
- The circuits and operational assumptions require further testing before security can be established.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.