Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check

Shielded Bitcoin is a 56-page plan for private bitcoin payments that needs no change to Bitcoin rules. It also needs nobody in particular to verify the transfers, and it still has no way to get real BTC in or out. Privacy came back as a sidecar, and the meter is running.

On 24 September 2026, three researchers published a 56-page specification for private bitcoin payments that requires no change to Bitcoin’s rules. Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of the cryptography firm [alloc] init wrote Shielded Bitcoin, and it borrows Zcash’s encrypted payment design: value sits in encrypted records called notes, and spending one publishes a marker that it was used plus a proof the sender owned the funds and had not created new ones, while amount, sender and recipient stay hidden. The market is hot. As of 25 September, Zcash’s shielded pools held about 4.9 million ZEC, roughly 29% of issued coins, worth about $7.8 billion after a sharp rally, and ZEC traded near $1,558 on 28 September.

Here is my read. The selling point is also the defect. Bitcoin would store the encrypted transfer data and verify nothing, and the checking moves to separate software that nobody is obliged to run. The paper does not yet say how real BTC gets in or out; as one critic put it, that means you are holding synthetics. This is not a new argument. The last time someone tried to put privacy into Bitcoin, in 2013, the proposal was rejected and privacy left to become a separate chain. The 2026 attempt comes back without asking for a fork, and pays for that by giving up verification and leaving the bridge unbuilt. So the judgement up front: privacy is a feature with a meter on it, measured in virtual bytes, in volunteer verification and in court time. Design a sidecar nobody is paid to verify and you have not shipped privacy. You have shipped a claim about privacy.

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check
A bank safe deposit vault, photographed in 1908. A shielded pool is the cryptographic version of that room: the door is public, the contents are not. Image: The Cleveland Trust Company, 1908 (public domain)

2013: The First Version of This Was a Patch to Bitcoin

Trace it backwards. Zerocoin was proposed in 2013 by Matthew D. Green and his graduate students Ian Miers and Christina Garman at Johns Hopkins. It was designed as an extension to the Bitcoin protocol, a way to build coin mixing into the protocol itself, so a coin could be destroyed and minted again to erase its history. By design, it was not compatible with Bitcoin. The plan was to fold it into Bitcoin. The Bitcoin community did not accept it, so the developers launched it as an independent cryptocurrency instead. Then, on 16 November 2013, Green announced Zerocash, which also shields the amount transacted, cuts transaction sizes by 98%, and, unlike Zerocoin, requires an initial setup by a trusted entity.

Zerocash was computationally expensive: generating a proof took up to 3.2 GB of memory, which in 2013 was most of a modest machine. Later work cut that to about 40 MB. The interesting part is not the number. It is where the cost went. Move the mixing work off the base layer and it does not disappear; it reappears as memory, as setup, and as a trust assumption about whoever ran that setup. That is the first time in this story a design tried to make privacy cheap by relocating the expense. It was not the last.

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check
A printable bitcoin wallet, with the receiving address printed next to the private key that spends it. That is the amount of transparency the new design is trying to remove. Image: FlippyFlink (CC BY-SA 4.0)

2016: Privacy Shipped as a Separate Chain, With a Ceremony Attached

Three years later the bill came due in a different form. Zcash‘s initial release was 28 October 2016. It was developed by cryptographers at Johns Hopkins University and MIT, its code derived from bitcoin, and it is a fork of Bitcoin Core. It carries two kinds of address: transparent addresses that behave like bitcoin addresses, and shielded addresses whose transaction data is encrypted. Shielded transactions can be verified as valid without revealing sender, recipient or amount. Users can move funds between the pools, the optional privacy model is meant to preserve fungibility, and private viewing keys let designated third parties audit.

Then the ceremony. Instantiating the Zcash network required a master private key, and that key had to be destroyed afterwards, or someone could generate counterfeit coins. To keep any one person from holding it, software let people in six different locations generate the key collaboratively, use it to instantiate the network, and then destroy the computers involved.

Say plainly what that was: an admission that the correctness of the system rested on a procedure, not on maths alone. A proof system whose soundness depends on a ceremony going well is a proof system with an operations team standing next to it. That team can be run well. It cannot be proven to have been run well.

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check
Zooko Wilcox-O’Hearn, who led the Zcash Company. The launch needed a ceremony in six different locations and then six destroyed computers. Photo: Tobias Klenze (CC BY-SA 4.0)

2019: The Ceremony Was Already Solved

In 2019 an Electric Coin Company researcher, Sean Bowe, discovered Halo, a technique for generating zero-knowledge proofs without requiring a trusted setup ceremony. That eliminated the need for the elaborate multi-party ceremonies used at launch. The ceremony problem was solved seven years ago.

Now the sting. The 2026 proposal, by its own authors’ account, still requires a cryptographic setup whose security depends on at least one participant acting honestly. That is a solved problem reintroduced. A design that walks back past an established result is not evolving. It is regressing.

2024 and 2025: What Base-Layer Privacy Cost in Court

Before the architecture, the price list. Samourai Wallet was a privacy-focused Bitcoin wallet with a CoinJoin mixing tool, open source, released in 2015 and operated until 2024. In April 2024 the US Department of Justice charged its founders, Keonne Rodriguez and William Lonergan Hill, alleging the service furthered money laundering and constituted operating an unlicensed money transmitting business. The indictment alleged the mixing feature was used to launder $100 million in criminal proceeds.

A later-revealed DOJ memorandum acknowledged that the legality of crypto-mixing services was not fully settled under the financial regulatory framework and that the tools are not inherently illegal. The case reportedly caused internal tension between the DOJ and FinCEN over whether such wallets are money transmitters at all. Critics called it an attack on open source development and financial privacy, with parallels to the historical prosecution of encryption software.

Then the outcome. Rodriguez and Hill pleaded guilty in July 2025. On 6 November 2025 Rodriguez was sentenced to 5 years in prison, three years of probation after release, and a $250,000 fine. He is still inside. On 26 September 2026, Bitcoin Magazine published his “Samourai Letter #7”, syndicated from The Rage, documenting “the absolute worst 30 days of my life” during federal prison transit between institutions, alongside a petition to free him and Hill.

Here is the engineering conclusion. Any base-layer change to how bitcoin handles privacy puts a named person in the frame for what everyone does with it. That is the price list. Against it, a design that leaves Bitcoin’s rules untouched starts to look like a feature, because the operators of a sidecar are not the ones writing the protocol the state can point at.

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check
A United States federal courthouse. Samourai Wallet’s founders were charged in April 2024, pleaded guilty in July 2025, and Keonne Rodriguez was sentenced that November. Photo: General Services Administration (public domain)

2026: Keep Bitcoin’s Rules and Move the Checking Somewhere Else

Now the architecture, and where the checks went. In Shielded Bitcoin, bitcoin-denominated value is held in encrypted records called notes. Spending one publishes a marker showing it was used, plus a mathematical proof that the sender owned the funds and had not created new ones, with amount, sender and recipient hidden. But Zcash’s blockchain checks those proofs itself. Shielded Bitcoin would publish the transfer data on Bitcoin and leave the checks to separate software that anyone could run. The consequence is exact: a Bitcoin transaction could be confirmed while the private payment recorded inside it failed Shielded Bitcoin’s own checks.

Think about what “anyone could run” means. It is a description of who may verify, not who must. Nobody is on duty. Nobody is on the hook. If the checks fail and no one is watching, the Bitcoin layer does not care, and it is not built to. A security property maintained by volunteers is not a service level. It is a hope, and hopes do not come with an uptime number.

The authors concede some of this themselves. Transfer timing and fee payments remain visible. An efficient way for lightweight wallets to verify the reconstructed payment history is listed as future work. On a ledger where the base layer verifies nothing, that reconstructed history is the only thing standing between a user and a wrong answer about their own money, and it is not built yet.

Privacy Came Back to Bitcoin as a Sidecar Nobody Has to Check
A single-board computer of the kind that runs a verifying node. Anyone can run the checks; nobody is obliged to. Photo: Anil Öztas (CC BY 4.0)

What Is Still Missing Is the Bridge

The 56-page specification does not explain how ordinary BTC would enter the system or be released when someone wanted to withdraw. The authors reserve those mechanisms for a separate paper using PIPEs, a technique designed to lock a Bitcoin signing key until specified conditions are met. Their claim that users retain control of their funds covers transfers inside the system and explicitly excludes deposits and withdrawals.

That is the hole under the whole design: everything promised is about value already inside it. Mert Mumtaz, cofounder of Helius and a Zcash proponent, was blunt about it on X. He called it a synthetic ledger with significant tradeoffs. He pointed to a trusted setup and to no fee anonymization, meaning the Bitcoin wallet paying to publish a private transfer could still be visible. And he wrote the line that captures the bridge problem:

no in-protocol mechanism for getting actual BTC in or out (which means you are holding synthetics)

He also said it would need years of further research and development, while adding that he respected the work. The authors themselves list these limits, and a specification that names its own holes is worth more than one that does not. Plenty of papers paper over the gap. This one points at it.

There is also a cost that never goes away. Komarov estimated a private transfer at roughly 700 virtual bytes, against 100 to 200 for an ordinary bitcoin transaction, which puts miner fees at about four times as much at an equivalent fee rate. Four times the fee, permanently, for a payment whose verification is optional. There is no launch date for the system.

Bitcoin is not the only chain looking at this. Ethereum is reviewing a proposal for a shared private pool that would let people transfer ether and other tokens without publicly revealing payment details, and its authors cite payroll, treasury management and donations as uses that fully public transactions serve badly. Same demand. Different base layer.

The Verdict

The demand, though, is real and it is measurable. Zcash’s shielded pools held about 4.9 million ZEC, roughly 29% of issued coins, worth about $7.8 billion after the rally. There were roughly 63,000 shielded transactions in the busiest week for private transfers since 2022. Reported weekly network transfer volume exceeded $23 billion, the largest weekly total since 2021. People are not asking for privacy as a thought experiment. They are paying for it.

Cypherpunk, the company that holds and mines Zcash, welcomed the research and did not treat it as competition. Its line is worth keeping:

Privacy works best when built into the base layer. Not requiring Bitcoin changing is this design’s biggest selling point, and also its biggest drawback.

That is a company with a competing product stating the tradeoff cleanly. I respect it.

So close the timeline with the only thing that matters operationally. Either someone is paid and obliged to verify the sidecar, at a stated cost and a stated rate, or the honest description of what has been built is a claim about privacy with a bill still to be paid. Everything else is presentation.

The design that ships is rarely the cleverest one. It is the one someone is paid to run at three in the morning. Shielded Bitcoin has a clever design and nobody on call. Bytes are the part of this you can measure today, and 700 of them per payment is the meter running.

Bitcoin

Q-Day Field Notes: Bitcoin's Quantum Bill Dropped 79% in a Week

2026-9-27 20:40:26

Bitcoin

Daily Dividends Are What a Bitcoin Treasury Looks Like Under Strain

2026-9-28 19:51:32

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search