The research team [[ alloc ] init ] has released a new proposal titled Shielded Bitcoin, aiming to achieve stronger transaction privacy on the Bitcoin mainchain without introducing soft forks, modifying Bitcoin's consensus rules, or relying on operators.
This solution does not directly modify the Bitcoin network; instead, it operates using a meta-protocol approach. Transaction data is written onto the Bitcoin blockchain in the form of OP_RETURN and witness fields, which are then read, verified, and used to maintain the state by an independent indexer. The Bitcoin network itself does not recognize these transactions, nor does it perform any validity checks on them.
Transaction verification is handed over to the indexer.
According to the proposal design, the transactions of Shielded Bitcoin are essentially segments of data with prefixes. Once they are written onto the Bitcoin blockchain, they can be captured by external indexers. The indexers need to determine whether the transactions are valid before deciding whether to incorporate them into the system state.
This means that even invalid transactions may appear on the chain, but they will not be included in the balance updates by compliant indexers. The research team stated that this design allows the scheme to be implemented without altering the underlying rules of Bitcoin, while still maintaining verifiability on the chain.
Similar to the Bitcoin UTXO model, this system also has a corresponding “ticket” structure to represent unspent assets. However, instead of directly deleting spent outputs, it introduces a nullifier mechanism to publicly mark that a certain asset has been used, without revealing which specific transaction it was spent from.
Zero-knowledge proofs are responsible for preventing double-spending.
The indexer continuously maintains two sets of core data: one is the growing Merkle tree of bills, and the other is the used nullifier collection. When users initiate a transaction, they need to submit the public nullifier, as well as a zero-knowledge proof.
- The bill indeed exists in the Merkle tree.
- Transaction has obtained authorization from the corresponding private key.
- No arbitrary issuance of assets
In this structure, external observers are unable to directly determine which specific transaction is being executed, but the system can still check whether nullifier appears repeatedly, thereby achieving a similar anti-double-spending effect to that of Bitcoin.
PIPEs v2 Used for gold in and out

The proposal also designs an in-and-out gold mechanism with the Bitcoin mainchain. The team plans to use PIPEs and v2 to achieve anchoring. According to the article, this is a scheme based on witness encryption that allows for the unlocking of keys after meeting specific zero-knowledge proof conditions.

If this part is implemented, users will be able to deposit Bitcoin into the Shielded Bitcoin system and then complete their withdrawal through on-chain verification when the conditions for withdrawing funds are met, without the need for the operator, federal custody, or third-party management of their funds.
Additional information:The research team stated that the complete paper on the entry and exit mechanism for the system is still being written and will be published separately later on. The article also mentioned that this solution is close to the privacy design of the Zcash blocklist, but users will still face additional privacy considerations when entering and exiting the system.












