陈剑Jason|9月 29, 2026 03:04
The recent paper that enables Zcash privacy transfer without splitting BTC has become a hot topic and sparked a lot of discussion. The author is @ nemotherone, the founder of the Bitcoin cryptography laboratory Alloc Init, who graduated from the Mathematics Department of Moscow University and has been engaged in cryptography research ever since. The core of Zcash's ability to achieve privacy transfer lies not in encrypting the transaction itself, but in introducing an independent accounting model. In the privacy pool, the money is no longer UTXO like BTC, but encrypted bills, including the receiving address, amount, random number, and key. Then, these bill information are converted into a promise that cannot be deduced back like a hash. On the chain, only the promise is publicly disclosed, not the bill itself. Assuming Alice transfers 10 ZECs to Bob, Bob receives a bill=(Bob's address, 10 ZECs, random number) ...), then converted into a meaningless hash promise and published on the chain, so everyone only knows that a new ticket promise has been generated on the chain and added to the privacy pool, but cannot obtain the content of the corresponding ticket from the promise.
But the most crucial thing here is to prove that Alice really legally owns a certain ticket so that she can spend it. So, ZK is used to prove to the whole network that I know there is a ticket in the privacy pool and I own it. At the same time, a Nullifier is introduced as the spending tag for each ticket to avoid double spending.
So roughly speaking, Zcash has added an additional privacy pool on a normal public chain, which enables it to have privacy transfer function. So, with the same logic, can we also add a similar privacy pool to BTC? This is what this paper explores and refers to as Shielded Bitcoin.
But the most troublesome thing here is that Zcash's privacy pool is a part of the native public chain, and nodes in the consensus layer already understand what bills, commitments, ZK, and other things are. Although privacy pools can be established on Bitcoin, as an additional thing, they don't even recognize the bills and commitments you throw to nodes.
At this point, we are facing three problems:
Who will maintain this privacy pool?
Who will verify the validity of transactions in the privacy pool?
Who will ensure that the BTC in the privacy pool is genuine?
So adding a privacy pool is not difficult, but the challenge is how to make Bitcoin still constrain this privacy pool from cheating and avoid issues such as double spending and issuance without Bitcoin recognizing the privacy pool.
Shielded Bitcoin is not about transforming Bitcoin nodes to learn about privacy pools, but simply not letting Bitcoin manage the privacy pool. It is still only responsible for storing and sorting data, and moving the Zcash privacy ledger onto Bitcoin to complete the task. In fact, by this point, you have a vague feeling that you cannot express, as if it is on your lips but cannot be described clearly, yes! That's right!
BTC L2!
In the past two years, a large number of VC project parties have created a lot of industrial waste of BTC L2 to expand Bitcoin, but they have not grasped the real pain point of Bitcoin. It is not expansion, but privacy.
Shielded Bitcoin to some extent adopts the idea of BTC L2, where the Bitcoin mainnet is only responsible for data publishing and sorting, and privacy status is completed on Bitcoin.
Assuming Alice has 10 BTC and wants to transfer 3 to Bob, a regular Bitcoin transfer would involve Alice's UTXO publicly trading 10 BTC, and Bob receiving 3 BTC and giving Alice 7 change.
Everyone can see the transaction amount and input/output objects.
Shielded Bitcoin, on the other hand, first generates a ticket based on Alice's ownership of 10 BTC, enters it into a privacy pool, encrypts the ticket, and then sends it to the chain. When Alice spends these 10 BTC, she uses ZK to prove that she knows a legitimate ticket exists and has the right to spend it.
Then create a new ticket containing 3 BTC, Bob's address, and a random number At the same time as sending the ticket to the privacy pool, send the commitment to the chain.
Bob's own wallet has a decryption method for the bill, so he can know through the chain that Alice sent him 3 BTC and recover his own Note to receive BTC.
So, upon seeing this, you may not find it difficult to implement a privacy transfer solution on Bitcoin, as all the technologies such as ZK and L2 are very mature.
The only problem is that both the previous expansion and the current privacy are re added on top of Bitcoin, and the security and reliability are not entirely guaranteed by the native Bitcoin.
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink