Researchers have proposed a way to add Zcash-style private transfers to Bitcoin without requiring a soft fork. The idea is simple on paper: wrap a transaction in zero-knowledge proofs so nobody can see the amount, the sender, or the recipient. The execution, according to some critics, is far from settled.
What the Proposal Actually Does
The proposal, titled “Shielded Bitcoin,” aims to graft privacy onto Bitcoin’s existing protocol. Instead of exposing every detail of a transaction on the blockchain, Shielded Bitcoin would let users prove they’ve moved funds without revealing who sent them or how much was sent. The catch is that this privacy relies on something called an anonymity set — a crowd of other transactions that hide yours.
Why Zcash Already Has the Advantage
The biggest objection comes from Vadim Zavodil, a developer who posted his concerns on X. His argument is blunt: Zcash has spent years building a real shielded pool, and a new system starts at zero.
“Privacy is a function of the crowd. Zcash has a real shielded pool built over years,” Zavodil wrote. “A brand new metaprotocol starts at zero, so your first private transfer hides in a crowd of one.”
That means the very first private transfer on a new system would be instantly identifiable. There is no crowd to blend into, because the crowd does not exist yet.
The Shielded Bitcoin Team’s Response
The researchers behind the proposal acknowledge the problem in a companion post. They note that large deposits do not automatically create a large anonymity set. Even if someone puts a huge sum into a private wallet, that does not necessarily obscure the transaction — it just makes it a larger sum in a smaller crowd.
They also warn that observers may still be able to narrow down relationships between transfers if a small number of actors create most notes or if wallets exhibit distinctive behavior. In other words, the privacy breaks down not because the math fails but because the human pattern of use gives away clues.
Other Experts Weigh In
Pierre-Luc Dallaire-Demers, founder of post-quantum cryptography firm Pauli Group, took a different line. He described the construction as interesting but “not quantum resistant at all.”
Dallaire-Demers later said he was exploring what a fully post-quantum version could look like, assuming Bitcoin eventually adopts a post-quantum signature scheme. The implication is that the current design may need a complete overhaul before it can survive future computing advances.
Eli Ben-Sasson, the Zerocash co-author and CEO of StarkWare, was more supportive of the proposal’s direction. In response to Alloc Init’s announcement, Ben-Sasson said the original intent behind the Zerocash paper, which preceded Zcash, was to bring privacy to Bitcoin.
He has not yet read the Shielded Bitcoin paper, but he would like to see the vision of privacy and scalability through zero-knowledge proofs materialize on Bitcoin’s base layer.
Ben-Sasson’s support carries weight because he helped build the foundation that Shielded Bitcoin is trying to apply to Bitcoin. But his endorsement is qualified — he has not read the paper yet, and he is not committing to its specifics.
The Crowds Problem
The core technical challenge is what Zavodil identified: privacy requires a crowd. A single private transaction is trivially traceable. A million private transactions blurred together is nearly impossible to trace.
This is why Zcash’s shielded pool matters. It has been accumulating transactions for years, and each new deposit adds to the anonymity set. A new system has none of that history.
The Shielded Bitcoin team’s acknowledgment of the issue is honest, but it is not a solution. They note that large deposits do not automatically create a large anonymity set — which is true — but that observation does not change the starting condition. A new system begins with a crowd of one, and it takes a long time to grow from there.
What Comes Next
The proposal is still in development, and the community debate is just beginning. Zavodil’s criticism has been answered with a nod, but not with an answer. The quantum resistance concern from Dallaire-Demers remains open.
The path forward is unclear. The researchers have acknowledged the limitations, and the supporters have expressed enthusiasm, but the actual engineering work has not yet begun.
| Who | Role | Position |
|---|---|---|
| Vadim Zavodil | Developer | Critic of the proposal, citing the lack of an established anonymity set |
| Pierre-Luc Dallaire-Demers | Founder, Pauli Group | Concerned about quantum resistance; exploring a post-quantum version |
| Eli Ben-Sasson | Co-author, Zerocash; CEO, StarkWare | Supportive of the privacy vision, though he has not read the paper |
| Key Claim | Source Reaction |
|---|---|
| Privacy is a function of the crowd | Agreed, but a new system starts at zero |
| Large deposits create a large anonymity set | Acknowledged as false — large deposits do not automatically create a large crowd |
| Quantum resistance is required | Not addressed directly; Dallaire-Demers flagged it as absent |
The Bottom Line
The proposal is clever. The math may work. But the privacy promise is hollow until the crowd exists. A private transfer in a crowd of one is not private — it is just hidden until someone looks.
Zavodil’s point is the sharpest one on the table. You can build the best cryptographic wrapper in the world, but if there is nothing inside it, the wrapper tells you everything. The anonymity set is not a feature of the code; it is a feature of the usage. And usage takes time.
The researchers have acknowledged the problem. Whether they can solve it is another matter entirely.
Source material: “Researchers propose Zcash-style private Bitcoin transfers without a soft fork,” Cointelegraph.
Get the Notebook.
The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

