On September 4, the price of Zcash surpassed $1000 for the first time since 2018, fueled by the launch of a Grayscale exchange-traded fund on August 25.

On September 24, the company [alloc] init released the specifications for Shielded Bitcoin. The developers aim to integrate Zcash's privacy model into Bitcoin's network without requiring a soft fork. However, a working implementation is still in the works, and the authors plan to detail the mechanism for entering and exiting the system in a forthcoming study.

In collaboration with the Bitcoin mixer Mixer.Money, we explore how Shielded Bitcoin functions, where it leaves traces, and how to sever those traces now.

Bitcoin as a Public Bulletin Board

Transactions on the Bitcoin network are visible to all. Although names are not recorded in the blockchain, on-chain analysis can group addresses into clusters based on common inputs and change, which are then matched with exchange data.

Tools like CoinJoin and PayJoin partially address this issue by obfuscating the links between senders and receivers. While stealth payments prevent the reuse of addresses, the transaction amounts remain visible. Zcash conceals those amounts within its own network.

Shielded Bitcoin adopts the privacy mechanics of anonymous cryptocurrencies but does not utilize a separate blockchain. Mikhail Komarov, the founder of [alloc] init, explained the concept on the Delving Bitcoin forum:

“Imagine Bitcoin as a public bulletin board: it publishes data and establishes their order, and anyone can apply the rules of Shielded Bitcoin to determine the final state.”

Co-authors include former Chaincode Labs research head Clara Shikhelman and Alexey Moskvin. The protocol's workings are best illustrated through their example:

Path of 1 BTC through an encrypted pool. Source: Delving Bitcoin.

Entry. Alice has 1 BTC in a standard address. She transfers the coins into the system and receives a note for the same amount in return. This note acts like a “bill,” similar to an unspent transaction output (UTXO), but its content is encrypted and only understandable by the owner. The entry itself is public: everyone can see that Alice sent 1 BTC from her address.

Transfer. Alice pays Bob 0.3 BTC. He receives a note for that amount, while the remaining 0.7 BTC is returned to Alice as change. In the blockchain, this step appears as a regular Bitcoin transaction with encrypted data: the amounts, sender, and recipient are not visible.

A zero-knowledge proof ensures the integrity of the transaction. Without revealing specific details, it confirms that Alice owned the funds and that the sum of the new notes equals the original. A nullifier, published alongside the transaction, prevents double spending.

Exit. Bob withdraws his 0.3 BTC back to a regular Bitcoin address. This transaction is again public: the amount, time, and recipient address are visible.

While Shielded Bitcoin conceals who paid whom and how much, it does not hide the fact that a payment occurred. An observer can see the time of the transaction, fees, and the number of spent and created notes.

The Cost of Privacy

Such privacy comes at a price. According to the authors' calculations, a standard transfer (two notes in and two out) occupies 610 bytes. Currently, this data is placed in the OP_RETURN field, which is designated for arbitrary information, requiring 625 vB, excluding the rest of the transaction. Alternatively, using the witness section would require two separate operations totaling 438 vB, but this method has not been included in the current specifications.

Komarov noted in a post on Delving Bitcoin that transfers within the pool occupy more space than standard Bitcoin transactions, "but the difference remains within an order of magnitude." He stated that the exact size depends on the operation's form and the publication method, which also affects fees.

In the reference version of the protocol, the authors adopted the Groth16 proof system, which requires a one-time trusted setup. If conducted by multiple participants, as was done with Zcash, it would prevent record forgery as long as at least one participant remains honest. The final choice of proof system is still open.

Errors in the scheme pose risks as well: since amounts are concealed, excessive emissions from outside can go unnoticed. In late May, security engineer Taylor Hornby discovered a vulnerability in Zcash's Orchard pool, potentially allowing for the creation of counterfeit coins since 2022. The pool was replaced in the Ironwood update, and withdrawals from the old one were limited to the amount of confirmed deposits.

A similar scenario occurred in practice in the Liquid sidechain, where transfer amounts are also hidden. Due to a transaction verification error, unidentified individuals issued uncollateralized L-BTC and withdrew around 4000 real BTC ($320 million) from the federation's reserves. Eventually, 3400 BTC were returned. A similar bug in Shielded Bitcoin could allow the exchange of counterfeit notes for other participants' funds.

Another risk is associated with entry and exit. Coins must enter and exit through storage in the main network. To ensure their rules operate without changing consensus, the authors rely on the PIPEs v2 scheme, which [alloc] init researchers presented in February. This is based on witness encryption. The storage key is encrypted in a way that only someone who proves, for instance, they burned their note when exiting the pool can unlock it. According to Gizmodo, this part of the construction remains unfinished.

Robin Linus, the creator of BitVM and co-author of the alternative Shielded CSV protocol, stated that he respects the attempts to incorporate such rules into the first cryptocurrency without a soft fork. However, he expressed concerns that the cryptography they rely on is "still experimental, and its safety assumptions are far from established." Linus believes that trust in it for Bitcoin applications will only come after many years of scrutiny, and realistically, such confidence may never materialize.

Komarov did not dispute this assessment. In a response, he acknowledged that witness encryption "is indeed quite new (about six years old)." Shikhelman added in an interview with bitcoin++ Insider that this technology has been studied since 2013, but it has not yet transitioned to practical industrial-level cryptography. The encryption scheme from February was successfully attacked by the authors and participants of their open competitions. According to Shikhelman, vulnerabilities were addressed, but the revised version has not yet been released, and it has not undergone the same level of scrutiny as the original. An updated paper is expected by the end of the year.

Where Traces Remain

Even secure stores cannot hide entry and exit points. In the same interview, Shikhelman explained the boundary of protection:

“It is crucial to distinguish between privacy within the protected system, provided by cryptography, and privacy at its boundaries. The latter depends on how users enter and exit the system and interact with Bitcoin.”

For instance, if a user deposits an unusual amount of 0.80085 BTC into a pool, and an hour later, almost the same amount is withdrawn to a new address, the encryption remains unbroken, but the connection is evident. The researcher clarified on the forum that exit storages will have fixed denominations, and they can only be utilized for exact amounts. Other methods, like atomic swaps, will allow for the withdrawal of arbitrary BTC amounts.

This kind of analysis has already been conducted on Zcash. In 2018, researchers from University College London examined how often the amounts entering a protected pool match those exiting. They focused on values that appeared in the network history exactly twice: during deposit and shortly after withdrawal. Based on this criterion, they linked entry and exit for 28.5% of all coins ever deposited in the pool. Notably, 70% of this volume was withdrawn no later than 25 minutes after the deposit, with the majority of these coins (87%) being transferred by project founders and miners.

The authors of Shielded Bitcoin reference this study, concluding that even a large pool does not guarantee anonymity.

Transaction fees also leave a trace. Each transfer in the pool is recorded in the blockchain as a standard Bitcoin transaction. Fees for miners are paid from a public address, just like any other payment. If Alice uses these funds from her main wallet, an observer will not know the amounts or recipients. However, they will see that all operations were initiated by her and when.

“Publication fees can become another signal if they are repeatedly paid from the same recognizable Bitcoin wallet,” Komarov cautioned in his post on Delving Bitcoin.

Using a separate wallet for fees helps only partially. The specifications note that its reuse or predictable top-ups can still reveal connections. In the future, fees are suggested to be paid from a special storage on PIPEs: access to it would be granted by proof rather than the owner's address. However, the authors admit that this approach "does not eliminate leakage during publication": observers can still notice when and how often it is used.

Thus, encryption only protects what occurs within the pool. Users must manage the amounts and timing of entries and exits, as well as the wallet for fees, on their own.

How to Sever Traces Now

Currently, Shielded Bitcoin exists only on paper: a workable implementation is lacking, the mechanisms for storing funds for entry and exit have not been described, and the cryptography is still undergoing testing. For those looking to sever on-chain connections now, more familiar tools like the Bitcoin mixer Mixer.Money are available.

This service breaks down incoming funds and distributes them to private investors and traders on exchanges. The client receives liquidity from other exchanges in return. There is no direct transaction between incoming and outgoing transfers in the chain.

“Any privacy scheme is exposed by the amounts and timing at entry and exit. In 'Complete Anonymity,' these are determined not by the client but by the system: it divides the payout into parts, selects wallets without change, and chooses the timing for sending,” explained Mixer.Money.

The amounts are not hidden by the mixer: payouts are visible in the blockchain but appear as ordinary withdrawals from an exchange. Mixer.Money promises to return coins within six hours after the first transaction confirmation and issues a guarantee letter with a PGP signature for each request.

While Shielded Bitcoin and the mixer aim to solve the same problem, they do so in different ways. The protocol promises to operate without intermediaries and conceal amounts but is not yet functional. The mixer requires trust but is available now. If the pool is eventually launched, funds obtained through Mixer.Money could be directed to replenish the fee wallet, ensuring its history does not lead back to the main wallet. However, if all transfers are paid from it consecutively, they will still link together.

To start, users can take advantage of a free test on the Mixer.Money website: 0.001 BTC will be returned to one address without a fee.

Follow ForkLog on social media:

Telegram (main channel) Facebook X Did you find an error in the text? Highlight it and press CTRL+ENTER