Product1 publisher3 min readPublished
Bitcoin privacy without a fork hinges on encryption Alloc Init has not finished
Alloc Init's Shielded Bitcoin paper claims Zcash-style private transfers on Bitcoin with no soft fork or consensus change. Moving coins into and out of the pool still depends on witness encryption the authors have not finished.
The Product Desk · Product desk

What happened
- Recipients, amounts and the links between old and new coins would sit in encrypted notes instead of in Bitcoin's public UTXO graph.
- Alloc Init COO Scott Odell said Shielded Bitcoin "is not a mixer" and is closer in design to Zcash than to the Ethereum-based Tornado Cash.
- Johns Hopkins researchers proposed Zerocoin in 2013 and Zerocash in 2014 as privacy extensions for Bitcoin, and Bitcoin adopted neither.
- A February TRM Labs report found that 48% of darknet markets launched in 2025 accepted only Monero.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- contradiction The bridge-free pitch holds only for coins already inside the pool, so anyone weighing it should treat the entry and exit path as an open bridge problem until the vault design is complete.
- constraint A wallet or custody team can prototype in-pool transfers from the paper today, but shielded deposits and withdrawals cannot ship until the witness-encryption construction exists.
- exposure Holders of shielded bitcoin would depend on the soundness of the proofs for supply integrity, because the public UTXO count anyone can check today would not cover their coins.
- decision Teams deciding whether to plan for Shielded Bitcoin can set fork politics aside and track outside review of the cryptography instead.
Earlier this week, the group claiming the Revolut customer-data leak, iamnotavillain, asked for about 6,000 XMR, roughly $3 million, instead of bitcoin or ZEC [18]. Gizmodo reports that Monero is still often the asset people reach for when they want a private payment [15]. Ransomware crews still name XMR as a preferred payment, according to a February TRM Labs report, even though the bills that get paid are usually in bitcoin [17].
The Zcash figures measure something else. ZEC trades around $1,540 on CoinGecko, up more than 2,700% over the past year [11], and about 96 times its July 2024 low near $16 [13]. According to Gizmodo, bitcoin proponents have criticized the rally as a short-term trade on the idea of privacy, not a sign that people use Zcash for its intended purpose [14].
A consensus change needs buy-in from Bitcoin's very diverse userbase, and Gizmodo calls that a daunting task for anyone adding something new [3]. Its account of why Bitcoin passed on Zerocoin and Zerocash is mostly technical, though. The cryptography was young, the proofs were heavy, and the early constructions needed a trusted setup [10].
Shielded Bitcoin's parts are at different stages. The paper specifies how notes move once bitcoin is inside the shielded pool [6]. Deposits and withdrawals run through base-layer vaults that depend on the unfinished witness-encryption construction [7]. Supply auditing is the third part, and Gizmodo calls it a key hesitation with any Zcash-style design, this one included [19].
Clara Shikhelman, Alloc Init's head of protocol research and a former Chaincode Labs researcher, summarized the proposal as "No soft forks, no bridges, no operators, just Bitcoin." [5] The first phrase matches the design [3]. The second is disputed. "Both still need a bridge," David Seroy wrote on X, comparing Shielded Bitcoin with a rival design formerly called ShieldedCSV [20]. He added: "If @allocinitxyz cracks Witness Encryption you could build a better bridge (still unsolved)." [20] Gizmodo traces the bridging problem back to at least the 2014 sidechains paper [8].
The audit problem has a recent case. In June, a soundness bug in Zcash's Orchard pool that could have let extra ZEC appear with no public trace was found and patched by hard fork [22]. The Zcash Foundation said there was "no evidence of unauthorized value creation." [23] In a fully shielded pool, outsiders cannot easily check a statement like that by adding up coins, the way anyone can sum transparent UTXOs on Bitcoin [19].
In my view, Shielded Bitcoin is for now a document for cryptographers. For a wallet team or custody desk deciding whether to plan around it, the test is a 2x2. One axis asks whether a component is finished. The other asks whether anyone outside Alloc Init has checked it. Only a component in the finished, externally checked cell belongs on a product roadmap. In-pool transfers are specified [6]. The vaults are not finished [7]. Gizmodo's report does not describe any independent review of the paper. With no fork required, what Alloc Init needs is its witness-encryption work finished and checked by people who did not write it [7].
What to watch
- Alloc Init publishing a finished witness-encryption construction for the base-layer vaults that move bitcoin into and out of the pool.
- Independent cryptographers publishing a review, or a break, of the paper's in-pool note design.
- A wallet or custody provider announcing support for shielded deposits, the first sign the no-fork design reaches ordinary users.