Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
Bitcoin transfers are public. Anyone who knows an address can see the amount, the timestamp and every further payment attached to that address. On September 24, 2026, three researchers published a draft meant to change that without altering the Bitcoin protocol itself. It is called Shielded Bitcoin.
For you as a holder this is a paper, not a product. There is no software you could install. The occasion is still a good reason to settle a question many investors in Germany have never asked: how much does your own wallet give away today, what does your exchange collect anyway, and what would change if a scheme like this ever ran in production? This article places the proposal in context and then names the points you can check today regardless of it. The Bitcoin price plays no part here for once.
Shielded Bitcoin: what the paper of September 24, 2026 says
It was written by Clara Shikhelman, Mikhail Komarov and Aleksei Moskvin of the cryptography research firm [[alloc] init]. The document runs to 56 pages and carries the title “Shielded Bitcoin: Private Transfers on the Bitcoin L1”. It describes a metaprotocol. A metaprotocol is a set of rules that sits on top of an existing blockchain and uses its data, without the blockchain knowing or enforcing those rules.
The stated goal: sender, recipient, transfer amount and the link to earlier payments are all meant to stay hidden. Bitcoin’s consensus rules remain untouched. No soft fork is required, meaning no coordinated rule change that a majority of node operators would have to agree to. That is precisely what separates the proposal from earlier attempts at more privacy on Bitcoin, which have repeatedly failed to win that agreement. The authors publish their work on the lab’s research page, which holds Shielded Bitcoin alongside the preparatory work on the underlying Bitcoin vaults.
One point matters for context: a paper is not a deployment. So far there is no implementation, no users and no pool holding any actual funds.
Encrypted notes, nullifiers and zero-knowledge proofs: the three building blocks
The draft borrows its parts from Zcash, an older cryptocurrency with encryption built in. Three terms carry the whole scheme.
A note is an encrypted record that holds an amount and the entitlement to it. In this system it replaces what would otherwise be an openly readable transaction output on Bitcoin. A nullifier is a public identifier that marks a note as spent without revealing which note it is. It prevents the same amount from being spent twice, which makes it the counterpart to the double-spend lock of the Bitcoin blockchain. A zero-knowledge proof, finally, is a mathematical demonstration that a statement holds true without disclosing the data it rests on.
Every transfer carries such a proof with it. The proof establishes two things: that the sender is entitled to the notes being used, and that the sum of the inputs matches the sum of the outputs. Neither the amount nor the origin can be read out of the proof itself. As its proof system the paper names Groth16, an established and very compact scheme that does, however, require a trusted setup ceremony. The technical debate returns to that point below.

Metaprotocol instead of soft fork: why Bitcoin nodes verify none of it
The core idea is awkwardly simple. Bitcoin is used purely as a publication and ordering layer. The chain stores encrypted data without ever interpreting what it contains. Verifying the proofs falls to separate software, an indexer, which each participant either runs themselves or trusts someone else to run.
The advantage is obvious: there is nobody to convince. Whoever wants to take part installs the software, and the remaining node operators notice none of it. The price is just as clear. The security of the scheme then no longer rests on the computing power of the miners but on the correctness and adoption of that additional software. Should it fail or never catch on, all that remains on the chain is a data stream nobody can interpret any more.
That is where the approach differs from older concepts such as Shielded CSV, which keep part of the data locally with the user. Here everything sits on Bitcoin, only encrypted.
Hold your Bitcoin in self-custodyOP_RETURN, 625 vBytes and Bitcoin Core v30: what Bitcoin privacy costs in fees
Data volume is the bottleneck. An ordinary Bitcoin payment takes up roughly 100 to 200 virtual bytes depending on its construction. A shielded transfer under this draft sits well above that. Decrypt puts the figure at 625 virtual bytes for a transfer with two inputs and two outputs, while BTC-Echo speaks of around 700 virtual bytes and, following from that, roughly four times the fees. The numbers differ because they describe different constellations; the order of magnitude is reliable, the exact figure is not.
That such a data volume fits on the chain at all is down to a change from autumn 2025. With Bitcoin Core version 30, the ceiling for the OP_RETURN data field was raised from 80 bytes to 100,000 bytes, and several such fields per transaction have been permitted since. OP_RETURN is an output type that explicitly carries no monetary value and only takes data. The change was and remains contested within the Bitcoin developer community; critics such as Luke Dashjr and Nick Szabo warned of bloated data sets and higher running costs for node operators.
For you this means two things. First, privacy under this model would not come as a by-product but as a service you pay noticeably more for on every transfer. Second, the proposal depends technically on that limit staying in place. Reversing the decision would pull the ground out from under it.
What Shielded Bitcoin does not hide: timing, fee and the number of inputs and outputs
The draft is remarkably candid on this point, and that belongs in any assessment. What stays hidden is the amount, the sender, the recipient and the connection to earlier notes. What stays publicly visible is the timing of a transfer, the fee paid for it and the number of inputs and outputs.
That sounds harmless and is not. Anyone analysing payment flows has worked with exactly this kind of metadata for years. A conspicuous combination of timing and fee can tie a transfer to an event even when the amount is encrypted. The fewer participants use the system, the more telling those remnants become.
The way in and back out is also unresolved. How Bitcoin enters the shielded area and leaves it again is not settled in the paper, which points instead to separate work on so-called Bitcoin PIPEs in its second version. What is missing is therefore the very place an observer would start with: the transition between the open chain and the encrypted pot.
Anonymity set and trusted setup: the objections from the cryptography debate
Reactions from the cryptography scene were mixed, and the objections are concrete enough to name their authors.
Vadim Zavodil countered that privacy is a function of scale: Zcash has a shielded pool grown over years, whereas a new system starts from zero. The objection hits a sore spot, because encryption is of little use when only a handful of participants share the same pot. The technical term for that quantity is the anonymity set: the number of transactions a single transaction can be confused with.
Pierre-Luc Dallaire-Demers criticised the system as not quantum-resistant at all. That refers to the proof system in use, whose security rests on mathematical assumptions a sufficiently powerful quantum computer could break. On top of that comes the Groth16 setup ceremony already mentioned: whoever runs it briefly holds a secret that could later be used to produce false proofs. Such ceremonies are therefore conducted with many independent participants, but the residual risk cannot be removed entirely.
On the other side there is agreement with the direction of travel. Eli Ben-Sasson, one of the best-known names in the field of zero-knowledge schemes, voiced support while noting that he had not yet read the paper. That caveat belongs to the record: a well-disposed first reaction is not a technical review.
How public your Bitcoin addresses are today: address reuse and xpub
Here the subject turns practical, and here lies the part you can deal with today regardless of any research paper.
The biggest avoidable mistake is reusing a receiving address. Modern wallets generate a fresh address for every incoming payment automatically. Using one fixed address instead, in an email signature, on a website or in a donation appeal, links all incoming payments together and makes the entire balance at that address visible to anyone who knows it.
The second point is less well known and carries more weight. The extended public key, usually abbreviated to xpub or zpub, is a key from which all addresses of a wallet can be derived, past and future alike. It cannot move funds. Entering it into a portfolio tracker, a tax tool or a watch-only application, however, hands that provider a permanent and complete view of your holdings. So check which services you have ever given your xpub to, and whether you still use them.
Third, the selection of incoming payments, known as coin control. Good wallets let you label individual inputs and pick them deliberately. That keeps a payment from inadvertently merging funds from different sources and exposing connections that were not visible before. Which devices and programs offer the feature at all varies widely; our hardware wallet comparison lists the specifications of the common devices.

Transfer of Funds Regulation and the travel rule: what your exchange records on every withdrawal
This is where the effect of any on-chain encryption scheme ends, and explainers on the subject regularly overlook it.
The governing text is Regulation (EU) 2023/1113 on information accompanying transfers of funds and certain crypto-assets, known as the Transfer of Funds Regulation. It entered into force on June 29, 2023 and has applied since December 30, 2024. The obligation it sets out is colloquially called the travel rule: crypto-asset service providers must obtain information on the originator and the beneficiary of a transfer, retain it, pass it to the counterparty and make it available to the competent authorities on request.
For withdrawals to a self-custodied address, the European Banking Authority has published separate guidelines requiring providers to carry out a risk assessment of such transfers. In practice you encounter this as a question about who owns the destination address, sometimes combined with proof of control over it.
The consequence is sober: the route your bitcoin takes from a regulated exchange to your own wallet is documented, permanently, and independently of whatever happens on the blockchain afterwards. A scheme like Shielded Bitcoin could hide what you do with your holdings after the withdrawal. It cannot hide that you withdrew them.
The holding period under Section 23 EStG: why Bitcoin privacy does not replace your records
The German framework sets a second limit, and it works in the opposite direction. Under income tax law, gains from the sale of crypto-assets fall under the private disposal transactions of Section 23 of the German Income Tax Act. Hold for longer than a year and the gain is tax-free. Sell earlier and it is taxed at your personal rate, provided the exemption threshold is exceeded.
The burden of proof is what counts. The taxpayer has to document the acquisition date and the acquisition cost, not the tax office. Obscuring your payment flows towards third parties also obscures them towards yourself, unless you keep your own complete documentation. Privacy gained then turns into proof lost, and that costs real money.
In practice: keep your own record, independent of any exchange and any tool, with the date, the quantity, the euro value and the origin of every tranche. Tools take the arithmetic off your hands; the evidence remains your job. Which programs offer which import routes and report formats is set out in the comparison of crypto tax tools. A revision of the holding period is currently under political discussion; as long as nothing has appeared in the Federal Law Gazette, the wording of the provision continues to apply unchanged.
Keep your records straightChecking Shielded Bitcoin: what to take away
The proposal is notable because it sidesteps the political hurdle that privacy extensions on Bitcoin have failed at so far. It is also research and not a tool: no software, no pool, no solved entry and exit, open questions on quantum security and on the setup ceremony. Reading an imminent change to your own position into it goes too far. Using the occasion to put your own starting position in order uses it correctly.
- Go through your addresses and your xpub. Check whether you use a fixed receiving address anywhere, and list the services you have given your extended public key to. Delete the links you no longer use. If your wallet offers neither a fresh address per incoming payment nor a selection of inputs, a switch is worth considering; the common programs and their features are in the software wallet comparison.
- Separate custody from the trading venue. Holdings you intend to keep for longer do not belong permanently on an exchange account. Which device suits the size of your holdings and your technical requirements is covered by the hardware wallet comparison; pay explicit attention to coin control support.
- Secure your evidence independently. Record the date, quantity, euro value and origin of every tranche in a list of your own, one you will still have if a provider shuts its service down. Which tool imports your trading venues cleanly and produces a report the tax office can work with is shown by the comparison of tax and portfolio tools.
The next public date on the subject is announced for September 28, 2026, when Clara Shikhelman is due to present the draft at a Bitcoin conference in New York. Until then, Shielded Bitcoin remains exactly what it is: a carefully worked-out proposal whose practical viability nobody has tested yet.
(As of September 25, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
- Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
- Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
- FIBE Berlin 2026 Review: Bitcoin, AI Trading & Tokenization at Europe's Biggest FinTech Conference
- 387.5 million dollars at Bitget: the attack ran through a bought-in security product, what to watch now
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
October 2, 2026 1:42 PM

Arkham Intelligence: who does this wallet address really belong to?
The analytics platform attaches names to blockchain addresses and has been paying bounties for unmasking wallets since July 2023. What comes out of it, where the assignment goes wrong, and how you keep your own trail shorter.
September 30, 2026 4:15 PM

Zcash today: 2,746 ZEC from the Bitget hack vanish into the Ironwood pool
Wallets from the Bitget break-in pushed 2,746 ZEC into Zcash's Ironwood pool on Wednesday morning, roughly $3.9 million. What the shielding means for tracing, and what applies to your exchange account from July 2027.
August 21, 2026 4:27 PM

Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
On 19 August 2026 BaFin published two consumer notices on wallet offerings. Who controls the means of access decides whether an authorisation is needed.
September 2, 2026 10:31 PM

ECX Fork of Bitcoin: When the Snapshot at Block 973,728 Really Lands
Layertwo Labs is copying Bitcoin's ledger onto a new chain and crediting every bitcoin with one ECX. Our own measurement shows the three fork stages hang on difficulty periods, and the snapshot reported for October 31 will most likely fall on November 1.
August 15, 2026 9:31 PM

Crypto Exchange Shutting Down: What to Do Before the Deadline Passes
Binance, BitMart, Luno and Revolut have ended or cut back their European business within seven weeks. This guide shows which deadline expires first, how a forced sale is treated for tax, and what to secure before the account closes.
September 23, 2026 10:11 AM

Kraken: 45 coins are on cancel only, 21 were announced – what to check when trading pairs are blocked
On September 23, 2026 we counted the public market directories of three trading venues. At Kraken, 82 of 1,450 trading pairs are listed as cancel only, a state in which an order can only be cancelled and no longer executed. The 45 underlying assets affected include just 21 that appear in the delisting notice we reported on September 3.
September 23, 2026 4:12 AM

How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
Your own crypto wallet is set up in twenty minutes, yet a single step decides everything that follows. This guide takes you through wallet type, recovery words and the test amount, and sets out what BaFin and the tax office expect.
September 7, 2026 1:27 PM

Liquid Network: Around 4,000 Bitcoin Drained via a Peg-Out, and What L-BTC Holders Must Check Now
Around 4,000 Bitcoin drained out of the Liquid Network federation wallet on September 6, even though no key was stolen. The network is halted and redemption is blocked. Here is what you should check now as an L-BTC holder.
August 30, 2026 10:38 PM

Crypto Cards: Where Your Card Balance Really Sits and What the August 28 Solana Exploit Reveals About It
An attack on a card balance contract on Solana took the loaded balance from 1,685 users while their wallets stayed untouched. The case shows why it matters whether your crypto card holds funds as e-money at a licensed institution or in a smart contract.
September 11, 2026 1:26 PM

Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.
June 24, 2024 8:16 PM
Bitcoin News Today: Bitcoin CRASH OVER or MORE Down To Go?
Bitcoin Price Crash below 60k, and the crypto market follows. Why this decline and how low can it go?
July 1, 2025 2:12 PM

Germany’s Banking Giants Go Crypto: Deutsche Bank and Sparkassen, the 2026 Launch Status
Deutsche Bank plans crypto custody for institutional clients by the end of 2026, the Sparkassen want to offer crypto trading in their app from mid-October. Where both plans stand.
February 15, 2025 11:34 AM

Bitcoin Price Surges Amid International Governmental Adoption - Can It Break $100K?
Bitcoin price is on the rise, fueled by massive international adoption and growing interest in crypto custody services. Will these developments push Bitcoin past the elusive $100K mark?
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 26, 2026 4:14 PM

Bitget Withdrawals Resume on September 28: What to Check on a Residual Balance Now
Bitget is releasing the withdrawals frozen after the September 24 incident in four stages from September 28. For a residual balance held from Germany that is a deadline, not a reason to wait.
September 26, 2026 7:34 AM

Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
September 3, 2026 4:41 AM

Kraken Delists 21 Tokens: Trading End on September 11 Has Passed, Withdrawals Run Until December 10
As of September 27, 2026: Kraken had set the end of trading and deposits for 21 cryptocurrencies for September 11, 2026 at 14:00 UTC, and that date has passed. According to the exchange, withdrawals remain possible until December 10, 2026 at 15:00 UTC. Our September 3 survey showed that none of these tokens could be deposited at Bitvavo, Coinbase or Bitstamp.
August 23, 2026 7:34 PM

Buying Zcash Despite the EU Trading Ban: What Happens to Your ZEC From July 2027
From July 10, 2027 the EU anti-money-laundering regulation takes anonymity-enhancing crypto-assets out of regulated trading venues. What Article 79 forbids in its actual wording, why your own ZEC holding is not caught by it and what to sort out before then.
August 20, 2026 4:20 AM

Crypto Exchange Delisting: What Happens to Your Tokens When Trading and Withdrawals Close
A delisting runs in four stages, and only one of them is genuinely dangerous: the end of the withdrawal deadline. Using two live OKX dates as the example, we show what happens at each stage and how to tell whether it affects you.
August 19, 2026 10:24 AM

Privacy Coins and EU Anti-Money-Laundering Law: An Assessment of the Ban From July 2027
Article 79 of the EU anti-money-laundering regulation bars crypto service providers from keeping accounts that obscure transactions, and it names anonymity-enhancing cryptocurrencies explicitly. This assessment separates the documented wording, including the 10 July 2027 application date, from what follows for individual coins.
August 19, 2026 7:27 AM

Blockchain Rollback After an Exploit: What Happens to Your Tokens When a Chain Is Reset
At Harmony, roughly four billion ONE were minted without authorisation, and a rollback of the chain has been on the table ever since. This piece explains what a blockchain rollback means technically, when it can still succeed, and what it triggers for your holding period.
August 11, 2026 1:32 PM

How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
The Coldcard case pushed the manufacturer question to the front, while barely touching on where the backup is kept. This guide places paper, steel, the passphrase and splitting methods against the BIP-39 and SLIP-0039 standards.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
More from CryptoTicker
