TL;DR — Shielded Bitcoin is Zcash's 2018 Sapling playbook stuffed into
OP_RETURN, validated by nobody on Bitcoin, secured by a trusted setup Zcash retired in 2022, and backed by BTC that can't get in or out yet. Meanwhile Zcash already shipped a formally verified pool (Ironwood), lands NU7 on Nov 5, and is building Tachyon, which gets rid of the very architecture Shielded Bitcoin just copied.
- Zcash under a different name. Notes, commitments, nullifiers, diversified addresses, viewing keys: every one of them comes from Zcash.
- Bitcoin validates none of it. Bitcoin orders the bytes. Off-chain indexers decide what's real.
- The ceremony is back. It uses Groth16, because Bitcoin blockspace is too expensive for Halo.
- There's no door. The BTC peg depends on PIPEs witness encryption. It's experimental and unpublished, and the authors make no security claims about entry or exit.
- Zcash is on the next thing. Ironwood → NU7 → Tachyon.
What it actually is
[[alloc] init] published Shielded Bitcoin on September 24, 2026 (Decrypt). A private transfer is a Zcash-style spend proof packed into an ordinary Bitcoin transaction: ~625 vbytes for 2-in/2-out, carried in OP_RETURN.
Bitcoin sees opaque bytes. An invalid shielded transfer can be mined perfectly legally, and indexers simply ignore it. Bitcoin isn't enforcing anything here. It's acting as a timestamped hard drive.
%%{init: {"flowchart": {"htmlLabels": false}}}%%
flowchart LR
subgraph Z["ZCASH"]
direction TB
z1["Shielded tx"] --> z2["Every full node verifies<br/>proof + nullifiers + balance"]
z2 --> z3["ZEC state<br/>enforced by consensus"]
end
subgraph B["SHIELDED BITCOIN"]
direction TB
b1["Shielded tx in OP_RETURN"] --> b2["Bitcoin orders bytes<br/>validates nothing"]
b2 --> b3["Off-chain indexers verify"]
b3 --> b4["shBTC meta-state"]
b4 -. "PIPEs peg<br/>not yet published" .-> b5["Locked BTC"]
end
In Zcash, privacy is part of consensus. In Shielded Bitcoin, it sits on top of consensus and hopes the BTC underneath goes along with it.
The trusted-setup punchline
Zcash spent six years getting rid of the ceremony:
- Sprout (2016): trusted setup
- Sapling (2018): Groth16, still a trusted setup
- Orchard (2022): Halo 2, no trusted setup, no toxic waste
- Ironwood (July 2026): formally verified shielded pool
- Tachyon: Halo-style recursion (Ragu), still no ceremony
Bitcoin's first serious shielded design goes straight back to step 2.
It's not that they can't use Halo. Halo 2 is open source. They can't afford it:
On Bitcoin every byte is a fee, so Bitcoin's own blockspace costs push its privacy design back to 2018 cryptography. Zcash made the trade the other way years ago. (Halo 2 size per ZIP 225.)
The missing half: where's the BTC?
A shielded ZEC note is ZEC. A shielded BTC note is only a claim on BTC that has to be locked somewhere, and Bitcoin Script can't check a SNARK.
The proposed fix is PIPEs: witness-encrypt a Bitcoin private key so that only a valid proof can decrypt it. That's clever and still experimental. The costs are enormous, and a decrypted key is just a key: it releases once, and after that it can sign anything.
The peg paper, the part that makes this actual private Bitcoin, doesn't exist yet. What shipped this week is the easy half.
Consensus matters when things break
This year Taylor Hornby found a counterfeiting flaw in Orchard's circuit. It was never exploited. Because Zcash consensus understands its own shielded pool, the fix went in at the consensus layer (crypto.news):
- Ironwood, a formally verified replacement pool backed by 2,700+ machine-checked theorems
- A consensus turnstile that caps how much can ever leave Orchard
- Quantum-recoverable notes built in
Shielded BTC has no equivalent. Bitcoin doesn't know the pool exists. And if the peg works the way PIPEs v2 describes, the release condition is fixed when the key is encrypted. A bug in that condition can't be patched later, because nobody holds the key needed to re-lock the funds.
Zcash is already past this
Shielded Bitcoin copies the Sapling-era wallet model, where every wallet trial-decrypts every ciphertext on the chain. Tachyon gets rid of that model (CoinDesk):
| Shielded Bitcoin | Zcash (Ironwood → Tachyon) | |
|---|---|---|
| Who validates private state | Off-chain indexers | Every full node, by consensus |
| Proof system | Groth16, trusted setup | Halo 2 / Ragu, no setup |
| Asset | Claim on BTC via unpublished peg | Native ZEC |
| Wallet sync | Trial-decrypt the chain | Oblivious sync via untrusted servers |
| Node storage | Grows forever | Pruned: recent nullifiers only |
| Bug response | Release rule frozen at vault creation | Consensus turnstile + verified pool |
| Post-quantum path | Not specified | ZIP 2005 → ML-KEM → PQ pool |
Bitcoin researchers are rebuilding Zcash's past while Zcash ships its future.
The one honest concession
The asset would be BTC, and it needs no soft fork. That's the whole appeal, and it's real. But it's a pitch about distribution, not engineering. Take away the ticker and you have an unverified metaprotocol, a 2018 proof system with a ceremony, and a peg that doesn't exist yet.
Verdict
Zerocoin started in 2013 as a plan to add privacy to Bitcoin. Bitcoin wouldn't take it, so Zcash was built. Thirteen years later, Bitcoin's best private design is a partial copy of Zcash, and it can only work by keeping Bitcoin itself out of the loop.
If you want shielded money that consensus actually enforces, with no trusted setup and a roadmap past quantum computers, it already exists.
It's called Zcash.

