[alloc] init unveils Shielded Bitcoin for Zcash-style privacy without protocol forks

Electric Coin Company / Wikimedia Commons (Public domain)

[alloc] init unveils Shielded Bitcoin for Zcash-style privacy without protocol forks

The cryptography firm's 'Shielded Bitcoin' metaprotocol uses witness encryption to enable private transfers directly on Bitcoin's base layer, no soft fork required.

New York-based cryptography firm [alloc] init has introduced what it calls “Shielded Bitcoin,” a metaprotocol designed to bring Zcash-grade transaction privacy to Bitcoin’s base layer without changing a single line of Bitcoin’s consensus code. The system uses encrypted notes, nullifiers, and zero-knowledge proofs, all published directly on the Bitcoin blockchain, to create shielded transfers that look like ordinary Schnorr signature transactions on-chain.

How PIPEs v2 makes it work

The technical foundation is something the team calls Bitcoin PIPEs v2, detailed in a paper published on February 5, 2026, by a 10-member research team. PIPEs v2 introduces witness encryption to Bitcoin, a cryptographic technique that locks private keys behind what mathematicians call non-deterministic polynomial (NP) statements. In simpler terms, it creates spending conditions that are enforced by pure math rather than by Bitcoin’s scripting language or its consensus rules.

The specific mechanism uses something called an Arithmetic Affine Determinant Program (AADP)-based witness encryption scheme. AADP is a mathematical framework that allows the system to verify complex conditions about transactions without exposing the underlying data. It’s the engine that makes the shielded pool possible while keeping everything compatible with Bitcoin as it exists today.

Advertisement

Misha Komarov, founder and CEO of [alloc] init, summarized the philosophy concisely.

“Programmability lives in cryptography, not Script.”

The system requires no soft forks, no multisig arrangements, no BitVM-style fraud proofs, and no trusted setup ceremonies. Verification and recovery require only a Bitcoin node and an indexer, with no operators, federations, or alternative chains involved.

The Zcash parallel, minus the Zcash baggage

The Shielded Bitcoin design explicitly mirrors Zcash’s shielded pool architecture. By transplanting this privacy model onto Bitcoin, [alloc] init is betting that the demand for private transactions exists but that users don’t want to leave Bitcoin’s network effects, liquidity, and security model to get it.

[alloc] init’s proposal carries its own caveats. Current storage costs for the implementation sit at approximately 330 TB, a number that would make even well-resourced node operators wince. For context, a typical Bitcoin full node today requires roughly 600 GB of storage. The team has set a target of reducing that footprint to around 100 GB, but that optimization hasn’t been achieved yet.

What this means for Bitcoin’s privacy landscape

Existing privacy tools for Bitcoin, like CoinJoin implementations such as Wasabi Wallet and Samourai Wallet, have faced increasing legal pressure. Samourai’s founders were arrested in 2024 on money laundering charges, sending a chill through the Bitcoin privacy ecosystem.

The gap between 330 TB and 100 GB is where ambition meets reality, and that’s where the real work begins.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
[alloc] init unveils Shielded Bitcoin for Zcash-style privacy without protocol forks
[alloc] init unveils Shielded Bitcoin for Zcash-style privacy without protocol forks

The cryptography firm's 'Shielded Bitcoin' metaprotocol uses witness encryption to enable private transfers directly on Bitcoin's base layer, no soft fork required.

Electric Coin Company / Wikimedia Commons (Public domain)

New York-based cryptography firm [alloc] init has introduced what it calls “Shielded Bitcoin,” a metaprotocol designed to bring Zcash-grade transaction privacy to Bitcoin’s base layer without changing a single line of Bitcoin’s consensus code. The system uses encrypted notes, nullifiers, and zero-knowledge proofs, all published directly on the Bitcoin blockchain, to create shielded transfers that look like ordinary Schnorr signature transactions on-chain.

How PIPEs v2 makes it work

The technical foundation is something the team calls Bitcoin PIPEs v2, detailed in a paper published on February 5, 2026, by a 10-member research team. PIPEs v2 introduces witness encryption to Bitcoin, a cryptographic technique that locks private keys behind what mathematicians call non-deterministic polynomial (NP) statements. In simpler terms, it creates spending conditions that are enforced by pure math rather than by Bitcoin’s scripting language or its consensus rules.

The specific mechanism uses something called an Arithmetic Affine Determinant Program (AADP)-based witness encryption scheme. AADP is a mathematical framework that allows the system to verify complex conditions about transactions without exposing the underlying data. It’s the engine that makes the shielded pool possible while keeping everything compatible with Bitcoin as it exists today.

Advertisement

Misha Komarov, founder and CEO of [alloc] init, summarized the philosophy concisely.

“Programmability lives in cryptography, not Script.”

The system requires no soft forks, no multisig arrangements, no BitVM-style fraud proofs, and no trusted setup ceremonies. Verification and recovery require only a Bitcoin node and an indexer, with no operators, federations, or alternative chains involved.

The Zcash parallel, minus the Zcash baggage

The Shielded Bitcoin design explicitly mirrors Zcash’s shielded pool architecture. By transplanting this privacy model onto Bitcoin, [alloc] init is betting that the demand for private transactions exists but that users don’t want to leave Bitcoin’s network effects, liquidity, and security model to get it.

[alloc] init’s proposal carries its own caveats. Current storage costs for the implementation sit at approximately 330 TB, a number that would make even well-resourced node operators wince. For context, a typical Bitcoin full node today requires roughly 600 GB of storage. The team has set a target of reducing that footprint to around 100 GB, but that optimization hasn’t been achieved yet.

What this means for Bitcoin’s privacy landscape

Existing privacy tools for Bitcoin, like CoinJoin implementations such as Wasabi Wallet and Samourai Wallet, have faced increasing legal pressure. Samourai’s founders were arrested in 2024 on money laundering charges, sending a chill through the Bitcoin privacy ecosystem.

The gap between 330 TB and 100 GB is where ambition meets reality, and that’s where the real work begins.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.