Misha Komarov, founder of [alloc] init, a firm working on ways to add features such as privacy to Bitcoin without changing its code, said his team is working on “shielded Bitcoin,” a private pool modeled on Zcash that would run on Bitcoin as it exists today, with no soft fork and no company operating it.

“It’s basically Zcash,” Komarov said in an interview recorded Sept. 10 for Unchained Premium. Users would deposit bitcoin into the pool, receive an encrypted note they can send, spend or split, and later present that note to withdraw. “We don’t need any soft forks,” he said.

Proposals to add new functions to Bitcoin’s code for this kind of feature have not been adopted, Komarov said. His firm’s approach, which it calls Bitcoin PIPEs, instead uses a technique called witness encryption to lock a Bitcoin key that can be unlocked only by someone who proves they followed the rules. The team published the second version of that research in February and has pitched the technique as a way to add privacy, among other features, to Bitcoin’s base layer.


This story is brought to you by Unchained Premium.

Subscribe to get exclusive interviews, a subscriber-only chat group, and show transcripts.

Upgrade


Four Times the Fees

Each shielded transaction would carry an encrypted note of about 700 vbytes, Komarov said, against roughly 100 to 200 vbytes for a typical Bitcoin transaction. “So we’re talking about four times larger,” he said, with fees to miners rising by the same multiple, which he said is “not catastrophic.” The more people use the pool, the stronger its privacy, he added.

Still Experimental

“But it’s still pretty experimental,” Komarov said of witness encryption. The encrypted files the scheme depends on remain enormous. [alloc] init said on Sept. 10 that it had cut them to about 8 terabytes, down from roughly 300 terabytes within the past year by Komarov’s account, and it has run open challenges since May inviting researchers to break small instances of the scheme.

Shielded pools carry their own risk. Zcash, whose token reached an eight-year high in August, patched a flaw in June that could have let an attacker mint unlimited counterfeit coins. Komarov said the firm plans to reuse tooling that makes its code easier to audit, and rely on repeated audits.

He gave no launch date but said that in about a year it would be too late to shape the design, urging Bitcoin users to weigh in now: “the good time to express your opinions on, like, the protocol design is right now.”

Related Listen: Zcash, Ethereum, Aztec, Canton and More: Which Chain Will Win the Privacy Race?