Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Growth stocks coverage continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK

Finance

Shielded Bitcoin plan borrows Zcash-style privacy without changing Bitcoin's rules

How a new proposal would borrow Zcash's privacy tricks, and what is still missing

Credit: Shutter Speed by Unsplash
Shutter Speed by Unsplash

Bitcoin is often described as anonymous, but it is closer to the opposite. Every transaction sits on a public ledger that anyone can read. It shows which addresses sent how much to which other addresses.

Once someone links an address to a real person, through an exchange account or a single careless payment, their whole financial history can be traced.

How Zcash does it

Zcash, a rival cryptocurrency, solved this years ago with "shielded" transactions.

The amount, the sender and the receiver are all hidden.

Yet the network can still confirm that nobody is spending money they don't have or spending the same coins twice.

It does this with three ideas.

First, money is held in encrypted records called notes, which work like sealed envelopes of cash that only the owner can open.

Second, spending a note publishes a nullifier, a unique tag that marks the envelope as used without revealing which one it was.

If the same tag appears twice, the second spend is rejected.

Third, each transaction carries a zero-knowledge proof, a piece of maths that shows the transaction follows the rules without revealing any details.

It is a bit like proving you are over 18 without showing your date of birth.

Why not just add it to Bitcoin?

The obvious move would be to build this into Bitcoin itself.

That would require a soft fork, a change to Bitcoin's rules that needs broad agreement across a famously cautious community.

Such changes can take years, or never happen at all.

Bitcoin as a noticeboard

[alloc] init, a cryptography firm that develops protocols for Bitcoin, wants to leave Bitcoin's rules alone and use the network as a noticeboard instead.

The encrypted transactions are written onto the Bitcoin blockchain as ordinary data, which Bitcoin already allows.

Bitcoin records them permanently and puts them in order.

It has no idea what they mean, and it doesn't check them.

The checking is done by separate software, which anyone can run.

This software reads the blockchain, picks out the shielded transactions, verifies the proofs and ignores anything invalid.

Think of Bitcoin as a public board that pins up whatever it is given, in the order it arrives.

Shielded Bitcoin pins up coded messages.

Anyone with the right decoder can work out which messages are valid and who owns what.

Everyone else sees only gibberish.

The missing piece

The idea has some clear weaknesses, and the biggest is getting money in and out.

The paper explains how private transfers work once bitcoin is already inside the system.

It does not explain how you would lock up real BTC to enter it, or reclaim real BTC when you leave.

Without that, the system shuffles around a representation of bitcoin rather than the real thing.

The firm says a second paper will solve this with PIPEs, its technique for locking bitcoin in a vault that only a valid proof can open.

Other catches

The system needs a trusted setup, a one-off ceremony that generates the cryptographic keys.

The secret material it produces must be destroyed.

If anyone kept a copy, they could in theory create money out of thin air without being detected.

Some information still leaks, because the fees paid to Bitcoin are visible.

Each shielded transaction also takes up about four times the space of a normal Bitcoin payment, so it costs more to send.

Privacy depends on crowds, too.

Hiding among 10 users protects you far less than hiding among 10 million.

The system only becomes truly private if lots of people use it.

Where it stands

For now, Shielded Bitcoin is a detailed blueprint, not a product.

Nobody can use it yet, and there is no launch date.

The hardest piece, connecting it safely to real bitcoin, has not been published.

Its appeal is that Bitcoin could gain Zcash-style privacy without anyone having to win the long political fight over changing the rules.

Its weakness is that without changing the rules, Bitcoin can't guarantee any of it.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Growth stocks coverage continues on .com
Go to Proactive UK

Today’s Edition