Shielded Bitcoin: Private Transfers on Bitcoin L1
310
502
2,933
1,328,360
Thanks for having us on, Laura!
🔐 Shielded Bitcoin is coming, and it needs no soft fork. Misha Komarov (@nemothenoone), founder of @allocinitxyz and co-founder of @nil_foundation, tells @laurashin how Bitcoin PIPEs uses witness encryption to bring Zcash-style privacy to Bitcoin without touching its protocol. Subscribe to Unchained Premium to watch! unchainedcrypto.com/can-this…
3
28
4,834
Come find @ClaraShik at @BitDevsNYC meetup today to learn about Shielded Bitcoin design!
Hot! 🔥 Tonight at BitDevs, @ClaraShik will present the amazing work AllocInit has just published (today!) about private bitcoin transfers without consensus changes. RSVP on meetup or luma: meetup.com/bitdevsnyc/events… luma.com/4l4jywq0
3
3,366
Learn about Bitcoin PIPEs v2 and Shielded Bitcoin in a recent conversation of @nemothenoone with @stephanlivera!
Bitcoin PIPEs v2: Covenants Without a Soft Fork | Misha Komarov SLP776 @nemothenoone of @allocinitxyz walks through Witness Encryption–gated keys, pre-covenants, vault exits, and ciphertext-size trade-offs in PIPEs v2. Timestamps 00:00 — Intro: Misha & Bitcoin PIPEs v2 00:27 — Background: BitMessage to =nil; 01:31 — Soft-Fork Fatigue & Nice-to-Haves 03:24 — Emulate Opcodes Without Soft Forks 04:54 — Witness Encryption Unlocks Keys 06:01 — Witness Encryption vs Bitcoin Witness 09:00 — PIPEs v1 vs v2: FE to WE 11:39 — Ciphertext Size & Cost Trade-offs 15:28 — Vaults as the Unhappy Path 16:23 — PIPEs vs Sigbash Cosigner 18:05 — DKG Setup & 1-of-n Trust 21:11 — Shared Vaults & Lending Use Cases 23:24 — Beyond Canonical OP_VAULT 26:35 — Shielded Bitcoin vs Shielded CSV 32:17 — Self-Custody Peg-In and Peg-Out 37:14 — On-Chain Footprint Walkthrough 39:42 — Security Challenges & Code Roadmap
2
3
17
5,654
Enjoy this conversation with @isabelfoxenduke, @nemothenoone, and @ClaraShik discussing Shielded Bitcoin and PIPEs v2. Thanks for having us on, Isabel.
PIPEs, Witness Encryption & the Future of Privacy on Bitcoin | with Misha Komarov and Clara Shikhelman 🔗 YouTube: piped.video/eMIZFFfU3PI Today, @allocinitxyz co-founder @nemothenoone and Head of Protocol Research @ClaraShik join me to unpack PIPEs — a framework that could potentially make binary covenants possible on Bitcoin without the need for a soft fork, enabling truly trustless bridges amongst other expressive functionality. Leveraging advancements in Witness Encryption — one of the most cutting-edge areas of advanced theoretical cryptography — PIPEs enables the execution of Bitcoin signatures by proving correct computation (e.g. of account balances on layer 2s and metaprotocols). Although the underlying cryptographic assumptions remain experimental and unhardened, Komarov and Shikhelman believe PIPEs could deliver the functionality of covenant-enabling upgrades like OP_CAT without the need for protocol-level changes—making PIPEs one of the most significant potential developments for Bitcoin since the advent of BitVM. The team also announced their first proposed use case this morning: a privacy protocol titled "Shielded Bitcoin." In this episode, we unpack the theory and the practice of how this technology is evolving — and what the new road ahead looks like for PIPEs, Shielded Bitcoin and beyond. This episode of Bitcoin Rails is brought to you by: LayerTwo Labs @LayerTwoLabs — developing research, software, and technologies for scaling Bitcoin via the integration of Drivechains (BIP 300/301) Hashi on @SuiNetwork — a primitive for executing Bitcoin DeFi transactions, without having to trust a federated bridge or other centralized entity BitBox @BitBoxSwiss — an open-source Bitcoin-only hardware wallet, with smooth UX and no compromises on security. Check out Bitbox [dot] swiss and use code BITCOINRAILS to get a discount TIMESTAMPS: 🎙️ 01:42 Tying PIPEs to the mission at [[alloc] init] 🔓 08:31 Defining witness encryption and conditional decryption 🛠️ 23:59 Shifting from functional encryption (PIPEs v1) to witness encryption 📜 26:17 Outlining pre-covenants vs. post-covenants on Bitcoin 🏎️ 39:37 Why PIPEs v2 is far from the end of the road 🌐 56:57 Building meta-protocols and avoiding external sequencer risks 👀 1:05:00 Implementing optional compliant privacy via viewing keys ⚡ 1:15:33 Comparing PIPEs to BitVM and rendering BIPs obsolete 🎲 1:23:07 Evaluating the min-rank hardness assumption
5
4
22
4,423
Latest piece for @BitcoinMagazine on @allocinitxyz's new Shielded Bitcoin proposal. This in combination with their work on PIPEs could lead to a very big privacy win for Bitcoin. Details on the protocol here: bitcoinmagazine.com/technica…
2
13
44
3,136
Shielded Bitcoin: Private Transfers on Bitcoin L1
310
502
2,933
1,328,360
Find us at the Bitcoin Research Week to talk about PIPEs v2 updates and its applications!
Replying to @sr_gi
This year we'll have @0xgazelle, @jesseposner and @robin_linus talking about advances in topics from last year's Bitcoin Research Week (PQ, Nested MuSig and ZKP), plus @stevenroose3, @nemothenoone and @nadav_kohen covering hot topics in Bitcoin (Ark, PIPEs v2 and Isogenies).
1
8
2,363
Last week at Swiss Crypto Day, @towa_patrick presented the latest AADP WE improvement for PIPEs v2 featuring the reduction of a ciphertext size to ~8TB for 100 bits of security. Slides: swisscryptoday.github.io/ass…
9
1,315
Watch @michelabdalla talking about Bitcoin PIPEs v2/AADP WE, its ciphertext size reductions, attacks and defenses as preliminary open challenges results at a Bitcoin Cryptography Workshop organized by @SanjamGarg and @ssrivatsan97 at SBC26! piped.video/watch?v=mf6fv78L…
1
6
1,923
Learn more about the PIPEs v2/AADP WE commutator attack and patch in a blog post: allocinit.xyz/posts/commutat…
Open challenges for AADP WE are happening! A commutator-based attack breaking both AADP and the original ADP for sparse circuits was submitted. We are aware of the mitigation that fixes this class of attacks in characteristic 2 and are working on extending it to characteristic p. Congratulations to the submitter, we will be in touch!
4
8
1,958
Open challenges for AADP WE are happening! A commutator-based attack breaking both AADP and the original ADP for sparse circuits was submitted. We are aware of the mitigation that fixes this class of attacks in characteristic 2 and are working on extending it to characteristic p. Congratulations to the submitter, we will be in touch!
Today we announce: AADP WE Open Challenges. Recently we proposed a new witness encryption scheme based on Arithmetic Affine Determinant Programs which we intend to use in Bitcoin PIPEs v2, unlocking a wide range of applications and eliminating the need for trusted parties. Now we invite anyone to break small instances of our new scheme or to discover structural properties that were unknown before. Details here: allocinit.notion.site/challe… Special thanks to @zeroknowledgefm @zkproof @IACReurocrypt for organizing the conference week in Rome that we're announcing these at in person.
6
3,194
In case you missed it in Vegas, here is our full preso including slides from @TheBitcoinConf. We discuss what PIPEs are all about and how witness encryption can be used to enforce arbitrary logic on Bitcoin. This means: trustless vaults, covenants, and non-interactive ZKPs on Bitcoin without protocol changes or trusted parties. Also, we discuss getting rid of multi-sigs using PIPEs. piped.video/watch?v=jPTa3gZL…
1
3
16
2,159
Today we announce: AADP WE Open Challenges. Recently we proposed a new witness encryption scheme based on Arithmetic Affine Determinant Programs which we intend to use in Bitcoin PIPEs v2, unlocking a wide range of applications and eliminating the need for trusted parties. Now we invite anyone to break small instances of our new scheme or to discover structural properties that were unknown before. Details here: allocinit.notion.site/challe… Special thanks to @zeroknowledgefm @zkproof @IACReurocrypt for organizing the conference week in Rome that we're announcing these at in person.
3
27
78
10,949
If you’re in Rome for @IACReurocrypt, come learn about Bitcoin PIPEs v2 and AADP Witness Encryption this Saturday, May 9! Head of Cryptography Research, Handan Kilinc Alper (@HandanKAlper) from our team will present PIPEs v2 at CTB ’26 this Saturday. 4:50 pm | CTB 2026 (ctb-workshop.org) → Sapienza University of Rome | Aula II (Classroom II). Enter via Scienze Statistiche Entrance of building CU002. University map: eurocrypt.iacr.org/2026/file… Come learn and ask questions. See you there!
4
21
1,472
We made it to Rome! Find us at zkSummit14, ZKProof, and Eurocrypt from May 7-14 sharing our latest research on Witness Encryption and Bitcoin PIPEs. Come say hi if you see us around; @nevernotrunout, @HandanKAlper, @michelabdalla, @levs57, @towa_patrick, @mschofnegger, and others are here for the conferences and our cryptography research team offsite. And if you see Michel (@michelabdalla) please wish him a big congrats — he just received the RSAC Test of Time Award. We'll definitely be celebrating this!
1
1
42
1,585