Shielded Bitcoin: Private Transfers on the Bitcoin L1

Hmm, I suppose for a “true” sidechain where the sidechain has a different set of miners as the true Bitcoin blockchain, as in the original sidechains paper, this distinction makes sense.

However, I think for the purposes of what is effectively a sidechain published inside the true Bitcoin blockchain, the distinction does not matter.

With the original sidechains paper, at some point, on the true Bitcoin blockchain, the amount must be released, at which point challenging with a heavier chain is no longer possible. If after that timeout, you come into possession of a heavier chain on the sidechain that contradicts the peg-out, the coins on the true Bitcoin blockchain have already been released, so it is too late.

In the case of a sidechain or sidechain-like construction whose publication is itself tied to the true Bitcoin blockchain (as in this proposal, or with qevirpunvaf), that timeout can be encoded as the requirement to present a Bitcoin header chain of that length, proving burial of a block that contains (a commitment to) the peg-out sidechain-side transaction.

Whether to make any scheme similar to this a “sidechain” or not is largely a detail of whether the transactions are encoded directly into some OP_RETURN or similar in the true Bitcoin blockchain, or only commitments to those transactions, with the transaction data being stored in a separate network.