Modulus Read the documentation

Layer one

The contract is the specification.

Applications on Modulus are written as first-order logic predicates. A transaction that cannot be proved to satisfy them never happens.

There is no bytecode, no virtual machine and no execution layer. Conditions are checked, and state moves when the mathematics permits it. Most serious losses in this industry are due to code doing something other than what its author meant. There is no such gap here.

766–10,200×faster to prove
4–56×smaller proof
30–1,700×less prover memory
market.swap Predicate
swap(x, y, x′, y′, in, out) ⟺

    x′ = x + in
  ∧ y′ = y − out
  ∧ (1000·x + 997·in) · y′ ≥ 1000 · x · y
  ∧ x > 0 ∧ y > 0
A Uniswap-style exchange. This is the entire contract.

Measured

Three orders of magnitude, on hardware you already own.

Every figure below came from one desktop CPU. No accelerator, no cluster, no proving farm and no queue.

4.82ms

to prove fib(10,000). The leading zkVMs take 3.69 to 49.24 seconds for the same claim, the same algorithm and the same machine.

49.8KB

of proof, against 209.6 KB to 2.78 MB. Smallest of the five, on under 10 MB of prover memory.

SystemProveVerifyProofProver memory
Modulus zkFOL4.82 ms1.4 ms49.8 KBunder 10 MB
RISC Zero, composite3.69 s11.8 ms209.6 KB312 MB
RISC Zero, succinct14.73 s12.4 ms223.3 KB1.39 GB
SP1, core13.32 s74.3 ms2.78 MB9.39 GB
SP1, compressed49.24 s32.9 ms1.27 MB17.00 GB

AMD Ryzen 7 5700X, Linux, CPU proving only. zkFOL 0.4.0 against RISC Zero 3.0.5 and SP1 6.3.1, median of three runs. Every system proves fib(10,000) mod 7919 by fast doubling. The full tables carry the bounds check and the exact-integer route.

By construction

Three properties every application on the chain inherits.

On every other platform a developer writes down what the contract should do, then writes code that is meant to do it. Those are two separate things, and when they disagree, the difference is what an attacker takes. On Modulus you write the rule, and the chain enforces that rule directly.

01

A contract cannot drift from its specification.

The rule the author writes is the rule the chain enforces. It is compiled, but into constraints that say the same thing, by one compiler whose soundness and completeness are published. Nothing is reinterpreted on the way down, no bytecode stands in for the author's meaning, and no team writes the constraints by hand.

02

A defect refuses instead of paying out.

Everywhere else, a broken contract pays the attacker. Here it declines to act. Failure surfaces at proving time, on the author's own machine, before anything reaches the network.

03

You stop paying the network to compute.

Everywhere else you pay the network to run your code, so a more complicated contract costs more and a busy network costs more again. Here the work happens on your own machine before you submit, and the chain only checks the result. The fee is the same whether the contract is simple or elaborate, and whether the network is quiet or busy. A transaction that would fail never reaches the network to be charged for.

Privacy

Private state, publicly verifiable, at no extra cost.

Every transaction on Modulus already carries a proof. Keeping the underlying data private costs nothing on top of that, because the proof was always the thing being checked. Withhold the data and the guarantee holds exactly as it did before.

Balances that stay private and stay auditable.

A supervisor verifies solvency without reading a single account.

Order flow that never leaks.

Trades settle correctly while the book stays closed to everyone outside it.

Compliance proved, not disclosed.

A regulator checks that every transfer satisfied the rule, without seeing the transfers.

Worked example

We proved that a 9×9 sudoku with seventeen clues had a valid solution, in 16 milliseconds on a desktop, without revealing a single square.

Now replace the grid with your balance sheet, your positions or your counterparty exposure. The property is identical and so is the cost.

What review becomes

The entire contract fits on one screen.

The exchange predicate at the top of this page is the whole contract. Four conditions, with nothing running underneath them. The Uniswap V2 pair contract that does the same job is 202 lines of Solidity, and the virtual machine it runs on is a great deal more. A payment predicate says value is conserved and the spender authorised it. An escrow predicate says when funds may move and to whom.

Reviewing one means checking a few lines against the rule they were meant to express. The compiler that turns it into constraints is shared, and proved sound once for every application rather than argued again for each one. Elsewhere the review is the contract, the compiler that produced its bytecode and the machine that runs it, per application, every time. That is the difference between an afternoon and a line item the industry currently prices at $50,000 to $500,000 an engagement.

Get the developer preview.

Reproduce every figure on this page on your own machine.