Cloudy is a decentralized storage platform that settles on Arbitrum with zk proofs verified on-chain. Anyone can upload files, or become a provider and earn USDG for hosting. All secured by client-side encryption, erasure-coded redundancy across providers, on-chain challenges, and incentives that reward reliable providers and compensate data owners.
Check 412: 16 random pieces, one 356-byte proofYour encrypted data Challenged at this check
Why Cloudy
First storage platform verified on Arbitrum
Storage proofs, payments and penalties all settle on Arbitrum, so apps can rely on off-chain data the way they rely on on-chain state. Any contract can check a file’s storage status in its own transaction, and users pay in USDG on the chain they already use, with no bridge, no second chain and no extra token.
Fast, cheap zk storage proofs
Each check is answered by one compact zk proof (an SP1 STARK wrapped in Groth16), made in about a minute on a single GPU and verified on-chain at a small fixed cost, however large the data. Frequent checks stay cheap, which keeps storage affordable and lets anyone with a GPU become a provider.
Others: Merkle-proof systems such as Filecoin PDP pay on-chain gas for every sampled piece, and zk designs built on Poseidon2 hashing, such as Codex, make the data owner hash for days (about 76 h for 1 TB, versus under 2 h with Cloudy’s keccak).
Compensation system for data owners
A provider that fails to keep or serve the data loses USDG collateral to the data owner, enforced by the contract. Owners are assured of compensation, and providers have real money at stake to keep data safe.
Fast retrieval, enforced on-chain
Providers that deliver fastest earn more, and a provider that withholds data can be forced to publish it on-chain. Owners get their data back quickly whenever they need it, for free, and no provider can hold it hostage.
Others: Only about 13% of Filecoin retrievals succeeded in a 2024 measurement, and Storj, Sia and Shelby charge for every read.
Survives provider loss
Reed-Solomon erasure coding lets any one third of the providers rebuild the file, so data stays recoverable even if most providers disappear or lose it, for no more than 3× storage.
At a glance
Topic
Cloudy
Existing systems
Where proofs are verified
On Arbitrum, by SP1’s official audited verifier
None of 17 surveyed networks verifies or slashes on Arbitrum
Who receives the penalty
The data owner, in the same transaction
None of 12 systems checked pays the owner. Filecoin PDP: the provider only loses that period’s payment
Catching a provider that dropped 1% of the data
14.9% per check; about 80% over 30 days (10 checks)
Filecoin PDP: 4.9% per day; 77.9% over 30 days (30 daily checks)
On-chain cost of a proof
One 356-byte proof, about 247k gas in the verifier, whatever the sample count or data size
Plain Merkle proofs (PDP-style): about 26k gas per sample
Hash the user’s machine must compute
keccak: a 1 TB file’s tree in the browser in about 16 min to 1.8 h
Poseidon2-based designs (e.g. Codex): about 76 h for the same tree
Trusted setup
SP1’s shared setup, 18 contributors including Offchain Labs
EthStorage ran its own ceremony with 287 participants
Reads
Free for the owner; fastest third paid double; withholding challengeable on-chain
The data owner encrypts a file on their own device, splits it into redundant shards and places a storage order on Arbitrum, priced in USDG.
2
Match
Orders and provider offers meet in an on-chain order book. Each matching provider takes one shard, checks it against the order, and locks USDG collateral to accept the contract.
3
Prove
Arbitrum regularly challenges providers on random pieces of the data. Each answers with one zk proof (an SP1 STARK over a keccak Merkle tree, wrapped in Groth16), generated in about a minute and verified on-chain at a fixed cost, whatever the file size.
4
Retrieve
The owner downloads from several providers at once, for free.
5
Enforce
A provider that won’t deliver can be challenged on-chain to publish the data. A provider that fails to prove or serve the data loses collateral to the data owner.
6
Incentive
Providers that deliver data fast earn a larger share of each payment, which keeps downloads fast and makes withholding data unprofitable.
7
Resilience
Thanks to Reed-Solomon erasure coding, any one third of the providers can rebuild the whole file, so data survives even if two thirds of them lose their data.
Who uses it
Data owners
Individuals, businesses, apps, RWA issuers and AI agents that need files stored with guarantees. They use the web app in a browser, or Cloudy Node.
Providers
Anyone with spare disk space and a GPU, who earns USDG for hosting. They use Cloudy Node.
Other smart contracts
Any contract on Arbitrum can read whether a file is stored validly and act on it. For example, a sample RWA token only mints while its documents are safely stored.
Components
Component
Role
Who uses it
Cloudy contracts
Run the order book, payments, proof checks, incentives and penalties on Arbitrum, and publish storage status
Cloudy Node, the web app and other smart contracts
Cloudy Node
Rents and hosts storage, and generates the zk proofs for providers
Data owners, providers
Web app
Rents storage straight from the browser, with nothing to install
Data owners
Relay network
Helps browsers and nodes reach providers behind routers, and forwards encrypted traffic only when a direct connection fails
Cloudy Node and the web app, in the background
Sample RWA contract
Mints tokens only while their documents are stored validly
RWA issuers (example)
Get Cloudy Node
One app for both roles: rent storage with faster uploads and downloads, or rent out your spare disk and earn USDG. Desktop app and command line, for Windows and Ubuntu.