Image

Smart Contracts for
Bitcoin-like Blockchains

Simplicity is a low-level smart contract language live on Liquid today. Write contracts in SimplicityHL, a high-level language that compiles to Simplicity.

Why Simplicity?

Know what your contracts do
before they run.

A Simplicity contract is a spending condition on coins: it doesn't call other contracts, touch shared state, or loop without bound. That narrower model makes contracts easier to analyze. Their resource use is known ahead of time, and the language has a formal, machine-checked specification.

ImageExecution costs bounded before you broadcast.
ImageNo external calls, so a smaller attack surface.
ImageA formally specified and verified core language.
ImageOnly the executed branch is revealed on-chain.

How Simplicity Works

Verifiable, Predictable Execution.

Simplicity is an alternative to Bitcoin Script: a low-level language expressive enough for covenants and financial instruments, with a formal specification and resource bounds you can compute before execution. Developers write SimplicityHL, full nodes execute Simplicity. Learn more.

SimplicityHL in the editor
Image

Familiar to Read

SimplicityHL looks like Rust: let, match, typed functions. Underneath, a program is a predicate over a transaction. It either authorizes a spend or it doesn't. There's no heap, no global state and no unbounded loops.

Image

Explicit to Reason About

Everything a contract depends on is in front of you: the transaction it inspects, the witness data it receives, and the conditions it asserts. Nothing else can change that state while it runs.

Image

Compiled to Simplicity

The SimplicityHL compiler turns your code into Simplicity, the low-level language that full nodes execute. Common operations like hashing and signature checks run as optimized jets.

Coming from the EVM?

The EVM offers more flexibility and composability. Simplicity is deliberately more restrictive, trading some of that flexibility for stronger security guarantees.

State
EVM

Each contract keeps persistent storage that its functions read and write.

Simplicity

State lives in the coins (UTXOs) a contract locks and is carried forward in transaction outputs.

Checks
EVM

require(cond) reverts the call.

Simplicity

assert!(cond) fails the program, making the transaction invalid.

Costs
EVM

Gas is metered at runtime, and a reverted transaction still pays for the gas it used.

Simplicity

CPU and memory use have a static upper bound, known before broadcast. Invalid transactions are never mined.

Authorization
EVM

msg.sender identifies the caller.

Simplicity

Signatures are checked explicitly, e.g. jet::bip_0340_verify.

Composition
EVM

Contracts call each other, and one call can trigger many others.

Simplicity

No contract calls. Several contracts compose by being spent in the same transaction.

Re-entrancy
EVM

Guarded against with checks-effects-interactions or ReentrancyGuard.

Simplicity

Not a class of bug. With no external calls, execution can’t be re-entered.

Tokens
EVM

ERC-20 and ERC-721 contracts.

Simplicity

Native Liquid assets, issued at the protocol level. Contracts constrain how they move.

Built with Simplicity

Open-source protocols, demos, and research projects on Liquid.

Image
Demo

P2P Lending

A peer-to-peer lending protocol in pure SimplicityHL. Borrowers post collateral, lenders fund offers, and the covenant enforces repayment or liquidation at expiry.

Image
Demo

Decentralized Asset Management Protocol

Regulated assets on Liquid. A Simplicity covenant enforces whitelists, blacklists, and transfer limits with no issuer signature on each transfer, and issuers can produce signed confidential audit reports.

Image
Demo

Native Multisig

Multisig custody contracts with Rocq proofs that reach from the security model all the way down to the deployed compiled bytes.

Image
Reference

Options & Offers

Option and option-offer contracts, plus on-chain state management patterns, built with Smplx and tested on a local Liquid regtest.

Image
In Development

Price Oracle

A Simplicity-powered, decentralized price oracle for Liquid. The draft specification is public and development happens in the open.

Image
Research

Post-Quantum Signatures

A SHRINCS hash-based signature verifier written in Simplicity, used by the PQ Liquid Wallet to sign transactions on Liquid testnet.

Built on a Verified Core

Simplicity is formally specified in Coq, with key parts of its implementation verified against that specification. Financial applications get a small, precisely defined base: bounded costs, no shared state, and no ambiguity in what the consensus layer will do. Issue assets, build programmable capital markets, and settle trades on Liquid, a Bitcoin sidechain.

Verified core illustration

Try Simplicity Now

Start from the example contracts and the standard library, or write your own. Live on Liquid with native multi-asset support, and available on a Bitcoin signet for experimentation.

Simplicity on Liquid and Bitcoin