Filecoin is a market for storage with a cryptographic audit attached. A client pays a storage provider (SP) to keep some data for a fixed term, and the chain checks, continuously and without trusting the provider, that the data is still there. The provider has money locked up that it loses if the checks fail. Everything else, from sealing to Filecoin Plus, is machinery built around that idea.
Storage providers and sectors
Storage providers (once called miners) contribute disk space to the network. That space is organised into sectors, fixed-size units of 32 GiB or 64 GiB. A sector is the thing that gets proven, pledged and penalised; individual files are never tracked on their own.
A sector can be:
- Committed capacity (CC): full of zeros. The SP proves space, earns block rewards, and can later fill it with real data.
- A deal sector: containing client data, packed as one or more pieces.
Each piece has a piece CID (sometimes called CommP, starting baga...), a commitment over the padded data. That is different from the IPFS payload CID (bafy...) of the content inside it, a distinction that matters when you look up your data later.
Sealing and Proof-of-Replication
Before a sector counts, the SP seals it: runs the data through a slow, deliberately sequential encoding (Stacked DRG) keyed to that SP and that sector. The output is a replica that is unique even if two providers store identical data, or one provider stores the same data twice.
Sealing takes hours and serious hardware (lots of RAM, GPUs for the proof stages). At the end the SP posts a Proof-of-Replication (PoRep) on-chain, a SNARK showing that the sealed replica really is an encoding of the committed data. This stops two cheats: pretending to store many copies while keeping one, and generating the data on demand instead of storing it.
Snap Deals let an SP drop client data into an existing CC sector without redoing the full seal, which is why providers often keep a stock of CC sectors ready.
Proof-of-Spacetime: WindowPoSt and WinningPoSt
PoRep proves the data was stored once. Proof-of-Spacetime proves it is still stored, over time. There are two kinds:
| Proof | When | Purpose | If missed |
|---|---|---|---|
| WindowPoSt | Every sector, once per 24-hour proving period | Prove every committed sector is still intact | Sector becomes faulty, fault fees are charged, power is lost |
| WinningPoSt | When the SP is elected to produce a block | Prove a randomly chosen sector is available right now | The SP misses the block and its reward |
The 24-hour proving period is split into 48 deadlines of 30 minutes, and each sector belongs to one deadline. Chain randomness picks which data is challenged, so the SP can't predict it and precompute answers. A sector that stays faulty for 42 days in a row is terminated automatically.
Consensus (Expected Consensus) elects block producers in each 30-second epoch in proportion to their quality-adjusted power, which is how storage turns into rewards.
Collateral and slashing
Providers put FIL at risk at several levels:
- Initial pledge: locked when a sector is committed, sized from expected block rewards and network conditions. It is returned when the sector expires cleanly.
- Deal collateral: optional amounts both sides lock in a deal.
- Vesting rewards: 75% of block rewards vest over 180 days, so a provider always has unvested rewards that penalties can be taken from.
Penalties include fault fees for each day a sector is faulty, termination fees for ending a sector before its commitment is up, and consensus fault slashing for misbehaviour such as double-signing blocks. When a deal sector is terminated early, the provider also loses its deal collateral. Clients don't need to monitor any of this; the chain enforces it.
Deals vs verified deals
A storage deal fixes the piece CID, the provider, price per epoch, start epoch and duration (at least 180 days). Payment is escrowed and released as the provider keeps proving.
Filecoin Plus changes the economics. Clients whose data is judged useful receive DataCap from allocators (formerly called notaries). A deal paid with DataCap is a verified deal, and sectors holding verified data carry 10x quality-adjusted power, so they win far more block rewards. That is why many providers store verified data for free, or even pay for it: the reward subsidy is worth more than the storage fee.
If you have a large, public or otherwise useful dataset, applying for DataCap is usually the difference between paying for storage and not paying.
Retrieval is not proven
This is the part people miss: PoRep and PoSt prove storage, not service. A provider can pass every proof and still be slow or unwilling to hand the data back.
For fast retrieval, providers keep an unsealed copy alongside the sealed replica and serve it over HTTP or IPFS protocols. Without one, unsealing can take hours. Providers can announce the payload CIDs they hold to the InterPlanetary Network Indexer (IPNI), so IPFS-style clients can discover them. Retrievability is measured by community checkers and reputation systems rather than guaranteed by consensus, and newer proof designs such as Proof of Data Possession (PDP) target hot, quickly retrievable data. In practice, choose providers with a track record of serving data, and store more than one copy.
Filecoin and IPFS
Filecoin uses IPFS's data model: content is chunked into IPLD blocks, addressed by CIDs, and shipped to providers as CAR files. A typical preparation step:
ipfs add -r --cid-version 1 ./dataset # last line: payload root CID (bafy...)
ipfs dag export bafy...rootCID > dataset.car # CAR file to hand to a provider or onramp
The CAR becomes (part of) a piece, and the piece is sealed into a sector. Keep both identifiers: the payload CID is how you and IPFS clients refer to the content; the piece CID is what the deal on-chain refers to.
The FVM
The Filecoin Virtual Machine (live since 2023) runs user contracts, including EVM-compatible ones via the FEVM, so Solidity and standard Ethereum tooling work. Contracts can read deal state and, with Direct Data Onboarding, take part in how data gets committed. That enables things like contracts that automatically renew or replicate deals (perpetual storage), data DAOs that pay for datasets, and pools that lend FIL to providers for collateral.
Onramp or direct deals?
| Onramp / pinning service | Direct deals | |
|---|---|---|
| Data size | Any, including single files | Best for large datasets (many GiB to PiB) |
| Setup | API key, upload | Data prep, provider selection, deal tooling |
| Retrieval | Usually a hot IPFS copy plus Filecoin backup | Depends on your chosen providers |
| Cost | Subscription or per-GB | Often cheap or free with DataCap |
| Control | The service picks providers and renews | You pick providers, replicas and terms |
Use an onramp for app data, NFT assets and anything under a few GiB. Services built on Filecoin aggregate many uploads into one piece and can give you a proof that your data is included in a specific deal. Small files on their own waste a 32 GiB sector.
Make deals directly when you have a large dataset, can qualify for DataCap, and want to choose providers (for geography, retrieval quality or independence). Budget time for data preparation, for spreading several replicas across unrelated providers, and for monitoring and renewing deals before they expire.
Summary
| Concept | What it does |
|---|---|
| Sector | Unit of storage that is sealed, proven and pledged |
| PoRep | Proves a unique sealed replica was created |
| WindowPoSt | Proves every sector is still stored, each day |
| WinningPoSt | Proves storage when producing a block |
| Collateral | FIL a provider loses for faults or early termination |
| Filecoin Plus / DataCap | 10x power for verified deals, subsidising storage |
| Retrieval | Not enforced by proofs; pick providers who serve data |
Get the weekly commit
New blockchain deep dives every week.