LibraryInteroperability2023Design paperCorpus record
Hyperlane: modular interchain security
Hyperlane. Hyperlane.
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
A reading of the project's public design document. Not a copy, not a benchmark, and not an offer.
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
- Evidence
- Primary paper
- Re-measured
- No
- Assumptions
- 3
- Records linked
- 2
01 Claim ledger
What the paper is allowed to say
Each row is a sentence already in the study. The status is the same on every row: a model claim, not a live measurement.
Claim 01 · Paper model
The defect
Modular security is a choice. If the application never chooses, it has the default, and the default is the trust assumption.
Claim 02 · Paper model
The proposal
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
Claim 03 · Paper model
The mechanism
The mailbox accepts a message when the configured module accepts it. The module might be a multisig, a threshold, or something that claims to be a light client.
Claim 04 · Paper model
The bound
This note does not rank modules.
02 Three cuts
Observation, model, falsifier
A desk does not stop at the summary. Each claim is cut three ways, using only this study's own assumptions and checks. Nothing here is a new figure.
01 The defect
Observation
What the study says
Modular security is a choice. If the application never chooses, it has the default, and the default is the trust assumption.
Model
What has to hold
You are reading Hyperlane's protocol docs. The module in a deployment is the fact that matters.
Falsifier
What would retire it
Which interchain security module does the application configure?
02 The proposal
Observation
What the study says
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
Model
What has to hold
You are reading Hyperlane's protocol docs. The module in a deployment is the fact that matters.
Falsifier
What would retire it
Which interchain security module does the application configure?
03 The mechanism
Observation
What the study says
The mailbox accepts a message when the configured module accepts it. The module might be a multisig, a threshold, or something that claims to be a light client.
Model
What has to hold
You are reading Hyperlane's protocol docs. The module in a deployment is the fact that matters.
Falsifier
What would retire it
Which interchain security module does the application configure?
04 The bound
Observation
What the study says
This note does not rank modules.
Model
What has to hold
You are reading Hyperlane's protocol docs. The module in a deployment is the fact that matters.
Falsifier
What would retire it
Which interchain security module does the application configure?
03 Sequence
One action, as an operating tape
- 01The mailbox accepts a message when the configured module accepts it. The module might be a multisig, a threshold, or something that claims to be a light client.
- 02The module is not the transport. Relayers carry bytes. The module decides whether the bytes count.
- 03A default module that is a small signer set is an honest description, not a failure of the docs, as long as the docs say so.
04 Load-bearing
The argument, and where a pitch drops it
What the name has to mean
The cut
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
An application that picks a single signer has chosen a single signer, whatever the brand says.
What actually moves
The cut
The module is not the transport. Relayers carry bytes. The module decides whether the bytes count.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
It states no message count.
What a later deployment may change
The cut
A default module that is a small signer set is an honest description, not a failure of the docs, as long as the docs say so.
Why it carries weight
If this cut is skipped, the paper's name is being used without the mechanism that makes the name mean anything.
Where it is dropped
An application that picks a single signer has chosen a single signer, whatever the brand says.
05 Register
What has to be true
Model · Not re-measured
You are reading Hyperlane's protocol docs. The module in a deployment is the fact that matters.
Model · Not re-measured
The document is the one at the source URL. A marketing page with the same brand is not this text.
Model · Not re-measured
No price, supply, yield, or adoption figure is added by this desk.
06 Divergence
What happened after the paper
An application that picks a single signer has chosen a single signer, whatever the brand says.
A later client, parameter set, or reward formula is a different object. Cite this paper for the mechanism. Cite a primary release for the network. This desk has not re-run the proof.
07 Pre-mortem
What to check before you use the idea
- 0 of 3 marked on this browser. A mark is a reading note, not a pass, a rating, or a recommendation.
08 Anatomy
The paper, in the order a builder needs
The problem it names
Modular security is a choice. If the application never chooses, it has the default, and the default is the trust assumption.
What the design proposes
- The mailbox accepts a message when the configured module accepts it. The module might be a multisig, a threshold, or something that claims to be a light client.
- The module is not the transport. Relayers carry bytes. The module decides whether the bytes count.
- A default module that is a small signer set is an honest description, not a failure of the docs, as long as the docs say so.
How the mechanism is specified
- The mailbox accepts a message when the configured module accepts it. The module might be a multisig, a threshold, or something that claims to be a light client.
- The module is not the transport. Relayers carry bytes. The module decides whether the bytes count.
- A default module that is a small signer set is an honest description, not a failure of the docs, as long as the docs say so.
What this page does not treat as proven
- This note does not rank modules.
- It states no message count.
- An application that picks a single signer has chosen a single signer, whatever the brand says.
Why the desk still reads it
Hyperlane publishes message passing where the application picks an interchain security module, instead of inheriting one unnamed verifier.
09 Lexicon
Terms, opened into the record
- Interchain security module
- The component that decides whether a remote message is accepted.
- Mailbox
- The contract that holds that decision. It is not the verifier by itself.
10 Repository
Every linked record on this page
Underlined words open a page that already exists: a concept, a protocol profile, a failure record, or another paper. If a word is not underlined, this desk does not have a record for it.
Concepts
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
