Skip to content
— CH. 1 · INTRODUCTION —

Proof of stake

9 min listen · Ch. 1 of 6
6 sections
  • Proof of stake arrived on the blockchain scene in 2012 with a cryptocurrency called Peercoin. It was a quiet beginning for a protocol that would eventually challenge the dominant way the world runs blockchains. At the heart of the idea is a deceptively simple question: what if, instead of burning electricity to earn the right to add transactions to a ledger, you simply proved that you already owned a piece of the network?

    The answer to that question has split the cryptocurrency world ever since. On one side sits proof of work, a method that demands vast computational effort and the energy costs to match. On the other sits proof of stake, which selects the people who record new transactions in proportion to how many coins they already hold. The difference is not just technical. It touches on who controls a network, how secure it can be, and whether a blockchain can ever be considered environmentally responsible.

    By September 2022, Ethereum, the second-largest cryptocurrency, made the switch from proof of work to proof of stake. Its energy use was estimated to have dropped by over 99%. That single moment brought all the old debates roaring back: Is proof of stake safe? Does it hand too much power to the already wealthy? And what does the United States government think it even is?

  • In a proof-of-work blockchain, the people who record transactions are called miners, and they compete by solving computationally expensive puzzles. Proof of stake replaced this competition with a different kind of gatekeeping. In a proof-of-stake blockchain, the people who append transactions are called minters or validators, and they are chosen based on how many tokens they hold.

    For a transaction to become part of a blockchain, it must be added to the chain by one of these validators. Most protocols reward validators for doing this work, giving them a financial stake in keeping the system running honestly. The security of the whole network depends on this incentive structure. If an attacker wants to take over a majority of validation, they first need to acquire a large fraction of the total tokens on the blockchain, which is expensive and conspicuous.

    Researchers Riposo and Gupta developed a formal mathematical model showing exactly what a staker can expect to earn. Their forward-method model computes staking rewards as a return per block-validation period, and they proved that the resulting interest equals the ratio of the average staking gain to the total staked coins. Their work also incorporated slashing, the practice of penalizing validators for misbehavior, showing that slashing reduces expected rewards. They also incorporated Maximal Extractable Value, known as MEV, which links transaction-fee extraction directly to average staking gain.

  • Because proof of stake requires so little computation to add a block, it opened a set of attack vectors that simply do not exist in proof-of-work systems. The most striking is the long-range attack, sometimes called Alternative History or History Revision in academic literature. In a proof-of-work scheme, rewriting the past is impractical because it demands redoing an enormous volume of computation. In proof of stake, that barrier largely disappears.

    The early stages of any blockchain are especially vulnerable to these rewrites. Fewer stakeholders were involved back then, which makes collusion easier. If a malicious group could rewrite that early history, they could, for example, redo the entire record and collect all the per-block and per-transaction rewards that were originally paid out to honest validators.

    A separate weakness is called the Nothing-at-Stake attack. Because validators do not spend significant computing power on the validation process, they have little reason not to approve every competing version of the chain that comes their way. Accepting multiple forks maximizes their chances of earning a fee. This permissiveness can enable double-spending, where the same digital token gets spent more than once. One mitigation is economic finality: penalizing validators who sign off on conflicting chains.

    Bribery attacks are also more potent in a proof-of-stake environment. An attacker can financially induce validators to approve a rival fork, and the low computational cost of adding blocks in PoS means that even former stakeholders who no longer hold significant tokens can be recruited to help rewrite history from a point when they did hold enough stake to claim a majority.

  • Early proof-of-stake implementations converged into two broad design families: Byzantine-fault-tolerance-based approaches and chain-based approaches. Researcher Bashir identified three further subtypes within the broader PoS family.

    Chain-based proof of stake closely mirrors the proof-of-work model. Rather than having every validator compete to solve the same puzzle as fast as possible, the scheme adjusts the difficulty of each validator's puzzle based on how much stake they hold. High-value stakeholders solve easier puzzles, avoiding the need for excessive hardware.

    Nominated proof of stake, also called committee-based PoS, selects a committee of validators using a verifiable random function. Validators with larger stakes are more likely to be elected, and once chosen, they take turns producing blocks in a random order. This design is used in the protocols known as Ouroboros Praos and BABE.

    BFT-based proof of stake follows a three-step cycle: a proposer is randomly selected and puts forward a block; other validators obtain this pool, validate it, and vote; then BFT consensus locks in the most-voted block. The scheme holds as long as fewer than one-third of validators are dishonest. Tendermint and Casper FFG both use this model.

    Delegated proof of stake, used by EOS, Lisk, and Tron, runs a two-stage election: stakeholders first vote in proportion to their holdings to elect a committee of witnesses, then those witnesses rotate through producing and approving new blocks. Fewer total validators means consensus forms faster. Finally, liquid proof of stake, used by Tezos, lets anyone with a stake declare themselves a validator, while smaller holders can delegate their voting rights to larger players in exchange for periodic payouts, with the freedom to switch allegiance at any time.

  • Critics have argued that proof of stake tilts power toward users who already hold large amounts of cryptocurrency. Because the probability of being selected to validate, and thus earn rewards, scales with holdings, wealth compounds in the hands of those who already have it. This dynamic, critics contend, could give large holders outsized influence over the management and direction of a blockchain.

    The legal picture in the United States added a further layer of uncertainty. The Securities and Exchange Commission argued that staking rewards are the equivalent of interest, which would classify coins such as ether and ada as financial securities. In 2024, the SEC sidestepped a direct ruling by approving Ethereum market funds on the condition that those funds did not stake their coins.

    That condition carried a real financial cost. Not staking meant those funds were forgoing roughly 3% of potential annual returns. The staking rate for ether stood at 27% of total supply, a notably low figure compared with Cardano at 66% and Solana at 63%. The gap between those numbers reflects different degrees of adoption and different economic incentive structures across proof-of-stake networks.

  • A study from the University of London, published in 2021, put hard numbers to the energy argument. It found that Bitcoin, running on proof of work, consumed roughly a thousand times more energy than the highest-consuming proof-of-stake system studied, even when Bitcoin was given the most favorable conditions in the comparison. Most proof-of-stake systems, the study found, consume less energy than PoW across most configurations.

    In January 2022, Erik Thedeen, the vice-chair of the European Securities and Markets Authority, called on the European Union to ban the proof-of-work model in favor of proof of stake specifically because of the energy difference. The political pressure that followed was one factor in the broader conversation about blockchain's environmental footprint.

    Ethereum's September 2022 transition to proof of stake was estimated to have cut the network's energy use by over 99%. That figure gave critics of proof of work their clearest data point yet. What started with Peercoin in 2012 as a minority approach had, within a decade, been adopted by the second-largest cryptocurrency network in the world, with the energy savings large enough to register in national-level climate discussions.

Continue browsing

Common questions

What is proof of stake and how does it work?

Proof of stake is a class of blockchain consensus mechanisms that selects validators in proportion to the quantity of cryptocurrency they hold. Validators, sometimes called minters, are chosen to append new transactions to the blockchain, and most protocols reward them for doing so. The system deters attackers by requiring them to acquire a large fraction of the total tokens on the network before they can take over majority validation.

Which was the first cryptocurrency to use proof of stake?

Peercoin, introduced in 2012, was the first functioning implementation of a proof-of-stake cryptocurrency. Other cryptocurrencies including Blackcoin, Nxt, Cardano, and Algorand followed before the approach became widely adopted.

When did Ethereum switch to proof of stake?

Ethereum switched from proof of work to proof of stake in September 2022. The transition, which came after several proposals and some delays, was estimated to have cut Ethereum's energy use by over 99%.

How much energy does proof of stake use compared to proof of work?

A 2021 study by the University of London found that Bitcoin, which runs on proof of work, consumed roughly a thousand times more energy than the highest-consuming proof-of-stake system studied. Most proof-of-stake systems cause less energy consumption than proof of work across most configurations.

What are the main security risks of proof of stake?

The main vulnerabilities include long-range attacks, where a malicious group rewrites blockchain history by exploiting the low computational cost of adding blocks, and the Nothing-at-Stake attack, where validators have an incentive to approve every competing chain fork. Bribery attacks are also more potent in proof-of-stake systems because rewriting a large portion of history is computationally cheap.

What is the SEC's position on proof of stake staking rewards?

The U.S. Securities and Exchange Commission has argued that staking rewards are the equivalent of interest, which would classify coins such as ether and ada as financial securities. In 2024, the SEC approved Ethereum market funds on the condition that they did not stake their coins, causing those funds to forgo roughly 3% of potential annual returns.

All sources

20 references cited across the entry

  1. 1On PeerCoin Proof of Stake for Blockchain ConsensusWenbing Zhao et al. — ACM — 26 March 2021
  2. 2JournalBlockchain without Waste: Proof-of-StakeFahad Saleh — 2021-03-01
  3. 4JournalEvaluation of Energy Consumption in Block-Chains with Proof of Work and Proof of StakeRong Zhang et al. — 2020
  4. 5JournalA Crypto Yield Model for Staking ReturnJulien Riposo et al. — 2024-02-15
  5. 6Securing Proof-of-Stake Blockchain ProtocolsWenting Li et al. — Springer International Publishing — 2017
  6. 7MagazineThe Crypto World Is Getting Greener. Is It Too Little Too Late?Samantha Hissong — July 9, 2021
  7. 8JournalProof-of-Stake Consensus Mechanisms for Future Blockchain Networks: Fundamentals, Applications and OpportunitiesCong T. Nguyen et al. — 2019
  8. 17Book2021 IEEE 21st International Conference on Software Quality, Reliability and Security Companion (QRS-C)Moritz Platt et al. — 2021