LibraryConsensus2017Design paperCorpus record
Casper the Friendly Finality Gadget
Casper FFG. Vitalik Buterin and Virgil Griffith.
A finality overlay. Validators cast two rounds of votes so that a chain of checkpoints becomes justified and then final. Equivocation can be slashed. The gadget does not, by itself, propose blocks.
Casper FFG finalises checkpoints on top of some other proposal rule. Validators make supermajority links. A checkpoint that is justified and then final can be reversed only by slashing a quorum that signed both sides.
The five-minute read
It is a gadget
The paper does not propose blocks. Something else builds a chain. Casper looks at checkpoints on that chain and decides which of them an accountable set has committed to.
Justify, then finalise
A supermajority link from an earlier justified checkpoint to a later one justifies the target. A further link can finalise the earlier checkpoint. The two-step is what creates a slashable conflict.
Accountable safety
If two conflicting checkpoints both finalise, at least one third of the stake signed illegally. You can show the signatures. You cannot un-break the applications that already acted.
Gasper is not this PDF
Ethereum's post-merge finality uses a Casper-style gadget beside LMD-GHOST. Client rules, inactivity leaks, and the validator set are later specifications.
One action, walked through
- A proposal mechanism produces blocks. Epoch or checkpoint boundaries are defined on that chain.
- Validators vote for a link between a source checkpoint and a target checkpoint.
- If a supermajority votes for the link, the target is justified.
- If a justified checkpoint is itself the source of a further supermajority link, it can become final.
- A validator that votes for two conflicting links, or that surrounds one vote with another, is slashed.
The argument, unpacked
Finality is slower than the head on purpose
The head of the proposal chain can move every slot. The final checkpoint waits for two rounds of votes. A product that calls the head final has left the paper.
Slashing identifies, it does not repair
Accountable safety gives you someone to punish after a catastrophe. It is not a refund for the transactions that sat on the losing checkpoint.
What has to be true
- Fewer than one third of the stake signs conflicting votes. A larger coalition can finalise two histories.
- Votes are attributable to stake that can actually be destroyed. A vote from an empty identity is not a slash.
- The proposal mechanism keeps producing checkpoints. The gadget does not conjure them.
- Clients wait for finality when they need it. The protocol does not force every light client to do so.
What happened after the paper
Ethereum's research used this gadget and then specified Gasper, which pairs it with a different fork choice and with inactivity penalties. Other chains borrowed the words friendly finality without the vote rules. The 2017 paper is the definition of the two-phase link, not a map of a live validator set.
What to check before you use the idea
- What proposes blocks, and what only finalises them?
- How many rounds of votes sit between the head and a final checkpoint?
- Which votes are slashable, and is the stake actually locked?
- Is the live system Casper FFG or a later combination?
Terms
- Supermajority link
- A vote by at least two thirds of the stake from one checkpoint to a later one.
- Accountable safety
- Conflicting final checkpoints imply identifiable stake that broke the voting rules.
The problem the paper names
A longest-chain rule gives probabilistic finality. Casper FFG asks for a checkpoint that an accountable set has signed, so reversing it requires showing that a quorum broke the rules.
What the design proposes
- A proposal mechanism underneath. The gadget only finalises checkpoints of that proposal.
- A supermajority link from one checkpoint to a later one justifies the target.
- A justified checkpoint with a further link can be finalised.
How the mechanism is specified
- Safety is the usual quorum intersection, plus the slashing condition on two votes that violate the fork rule.
- Accountable safety means you can point at the keys that signed both sides. It does not mean the reversed blocks become harmless.
- Ethereum's later Gasper combines a fork choice with this style of finality. Gasper is not this paper.
What this page does not treat as proven
- The gadget assumes a validator set and a way to slash. It does not define issuance, or a client.
- Finality lags the head of the chain on purpose. The head can still reorg before the checkpoint.
- A paper from 2017 is not a description of Ethereum after the merge.
Why a venture studio still reads it
Ask whether the team has a proposal rule and a finality rule, and whether they have confused the two. Then ask which keys would be slashed if both sides finalised.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
