LibraryConsensus2016Design paperCorpus record
FruitChains: A Fair Blockchain
FruitChains. Rafael Pass and Elaine Shi.
Nakamoto consensus can pay a minority coalition more than its share of hash power, which is the selfish-mining observation. FruitChains records transactions in 'fruit' that hang off the chain, and pays out over a window so honest hash power gets roughly honest rewards.
FruitChains keeps Nakamoto's honest-majority security and changes the reward. Transactions sit in fruit that are easier to find than blocks. Rewards are averaged over a window so a minority of hash power cannot systematically earn more than its share by withholding.
The five-minute read
Selfish mining is the defect
The paper starts from the fact that a coalition can do better than its hash-power fraction by strategic withholding. Fairness is defined against that, not against a feeling about pools.
Fruit versus blocks
Fruit carry transactions and are mined at a lower difficulty. Blocks form the chain that decides which fruit are stable. The two objects are not interchangeable.
Approximate, over a window
The guarantee is that a long enough segment pays an honest coalition nearly its fraction. It is not a promise about the next block, and it is not exact.
Pools are a consequence, not the goal
Lower variance makes solo mining less painful. The paper says this lessens the need for pools. It does not abolish coordination among miners who want to reorder transactions.
One action, walked through
- Miners search for fruit and for blocks, at different difficulties.
- A fruit hangs off a recent block and carries transactions.
- A later block stabilises which fruit count.
- Rewards over a segment of length tied to the security parameter are shared so that honest hash power is paid approximately in proportion.
- A coalition below half the hash power cannot, in the theorem, gain more than a small factor by deviating.
The argument, unpacked
Fair is a defined word
Outside the paper, fair often means 'I should have been paid'. Inside the paper it means a fraction of hash power receives about that fraction of block rewards in a long window, with high probability. Do not import the wider word.
MEV is a later problem
The 2016 argument is about withholding and reward variance. A miner who includes the block honestly and still reorders the fruit's transactions for private gain is not the attacker this theorem bounds.
What has to be true
- Honest majority of hash power for the Nakamoto-style safety claims.
- Parameters, including the window, set as the paper requires for the approximation.
- Rewards and fees are actually distributed the way the fairness proof assumes.
- The hash function and the network model match a longest-chain argument.
What happened after the paper
FruitChains is the standard citation when a design claims to have fixed miner fairness. Check whether the design pays over a window and separates fruit from blocks. A new name for the longest chain does not inherit the theorem.
What to check before you use the idea
- What is the fruit, and what is the block?
- Over what window is fairness claimed?
- Does the attacker bound include transaction reordering, or only withholding?
- Is the citation used to justify a fee or a yield? It should not be.
Terms
- Fruit
- A lower-difficulty record that carries transactions and is later stabilised by the chain.
- Approximate fairness
- An honest coalition's reward share stays close to its hash-power share over a long segment.
The problem the paper names
If a miner can earn more by withholding blocks than by publishing them, the incentive story of the longest chain is incomplete. The paper wants approximate fairness: a fraction of the hash power should get about that fraction of the rewards.
What the design proposes
- Fruit are easier to mine than blocks and carry the transactions.
- Blocks still form a chain and also stabilise which fruit count.
- Rewards are spread across a window of the chain rather than paid only to the block finder.
How the mechanism is specified
- The fairness claim is approximate, over a long enough segment, and assumes an honest majority of hash power.
- The paper also argues that lower reward variance reduces the need to join a pool. That is a consequence it states, not a measurement of later pools.
- Consistency and liveness are meant to match Nakamoto under honest majority.
What this page does not treat as proven
- Fairness in the paper is about block rewards, not about transaction ordering or MEV.
- A protocol that pays more evenly can still be captured by a pool that coordinates the hash power.
- This does not set a fee, a price, or a yield.
Why a venture studio still reads it
When someone says miners are paid 'fairly', ask fair against which deviation. FruitChains answers selfish withholding. It does not answer a builder who reorders transactions inside an honest block.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
