Skip to content

LibraryStorage and networks2002Design paperCorpus record

Kademlia: A Peer-to-peer Information System Based on the XOR Metric

Kademlia. Petar Maymounkov and David Mazières.

Nodes have identifiers. Distance is XOR. Each node keeps contacts in buckets by distance, and a lookup walks toward the target in logarithmic steps.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

A network that says DHT should say which distance, which bucket size, and what a lookup returns when the closest peers are all the attacker.

The five-minute read

The defect

Finding a node in a large network by flooding does not scale. The lookup has to have a shape.

The rule

Nodes have identifiers. Distance is XOR. Each node keeps contacts in buckets by distance, and a lookup walks toward the target in logarithmic steps.

How it is put together

XOR is a metric. It is not a security claim. Buckets are replacement caches of peers. The paper is about lookup, not about paying for storage.

Where the claim stops

Kademlia does not authenticate the data.

One action, walked through

  1. Share node ids.
  2. On a lookup, ask the closest known peers for closer ones.
  3. Stop when the closest peers have been asked.
  4. What is the distance function?

The argument, unpacked

Why it is still on the desk

A network that says DHT should say which distance, which bucket size, and what a lookup returns when the closest peers are all the attacker.

After the text

IPFS and Ethereum's discovery protocol are descendants. The 2002 paper is the metric.

What has to be true

  • Kademlia does not authenticate the data.
  • Eclipse and sybil attacks sit outside the happy-path proof.
  • Many chains use the idea and change the parameters.

What happened after the paper

IPFS and Ethereum's discovery protocol are descendants. The 2002 paper is the metric.

What to check before you use the idea

  • What is the distance function?
  • How many peers are kept per bucket?
  • Does a lookup authenticate the record, or only find a peer?

Terms

XOR metric
Distance between two ids is the bitwise exclusive or, interpreted as a number.
Bucket
The peers a node remembers at one range of distances.

The problem the paper names

Finding a node in a large network by flooding does not scale. The lookup has to have a shape.

What the design proposes

  • XOR is a metric. It is not a security claim.
  • Buckets are replacement caches of peers.
  • The paper is about lookup, not about paying for storage.

How the mechanism is specified

  • Share node ids.
  • On a lookup, ask the closest known peers for closer ones.
  • Stop when the closest peers have been asked.

What this page does not treat as proven

  • Kademlia does not authenticate the data.
  • Eclipse and sybil attacks sit outside the happy-path proof.
  • Many chains use the idea and change the parameters.

Why a venture studio still reads it

A network that says DHT should say which distance, which bucket size, and what a lookup returns when the closest peers are all the attacker.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.