LibraryConsensus2016Design paperCorpus record
Cryptocurrencies without Proof of Work
Nothing at stake. Iddo Bentov, Ariel Gabizon and Alex Mizrahi.
The paper studies stake-based chain selection and the cost of signing every fork. It is one of the early formal attempts to replace work with a scarce key.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
Any staking design that cannot name what happens when a key signs two tips is still in the problem this paper states.
The five-minute read
The defect
Proof of work makes extending two forks expensive. Proof of stake, naively, lets a holder sign both.
The rule
The paper studies stake-based chain selection and the cost of signing every fork. It is one of the early formal attempts to replace work with a scarce key.
How it is put together
Signing a second fork is cheap if the key is not bonded. The protocol has to make equivocation detectable or unprofitable. Bootstrapping the randomness of the lottery is part of the problem.
Where the claim stops
This is not Ouroboros and not Casper.
One action, walked through
- Stake is the lottery ticket.
- A holder who signs two histories should be identifiable.
- The chain rule has to pick one history even when both are fully signed.
- Can one key sign two competing blocks?
The argument, unpacked
Why it is still on the desk
Any staking design that cannot name what happens when a key signs two tips is still in the problem this paper states.
After the text
Later protocols added slashable bonds and private leader election. Those are answers. This paper is the problem, written early.
What has to be true
- This is not Ouroboros and not Casper.
- It does not settle the long-range attack by itself.
- It is not a yield schedule.
What happened after the paper
Later protocols added slashable bonds and private leader election. Those are answers. This paper is the problem, written early.
What to check before you use the idea
- Can one key sign two competing blocks?
- Is that signature evidence, and is the stake still bonded?
- How is the leader lottery seeded?
Terms
- Nothing at stake
- The absence of a cost for extending every fork.
- Equivocation
- Two signatures from one key on conflicting histories.
The problem the paper names
Proof of work makes extending two forks expensive. Proof of stake, naively, lets a holder sign both.
What the design proposes
- Signing a second fork is cheap if the key is not bonded.
- The protocol has to make equivocation detectable or unprofitable.
- Bootstrapping the randomness of the lottery is part of the problem.
How the mechanism is specified
- Stake is the lottery ticket.
- A holder who signs two histories should be identifiable.
- The chain rule has to pick one history even when both are fully signed.
What this page does not treat as proven
- This is not Ouroboros and not Casper.
- It does not settle the long-range attack by itself.
- It is not a yield schedule.
Why a venture studio still reads it
Any staking design that cannot name what happens when a key signs two tips is still in the problem this paper states.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
