Skip to content

LibraryConsensus2018Design paperCorpus record

PHANTOM and GHOSTDAG

PHANTOM. Yonatan Sompolinsky, Shai Wyborski and Aviv Zohar.

A blockDAG protocol that still ends in one linear order. Honest blocks cluster. The parameter k is how wide that cluster may be. Kaspa is a later network in this line, not the paper.

PHANTOM keeps a blockDAG for throughput and then forces one linear order by colouring a well-connected cluster of blocks as honest. The parameter k is the network-delay assumption, written as a number.

The five-minute read

Why SPECTRE was not enough

Pairwise votes can leave two blocks unordered. Balances and contracts need one sequence. PHANTOM's job is the sequence.

Honest blocks cluster

If propagation is fast relative to the block rate, honest blocks see each other. Their anticone stays small. An attacker publishing in private has a large anticone against the honest set.

k is the whole security knob

k is the largest anticone the protocol will still call honest. It must cover normal delay and must not cover a patient attacker. There is no universal k.

Kaspa is later

The paper defines GHOSTDAG, the greedy colouring. A live network chooses k, a block rate, and a monetary policy. Those choices are not theorems.

One action, walked through

  1. A miner publishes a block that points at every tip it knows.
  2. Nodes colour the DAG, searching for a k-cluster: a set whose internal anticones are at most k.
  3. The largest such cluster is treated as the honest backbone.
  4. A topological order of that cluster, then of the rest, is the ledger order.
  5. Confirmation is a claim that a block's place in that order is stable.

The argument, unpacked

The DAG is not the ledger

Throughput comes from accepting many blocks. Safety for applications comes from the order imposed afterward. A product that exposes the DAG and never states the order has stopped halfway through the paper.

Wrong k fails in a specific direction

Too small, and ordinary latency paints honest blocks as attackers, so the chain stalls or forks itself. Too large, and a withheld attacker sits inside the cluster and gets ordered with everyone else.

What has to be true

  • Most hash power is honest and publishes promptly.
  • The maximum honest anticone really is bounded by k at the chosen block rate.
  • Nodes see the same DAG eventually. A partitioned miner colours a different graph.
  • Users wait until the colouring of their block is stable, not until the block merely exists.

What happened after the paper

Kaspa is the public network associated with this line of research. Its parameters and clients moved after the paper. GHOST and SPECTRE remain different algorithms. Cite the 2018 paper for the colouring, and cite a live client only for what that client does.

What to check before you use the idea

  • What is k, and what delay and block rate justify it?
  • Is the order a topological sort of a coloured cluster?
  • What happens to a block outside the cluster?
  • Is the live system still GHOSTDAG or a later commit rule?

Terms

Anticone
Blocks that neither precede nor follow a given block. They are the ones it did not see and that did not see it.
k-cluster
A set of blocks whose anticones inside the set are no larger than k.

The problem the paper names

SPECTRE can confirm fast and still leave some pairs of blocks without a total order. Contracts and account balances want one order. PHANTOM tries to keep the DAG's throughput and still linearise it.

What the design proposes

  • Blocks point at every block the miner has seen, not only one parent.
  • A colouring separates a well-connected honest cluster from an attacker's anticone.
  • The linear order is a topological sort of that cluster, then the rest.

How the mechanism is specified

  • k is the largest honest anticone the designer will tolerate. It encodes the assumed network delay.
  • Set k too small and honest blocks look like an attack. Set it too large and an attacker fits inside the cluster.
  • Confirmation is a statement about that colouring, not about a single chain length.

What this page does not treat as proven

  • The paper does not describe Kaspa's current parameters, clients, or monetary policy.
  • A linear order is not instant finality. Reorgs of the colouring are still the threat model.
  • GHOST, SPECTRE, and PHANTOM are three papers. Citing one name for all three is a mistake.

Why a venture studio still reads it

Ask which object is ordered: a chain, a pairwise vote, or a coloured DAG. Then ask what k assumes about how fast blocks actually travel.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.