LibraryConsensus2017Design paperCorpus record
Snow White: Robustly Reconfigurable Consensus
Snow White. Phil Daian, Rafael Pass and Elaine Shi.
A proof-of-stake design in the sleepy model: honest nodes may be offline, and the set of stakeholders can change. It is an academic predecessor, not Cardano and not Ethereum.
Snow White is a proof-of-stake protocol in the sleepy model: honest stakeholders may be offline, and the eligible set changes, without treating every sleeping honest node as an attacker.
The five-minute read
Sleep is not corruption
Nakamoto-style arguments often need honest participants to be awake and mining. Snow White's model allows honest keys to be offline and still counts the adversary only among the corrupt, not among the asleep.
The committee changes
Stake moves. The protocol has to decide which old keys can still speak, and for how long, so a sold key cannot rule the present.
It is still a chain
The fork choice is in the longest-chain family over eligible blocks. This is not a BFT quorum and not Ouroboros's slot lottery, though it is part of the same conversation.
No product is attached
There is no delegation market, no liquid staking receipt, and no wallet in the paper. Those are later economic objects with their own failures.
One action, walked through
- Stakeholders register stake under the reconfiguration rule.
- Eligible leaders for an epoch are determined from that stake and from randomness the adversary should not freely grind.
- An eligible leader who is awake publishes a block extending the chain they adopt.
- Nodes apply the fork choice to eligible blocks they have seen.
- A later epoch refreshes eligibility so old stake loses its voice on the schedule the paper defines.
The argument, unpacked
The model is the result
The contribution is a security statement that does not pretend every honest holder is online. A chain that copies a staking sentence and then assumes full participation has not used the theorem.
Reconfiguration is where stake protocols lie
If yesterday's keys can still sign today's blocks without bound, the present stake does not govern. Snow White is one attempt to cut that off. The cutoff has to be real in the client, not only in the paper.
What has to be true
- Corrupt stake is below the paper's threshold relative to awake honest stake, not relative to all coins ever issued.
- Randomness used for eligibility is not cheaply grindable by the adversary.
- Honest nodes that are awake follow the fork choice. Strategic silence is outside the basic claim.
- Network delay sits inside the model's bound during the periods the proof uses.
What happened after the paper
Snow White sits in the 2016–2017 cluster of proof-of-stake papers with Ouroboros, Algorand, and Thunderella. None of them is the specification of Ethereum, Cardano, or Solana. It remains the citation for the sleepy assumption, which most investor decks skip.
What to check before you use the idea
- Are offline honest holders treated as absent or as faulty?
- When does an old key lose eligibility?
- Can the leader lottery be ground by trying many tickets?
- Is the fork choice longest-chain or a quorum?
Terms
- Sleepy model
- Honest participants may be offline without being counted as attackers.
- Reconfiguration
- The scheduled change in which stake is allowed to produce blocks.
The problem the paper names
Nakamoto's protocol assumes honest hash power is awake and racing. Proof of stake needs a committee drawn from a changing set of keys, some of which are asleep, without letting an old committee rewrite the present.
What the design proposes
- A sleepy execution model. Offline honest nodes are not counted as corrupt.
- Periodic reconfiguration of who may produce blocks.
- A longest-chain style rule over blocks from the eligible set.
How the mechanism is specified
- Eligibility is determined from stake and randomness that an adversary should not grind freely.
- The security statement is about corrupt stake versus awake honest stake, inside the model's delay bound.
- Nothing in the paper is a wallet, a delegation market, or a fee rule.
What this page does not treat as proven
- Do not cite Snow White as the consensus of any chain that merely uses the words proof of stake.
- Sleepiness is an assumption about honest users, not a feature you can bolt on after measuring uptime.
- The paper does not analyse liquid staking or exchange custody of keys.
Why a venture studio still reads it
Ask which honest participants are allowed to be offline before the theorem stops applying. Most production decks never answer.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
