What Is Proof of Stake? You Bond Capital Instead of Burning Electricity.

Proof of stake secures a chain by locking capital that the protocol can take away, not by spending electricity. Here is how validators are rewarded, punished and finalised.

Proof of stake is usually explained as “proof of work without the electricity”, and that description is accurate and almost useless. Both systems solve the same problem, which is getting thousands of strangers to agree on a single ordering of transactions without a referee, but they spend different resources to do it and they inherit different failure modes. The resource is not there to perform work in the ordinary sense in either design. It is there to make cheating expensive and honest behaviour profitable, and the whole article follows from that one sentence.

This piece works from the validator upward: what a validator is, what it deposits, how it is rewarded, how it is punished, what finality means when it is explicit rather than probabilistic, and where the design is genuinely weaker than proof of work. It is not an argument that one is better. It is an attempt to describe the machine accurately enough that the argument can be had with real numbers instead of slogans.

What Is Proof of Stake? You Bond Capital Instead of Burning Electricity.
A proof-of-stake validator is a small server process, not a warehouse of hardware. The scarce resource moved from the machine that computes to the capital that is locked and can be taken away. Photo: Derrick Coetzee, CC0, via Wikimedia Commons

The problem every chain has to solve

A blockchain is a list of transactions that many independent computers agree on. The hard part is not recording a list; the hard part is deciding whose version of the list is the real one when two nodes see two different transactions at the same moment, and doing so repeatedly, in public, with participants who have never met and may not be honest.

Any solution has to answer three questions. Who is allowed to add the next block? Why would anyone bother? And what stops an attacker from adding blocks that rewrite history? A consensus mechanism is the set of rules that answers those three questions together, and proof of work and proof of stake are two different answers that share one idea: make the right to propose a block scarce, and make the cost of misusing it higher than the reward.

The difference between them is what the scarce thing is. In proof of work, the scarce thing is physical computation, and the cost is paid in energy and hardware. In proof of stake, the scarce thing is capital, and the cost is paid in opportunity, because the capital is locked, exposed to penalties and unable to be used elsewhere while it secures the network.

Proof of work pays in electricity; proof of stake pays in locked capital

Proof of work turns a security guarantee into a physics problem. Miners expend real energy to produce a valid block, and the rule is that the chain with the most accumulated work is the true one. To rewrite history, an attacker must redo the work, which means controlling more computation than everyone else combined, which means buying and powering a large share of the world’s mining hardware. The bill is continuous, unavoidable and paid to electricity suppliers.

Proof of stake turns the same guarantee into a financial problem. Validators lock a stake, and the rule is that the chain the majority of the stake has attested to is the true one. To rewrite history, an attacker must control a majority of the stake, and a majority of the stake is a majority of the capital, which is visible, attributable and, crucially, destroyable by the protocol itself. The bill is opportunity cost plus the risk of losing the stake, which is not paid to a utility but retained by the network’s own rules.

What Is Proof of Stake? You Bond Capital Instead of Burning Electricity.
The two designs across six properties. The deepest difference is not energy use but who bears the cost: in proof of work it is the miner, continuously, while in proof of stake it is the validator, conditionally, and the protocol can take the cost back.

That last property is the point of the design. In proof of work, an attacker who has already done something invalid has spent the energy, and the energy is gone whether or not the attack succeeds. In proof of stake, the capital that supported an invalid action is still sitting in the protocol, and the protocol can destroy part of it after the fact. This is why slashing exists and why it has no real analogue in mining: the punishment can be applied to the attacker’s own assets rather than merely to their future income.

How a validator actually works

On Ethereum, a validator is a software process with a stake attached to it, and the stake is set at 32 ETH per validator. The economics of that number matter: it is small enough that joining the validating set is possible for an individual with capital, and large enough that the cost of acquiring a meaningful share of the network is daunting. A would-be validator deposits the stake, joins an activation queue, and begins to be assigned work.

The work comes in two forms. Once per assigned slot, one validator proposes a block, choosing from the pending transactions and assembling them into a candidate. In every slot, every other validator casts an attestation, a signed vote for which chain and which block the validator considers correct. Proposing is the visible task and attestation is the continuous one, and the security of the system rests far more on the second than on the first.

Time is organised into fixed slots and epochs. A slot is a window in which a block may be proposed, and a group of slots forms an epoch. This regular, metered clock is one of the quieter differences between the two designs. Proof of work produces blocks whenever a miner happens to find one, so block times vary and the chain’s rhythm is statistical; proof of stake assigns the right to propose on a known schedule, so the chain’s rhythm is a timetable. Predictability is a convenience for users and a structural difference for the protocol, because it makes explicit finality possible.

What Is Proof of Stake? You Bond Capital Instead of Burning Electricity.
One stake, two directions. Honest participation earns a yield; a defined class of misbehaviour burns part of the stake itself. The asymmetry between a small reward and a large, certain penalty is the mechanism, not a side effect.

Where the staking yield comes from

The yield a validator earns is not a dividend and not a payment from a company. It is the sum of a few protocol-level flows, and separating them is the only way to reason about whether the rate is sustainable.

The first component is issuance: the protocol mints new units for validators who participate, and it mints less per unit as more stake joins. That creates a self-adjusting yield, in which a higher proportion of the supply staked mechanically lowers the reward per validator. The second component is transaction fees, which users pay for block space and which are routed to the proposer. The third is a subtraction: a base fee is burned rather than paid out, so on a busy chain the amount of issuance that survives as a net reward can be small, and the validator’s income is a mix of a shrinking subsidy and a variable fee stream.

Two consequences follow that are easy to miss. A staking yield is not a risk-free rate, because it is compensation for locking capital, running a process reliably and accepting the slashing risk; treating it as a savings rate is a category error. And the yield is not a fixed promise from the protocol; it is an emergent result of how much stake is participating and how much fee revenue the chain is generating, which is why staking returns tend to fall as the network grows.

Slashing: the penalty that makes a promise expensive to break

Slashing is the punishment for a specific and narrow set of actions that are provably harmful or provably contradictory. The clearest case is signing two conflicting blocks or votes for the same height: a validator that signs both sides of a disagreement has produced cryptographic evidence of its own misbehaviour, and the evidence can be submitted by anyone, including a competing validator, who is usually rewarded for doing so.

The design has three deliberately uncomfortable features. The penalty is applied to the stake itself rather than only to the rewards, so the loss can be a meaningful fraction of the deposit and the validator is removed from the set. The evidence is self-contained, so a court of peers is not required; the proof of the offence is the pair of signed messages. And the penalty is severe enough relative to the reward that the expected value of an attack is negative, which is the entire point: the security budget is not the yield but the deterrent.

There is a second and gentler mechanism for a validator that is merely offline. Failing to attest does not trigger slashing, because being unavailable is not the same as being malicious, but the chain applies a slow inactivity penalty and eventually bleeds the stake of a validator that stays down during a period when the chain cannot finalise. The rule is calibrated so that an isolated outage costs a little and a coordinated attempt to stall the network costs a great deal.

Finality: from probabilistic to explicit

In proof of work, finality is a probability rather than an event. A transaction buried under six blocks is treated as settled because undoing it would require redoing the work of six blocks faster than everyone else, and the odds fall rapidly as more blocks pile up. Nothing announces that a transaction is final; the confidence is a number that approaches one.

Proof of stake can do arithmetic that proof of work cannot, because the validators are a known set with a known total stake. When two thirds of the stake attests to a checkpoint, the protocol records that checkpoint as finalised, and reverting it would require a large fraction of the stake to have voted for two conflicting histories, which is exactly the behaviour that slashing is designed to punish. Finality therefore becomes a discrete fact with a timestamp, generally reachable within a small number of epochs, rather than a statistic a user has to interpret.

The trade-off is what makes finality possible at all: because the validator set is known and the votes are attributable, the protocol can hold the voters accountable. Proof of work has no such list, which is why it can only offer accumulating confidence and never a signed commitment. Our explainer on what a blockchain actually chains covers the underlying data structure that both designs inherit.

The attack economics: thresholds, and what each one buys

The standard thresholds are quoted so often that they are worth stating with their meaning attached. A third of the stake is enough to interfere with finality, because finality requires two thirds and a blocking minority can prevent it from being reached. A half of the stake is enough to control which blocks are produced, which permits censorship and gives an attacker the tools to attempt a reorganisation. A two-thirds majority is enough to finalise a competing history outright, which is the most severe and most visible failure.

The economic argument for the design is that each of these positions requires acquiring and locking an enormous amount of the asset, that the acquisition is visible in advance, and that the attempt is punished by the loss of the very stake that makes the attack possible. The honest caveats are equally important: the deterrence depends on the stake being worth more inside the network than outside it, and on the attacker’s cost of acquiring a majority being high relative to what the attack gains. Those conditions hold well in most circumstances and are not axioms.

Liquid staking, and the centralisation that follows

Locking 32 ETH per validator, managing a machine and monitoring slashing is more work than many holders want, so a market grew around doing it for them. Liquid staking tokens represent a share of a staking pool, trade freely and can be used in other protocols, which restores the liquidity that staking removes. The holder gets a yield and a usable token; the operator gets a fee. Both sides are better off, and the network gets a concentration of stake under a small number of large operators.

That concentration is the centralisation risk the design did not eliminate. A protocol whose security budget is capital is only as decentralised as the distribution of that capital, and if a handful of operators control a large share of the stake, the theoretical threshold of a third or a half becomes a practical question about a few companies and the custody of their keys. The countervailing forces are real and partial: operator diversity, distributed validator technology that splits one stake across many machines, and the reputational cost of an operator that fails or misbehaves. None of them removes the risk, and the honest position is that proof of stake trades an energy problem for a governance and concentration problem rather than for no problem at all.

What proof of stake does not fix

Three objections are raised against the design, and each deserves a precise answer rather than a dismissal. The first is the nothing-at-stake criticism, the worry that forking is costless because a validator can sign on both branches without spending anything. The answer is that slashing prices this directly: signing both branches is the offence the penalty exists to punish, and the attacker loses stake rather than merely missing a reward.

The second is the long-range attack, in which an attacker with old keys fabricates a long alternative history from a point far in the past and presents it to a new node that has no recent information. Proof of stake answers this with weak subjectivity, a deliberate admission that a node joining the network needs a recent, trusted checkpoint rather than pure mathematics. A new node cannot distinguish a fabricated history from a real one on its own, and this is a genuine cost of the design rather than a misunderstanding.

The third is regulatory, and it has little to do with the mathematics. Staking looks to some authorities like a yield-bearing financial product, slashing looks like a risk passed to a customer, and a staking service looks like a custodial intermediary. How those questions are answered determines who can offer staking and under what rules, and it is the least settled part of the picture.

What Is Proof of Stake? You Bond Capital Instead of Burning Electricity.
The energy question is real and it is not the whole story. Replacing a continuous, external cost with a conditional, internal one changes who pays and when, and it does not by itself decide which set of risks is smaller. Photo: Trougnouf, CC BY 4.0, via Wikimedia Commons

The distinction worth keeping

Proof of stake secures a chain by making validators lock capital that the protocol can destroy, and it turns agreement into something measurable: a known set of voters, a metered clock, and explicit finality rather than accumulating probability. Proof of work secures a chain by making validators spend energy, and it turns agreement into something physical: accumulated work that must be redone to be undone. Both make cheating cost more than it pays; they differ in whose money is at risk and whether the protocol can reach in and take it.

The useful mental model is not “old versus new” but “two ways to make a promise expensive to break”. One spends continuously on a resource that leaves the system, which is transparent and open to anyone with hardware. The other locks capital inside the system that can be seized on proof of misbehaviour, which is efficient and concentrated. Read that way, the debate stops being about which mechanism is cleverer and becomes about which failures a network is willing to carry, and that is a question of governance as much as of engineering.

How Ethereum got here, and why the change was structural

Ethereum launched in 2015 on proof of work and moved to proof of stake in 2022, in a change that kept the same ledger and the same balances while replacing the mechanism that decided who produced blocks. That detail is worth pausing on, because it is the strongest practical argument that the two designs are alternatives rather than stages: the same network ran on one and then the other, and the transition was a coordinated upgrade rather than the launch of a new chain.

The move had three motivations, and only the first is usually mentioned. The energy argument is the visible one, since replacing continuous mining with staked capital removed most of the network’s electricity demand in a single upgrade. The economic argument is subtler and comes from the issuance side, because the rate at which new units are created fell sharply, changing the supply picture that miners and holders both respond to. The third is the security argument, and it is the one the designers emphasised: a capital-based penalty can be applied after the fact to an attacker’s own assets, which is a tool the electricity-based design does not have.

None of those motivations settled the debate, and the fact that they are still argued about years later is the most honest evidence that the choice is a trade rather than a solved problem. A network that values permissionless participation by anyone with hardware, or that distrusts a known validator set, will find reasons to prefer proof of work. A network that values explicit finality, low energy use and a penalty that reaches the attacker’s capital will prefer proof of stake. Both positions are consistent with the mechanics described above, which is precisely the point.

Frequently asked questions

What is the minimum to run a validator on Ethereum?

32 ETH per validator is the deposit, plus the cost of a reliable machine and monitoring. Pooled and liquid staking exist precisely because that threshold is high enough to exclude many holders from running a validator directly.

Is staking the same as lending?

No. Lending hands your asset to a borrower who owes it back. Staking commits your asset to securing a network, where it is locked, punished for specific misbehaviour and withdrawn through a queue. The yield resembles interest and the risk profile does not.

What actually triggers slashing?

Provably contradictory behaviour, above all signing two conflicting blocks or votes for the same height. Being offline does not trigger slashing; it triggers a slower inactivity penalty instead, because unavailability and malice are treated differently by design.

Why is finality said to be stronger under proof of stake?

Because the validator set and its total stake are known, the protocol can require two thirds of the stake to attest to a checkpoint and then record that checkpoint as final. Proof of work can only offer a probability that falls with each additional block, never a discrete signed commitment.

Does proof of stake remove the centralisation risk?

No, it relocates it. The security budget is capital, so the distribution of that capital becomes the question, and liquid staking concentrates stake under a small number of large operators. Distributed validator technology and operator diversity reduce the risk without removing it.

How do validators get paid?

Through a mix of newly issued units, a share of transaction fees and the effect of a base fee that is burned. The rate adjusts to how much stake is participating, so it is an emergent market outcome rather than a fixed rate offered by the protocol.

Sources and further reading

The Ethereum proof-of-stake specification defines validator deposits, slots, epochs, attestations, finality and slashing, and it is the primary source for the mechanics described here. The design’s treatment of weak subjectivity is documented in the same body of work and is the honest statement of the join-time trust requirement.

For related reading, see our explainer on what a blockchain actually chains, the mechanics of the older design in how Bitcoin mining works, and the change that moved Ethereum to explicit finality in the analysis of the Glamsterdam upgrade.

Blockchain

What Is a Blockchain? It Is a Chain of Hashes, Not a Chain of Blocks.

2026-10-1 12:48:43

Blockchain

Lloyds and Visa Settled $750,000 in USDC. Read the Pilot, Not the Headline.

2026-10-2 10:17:37

0 comment A文章作者 M管理员
    No Comments Yet. Be the first to share what you think
❯
Profile
Cart
Coupons
Check-in
Message Message
Search