Tech●●●●●Difficulty 4 of 5

Can you secure a cryptocurrency without burning electricity?

Swapping computing power for owned coins cut one blockchain's energy use by more than 99% in a single upgrade, but it opened the door to an attack with a name that sums up the whole trade-off: "nothing at stake."

▶ Start the story

Proof-of-work secures a blockchain by making attackers out-compute everyone else, but that requires spending enormous amounts of electricity. Yes, mostly: proof-of-stake protocols are consensus mechanisms that select validators in proportion to how much of the cryptocurrency they already hold, specifically to avoid the computational cost of proof-of-work. Instead of miners racing to solve puzzles, validators put up a stake of coins, and the network picks among them to approve the next block.

Two ways to secure a blockchain

Proof-of-work

  • Miners race to solve computational puzzles
  • Attacker needs a large fraction of computing power
  • Consumes huge amounts of energy

Proof-of-stake

  • Validators are chosen by coins held
  • Attacker needs a large fraction of all tokens
  • Far more energy-efficient

The first working version was Peercoin in 2012, though its design still resembled proof-of-work under the hood. The logic behind proof-of-stake's security is straightforward: validators must hold a meaningful quantity of tokens, so an attacker would need to acquire a large fraction of those tokens to attack the network. The cost of an attack moves from electricity to coins.

That different kind of cost comes with its own weaknesses, though. Because validating doesn't require spending much computing power or money, proof-of-stake systems are vulnerable to a problem nicknamed "nothing at stake": validators actually benefit from approving every competing version of the chain they're shown, since each successful validation pays out, creating an incentive to support multiple conflicting histories at once rather than committing to just one. Systems manage this by penalizing validators caught approving conflicting chains, or by designing rewards so there's no benefit to causing conflicts in the first place.

The switch isn't just theoretical. On 15 September 2022, Ethereum, whose currency ether is second only to bitcoin in market capitalization, switched its entire consensus mechanism from proof-of-work to proof-of-stake in an upgrade known as "The Merge," cutting the network's energy usage by more than 99% in a single event — turning an electricity-hungry mining operation into a system secured mostly by coins sitting in validators' accounts.

Quiz me

0/3

  1. 1.What does proof-of-stake use instead of computational power to select who validates the next block?
  2. 2.What is the "nothing-at-stake" problem in proof-of-stake systems?
  3. 3.What happened to Ethereum's energy consumption during "The Merge" in September 2022?

Recap

Proof-of-stake trades electricity costs for staked-coin costs, which creates its own new attack, nothing-at-stake, that needs separate fixes.

Surprising fact · Ethereum's 2022 switch to proof-of-stake cut its energy consumption by more than 99% in a single upgrade.

Sources (2)

No source, no claim. Every fact in this lesson (12 claims) cites at least one of these.

  1. [1]Proof of stake · Wikipedia
  2. [2]Ethereum · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗