CRYPTONEA 24
Cryptonea 24

Proof of Stake: what it is, where it came from, and how it actually works

From an almost forgotten 2011 forum thread to the 43.7 million ETH that secure Ethereum today: how proof of stake replaced electricity with collateral, how it punishes cheaters, what an attack would take and where it has stumbled.

Data as of 3 October 2026

Contents
  1. The problem it solves
  2. Where the idea came from
  3. One night in 2011 on bitcointalk
  4. How it works, from zero
  5. A real example: Ethereum's first proof of stake block
  6. The numbers that matter
  7. The mechanism in practice
  8. Who uses it and how versions differ
  9. Compared with the alternatives
  10. What it trades away
  11. What has gone wrong
  12. Common misconceptions
  13. The open questions
  14. The risks for the reader
  15. Sources

Proof of stake is a consensus mechanism: a set of rules that lets thousands of computers agree on one shared history of transactions. In it, the right to take part is secured with coins you lock up as collateral, which you can lose if you cheat [1].

The problem it solves is old and hard. How do computers that don't know each other agree when some of them may lie, and when there is no bank or administrator in the middle to keep the blockchain (the shared record of all transactions, grouped into linked blocks)? Bitcoin solved it with proof of work: the right to write the next block is earned by spending computing power and electricity. Proof of stake keeps the idea that taking part must cost something, but replaces electricity with capital that is put at risk.

Ethereum made the switch on 15 September 2022 [2]. On 3 October 2026 it had 43.7 million ETH locked up, 35.77% of supply, across 872,681 active validators (participants who lock up coins in order to check and produce blocks) [3].

This article covers where the idea came from, how it works step by step using a real block, which numbers hold it together, what it trades away, what has gone wrong and which criticisms remain open. It is for information only and is not investment advice.

The problem it solves

Picture a ledger that nobody in particular keeps, but that thousands of nodes (computers running the network's software) each hold a copy of. Every so often someone has to add the next page. If two nodes propose different pages, which one counts? And what if someone sends the same coin to two people at once, hoping half the world sees one payment and the other half sees the other? That is double spending, the reason digital money always needed a central bookkeeper.

Computer science had named the problem by 1982. Leslie Lamport, Robert Shostak and Marshall Pease described it as the Byzantine generals problem: generals besieging a city must agree on a joint move by sending messengers, while traitors hide among them. They proved that with plain messages, agreement is possible only if more than two-thirds of the generals are loyal. In smaller groups, a single traitor is enough to confuse two loyal generals [4]. The same limit appears in Practical Byzantine Fault Tolerance (PBFT) by M. Castro and B. Liskov (1999), which works correctly as long as fewer than one-third of participants misbehave [5]. "One-third" and "two-thirds" will come up throughout this article.

There was a second problem that classical theory did not have to face. In an open network anyone can create thousands of fake identities and vote thousands of times, so a vote has to cost something. Proof of work made it cost electricity. The creators of PPCoin, a coin that relied mainly on proof of stake, argued in 2012 that this dependence on energy is ultimately paid for by users, through inflation and transaction fees. They added that as the issuance of new bitcoin slows, pressure on fees to keep the network secure will grow [6].

Proof of stake's answer is that a vote can cost capital instead of electricity. That creates a new problem, which Vitalik Buterin described in 2014 as "nothing at stake". In proof of work, a miner has to split their computing power to back two versions of history. In proof of stake, the vote itself costs nothing, so in a naive system the profitable strategy is to vote for every version at once [7]. Much of the history of proof of stake is the effort to fix this.

Where the idea came from

The idea first appeared in public on a forum. On 11 July 2011 a bitcointalk user called QuantumMechanic proposed proof of stake as an alternative to proof of work [8]. ethereum.org notes that a BitcoinTalk user proposed the basic idea in 2011, as an upgrade to Bitcoin [9]. The discussion that followed deserves its own section, so we tell it below.

The idea took the form of a coin with Peercoin, originally PPCoin. Its technical paper is dated 19 August 2012 and signed by Scott Nadal and Sunny King [6], a pseudonym [10]. The authors state that they discovered the idea independently in October 2011 [6]. The design was a hybrid: proof of stake provided most of the security, while proof of work mainly served to issue the first coins [6].

At the heart of PPCoin was coin age: amount multiplied by holding period. Someone who holds 10 coins for 90 days has accumulated 900 "coin-days" [6]. The more coin age you spent, the easier it was to produce a block. The same paper also admitted a weakness. To protect its history, the network relied on a "centrally broadcasted checkpoint mechanism", sent out a few times a day to "freeze" the chain. The authors acknowledged this was a form of centralisation, which they considered acceptable until a distributed solution was found [6].

Research then moved to Ethereum. In January 2014 Buterin described "Slasher", the first algorithm that asked voters to post a deposit they would lose if they voted for two conflicting versions [7]. In November of that year he conceded that a deposit only works against recent forks. For attacks that start far in the past, he proposed weak subjectivity: a new node needs a recent reference point, namely the hash (digital fingerprint) of a recent block, which he described as "getting a block hash from a friend" [7].

In 2017 Vitalik Buterin and Virgil Griffith published "Casper the Friendly Finality Gadget". It describes two schools: chain-based proof of stake, which imitates mining (Peercoin, Blackcoin, Iddo Bentov's work), and proof of stake built on the theory of Byzantine faults, first introduced by Tendermint [11]. Casper's key innovation was accountability: if a validator breaks a rule, the violation is detected, the culprit is identified and loses their deposit. According to the authors, this solves "nothing at stake" [11]. The same year, Aggelos Kiayias, Alexander Russell, Bernardo David and Roman Oliynykov presented Ouroboros at the CRYPTO 2017 conference [5]. In 2020 a team including Buterin and Danny Ryan described Gasper, which combines Casper FFG with the LMD GHOST fork-choice rule [5]. On 15 September 2022 Ethereum's original network merged with the Beacon Chain, a separate proof of stake chain, in the event known as the Merge [2].

The foundations predate crypto: the generals problem is from 1982 and PBFT from 1999 [4][5]. Proof of stake added something classical theory did not need to answer: who gets a vote when anyone can join the network.

One night in 2011 on bitcointalk

On 11 July 2011, at 04:12 according to the forum's timestamp, QuantumMechanic opened a thread titled "Proof of stake instead of proof of work" in bitcointalk's technical discussion section. His proposal was simple: the "vote" on which transaction history counts should not be weighted by computing power, but "weighted by the number of bitcoins you can prove you own" [8].

The same first post contained an idea that would take years to become common. People who did not want to check transactions themselves could delegate their vote to trusted delegates, and new coins and fees would be shared among those delegates according to the votes they collected [8]. In effect, it was the first description of delegation and staking pools.

Replies came quickly. At 04:37 user eastendtech wrote that the system would only reward people who are already rich, a scenario where the rich get richer [8]. Meni Rosenfeld called the idea brilliant and wrote that its author deserved a place next to Satoshi. In November 2013 he went back and retracted the praise [8]. gmaxwell replied that the software's checkpoints already did the job, without handing power to people who simply hold a lot of bitcoin [8]. User hashcoin called it the obvious way to reach consensus, one that fails because of the bandwidth it needs, and QuantumMechanic admitted that something so obvious had seemed suspicious to him from the start [8].

The most concrete criticism came from Mike Hearn. He calculated that if checking one digital signature takes about 2 milliseconds, a 10-minute block leaves time to check at most about 300,000 keys, far fewer than you would need to trust the result. He added that if only a few delegates end up voting, the system would look like an open-source SWIFT, where a few big players agree among themselves [8].

That is what the documents show. What follows is our reading.

Within a few hours, strangers raised the three questions that are still open today. The first is concentration: if votes follow wealth, who ends up controlling the network? The second is delegation: if most people hand their vote to someone else, how many are actually deciding? The third is the cost of verification: how do you check hundreds of thousands of votes without the network collapsing? Ethereum answered the third with committees, as we will see. The first two return in the sections on risks and open questions under other names: liquid staking, exchanges, market share.

How it works, from zero

Take an everyday picture: a committee of auditors keeping a shared ledger. To join, each member posts a deposit. Every few seconds a draw is held and one member writes the next page. A group of other members, also drawn by lot, checks the page and signs that it is correct. Anyone caught signing two different pages for the same position loses part of their deposit and is expelled.

On Ethereum, the committee members are the validators. To become one, you deposit at least 32 ETH into a smart contract (a program that runs automatically on the blockchain) and run three programs: an execution client, a consensus client and a validator client [1]. Locking up coins this way is called staking. After depositing, the new validator joins an activation queue that limits how many newcomers can enter the network over a given period [1].

Time is divided into slots of 12 seconds and epochs of 32 slots [1], or 6.4 minutes (our calculation: 32 × 12 = 384 seconds). In each slot one validator is chosen at random as the proposer: it builds the new block and sends it to the network [1]. Each participant's influence is proportional to the coins it has staked [11].

In the same slot, a random committee of at least 128 validators [12] votes on whether the block is valid. That vote is called an attestation. Committees divide the full validator set so that every active validator votes once per epoch rather than in every slot, which keeps the network's load manageable [1]. This is the answer to the problem Mike Hearn raised in 2011. To make manipulation harder, who will propose blocks is fixed two epochs in advance [13].

That leaves the question of when a page becomes final. The first block of each epoch is a checkpoint. Validators vote on pairs of checkpoints. When a pair gathers votes representing at least two-thirds of all staked ETH, the newer checkpoint becomes "justified" and the older one becomes "finalized" [1]. That is Casper FFG's job. If at some point there are two competing versions, nodes follow the LMD GHOST rule: they pick the branch with the greatest weight of attestations [1].

The analogy breaks down in four places. First, the draw is not equal: whoever posts twice the deposit has twice the influence [11]. Second, the deposit is in the system's own currency, so its value rises and falls with the system. Third, there is no outside judge: penalties are applied automatically by code, based on signed evidence. Fourth, deposits can be pooled through intermediaries: staking pools let people without 32 ETH take part [1], which brings back the 2011 question of who is really voting.

In every epoch each active validator votes exactly once, in one of the 32 slots, while the epoch's first block serves as the checkpoint.
In every epoch each active validator votes exactly once, in one of the 32 slots, while the epoch's first block serves as the checkpoint.

A real example: Ethereum's first proof of stake block

The best example is the first one. The last block mined with proof of work on Ethereum was 15,537,393, mined by F2 Pool at 06:42:42 GMT on 15 September 2022 [14].

First, the protocol decided who would produce the next block. Block 15,537,394 belongs to slot 4,700,013 of epoch 146,875 [15]. Since every epoch has 32 slots, the epoch begins at slot 4,700,000, so this was its 14th slot (our calculation: 146,875 × 32 = 4,700,000). The designated proposer was validator number 347,963 [15]. The beaconcha.in explorer attributes it to the entity "Celsius" [17]. That is the explorer's label, not a statement by the company.

Next, the validator gathered transactions. The block contained 80 transactions [15] and used 29,983,006 units of gas (the unit that measures computational work on Ethereum), 99% of the limit [16]. The base fee, the minimum fee per unit of gas, was 48.81179 gwei, and 1.46352 ETH was burned in total [16]. Burned fees go to nobody; they are simply removed from circulation [1].

Then the validator was paid. The address it had registered for collecting fees received 45.03137 ETH [16]. Almost all of it came from a single transaction, a "mint" of new tokens (digital units issued on top of a blockchain), which paid 36.82643 ETH in fees at about 420,000 gwei per unit of gas [16]. In other words, 81.8% of the reward for the first proof of stake block came from one transaction (our calculation: 36.82643 / 45.03137).

Finally, the block was confirmed. The explorer shows 128 attestations included in the block [16], and its timestamp is 06:42:59 UTC [15]. Seventeen seconds passed between the last mined block and the first proof of stake block (our calculation). Both explorers now show it as finalized [15][16]. You can see it at etherscan.io/block/15537394 and beaconcha.in/block/15537394.

The numbers that matter

The slot time is 12 seconds and an epoch is 32 slots [1]. The first number sets how often a block is added. The second sets how often the chain can be finalized, since checkpoints occur once per epoch.

The minimum stake for a validator is 32 ETH [1]. Since the Pectra upgrade, activated at epoch 364,032 on 7 May 2025 at 10:05 UTC, the maximum effective balance has risen from 32 to 2,048 ETH under proposal EIP-7251 [18][19]. The change is optional for each validator and lets rewards compound, where previously anything above 32 ETH did not count [18].

Rewards are calculated from a basic unit, the base reward, which is inversely proportional to the square root of all staked ETH [20]. The more people take part, the smaller the reward per ETH. The reward is split into five parts with weights: 14 for the vote on the source checkpoint, 26 for the vote on the target checkpoint, 14 for the vote on the head of the chain, 2 for taking part in a sync committee and 8 for proposing a block, adding up to 64 [20]. Attestations therefore account for about 84.4% of the maximum reward (our calculation: 54 / 64).

Penalties for negligence are mild. A validator that misses its source or target vote loses as much as it would have earned. There is no penalty for a missed head vote, nor for failing to propose a block [20].

Slashing (cutting a validator's stake as punishment) is a different category. It applies to three acts: signing two different blocks for the same slot, voting in a way that "surrounds" an earlier vote, effectively changing history, and voting for two candidate blocks for the same position [20]. The immediate penalty is 1/4,096 of the effective balance [1]. Pectra raised the quotient from 32 to 4,096, so the initial penalty for a 32 ETH validator is 0.0078125 ETH [21]. For a validator with 2,048 ETH, the immediate penalty is 0.5 ETH (our calculation: 2,048 / 4,096). The introduction of the relevant ethereum.org page still says "up to 1 ETH", a figure that matches the rules before Pectra (our calculation: 32 / 32 = 1 ETH). The body of the same page and the specifications give the new value [20][21].

Point in time What happens to the slashed validator
Day 0 Immediate penalty of 1/4,096 of effective balance and start of forced exit
Days 0 to 36 Small daily penalties, because it stays on the network without voting
Day 18 Correlation penalty, which grows the more validators were slashed around the same time and can reach the full balance
Day 36 Removal from the network

Table sources: [1][20].

The logic of the correlation penalty is that an isolated mistake costs little, while a coordinated attack by many validators can cost the entire stake [20]. Finally, if the chain goes more than four epochs without finalizing, the inactivity leak kicks in, described below [20].

These numbers change only through a hard fork (an upgrade that changes the network's rules and requires new software). Every upgrade needs explicit opt-in from the people running nodes [23]. The most recent, Fusaka, was scheduled to activate at epoch 411,392 on 3 December 2025 at 21:49:11 UTC [22]. The next, Glamsterdam, builds the separation between block proposers and block builders into the protocol (EIP-7732). It is scheduled for the Sepolia testnet (a test network) on 6 October 2026, while the date for mainnet (the main network) has not been decided [23].

The mechanism in practice

Who produces blocks and how they are chosen

Each slot's proposer is chosen pseudo-randomly through a mechanism called RANDAO [1], and the choice is fixed two epochs ahead [13]. Two roles are worth separating. An ordinary node runs the execution and consensus software, receives blocks and checks them, but does not vote and is not paid. Only a validator, with staked ETH and the third client, votes and earns rewards [1].

A validator is paid from two sources. Consensus rewards are added to its balance once per epoch [20]. Users' tips (priority fees) go to whoever proposes the block, while the base fee is burned [1]. It is penalised with lost rewards when it is negligent and with slashing when it signs conflicting messages [20].

Where rewards come from: revenue and dilution

Clarity matters here, because "staking yield" is often presented as interest. Consensus rewards are new issuance of ETH, created by the protocol [20]. Tips are real revenue, paid by users to get their transactions into blocks [1].

How large is issuance? Using the protocol's square-root relationship and its factor of 64 [20], and the 43.7 million ETH staked on 3 October 2026 [3], the theoretical maximum with full participation is about 13.38 ETH per epoch. That comes to about 3,010 ETH a day and about 1.10 million ETH a year, or roughly 2.52% of the amount staked (our calculation: 64 × √(43.7 million × 10⁹) gwei per epoch, times 225 epochs a day). The total supply implied by the same figures is about 122.2 million ETH (our calculation: 43.7 / 0.3577), so gross annual issuance is about 0.90% of supply. The seven-day yield recorded by validatorqueue.com on the same day is 2.63% [3]. The source does not explain the difference from 2.52%.

In plain terms: for someone who stakes, most of the yield is new coins that increase their share of the total. For someone who does not stake, the same issuance is dilution: their share of the total shrinks, before counting the fees that are burned. Only tips, and anything else users pay, are revenue in the economic sense.

When the amount staked doubles, total issuance rises by about 41%, while the yield per ETH falls by about 29% (our calculation from the square-root relationship).
When the amount staked doubles, total issuance rises by about 41%, while the yield per ETH falls by about 29% (our calculation from the square-root relationship).

Delegation, lock-ups and exit queues

On Ethereum, entry and exit are rate-limited. On 3 October 2026, 1,528,620 ETH was waiting to enter, with a wait of 26 days and 13 hours, and 786,833 ETH was waiting to exit, with a wait of about 14 days. After exit comes the "sweep" that moves funds to the withdrawal address, which was taking 7.6 days [3]. The limit was 256 ETH per epoch in each direction [3], or 57,600 ETH a day (our calculation: 256 × 225). The entry wait checks out arithmetically (our calculation: 1,528,620 / 57,600 ≈ 26.5 days).

Other networks make different choices. On Cardano, someone who delegates their ADA to a stake pool (a staking group run by an operator) keeps it in their wallet, with no lock-up, no minimum amount and no slashing. The first rewards arrive after about 15 to 20 days and then every epoch of about 5 days [24]. On the Cosmos Hub, the network's genesis parameters set an unbonding period of three weeks, slashing of 5% for double-signing and 0.01% for extended downtime, plus a ten-minute jail [25]. On Solana, stake goes through a "warmup" on entry and a "cooldown" on exit [26], and up to 25% of the staked amount can activate or deactivate per epoch [27].

What an attacker would need

The 1982 limits return here. Anyone controlling one-third of staked ETH can block finalization, since finalization needs two-thirds [1]. For that case there is the inactivity leak: when the chain fails to finalize for more than four epochs, the stake of validators not voting with the majority gradually "bleeds" away until the majority regains two-thirds [1].

To reverse a block that is already finalized, according to ethereum.org, an attacker must accept losing at least one-third of all staked ETH [1]. With 51% of the stake, an attacker could make its own version dominant for blocks that are not yet final. ethereum.org argues that honest validators could then coordinate, keep building on their own chain and remove the attacker's stake [1]. The same text says that "long-range" attacks, which start from very old blocks, are neutralised by the finality mechanism [1].

Using the figures for 3 October 2026, one-third of staked ETH is about 14.57 million ETH and two-thirds is about 29.13 million ETH (our calculation from 43.7 million [3]). We do not give a cost in dollars. We found no independent, dated estimate, and a simple conversion at the current price would mislead, because buying such quantities would itself move the price.

Finality: when a payment can no longer change

Finality is the point after which a transaction cannot be reversed without burning a large amount of ETH [1]. Proof of work has no such point, only a probability that shrinks with every new block. On Ethereum, finalization requires two consecutive checkpoints, so at best about 12.8 minutes (our calculation: 2 × 6.4). The Etherscan blog reported in 2023 that the average was 2.5 epochs [28], or about 16 minutes (our calculation).

For someone waiting on a large payment, this means the transaction appears in a block within seconds, but becomes irreversible in the protocol's sense after roughly a quarter of an hour. Other networks strike a different balance. On Solana, finality is currently about 12.8 seconds, and its new Alpenglow mechanism targets about 150 milliseconds [29][30]. Alpenglow has been approved by the community [29] and is running on the test networks, but it has not been activated on mainnet. The Solana Foundation's page, updated in September 2026, gave the third quarter of 2026 as the expected window, with no fixed activation time [30].

Time to finality depends on where the block falls within the epoch: the earlier a transaction lands in the epoch, the longer it waits for the next checkpoint.
Time to finality depends on where the block falls within the epoch: the earlier a transaction lands in the epoch, the longer it waits for the next checkpoint.

Who uses it and how versions differ

Proof of stake is not one algorithm but a family of designs. Cardano uses Ouroboros Praos, with one-second slots and epochs of 432,000 slots, or 5 days [31]. Because one block producer is nominated on average every 20 seconds, an epoch has about 21,600 such nominations [32]. Ouroboros belongs to the "synchronous" school and follows the longest-chain rule [5]. Solana combines Tower BFT with Proof of History [29][30] and computes its block-producer schedule per epoch of 432,000 slots, about two days [33]. Slashing is not enforced on Solana today [34]. Solana's slot time is being cut in stages from 400 to 200 milliseconds, according to the Solana Foundation, so we do not give it as a fixed value [30]. Tendermint, which the Cosmos Hub is built on, favours safety over availability: if less than two-thirds of the stake is online, it stops [5].

Network Mechanism Slot and epoch Slashing Exit or unbonding Finality
Ethereum Gasper (Casper FFG and LMD GHOST) 12 seconds, 32-slot epoch Yes, with correlation penalty Exit queue and sweep, see above About 12.8 to 16 minutes
Cardano Ouroboros Praos 1 second, 5-day epoch No No lock-up Probabilistic, longest-chain rule
Solana Tower BFT and Proof of History 432,000-slot epoch, about 2 days Not enforced Warmup and cooldown, up to 25% per epoch About 12.8 seconds, 150 ms target with Alpenglow (pending)
Cosmos Hub Tendermint family Not covered 5% for double-signing, 0.01% for downtime (genesis values) 3 weeks (genesis value) Halts if one-third is missing
Peercoin Hybrid, coin age Not covered No, in the 2012 design Not covered Central checkpoints in the 2012 design

Table sources: [1][3][5][6][24][25][27][29][30][31][33][34].

Compared with the alternatives

The authors of Casper split proof of stake into two schools: one that imitates mining with a chain of blocks and random assignment, and one built on the theory of Byzantine faults [11]. Ethereum combines the two: a chain that keeps moving and, on top of it, a finality mechanism [5]. Delegating your vote to representatives, an idea already present in the 2011 post [8], is used in various forms on many networks.

Approach What grants the right to take part How cheating is punished Finality What it trades away
Proof of work (e.g. Bitcoin) Computing power and electricity Wasted energy cost, no seizure of equipment Probabilistic High energy use
Chain-based proof of stake (e.g. Peercoin, Ouroboros) Staked coins Depends on the design Probabilistic More complex defence against attacks from the past
BFT-style proof of stake (e.g. Tendermint) Staked coins Slashing Immediate, if two-thirds vote Halts if one-third is missing
Hybrid (Ethereum, Gasper) Staked coins Slashing with correlation penalty After about two epochs Complexity

Table sources: [1][5][6][7][11].

The difference in the punishment column matters. Buterin noted in 2014 that a proof of work protocol cannot destroy the equipment of a miner who misbehaves, whereas proof of stake can take away the deposit itself, not just the reward [7]. Critics reply that proof of work's energy use is exactly what ties it to the physical world, as we will see in the open questions.

What it trades away

Energy. Here the difference is large. The Ethereum Foundation estimates that the Merge cut Ethereum's energy use by about 99.95% [2]. The Crypto Carbon Ratings Institute (CCRI), in a report commissioned by ConsenSys, estimated a reduction in electricity use of more than 99.988% and in carbon footprint of 99.992%, from nearly 23 million MWh a year to just over 2,600 MWh [35]. These are two estimates: one from the Ethereum Foundation itself and one from a report commissioned by a company in the Ethereum ecosystem.

Simplicity. ethereum.org itself admits that proof of stake is younger and less battle-tested than proof of work, more complex to implement, and requires three programs to take part [1]. Complexity has a cost, as the incidents in the next section show.

Objectivity. A new node in proof of work finds the right chain on its own, by following the greatest accumulated work. In proof of stake it needs a recent, trusted reference point, something Buterin explicitly accepted as "weak subjectivity" [7].

Liquidity. Staked capital does not move freely. On 3 October 2026, anyone wanting to leave staking on Ethereum waited about two weeks in the queue plus another 7.6 days for the sweep [3].

Decentralisation. Influence follows capital, and capital tends to gather around intermediaries. Coinbase, for example, reported that its validators accounted for an average of 12.17% of staked ETH in the first quarter of 2026 and said it is committed to staying below 30% [36].

What has gone wrong

2 February 2021: 75 Staked validators

On 2 February 2021, 75 validators run by the company Staked were slashed [37]. According to the company's own analysis, to improve performance it disabled the persistence of the Prysm client's database that protects against double signing across restarts. On the live network the validators restarted more often than in testing and signed a second version of the same blocks [37]. Staked said it would reimburse its customers for the slashed ETH and for lost rewards [37].

14 September 2021: Solana outage

On 14 September 2021 bots flooded Solana with transactions during a public token sale, and the network went offline. The duration is given as 17 hours by Protos [38] and almost 18 hours by The Block [39].

1 May 2022: another Solana outage

On 1 May 2022 at 03:00 UTC, validator operators completed a restart of the network, after an outage of roughly seven hours that began when the network failed to reach consensus [40].

11 and 12 May 2023: Ethereum briefly loses finality

On 11 May 2023, around 20:19 UTC, Ethereum suffered a significant lack of block production and finalization was delayed by four epochs. The next day the same happened for nine epochs, and an inactivity penalty was triggered [41]. According to the Prysm team's analysis, the cause was old attestations that triggered problems in the Prysm and Teku clients [41]. No mass slashings were reported, and Prysm v4.0.4 was released with fixes [41]. The network kept producing blocks, which shows why the design of rewards and penalties encourages spreading validators across many different clients [20].

6 February 2024: Solana halts for about five hours

On 6 February 2024 at 09:53 UTC, block finalization stopped on Solana. The cause was a bug in handling programs deployed with legacy loaders, which sent validators into an infinite loop. Because more than 95% of the stake was running the same version, almost all of them stalled on the same block [42]. Block production resumed at 14:57 UTC, after an upgrade to v1.17.20 and a restart of the network [40][42].

Early 2025: the inactivity leak on Holesky

Activating Pectra on the test networks exposed problems in the clients. The Holesky testnet suffered extensive inactivity leaks during its recovery, and the validators that exited would take about a year to be fully removed. For that reason a new testnet, Hoodi, was launched [43].

10 September 2025: slashing of validators using SSV

On 10 September 2025 two slashing incidents were detected among validators using SSV Network, a distributed validator technology that spreads a validator's duties across several operators. In the second incident, 39 validators belonging to the same cluster of operators were slashed [44]. According to SSV, Ankr confirmed the cause was an internal maintenance mistake that ran a second, parallel validator instance outside SSV. SSV states that the problem did not come from the protocol itself [44].

4 December 2025: the Prysm bug after Fusaka

A few hours after Fusaka activated, an activation scheduled for 21:49 UTC on 3 December 2025 [22], Prysm nodes ran out of resources while processing certain attestations [45]. Across epochs 411,439 to 411,480, 248 of 1,344 slots were missed (about 18.5%), participation fell to 75% and validators lost about 382 ETH in rewards [46]. The problem began about five hours after activation, around 02:50 UTC on 4 December (our calculation: 47 epochs × 6.4 minutes). The Prysm team first issued a temporary setting and then permanent fixes in versions v7.0.1 and v7.1.0 [45]. Participation did not fall below two-thirds, so the network did not lose finality [45].

How many have been slashed in total

Slashings remain rare, but sources disagree on the exact number. Reports from September 2025 put it at fewer than 500 validators since 2020 [47], while another report the same week cited MigaLabs data showing 525 [48].

Common misconceptions

"If my node goes down, I'll lose my coins." No. A validator that is offline loses roughly what it would have earned from its votes, and there is no penalty at all for failing to propose a block [20]. Slashing is for signing conflicting messages. The exception is the inactivity leak, which only starts when the whole network goes more than four epochs without finalizing [20].

"Every proof of stake network has slashing." No. On Cardano, delegation cannot lead to slashing [24], and on Solana slashing is not enforced today [34].

"Staking yield is interest." As we saw, most of it is new issuance [20]. It increases the share of those who stake and shrinks the share of those who don't.

"The Merge cut fees." ethereum.org lists this explicitly as a misconception: fees depend on demand relative to the network's capacity, and the Merge did not change the parameters that set capacity [2].

"With 51% you can rewrite all of history." For blocks that are already final, reversal requires burning at least one-third of staked ETH [1]. A majority can influence blocks that are not yet final, not rewrite final history for free.

The open questions

Concentration through liquid staking. Liquid staking is a service where a provider stakes coins on your behalf and gives you a token that represents them, which you can resell. In May 2022 Ethereum Foundation researcher Danny Ryan argued that such protocols "cannot safely exceed consensus thresholds" and advised allocators not to put capital into protocols holding more than 25% of staked ETH [49]. The share of the largest such protocol, Lido, is not measured the same way by everyone. According to Lido's own update to its tokenholders in February 2026, as reported by Spotedcrypto, it was 23% [50]. Bitget News put it at 19.4% in mid-July 2026 [51]. Both measurements are below the limit Ryan proposed, but eastendtech's question from 2011 remains.

Can proof of stake deliver genuinely distributed consensus? Andrew Poelstra argued in 2015 that proof of stake as a cheap route to distributed consensus "is simply not workable" [52]. His central argument is that a system relying only on resources internal to itself cannot decide on its own which history is valid. Ethereum's side does not deny that outside information is needed. Buterin acknowledged in 2014 that new nodes need a recent reference point from someone they trust, and argued that people are quite good at agreeing on something that simple [7]. The disagreement is not whether this dependence exists, but whether it is acceptable.

Complexity as a risk. ethereum.org acknowledges that proof of stake is more complex and less battle-tested [1]. The 2023 and 2025 incidents did not come from a flaw in the theory but from bugs in specific clients [41][45]. The more one client dominates, the bigger the potential problem when it makes a mistake.

Our view at CRYPTONEA 24 is that proof of stake has shown it can work at large scale and with minimal energy, but not that it stays decentralised on its own. That depends on choices holders make every day: where they stake, through whom and with what software.

The risks for the reader

The first risk is someone else's mistake. When you delegate your stake to a provider, the provider handles the keys and the nodes, and an operational error can lead to slashing, as the Staked and Ankr cases showed [37][44]. Whether you are compensated depends on the provider, not the protocol.

The second is time. On Ethereum, leaving staking is not instant: on 3 October 2026 the exit queue was about two weeks and the sweep added 7.6 days [3]. On other networks, such as the Cosmos Hub, unbonding was designed to take three weeks [25]. During that time the coin's value can change considerably.

The third is intermediaries. With liquid staking you add the risk of the smart contract and of the token you receive; with staking through an exchange you add the risk of the exchange itself. And the more capital gathers with a few providers, the larger the risk Danny Ryan described [49].

The fourth is dilution. If you hold a proof of stake coin without staking it, new issuance shrinks your share of the total [20]. Staking yield is not guaranteed and falls as the total amount staked rises [20].

The fifth is software. Even without a malicious attacker, client bugs have caused lost rewards and outages [41][42][45]. Finally, the rules that apply to crypto and staking can change.

Sources

  1. P: ethereum.org, Proof-of-stake (PoS), ethereum.org/developers/docs/consensus-mechanisms/pos, August 2026 (project source)
  2. P: ethereum.org, The Merge, ethereum.org/roadmap/merge, accessed October 2026 (project source)
  3. S: Validator Queue (beaconcha.in data), Ethereum Validator Queue, validatorqueue.com, October 2026
  4. P: Lamport, Shostak, Pease, The Byzantine Generals Problem, ACM TOPLAS 4(3), lamport.azurewebsites.net/pubs/byz.pdf, July 1982
  5. P: Buterin, Hernandez, Kamphefner, Pham, Qiao, Ryan, Sin, Wang, Zhang, Combining GHOST and Casper, arxiv.org/abs/2003.03052, March 2020 (project source)
  6. P: King, Nadal, PPCoin: Peer-to-Peer Crypto-Currency with Proof-of-Stake, decred.org/research/king2012.pdf, August 2012 (project source)
  7. P: Vitalik Buterin, Ethereum Foundation Blog, Proof of Stake: How I Learned to Love Weak Subjectivity, blog.ethereum.org/2014/11/25/proof-stake-learned-love-weak-subjectivity, November 2014 (project source)
  8. P: bitcointalk, Proof of stake instead of proof of work, bitcointalk.org/index.php?topic=27787.0, July 2011
  9. P: ethereum.org, Proof-of-stake FAQs, ethereum.org/developers/docs/consensus-mechanisms/pos/faqs, accessed October 2026 (project source)
  10. S: Wikipedia, Peercoin, en.wikipedia.org/wiki/Peercoin, accessed October 2026
  11. P: Buterin, Griffith, Casper the Friendly Finality Gadget, arxiv.org/abs/1710.09437, October 2017 (project source)
  12. P: ethereum.org, Ethereum Glossary, ethereum.org/glossary, accessed October 2026 (project source)
  13. P: ethereum.org, Block proposal, ethereum.org/developers/docs/consensus-mechanisms/pos/block-proposal, accessed October 2026 (project source)
  14. S: An Event Study of the Ethereum Transition to Proof-of-Stake, arxiv.org/abs/2210.13655, October 2022
  15. P: Etherscan, Block 15537394, etherscan.io/block/15537394, September 2022
  16. P: beaconcha.in, Block 15537394, beaconcha.in/block/15537394, September 2022
  17. P: beaconcha.in, Slot 4700013, beaconcha.in/slot/4700013, September 2022
  18. P: Ethereum Foundation Blog, Pectra Mainnet Announcement, blog.ethereum.org/2025/04/23/pectra-mainnet, April 2025 (project source)
  19. P: ethereum.org, Pectra, ethereum.org/roadmap/pectra, May 2025 (project source)
  20. P: ethereum.org, Proof-of-stake rewards and penalties, ethereum.org/developers/docs/consensus-mechanisms/pos/rewards-and-penalties, April 2026 (project source)
  21. P: Lido, LIP-27: Ensuring Compatibility with Ethereum's Pectra Upgrade, github.com/lidofinance/lido-improvement-proposals/blob/develop/LIPS/lip-27.md, accessed October 2026 (project source)
  22. P: Ethereum Foundation Blog, Fusaka Mainnet Announcement, blog.ethereum.org/2025/11/06/fusaka-mainnet-announcement, November 2025 (project source)
  23. P: Ethereum Foundation Blog, Glamsterdam Testnet Announcement, blog.ethereum.org/2026/09/17/glamsterdam-testnet-announcement, September 2026 (project source)
  24. P: Cardano Developer Portal, Staking, developers.cardano.org/docs/developers/curriculum/staking-governance/staking, accessed October 2026 (project source)
  25. P: Cosmos, Genesis Parameters, github.com/cosmos/mainnet/blob/master/params/README.md, accessed October 2026 (project source)
  26. P: Anza, Stake Delegation and Rewards, docs.anza.xyz/consensus/stake-delegation-and-rewards, accessed October 2026 (project source)
  27. S: Chorus One, Solana Staking Economics Primer, medium.com/chorus-one/solana-staking-economics-primer-91143e5c9c79, February 2021
  28. S: Etherscan Blog, Battle-Testing Ethereum's Finality, medium.com/etherscan-blog/battle-testing-ethereums-finality-8909ac1b8ab1, June 2023
  29. S: ForkLog, Alpenglow Begins Activation Phase in Solana Testnet, forklog.com/en/alpenglow-begins-activation-phase-in-solana-testnet, September 2026
  30. P: Solana Foundation, Alpenglow, solana.com/upgrades/alpenglow, September 2026 (updated) (project source)
  31. P: Cardano Docs, Cardano nodes, docs.cardano.org/about-cardano/learn/cardano-node, accessed October 2026 (project source)
  32. P: Cardano Developer Portal, Consensus & Staking, developers.cardano.org/docs/operate-a-stake-pool/basics/consensus-staking, accessed October 2026 (project source)
  33. S: GridPlus Docs, Proof of History, docs.gridplus.io/blockchain-basics/solana/proof-of-history, accessed October 2026
  34. S: Helius, Solana Staking Simplified, helius.dev/blog/solana-staking-simplified-guide-to-sol-staking, December 2024
  35. P: CCRI (commissioned by ConsenSys), The Merge: Implications on the Electricity Consumption and Carbon Footprint of the Ethereum Network, 4795067.fs1.hubspotusercontent-na1.net/hubfs/4795067/CCRI-ETH-Report-2022.pdf, September 2022
  36. S: HOKANEWS, Ethereum Staking Hits Record 34% of Supply, hokanews.com/2026/08/ethereum-staking-hits-record-34-of.html, August 2026
  37. P: Staked, February 2 ETH2 slashing event: Post-mortem, blog.staked.us/blog/eth2-post-mortem, February 2021
  38. S: Protos, CHART: Solana survived six years of near-death experiences, protos.com/chart-solana-survived-six-years-of-near-death-experiences, March 2026
  39. S: The Block, Solana confirms outage on mainnet, engineers are investigating, theblock.co/post/276174/solana-major-outage-mainnet-beta, February 2024
  40. P: Solana Status, Incident History, status.solana.com, accessed October 2026 (project source)
  41. P: Offchain Labs (Prysm), Post-Mortem Report: Ethereum Mainnet Finality (05/11/2023), medium.com/offchainlabs/post-mortem-report-ethereum-mainnet-finality-05-11-2023-95e271dfd8b2, May 2023 (project source)
  42. P: Solana (Anza), 02-06-24 Solana Mainnet Beta Outage Report, solana.com/news/02-06-24-solana-mainnet-beta-outage-report, February 2024 (project source)
  43. P: Ethereum Foundation Blog, Protocol Announcements, blog.ethereum.org/category/protocol, 2025 (project source)
  44. P: SSV Network, Post-Mortem: September 10th, 2025 Slashing Incident, ssv.network/blog/slashing-post-mortem-september-2025, September 2025 (project source)
  45. S: crypto.news, What broke Ethereum's Fusaka upgrade? Prysm post-mortem reveals the cause, crypto.news/what-broke-ethereums-fusaka-upgrade, December 2025
  46. S: COINOTAG (via Bitcoin Ethereum News), Ethereum Prysm Fusaka Mainnet Postmortem, bitcoinethereumnews.com/ethereum/ethereum-prysm-fusaka-mainnet-postmortem-42-epoch-window-shows-18-5-missed-attestations-and-382-eth-lost-in-validator-rewards, December 2025
  47. S: UNLOCK Blockchain, Ethereum Hit by Rare Mass Slashing, 39 Validators Penalized, unlock-bc.com/148610/ethereum-hit-by-rare-mass-slashing-39-validators-penalized, September 2025
  48. S: The Coin Republic, Ethereum Completes Biggest Validator Slashing in Proof-of-Stake Era, thecoinrepublic.com/2025/09/12/ethereum-completes-biggest-validator-slashing-in-proof-of-stake-era-details, September 2025
  49. P: Danny Ryan, The Risks of LSD, notes.ethereum.org/@djrtwo/risks-of-lsd, May 2022 (project source)
  50. S: Spotedcrypto, Lido Liquid Staking TVL: Why It's Now Ethereum's Largest Validator, spotedcrypto.com/lido-largest-ethereum-validator, September 2026
  51. S: Bitget News, Ethereum's staking ratio hits all-time high of 34%, bitget.com/news/detail/12560605524245, July 2026
  52. P: Andrew Poelstra, On Stake and Consensus, download.wpsoftware.net/bitcoin/pos.pdf, March 2015

This article is educational and for general information. The facts in crypto move quickly, so verify them before you act on anything here. This is not financial advice.

This article is educational and for general information. The facts in crypto move quickly, so verify them before you act on anything here. This is not financial advice.