Proof of work and proof of stake, and what choosing costs you

the next blockenergycapital
the same stake, paid in two different currencies — energy burned or capital locked up.

Proof of work and proof of stake buy the same thing — the right to write the next block and collect the reward for it — with two different resources. The first burns energy, the second locks up capital that can be destroyed.

in short
A network with no owner has to decide who writes the next block. Proof of work decides it by burning energy, proof of stake by locking up capital. The first buys security with a cost you can see, the second with capital that can be destroyed. Neither is as decentralized as it says it is.

Why does a network have to sacrifice something?

Because the three things it wants pull in different directions. Security means attacks cost more than they pay, and that what is written stays written. Decentralization means nobody can decide alone, and that switching one participant off doesn’t switch the network off. Scalability means many transactions, cheaply.
two out of three, and the third is what you pay
the networkwhat it keepswhat it pays
bitcoinsecurity, decentralizationseven transactions a second
ethereuma balance across the threea little on each
the fast networksscalability, securitywho can afford to validate
what each choice keeps and what it lets go.

Bitcoin keeps security and decentralization and lets scalability go, at seven transactions a second. Ethereum, after the move to proof of stake, looks for a balance across the three and pays a little on each. The fast networks like Solana or BSC keep scalability and security and pay in decentralization, because validating takes powerful machines.

Two of them come together, and the third is what you pay. Bitcoin keeps security and decentralization and settles for seven transactions a second — for the role it chose, a monetary system meant to last, that is a coherent price. Ethereum, after the move to proof of stake, looks for a balance and pays a little on both sides. The fast networks, from Solana to BSC, buy speed with hardware requirements that cut down who can take part, which is to say with decentralization.

It isn’t a law of physics, it is a practical constraint nobody has disproved yet. And it is how you read the promises. When a network announces transaction numbers far above everyone else’s, the right question isn’t how it manages that. It’s what it stopped doing.

How does proof of work buy security?

By spending. To propose a block you have to solve a computing problem with no shortcuts. You try until it comes out, and trying burns electricity. Whoever solves it first writes the block and collects the reward.

The defense comes from there. Rewriting the history of the blockchain takes more than half of all the computing power on the network — not for a moment, but for as long as the attack lasts. On bitcoin that means buying or building hundreds of millions of dollars of plant and then paying its bills, knowing that if the attack works the coin you are attacking loses value, and with it the point of what you just spent.

rewriting the blockchain takes more than half the computing power, and for as long as the attack lasts.

An attack on proof of work requires controlling more than half of the network’s total computing power, and holding it for as long as the attack lasts. On top of the cost of the machines, the continuous cost of the energy.

This is the elegant part of the mechanism. It asks nobody for trust and forbids nothing. It makes the attack possible but uneconomic, and lets the arithmetic defend the network. The flaw sits in the same sentence. That defense costs real energy, every day, for ever.

Who actually mines, in the end?

A few mining pools, which everyone else delegates to. The competition rewards whoever has cheap electricity and purpose-built machines, and from there on it is economies of scale. Whoever is already big produces for less, so grows.
the minersthe poolscan movecoordinate
many miners, few pools they delegate their computing power to.

The computing power is produced by very many miners but flows into a few mining pools that coordinate it. Those are the few doors a regulator can knock on, even when the miners could move elsewhere.

The result is that most of bitcoin’s computing power runs through a handful of pools. That doesn’t mean they can attack whenever they like — miners can move elsewhere at a moment’s notice, and would — but it does mean there are few doors to knock on, for a government or a court.

China showed how much geography weighs in 2021. Mining was banned, and the network’s computing power fell by about half in a few weeks. The network kept running, the miners moved, and within a year the level was back. The test worked in both directions. It showed the resilience and the concentration at once.

What does it cost in energy, and does that matter?

Bitcoin uses as much as a mid-sized country. Whether that is waste depends on what you think bitcoin is, and that is a question the numbers alone don’t answer.
the same energy, two readings
if you take it forthe right comparisonthe verdict
a monetary systembanks, cash, gold, supervisioncomparable or lower
a betnothing, it is pure costwaste
the same amount of energy, two different verdicts depending on what you think it is.

If bitcoin is an alternative monetary system, the consumption compares against everything it would replace — banks, cash, gold, physical security — and comes out comparable or lower. If it is a speculative asset, the same energy is spent holding up a bet. Public perception stays negative either way, and that is a regulatory risk.

If you take it for an alternative monetary system, the right comparison isn’t with a bank transaction but with the whole apparatus it would replace: branches, cash, mining and storing gold, physical security. On that scale the consumption is comparable, maybe lower. If you take it for an asset people speculate on, then it is energy burned to hold up a bet, and the comparison doesn’t stand.

Two true things stay outside this argument. A substantial share of mining runs on renewable energy, or on energy that would be lost anyway — gas that would be flared off, hydroelectric surpluses far from the grid. And public perception stays negative regardless of the detail, which is a concrete risk. Parliaments write the rules, not the consumption charts.

How does proof of stake buy security?

By putting the validator’s own money in the middle. Taking part means locking up your tokens, and whoever misbehaves loses some of them. It is called slashing, and nobody has to decide it — the protocol does.

Attacking here doesn’t take computing power but the majority of the locked tokens: an enormous amount of capital, which on top of that has to be bought on the market, pushing the price up while you accumulate it. And there is one difference that counts more than any other. If the attack works, the community can change the rules and burn the attacker’s stake.

proof of workproof of stakethe day after the attack
what the attacker is left with the next day — the machines, or nothing.

After an attack on proof of work whoever attacked keeps the hardware and can try again. After an attack on proof of stake the community can burn the attacker’s locked capital, and they are left with nothing.

Under proof of work, the day after an attack, whoever attacked still has their warehouses full of machines and can try again. Under proof of stake they are left with nothing. That is why, on paper, attacking a network built on locked capital costs more. It isn’t the price of the ticket. It’s that the ticket isn’t refundable.

Where does power concentrate under proof of stake?

In whoever holds the stake on everyone else’s behalf. The basic mechanism already rewards whoever has more — more tokens, more rewards, more tokens to lock up — but the real jump came from liquid staking. You put your tokens with somebody who validates with them, and in exchange you get a receipt that stands for them and stays tradable.

It is extremely convenient, and the whole market duly went into it. Today about 25% of Ethereum’s stake runs through Lido. It isn’t an attack and it isn’t a conspiracy. It is that three or four operators of this kind, put together, end up coordinating the majority of what was supposed to be spread out.

lido · 25%the next twoeveryone else
how much of ethereum’s stake runs through a single operator. source: lido’s share of ethereum’s stake, august 2026, 2026-08-19.

About 25% of Ethereum’s stake is delegated through Lido. A single operator coordinates a quarter of what proof of stake was meant to spread across many.

The difference from proof of work is subtler than it looks. There, miners can switch pool in an afternoon. Here, whoever delegated holds a receipt that is worth something for as long as that operator works, and getting out costs time and a few points of price. Moving from one operator to another isn’t an afternoon’s work the way switching pool is.

What is MEV, and why does it weigh more here?

It is the money you make by deciding the order of the transactions inside a block. Whoever proposes the block chooses what goes in, in what order, and what stays out. Each of those three choices is worth money.

The methods are well known. You see a large order coming in on a dex, you put one of your own in front of it and one right behind, and you collect the price difference you created yourself. Or you see a trade that pays and copy it by getting in front. Or you are first to liquidate a position that has just crossed its threshold. Nothing has to be broken. Getting there first is enough, and whoever orders the block always gets there first.

order coming ineveryone sees itI buy firstI move the priceyoursworse priceI sell backI collect
the same transaction, with two strangers around it — one before, one after.

Whoever orders the block can put a trade of their own in front of somebody else’s and one right behind it, pocketing the price difference produced by the transaction in between. It is the commonest form of value extracted from ordering.

Under proof of work the problem exists but is more diluted, because who will find the next block isn’t known in advance. Under proof of stake the turn is known. Whoever validates two minutes from now can prepare. That is where the worst incentive comes from — not attacking the network, but leaving a transaction out because it pays to. That is censorship, even if nobody calls it that. The fixes under way separate whoever builds the block from whoever proposes it, and they work. In exchange they add another layer of intermediaries.

How do they differ, point by point?

On four things, and on none of the four is there a clean winner. The cost of security: under proof of work it is external and continuous — energy and machines — so visible and measurable; under proof of stake it is internal, capital tied up, more efficient but also more circular, because the cost of the attack depends on the price of the token you are attacking.
four comparisons, no clean winner
proof of workproof of stake
cost of securityexternal: energy, every dayinternal: capital sitting still
finalityprobabilisticeconomic, past a point
who can enterwhoever has machines and poweranyone, but what you put in counts
regulatory riskthe ban, over consumptionthe order to leave things out
the four comparisons that matter.

Cost of security: external and continuous under proof of work, internal and circular under proof of stake. Finality: probabilistic against economic. Barriers to entry: high and physical against low, but with power proportional to capital. Regulatory risk: a ban over consumption against an order to censor, for whoever validates.

Finality: under proof of work it is probabilistic — the more blocks go by, the less thinkable going back becomes, but in theory you always can; under proof of stake, past a certain point, going back means destroying capital, so it is sharper. Barriers to entry: high and physical on one side, dedicated machines and cheap electricity, low on the other, where the reward stays proportional to how much you put in, so power stays where it already was.

Regulatory risk, last, changes in kind. Proof of work is challenged on consumption, and the bans arrive for environmental reasons. Under proof of stake whoever validates has a name and an address, and can be ordered to leave certain transactions out. The first risks the ban, the second risks obedience.

What is there beyond the two?

Variations, nearly all of them bought at the expense of decentralization. Proof of authority hands the blocks to a list of validators approved in advance. It is fast and wastes nothing, but it is a club, and it gets used where a club is acceptable — corporate blockchains, service networks.
proof of authorityapproved validators — fast, but a club
delegated proof of stakeelected validators — few lists, always the same ones
proof of history with stakemore throughput, more powerful machines
new mechanismselegant, little history behind them
the variants, and what they give up in exchange.

Proof of authority: validators approved in advance, fast but a club. Delegated proof of stake: validators elected by token holders, tends to settle into a few hands. Proof of history with proof of stake: transactions lined up by a cryptographic clock, needs powerful machines. New mechanisms like Avalanche and Algorand: elegant, with little history behind them.

Delegated proof of stake has the token holders vote to elect a fixed number of validators. On paper it is democracy; in practice the same lists win every time and power settles into a few hands. Solana puts a cryptographic clock alongside proof of stake, lining the transactions up before any vote happens. It works, and it asks for machines so powerful that the set of people who can validate is a small one.

Then there are the ones that changed how agreement itself is reached — Avalanche, Algorand and others — with elegant mechanisms and little history behind them. And that is the point that holds for all of them. The security of a consensus isn’t proved on a blackboard. It builds up over the years in which nobody managed to break it.

What to look at if you have to pick one?

It depends what you need it for, and the answer changes completely. If you are after something that has to be worth anything in twenty years, proof of work has an argument the others don’t: the cost of an attack is physical, you can see it, and the proof that it holds has been run every day for years. If you are building applications on it, proof of stake costs less and runs faster, and Ethereum is the obvious choice — as long as you keep an eye on how much stake ends up in a few hands.

If you are sizing up a new network instead, go back to the trilemma and ask what it sacrificed. If the answer is “nothing”, you are reading it wrong. And in both worlds look at the concentrations — the pools on one side, the liquid staking operators on the other — because that is where power piles up while nobody is watching.

The last thing is the least technical and the most useful: count the years. Bitcoin has been running for 17 and a half years, Ethereum’s proof of stake for four, everything else for less. Time doesn’t prove a mechanism is perfect. It proves only that so far nobody has managed it, and it is the one proof that can’t be sped up.

17 yearsbitcoin4 yearsethereum on stake
the years in which nobody managed to break them. source: bitcoin’s block zero, january 2009; ethereum’s move to proof of stake, september 2022.

Bitcoin has run without interruption since block zero in 2009, which is 17 and a half years. Ethereum’s proof of stake has run since September 2022, four years. Every other mechanism has less history behind it, and history is the one proof of security that can’t be sped up.

last checkedAugust 19, 2026
the words in this piece · 14
blockchain
a register of entries that sits on many machines at once, where every block carries the fingerprint of the one before it, and rewriting the past costs more than it pays.
burn
the permanent destruction of tokens: they are sent to an address nobody can move them from ever again, and the quantity in circulation falls.
dex
a decentralized exchange: the trades happen between wallets, with nobody holding the funds.
liquid staking
you put the coin into staking and get back a receipt that stands for it and stays tradable.
mev
the value extracted by reordering the transactions inside a block: whoever decides the order can put themselves in front of everybody else.
mining pool
a group of miners who put their computing power together and split whatever they find.
pool
the common till the trades happen on: whoever puts their own coins into it takes a slice of the fees.
proof of stake
the way of keeping a network standing by making whoever validates it lock tokens up, instead of spending energy.
proof of work
the way of keeping a network standing by making whoever validates it spend energy.
slashing
the punishment for validating badly in proof of stake: part of the tokens put up as security is taken away.
staking
locking tokens up to keep a network or a protocol running, and receiving a yield in return. the tokens stay tied up for a set time.
throughput
how many transactions a network manages to push through in a second.
token
the unit a protocol issues. it can serve to vote, to pay, to receive revenue, or to do nothing at all.
token holder
whoever holds a protocol’s token. it isn’t the same set of people as whoever uses it, and that is where a lot of the conflict comes from.
guide · checked August 19, 2026all the guides