Proof of work and proof of stake, and what choosing costs you
Proof of work and proof of stake buy the same thing — the right to write the next block and collect the reward for it — with two different resources. The first burns energy, the second locks up capital that can be destroyed.
Why does a network have to sacrifice something?
Bitcoin keeps security and decentralization and lets scalability go, at seven transactions a second. Ethereum, after the move to proof of stake, looks for a balance across the three and pays a little on each. The fast networks like Solana or BSC keep scalability and security and pay in decentralization, because validating takes powerful machines.
Two of them come together, and the third is what you pay. Bitcoin keeps security and decentralization and settles for seven transactions a second — for the role it chose, a monetary system meant to last, that is a coherent price. Ethereum, after the move to proof of stake, looks for a balance and pays a little on both sides. The fast networks, from Solana to BSC, buy speed with hardware requirements that cut down who can take part, which is to say with decentralization.
It isn’t a law of physics, it is a practical constraint nobody has disproved yet. And it is how you read the promises. When a network announces transaction numbers far above everyone else’s, the right question isn’t how it manages that. It’s what it stopped doing.
How does proof of work buy security?
The defense comes from there. Rewriting the history of the blockchain takes more than half of all the computing power on the network — not for a moment, but for as long as the attack lasts. On bitcoin that means buying or building hundreds of millions of dollars of plant and then paying its bills, knowing that if the attack works the coin you are attacking loses value, and with it the point of what you just spent.
An attack on proof of work requires controlling more than half of the network’s total computing power, and holding it for as long as the attack lasts. On top of the cost of the machines, the continuous cost of the energy.
This is the elegant part of the mechanism. It asks nobody for trust and forbids nothing. It makes the attack possible but uneconomic, and lets the arithmetic defend the network. The flaw sits in the same sentence. That defense costs real energy, every day, for ever.
Who actually mines, in the end?
The computing power is produced by very many miners but flows into a few mining pools that coordinate it. Those are the few doors a regulator can knock on, even when the miners could move elsewhere.
The result is that most of bitcoin’s computing power runs through a handful of pools. That doesn’t mean they can attack whenever they like — miners can move elsewhere at a moment’s notice, and would — but it does mean there are few doors to knock on, for a government or a court.
China showed how much geography weighs in 2021. Mining was banned, and the network’s computing power fell by about half in a few weeks. The network kept running, the miners moved, and within a year the level was back. The test worked in both directions. It showed the resilience and the concentration at once.
What does it cost in energy, and does that matter?
If bitcoin is an alternative monetary system, the consumption compares against everything it would replace — banks, cash, gold, physical security — and comes out comparable or lower. If it is a speculative asset, the same energy is spent holding up a bet. Public perception stays negative either way, and that is a regulatory risk.
If you take it for an alternative monetary system, the right comparison isn’t with a bank transaction but with the whole apparatus it would replace: branches, cash, mining and storing gold, physical security. On that scale the consumption is comparable, maybe lower. If you take it for an asset people speculate on, then it is energy burned to hold up a bet, and the comparison doesn’t stand.
Two true things stay outside this argument. A substantial share of mining runs on renewable energy, or on energy that would be lost anyway — gas that would be flared off, hydroelectric surpluses far from the grid. And public perception stays negative regardless of the detail, which is a concrete risk. Parliaments write the rules, not the consumption charts.
How does proof of stake buy security?
Attacking here doesn’t take computing power but the majority of the locked tokens: an enormous amount of capital, which on top of that has to be bought on the market, pushing the price up while you accumulate it. And there is one difference that counts more than any other. If the attack works, the community can change the rules and burn the attacker’s stake.
After an attack on proof of work whoever attacked keeps the hardware and can try again. After an attack on proof of stake the community can burn the attacker’s locked capital, and they are left with nothing.
Under proof of work, the day after an attack, whoever attacked still has their warehouses full of machines and can try again. Under proof of stake they are left with nothing. That is why, on paper, attacking a network built on locked capital costs more. It isn’t the price of the ticket. It’s that the ticket isn’t refundable.
Where does power concentrate under proof of stake?
It is extremely convenient, and the whole market duly went into it. Today about 25% of Ethereum’s stake runs through Lido. It isn’t an attack and it isn’t a conspiracy. It is that three or four operators of this kind, put together, end up coordinating the majority of what was supposed to be spread out.
About 25% of Ethereum’s stake is delegated through Lido. A single operator coordinates a quarter of what proof of stake was meant to spread across many.
The difference from proof of work is subtler than it looks. There, miners can switch pool in an afternoon. Here, whoever delegated holds a receipt that is worth something for as long as that operator works, and getting out costs time and a few points of price. Moving from one operator to another isn’t an afternoon’s work the way switching pool is.
What is MEV, and why does it weigh more here?
The methods are well known. You see a large order coming in on a dex, you put one of your own in front of it and one right behind, and you collect the price difference you created yourself. Or you see a trade that pays and copy it by getting in front. Or you are first to liquidate a position that has just crossed its threshold. Nothing has to be broken. Getting there first is enough, and whoever orders the block always gets there first.
Whoever orders the block can put a trade of their own in front of somebody else’s and one right behind it, pocketing the price difference produced by the transaction in between. It is the commonest form of value extracted from ordering.
Under proof of work the problem exists but is more diluted, because who will find the next block isn’t known in advance. Under proof of stake the turn is known. Whoever validates two minutes from now can prepare. That is where the worst incentive comes from — not attacking the network, but leaving a transaction out because it pays to. That is censorship, even if nobody calls it that. The fixes under way separate whoever builds the block from whoever proposes it, and they work. In exchange they add another layer of intermediaries.
How do they differ, point by point?
Cost of security: external and continuous under proof of work, internal and circular under proof of stake. Finality: probabilistic against economic. Barriers to entry: high and physical against low, but with power proportional to capital. Regulatory risk: a ban over consumption against an order to censor, for whoever validates.
Finality: under proof of work it is probabilistic — the more blocks go by, the less thinkable going back becomes, but in theory you always can; under proof of stake, past a certain point, going back means destroying capital, so it is sharper. Barriers to entry: high and physical on one side, dedicated machines and cheap electricity, low on the other, where the reward stays proportional to how much you put in, so power stays where it already was.
Regulatory risk, last, changes in kind. Proof of work is challenged on consumption, and the bans arrive for environmental reasons. Under proof of stake whoever validates has a name and an address, and can be ordered to leave certain transactions out. The first risks the ban, the second risks obedience.
What is there beyond the two?
Proof of authority: validators approved in advance, fast but a club. Delegated proof of stake: validators elected by token holders, tends to settle into a few hands. Proof of history with proof of stake: transactions lined up by a cryptographic clock, needs powerful machines. New mechanisms like Avalanche and Algorand: elegant, with little history behind them.
Delegated proof of stake has the token holders vote to elect a fixed number of validators. On paper it is democracy; in practice the same lists win every time and power settles into a few hands. Solana puts a cryptographic clock alongside proof of stake, lining the transactions up before any vote happens. It works, and it asks for machines so powerful that the set of people who can validate is a small one.
Then there are the ones that changed how agreement itself is reached — Avalanche, Algorand and others — with elegant mechanisms and little history behind them. And that is the point that holds for all of them. The security of a consensus isn’t proved on a blackboard. It builds up over the years in which nobody managed to break it.
What to look at if you have to pick one?
If you are sizing up a new network instead, go back to the trilemma and ask what it sacrificed. If the answer is “nothing”, you are reading it wrong. And in both worlds look at the concentrations — the pools on one side, the liquid staking operators on the other — because that is where power piles up while nobody is watching.
The last thing is the least technical and the most useful: count the years. Bitcoin has been running for 17 and a half years, Ethereum’s proof of stake for four, everything else for less. Time doesn’t prove a mechanism is perfect. It proves only that so far nobody has managed it, and it is the one proof that can’t be sped up.
Bitcoin has run without interruption since block zero in 2009, which is 17 and a half years. Ethereum’s proof of stake has run since September 2022, four years. Every other mechanism has less history behind it, and history is the one proof of security that can’t be sped up.
the words in this piece · 14
- blockchain
- a register of entries that sits on many machines at once, where every block carries the fingerprint of the one before it, and rewriting the past costs more than it pays.
- burn
- the permanent destruction of tokens: they are sent to an address nobody can move them from ever again, and the quantity in circulation falls.
- dex
- a decentralized exchange: the trades happen between wallets, with nobody holding the funds.
- liquid staking
- you put the coin into staking and get back a receipt that stands for it and stays tradable.
- mev
- the value extracted by reordering the transactions inside a block: whoever decides the order can put themselves in front of everybody else.
- mining pool
- a group of miners who put their computing power together and split whatever they find.
- pool
- the common till the trades happen on: whoever puts their own coins into it takes a slice of the fees.
- proof of stake
- the way of keeping a network standing by making whoever validates it lock tokens up, instead of spending energy.
- proof of work
- the way of keeping a network standing by making whoever validates it spend energy.
- slashing
- the punishment for validating badly in proof of stake: part of the tokens put up as security is taken away.
- staking
- locking tokens up to keep a network or a protocol running, and receiving a yield in return. the tokens stay tied up for a set time.
- throughput
- how many transactions a network manages to push through in a second.
- token
- the unit a protocol issues. it can serve to vote, to pay, to receive revenue, or to do nothing at all.
- token holder
- whoever holds a protocol’s token. it isn’t the same set of people as whoever uses it, and that is where a lot of the conflict comes from.