Ethereum Goerli testnet merge goes live before move to proof-of-stake
cnbc.com
cnbc.com
1. Transactions will get slightly cheaper, but only because they're increasing the block rate from every 13 seconds to every 12 seconds, not anything specific to the other cool stuff in the merge
2. The network will switch from proof-of-work to proof-of-stake, meaning that there will no longer be GPU demand or substantial energy consumption attributable to the Ethereum network.
3. For a cryptocurrency to be secure there has to be some barrier to participating in consensus. Now, instead of having to have a fancy GPU to run an Ethereum validator, the barrier will be that you instead have to "stake" 32 Ethereum (and risk losing it if your validator misbehaves). A staking reward of (I think) 5% a year will be issued for your trouble.
4. The Ethereum network will be more resistant to "short-range" forks, that is, forks that diverged from the proper chain "recently". (More resistant in the sense that it will be more expensive to execute an attack like that.)
5. Once you've staked your 32 Ethereum, you currently can't "unstake" it. The ability to withdraw your stake will be added in a future eth fork. It will have to be gated by some delay (maybe you can only withdraw your stake 6 months after you staked it). Attacking the chain via a "long-range" fork, that is, a fork that diverges from the proper chain longer ago than the withdrawal period, will be much cheaper or possibly even free.
6. Ethereum will still favor liveness over consistency. An attacker can't stop the chain, but they can prevent it from finalizing for a time (at expense to themselves).
7. Token issuance will go down, probably to below the burn rate, so the base Ethereum supply will go down over time
8. The chain will get deterministic finality after some number of blocks (I think something like a day's worth). That means that, once a block is finalized, it will never be rewritten. Network outages or attacks can prevent blocks from finalizing.
There only has to be a barrier for receiving rewards. Bitcoin full nodes validate everything but receive no rewards, and need no barriers.
I run one of the eth validator serious for LIDO. We have 10 validator keys for testnet (prater/goerli now just Goerli) and around 1000 for mainnet ethereum on the beacon chain (which will be the consensus chain post mainnet merge).
Why would anything change when the economic incentives haven't? Mining isn't getting less lucrative or necessary.
Put another way, if you know the true chain at time T, you also know it at time T+1. But if you're just joining the network, or you went offline for a bit, that means you don't know which chain is the true one and need some outside-of-protocol way of determining which fork to trust.
You might argue that Bitcoin is defined as the chain with the most hashpower, period. That would remove all subjectivity from Bitcoin, but it would mean that a 51% attacker could arbitrarily change the rules and steal people's funds. That's not how it actually works; a 51% attacker still has to follow the rules of the protocol for their blocks to be accepted by the non-mining nodes, and that means there's social consensus on the correct software to run the protocol.
There's no consensus needed on which rules to use. Everyone can use whichever rules they want, by using different versions of the software. Different rules define a different currency, like euro or dollar. Using the best currency with the best rules is just a game theoretic focal point. Everyone chooses to use the best version of the software, because they assume that everyone else does so too, even in the absence of communication. There is no "correct, current" software in Bitcoin, because it would be a single point of failure.
There's no objective protection against long-range attacks in PoS, because there's no hashpower to prove the canonical chain. It requires the provider of the "correct, current" software to decide which chain is the right one.
No, hash power and the rules decide it. If you have invalid signatures in your blocks, it doesn't matter how much hashpower your fork has, it won't be accepted as canonical by other forks.
- wait a bit to make sure that you can talk to different people on the network and see what each of them see
- check checkpoints on twitter or websites like etherscan (are they seeing the same thing I’m seeing?)
In projects like Mina, since you do not download the history of the chain (there’s a single zero knowledge proof of a few kB that covers the whole history) you must rely on a marker for “chain quality “ to differentiate potential forks.
Note that there was also some research on how to get signal from the transactions you see that you’re on the correct fork (from some ex colleagues working on libra): https://eprint.iacr.org/2019/1440.pdf
A long-range attack is when a validator withdrawals their stake, waits the withdrawal period (e.g. the 6 month delay delay mentions above), and then creates a fake chain starting from before they withdrew their staked eth.
Because in the "real" history (e.g. the ones that most nodes have seen over the past 6 months) the validator doesn't have Eth locked up still, there's no way to punish them. Thus, these long range attacks get very cheap (you could even imagine someone who pays validators for old keys -- aka, you don't even need to be a validator yourself).
These two facts together mean that PoS blockchains require some "weak subjectivity" - which pretty much means when you download and start syncing your node, you need to know a "finalized" block hash from the past 6 months (or within the withdrawal delay). This ensures you won't get tricked by a cheap long-range attack.
In practice, I don't think this will be much of a problem - clients can just do a new release with a new block has every few months for new users!
Let's say I'm an attacker and I do this. But now none of the subsequent blocks on the original chain will validate anymore because of hashes mismatching. I could of course validate new blocks but 6months+ of blocks from only one or a small number of validators (depending on how much validator capital one can amass for the attack) is going to be pretty obvious.
Unless the attacker can get a significant percentage of validators part of the attack, I can' see it work out in practice.
PoS is, as usual, vulnerable to attacks like grinding, and you can only paper over this.
That being said, the adoption of layer 2 technologies has taken off, and significantly impacted the demand for layer 1 blockspace.
I'm still confused at what happens if you create a valid block with the Ethereum you stake and then that block doesn't end up being part of the main branch.
So at any given time only one validator is going to create a block. If you create it, it's going to be included in the blockchain. If you don't create it (or you create but due to network problems fail to communicate it), then the blockchain skips a beat and someone else will create the next one.
If you want a user friendly introduction I recommend you Ben Edgington's book (WIP): https://eth2book.info/altair/
Or straight from the source: https://github.com/ethereum/consensus-specs
In proof of stake, the more crypto tokens you have, the more lottery tickets you get to win the right to write the next block.
In PoW the lottery is solving puzzles, that’s the energy inefficiency, in PoS the lottery is decided like a real lottery: with a random number generator (a distributed one at that, so that people agree that it was generated honestly)
Each block is published with a hash which is based on all the previous blocks plus its own data. All participants are racing to solve a puzzle: basically a big guessing game where the first to guess the winning number gets to make the next block. The game is to find a number which when combined with the previous hash and put through an expensive hash function comes up with a result which has a specific number of binary zeros at the end. Since hashes are one way functions the only way to solve the problem is for everyone to guess until the solution is found.
The first participant to find the solution gets to create the new block. They also check the last few blocks to see if anyone's been cheating by adding fraudulent transactions. If fraud is detected they just ignore those nefarious blocks like they never happened.
The algorithm scales with the number of participants by automatically making the "difficulty" higher by changing the size of the pattern that needs to be matched.
Lots of exciting features to land very soon that include Timelock Encryption, among several others.
Technical explainer can be found here: https://research.protocol.ai/tutorials/resnetlab-on-tour/dra... and documentation here: https://drand.love/docs/
How do you get verified (true) randomness without an oracle and without a connection to the analog world (proof of work)?
It would be amusing if the answer was randomness that came from a proof of work algorithm.
def totally_random():
return 42
In seriousness, solana’s proof of history is a super novel take ontop of proof of stake to solve this problem.It's almost certainly better for the environment / our continued existence than proof-of-work, if we must suffer cryptocurrency, but I don't trust people who were willing to continue to engage with proof-of-work for years to create an ethical (or even functional) alternative.
But this is always the way; leveraging trust where appropriate can allow great increases in efficiency, this is how society works, so you have a political spectrum where Ethereum is “responsibly pro social” and Bitcoin is still a kind of super trust less money with enormous energy costs to enable this somewhat superficial security property.
The "true" chain according to the new protocol is the one that has more signatories. Validators sign blocks as they're produced, and when a block gets more than 2/3rds of the signatures, it's finalized on the chain and won't be rewritten. (Well, it's much more complicated than that, but that's the general intuition.) When you sign a block, you get a reward on that chain, to incentivize people to participate in consensus.
So the question is, when there's a fork, what stops people from just signing blocks on both forks so they get the signing reward no matter which fork "wins"?
The protocol disincentivizes this by requiring validators to put up a stake of 32 eth, that gets "slashed" if you do that. Put another way, if there's a fork and you sign blocks on both sides of the fork, you lose part of your stake.
But that threat only works if you actually have a stake to lose. If it's been ${withdrawal_delay} months and you no longer have any eth staked, you can start signing blocks from a long time ago and the protocol can't slash you as punishment. So a group of 2/3rds of the former-validators could freely start a fork from ${withdrawal_delay} months ago, sign a bunch of blocks on it, and if their fork loses they'd face no penalty. Someone currently participating in consensus can see this is happening and won't be confused, but someone just joining the network will be.
The solution is pretty easy, if inelegant. When entering the network for the first time, if there are multiple competing forks, you'll just find someone you trust IRL and ask them which chain is the real one. If you've been offline for less than ${withdrawal_delay} months, you won't have to worry about this, but it is a problem for fresh users.
If you set ${withdrawal_delay} to infinity, this isn't a problem, but probably you don't want to do that. Once withdraws are enabled, there'll be some tooling to make it easy to figure out which chain is the real one, but I don't expect there'll be many forks that are remotely convincing.
To make up for this risk, Ethereum then relies on distributing recent 'weak subjectivity' snapshots (through other known nodes, block exploers, baked into client releases, etc) to make sure new folks can join the legitimate network and ignore an attacker's. Those snapshots basically rely on social legitimacy to help folks get going with the 'legitimate' chain. It is a trust assumption.
In contrast (at least in theory), in a proof of work network you can 'objectively' determine which of competing forks of a chain is the legitimate one by a simple metric, the 'longest chain with the highest difficulty'. The presumption made here though is that you will have an open internet and honest client software that will not censor the legitimate chain. A trust assumption is still made that those that introduce you to the p2p network aren't hiding a longer chain from you.
You are using that "social legitimacy" to know you are downloading the legitimate software, or viewing the legitimate source code, or documentation.
Your computer can't calculate if ethereum.org is the legitimate "Ethereum", or it's ethereum.io (just making it up).
2. The 'demand' from mining for GPUs is over-rated. It was a brief problem years ago. You are correct that energy usage for validation will go down.
3. One difference between bitcoin and eth... ethash is a memory hard algo so it doesn't require the fastest GPU. 4-5 year old GPUs are more ROI efficient. Everything is bound in the speed of the memory controller.
4. To be seen.
5. 'staking' today is just depositing ETH into an ETH1 contract that doesn't have a withdraw function. It will require forks to add that functionality.
6. Correct.
7. Correct. Although this likely won't have an impact on price like people think.
8. A fork could always change things.
https://www.pcmag.com/news/inside-the-gpu-shortage-why-you-s...
https://gamerant.com/nvidia-gpu-shortage-not-due-crypto-mini...
https://www.pcgamer.com/why-crypto-mining-wasnt-the-only-cul...
Like #2 is a statement by Nvidia who has a vested interest in lying, and has lied about the exact same issue so blatantly that they got fined by the SEC for it.
https://www.theverge.com/2022/5/6/23059930/nvidia-sec-charge...
Scalpers only come in when there's a shortage already, they don't cause shortages except at launch, they just delay items getting to the real users.
There's image and video evidence of dozens to hundreds of GPU mining rigs in a single room if you care to look.
Eg. https://cdn.discordapp.com/attachments/788512140322406473/90...
https://old.reddit.com/r/pcmasterrace/comments/r39ph3/found_...
https://old.reddit.com/r/pcmasterrace/comments/wganva/posted...
You're wrong about scalpers too. They know the market... of course they know to prey on every opportunity.
Your 'evidence' is really nothing. That's a few thousand gpus... not that many, honestly. They are also not top of the line gpus... which gamers want to buy. older rx470 polaris class gpus are more than enough for large mining farms.
full disclosure: i'm a huge gpu miner, so i definitely have some experience in this area.
> They are also not top of the line gpus... which gamers want to buy. older rx470 polaris class gpus are more than enough for large mining farms.
Way off the mark there, gamers not in the 1% don't buy top of the line GPU (as reflected in the Steam survey), they buy the budget to mid range price. When miners started buying GPU left and right in pallets, NVIDEA and AMD saw it and shift the manufacturing to the top of the line GPU where they have the highest margins even if the waffer would yield a lot less, because miners would buy them ASAP anyway. This reduced the amount of lower tier GPUs in the market.
Funny you mention the RX470, a GPU famously never in stock because of this dumb piramid scheme.
Nope, not at all. My business model doesn't depend on mining forever. I'm not playing down anything. I'm just saying that mining isn't the only reason (and at most 30% the reason) that GPUs were hard to find.
> Funny you mention the RX470, a GPU famously never in stock because of this dumb piramid scheme.
It came out 5 years ago and newer models replaced it.
Scalpers are a symptom of the supply/demand problem. Not a cause.
Scalpers buy up GPUs. There is less supply. That creates a problem.
Those GPUs are then sold immediately to real users. Scalpers do not increase demand.
Scalpers provide a service. They have automation or a way to buy stock fast at MSRP or closer to MSRP. Then they sell it to people who are willing to pay more in order to have the product now or avoid spending time to search for stock.
Scalpers cannot exist unless demand is greater than supply.
That changes what you said previously and isn't what I responded to. We are talking about supply, not demand.
Scalpers do not increase demand.
Scalpers offer a service to users to buy hard-to-find-products now without waiting or searching.
We are going to have to agree to disagree on this one. In the second link, it is in reference to tickets. At the end of the day, tickets are all the same. If you can't get the front row of the show, you'll accept something back a bit... because you want to see the show.
GPUs are different. Miners want specific brands and models and won't / can't accept anything else.
[1] https://www.reddit.com/r/buildapc/comments/pqcrg8/are_there_...
The only issue I’m still confused about is the incentive to add hardware to the network. Obviously the network needs to be resilient to attack on consensus but it also needs networking and physical hardware resilience. How is that incentivized in the PoS?
This incentivizes them to have reliable networking and hardware, running 24x7.
However they are heavily penalised if they are seen to do things like double-voting by accident, so they can't just put up duplicate systems and forget about it. High availability failover is something they can only do carefully.
This is different from the current proof-of-work miners. If a miner stops or screws up, they won't gain mining fees during the stop, but they don't lose anything either.
Now you might say well isn’t that a good thing for less resources but without an incentive to decentralize physically won’t there be a risk of centralization and potentially catastrophic outcomes for the network?
For the same reason that there are a number of mining companies too. But you're right, PoS doesn't 'fix' that problem.
One of the largest ones for eth and several other chains ($7B TVL) is LIDO, of which I’m an eth mainnet and testnet validator node operator. They distribute stake over many high quality validators and have very rigorous operational guidelines to ensure high quality operators only are allowed. I’m not shilling for LIDO but they are a very professional and well ran DAO that truly cares about what’s they’re doing.
One of the cool things they do is liquid staking. In most PoS networks, your funds are locked during a given time boundary, generally referred to as an Epoch. You start staking at an epoch beginning and can not access funds until the beginning of the next epoch. Validators are rewarded for reliably and securely (no double signing!) performing their task via staking rewards. Staking rewards are quite akin to inflation in more traditional monetary systems.
If the reward for staking is fixe at 5%, what keeps the issuance rate from being net positive?
Overall issuance can potentially be negative due to the burn effects of eip1559 - where the base transaction fee of an eth transaction is deleted from the network forever (akin to using oil/gas/petrol & then it's gone)
If 2>1 then net issuance is negative
It is your opinion that it in uninformative, for you, but for myself and many others, it is quite informative.
whats changed in that plan?
Also it started looking like zkrollups could do everything without loss of security or convenience, and with way better scaling than they ever hoped to get with the original sharding plan. So they removed execution from sharding, using it instead as just data for rollups.
Then someone came up with "danksharding" which is more like a RAID system than actual sharding.
The plan now is described in some detail here: https://members.delphidigital.io/reports/the-hitchhikers-gui...
Also, this is only 5% returns, which might really be negative if crypto crashed relative to USD.
This is a direct parallel of issues like home and car ownership. If you're not rich enough, you have to trust a 3rd party, and also get less for your money.
The only one I can see would make me the "cryptobro", to use the currently-popular phrase.
It's also quite ironic that you suggest the basis of Eth consensus be based on the strength of inter-personal trust. If that's how it works, then why bother with the complexities of Eth?
https://blog.ethereum.org/2015/03/03/ethereum-launch-process...
You can literally run an Ethereum PoS node in a Raspberry Pi.
I know one of the stated goals is for people to be able to run validators on commodity hardware, and as you've pointed out, builds exist for ARM devices and have been shown to run on a Raspberry Pi, but it remains to be seen if you can "in practice" run a mainnet validator on a Raspberry Pi. That would be ideal, though!
It is somewhat risky in my opinion as you don't have the resources to track multiple chain heads in the event of a split, but it does work under nominal chain circumstances.
"Type 1 aims to replicate Ethereum exactly, and so it has no way of mitigating these inefficiencies. At present, proofs for Ethereum blocks take many hours to produce. This can be mitigated either by clever engineering to massively parallelize the prover or in the longer term by ZK-SNARK ASICs. ... Personally, my hope is that everything becomes Type 1 over time, through a combination of improvements in ZK-EVMs and improvements to Ethereum itself to make it more ZK-SNARK-friendly."
They will need to financially incentivize people to run this hardware and will create an arms race around it. Just like Bitcoin.This isn’t the case with ZK provers. Each computation yields a solution, like regular fixed arithmetic math. Using more powerful FPGAs and adding more parallel provers, you can prove the same circuits in less time and less energy.
As hardware accelerated and parallel ZK proving technology increases, the amount of users and applications built on this technology can also increase. This is the opposite of Proof of Work, where more efficient mining rigs and higher hash rates will not lead to more network throughput or activity.
I'm saying that zk is being targeted for ASICs (Vitalik said it himself) and that zk will require some very specific compute needs that not everyone is going to be able to provide.
Every gamer (PC or console) that has used the "look at how much energy is being wasted" argument to be anti-crypto will have to eat their GPUs after the merge.
Bitcoin will be still wasting a crap load of energy, proportional to its value and has no plans to stop doing that.
You can be pro-crypto without being in favor of Bitcoin, you know? In fact, those who oppose crypto due to environmental concerns would help immensely if they stopped generalizing and became more specific about their arguments.
Bitcoin was a good first prototype, but it is clearly a failed experiment. It's not used as a currency, the "store of value" narrative is bogus. All it took was the first asset bubble to pop to demonstrate how BTC is only correlated with other stock prices.
It already loses to Ethereum in many metrics: transaction volume, number of wallets, decentralization (number of nodes participating in block validation) and so on. Layer-2 systems in Ethereum hold more Wrapped Bitcoin than lightning by orders of magnitude. Even if you really want to use BTC, the best way to transact bitcoin today is by wrapping it and using it on Ethereum.
IOW, stop criticizing "crypto" and start focusing on criticizing "Bitcoin". Be specific about your arguments, otherwise everyone will feel like they are on a Mexican standoff and you will never get the support to win the good fight.
The unethical thing is to keep BTC around just because there are so many sunk costs associated with it.
Look at Coingecko's list of ERC20 tokens, all of the top 60 tokens have a market cap above $1 billion. You can go ahead and remove Tether if you want, there is still another ~$100B there.
Bitcoin is not so dominant as the maxis would like to believe. It won't take much for Ethereum (as an ecosystem) to catch up, and when it does the flippening will come fast.
Not as big as “real ethereum” but I wouldn’t say no one cares.
Yes I've profited and no I won't give it to charity.
My opinion will never change, it's all a scam for pump and dumps schemes. There will never be a killer app attached to crypto. NEVER.
with the one they were told to by the de facto authority of the Ethereum world, FTFY
https://cointelegraph.com/news/usdt-issuer-tether-also-confi...
If the crypto crash has demonstrated anything, it's that there's an enormously incestuous relationship between these organizations. We have exchanges running mining operations, market participants investing in crypto mining companies, etc.
A massive economic implosion in the mining community is going to have knock-on effects throughout the ecosystem, and I can imagine market participants not wanting that to happen.
In the end I suspect you're right, but I don't think it's safe to say that only the miners are interested in preserving the status quo, and I don't think it's a foregone conclusion that a major PoW-based fork won't live on and divide the ecosystem.
I also am sure the miners will keep the PoW based chain alive. But I have trouble finding reasons why users, developers and businesses would support the PoW based chain in the long term.
I think it boils down to a coordination/signalling problem again. Miners want to mine on the fork that they expect to succeed, but it will only succeed if it gets listed on exchanges, exchanges will only list it after it gains serious adoption, but it will only get serious adoption if miners agree on a fork, etc.
A historical example of this is SegWit2x in Bitcoin. It was originally proposed as a protocol upgrade, seemed to gain broad support, but miners and exchanges weren’t universally signalling that they would adopt it, and in the end everybody chickened out, and the change failed to be adopted.
I explained why: Cross-investment within the ecosystem.
If, I dunno, say Coinbase has a large investment in a mining operation (and I'm completely making this up, to be clear), they're not gonna want a move to PoS because it'll destroy that investment.
We know for a fact that there's a ton of this type of cross-investment in the ecosystem, as evidenced by the ripple effects from the collapse of organizations like 3AC. It's not at all unreasonable to conclude that similar relationships could create incentives to keep the miners solvent.
Anyone in the community who's been paying attention has been well aware that staking was coming. The staking network has been running in parallel since December 2020, and about 12% of the current supply of ETH is deposited on it.
The PoS chain takes less than a minute to converge to a state where it's very unlikely for your transaction to revert, and in 12 minutes your transaction is finalized, meaning it can't revert without destroying a large percentage of staked ETH.
PoS ETH will have the researcher and dev community building on top of it for another decade or so. There's a long list of further improvements in the roadmap, including major increases in scalability.
Most of the ecosystem is moving to PoS. The popular rollups will be connected to the PoS chain, not to PoW. Major stablecoins backed by off-chain assets have already said they'll be backing the PoS chain, not PoW. Etc.
Also a user would have to make an effort to keep using the PoW one AFAIK.
Edit: To be clear, I’m not talking about banking operations, I’m talking about decision making by central bank leadership. One of the purported benefits of crypto is independence from the shadowy cabals that run the US dollar.
Except the Treasury isn’t actually all that shadowy - the staff have names, and are appointed through an ultimately democratic process. Whereas I really have no idea who is pulling the strings behind crypto and who they are accountable to. The original vision was for decentralized finance where nobody could pull the strings, but the level of coordination on display here in the PoW-to-PoS switch makes it obvious that strings exist and they are capable of being pulled.
Overall it’s very open, although they do have to draw the line somewhere and I assume the core dev’s weekly zoom calls and standups are not open to everybody to join lest it degrade into madness (these devs work across a range of independent companies and orgs fwiw). Even these calls and notes are shared btw.
It’s not quite force or coercion but it’s something close. It allows the Ethereum team to operate similar to a software company and retain tight control over the so called decentralized network.
This is a primary example of why many people argue that Ethereum operates more like a security.
https://arxiv.org/abs/1710.09437
https://arxiv.org/abs/2003.03052
To learn about the sharding plan and various other stuff in the roadmap, this is a great technical overview:
https://members.delphidigital.io/reports/the-hitchhikers-gui...
Hopefully you’ve heard by now that Ethereum has pivoted to a rollup-centric roadmap. No more execution shards – Ethereum will instead optimize for data-hungry rollups. This is achieved via data sharding (Ethereum’s plan, kind of) or big blocks (Celestia’s plan).
I've been following crypto for years and could probably explain Bitcoin in a pinch, but I'll cheerfully admit I have no clue what that means.
https://eth2.incessant.ink/book/00__introduction/00__forewor...
Bitcoin is a very simple system and very limited in its capabilities, but as far as modern blockchains go it is like the early room-size computers, Ford Model T, or Wright Flyer.
> Does proof-of-stake generally mean the more money you have the more influence you get over the consensus?
Ethereum does not have on-chain governance, so having more stake doesn't grant you more influence over the network or the rules of its consensus algorithm. What it gives you is a higher probability to be called to do your duty as a validator and get rewarded for it. But what that duty entails is defined in the protocol and implemented in code.
> If yes, how could this manifest itself if a bad actor had a lot of ETH and tried to manipulate the chain?
You would need to get 33% or 66% of the total stake to be able to do some damage. With 33% you can prevent the network from finalizing, i.e. agreeing that a block is part of the forever history of the network. With 66% you could write wrong blocks and make them part of the forever history of the network. The protocol has on-chain mechanisms to deal with the first situation but there are no on-chain mechanisms to deal with the second one and a solution would require social consensus off-chain.
> Could they theoretically jump favored transactions to the front of the line and/or charge less fees for their own transactions?
Anyone creating a block is free to order the transaction however they please and decide which ones are included. You cannot not charge fees, though. To use the network you have to pay certain amount of ETH and this amount gets spent or burnt as it's also referred, it simply disappears from existence.
> How does this affect mining pools?
They disappear, there is no more mining.
> Is a 51% attack any easier/harder/different?
Different and harder. Different for some of the explanations above (the % necessary are different and what can be done at this thresholds also changes). Harder because it's much much more expensive to acquire the stake necessary to attack, so the chain is more secure. But also because an attacker will get its stake slashed (destroyed) and will not be able to do it again. While in PoW, once you have the hashrate you can keep attacking the network ad infinitum or until the rest of the network gets more hashrate than you. It's as if an attacker in PoS would gets mining rigs burnt. PoW cannot do that because it delegates its security to an activity outside the chain (burn energy with specialized HW), but in PoS the stake is on-chain so there are more tools to deal with nefarious actors.
> Is a 51% attack any easier/harder/different?
Harder. With Ethereum's consensus, you need 2/3 of the validators conspiring to produce an attack on the chain.
With the current price of ETH, it’s unlikely that a single entity could gain enough of the supply to do anything like this, but it is a valid concern for smaller chains.
> Could they theoretically jump favored transactions to the front of the line and/or charge less fees for their own transactions?
Block proposers can already do this. How often you get to be block proposer, is proportional to the amount of stake you have.
Yes gaming and ai, but ethereum Mining was a large part of the gpu market.
It really tickles me to imagine the bewilderment of seeing a webdesign trend of starting every page with a giant static logo.
Does hashpower follow value, or does value follow hashpower?
How does Ethereum plan to deal Proof of Stake naturally monopolizing block creation and the Ether supply? In my estimation there are many compounding factors such as MEV and liquid staking with a massive economy of scale for first movers that combined with staking interest might make the top staking provider eventually hold the vast majority of Ether.
If the company that runs Lido is responsible for validating 99% of the blocks and the US Treasury Department comes knocking with a list of bad actors to blacklist, what happens next?
So how does this graph look for Ethereum? Pretty simple, if you have more than 32 ETH it's basically flat. You get the same APY irrespectively of your size. And if you have less than 32 ETH? Well, you can then stake with RocketPool (a decentralized staking pool) in which case your APY is 0.85 the full APY. So the graph for Ethereum is:
- 0.85 * APY between [0 ETH, 32 ETH)
- APY between [32 ETH, infty ETH)
Where APY is the yield returned by the network which depends on total amount staked in the network and network fee revenues.
This is a remarkably flat curve, which highlights that there are almost non-existent economies of scale in PoS as designed in Ethereum. If you do the same analysis for PoW you will find it requires significant investment in specialized HW (either top of the line GPU or ASICS), and there are significant economies of scale in the form of access to cheap or unusable sources of energy.
On-chain, yes. But there is an off-chain cost to operating the validators, and there is economy of scale there. You can run many 32-ETH validators on a single machine using almost the same resources as running a single one, so the amortized cost of the hardware goes down. And when you do need to expand to multiple machines, the same applies; you don’t need 10× the people to manage 10× the machines. Of course, you can pay somebody to operate the validator for you, and those parties benefit from economy of scale.
That's 876 kWh in a year and 1000 $ in HW. Energy costs vary from place to place but let's pick 0,2 $ / kWh. Which results in 175 $/year in energy. The computer can easily last you 5 years if not more, so 200 $ per year. Let's add internet costs too. 30$ x 12 = 360 $ / year.
Those are the operational costs. Once you have 32 ETH this is pretty negligible.
32ETH was calculated to be approximately the sweet spot, optimising various parameters.
When this decision was made, back in 2018, it cost very much less than it does now.
There are secondary mechanisms for staking with less (RocketPool) but in these, below a certain threshold you don't participate in the beacon chain directly. Instead your stake is combined with others to allow someone to run a beacon chain node on your behalf collectively, with the rewards shared back to you, and a small cut taken off. The cut is why the graph changes below 32ETH.
The fact that a decentralized P2P blockchain can have "too many nodes" is such a massive failure of engineering. It's honestly mind-blowing.
The Ethereum blockchain does scale to more nodes and use scalable P2P networking algorithms. It is only the active beacon chain nodes which are constrained. Just as many users with "full nodes" in the current PoW network do not run a mining operation, not everyone needs to run a beacon chain validator to participate in a decentralised way in the PoS network.
You may think it sounds easy or natural to scale, but actually there are some difficult trade-offs when coordinating global consensus over all state at once. Because communication grows faster than O(n) for n nodes in a flat structure, one of the solutions to that is an uneven power-law network (like a hierarchy), or communication latency rising (along with costs), but both of those are undesirable factors when optimising for fair decentralisation with reasonable latency and costs.
These issues don't arise on other P2P applications such as file sharing and VPN onion routing. That's because they don't need to provide a real-time global consensus of all state on a fixed time scale.
Some blockchains offer low latency local-only consensus, or optimistic consensus which might be rolled back, but those are also a negative for some purposes.
There are some techniques for arbitrary scaling while keeping all the other desirable properties, but they are still open research problems. Some of the most promising techniques use zero-knowledge proofs, but those are mathematically very compute intensive and the current techniques can't run something as complex as Ethereum in real-time yet on an ordinary high-end PC.
Even the PoS beacon chain being readied for the Ethereum merge depends on fairly advanced mathematical cryptography to work.
It really isn't as simple as you imagine.
There's an argument to be made that there is a centralizing force in the role of the consensus/security layer for the chain, because the asset being earned (ETH) can be staked and earn further returns - However, this role and phenomenon is mirrored in the PoW world. The difference is that the centralization happens one step removed from the on-chain asset - PoW miners consolidate profit into further mining investments, such that an increasing amount of the hash rate is owned by the largest miners, who can acquire improved access to electricity and/or equipment relative to smaller miners. One could argue that a PoS system actually has less room for exploitation, however, since you can't restrict a solo-stakers access to ETH, while you could restrict (or provide severe barriers to entry) on the competition of electricity/equipment.
The concern of the "top staking provider eventually holding the vast majority of Ether" is highly unlikely. Given that the asset will soon have ETH issuance cut by 90+% as part of the merge, and the fact that there is no mechanism by which top staking providers are incentivized more than the small solo-stakers, this would soon enter the realms of the purely theoretical, and seemingly take lifetimes to happen if one could even envision it happening at all without a reallocation into other investments.
MEV is being democratized as well (whether a good thing or not, will let you be the judge), with even solo-stakers being able to use an MEV client alongside validation clients in order to benefit from additional income on block proposals (see Flashbots mev-boost client, releasing alongside the merge).
Would love to better understand whether that better informs your perspectives on the subject, or what other concerns you still have.
In contrast, mining can drastically improve the return on capital by operating at larger and larger scales so as to get better and better deals on equipment and electricity. That kind scaling doesn't happen with proof of stake.
Yes and No. We saw what happened to very large mining farms that got wiped out in a matter of weeks as mining was cracked down on in china. Large ETH stakers wont be forced to liquidate their stake in the event they get kicked out of their current jurisdiction. In short, uncertainty about the future of crypto regulation makes it easier to be a staker than it does a miner.
Yes, this ensures a limited supply with PoW, right?
> If you try to remove real-world costs from that equation, you lose the counterbalancing effect.
I assume you can't remove real-world costs in the case of PoS, but yes I can see how the real-world costs will be much, much lower.
Are you saying that there is a good reason to keep those real-world costs higher? (pardon my ignorance, I haven't looked into the principle you describe here before).
If a centralized entity is told to include transactions by a proposer and they refuse for any reason, they will eventually lose their stake and fall out of the producer role.
They do, but the supply of the token also goes up, so their share of the supply doesn’t grow as much, and relative to other stakers, it doesn’t grow in proportion at all. It is true that inflation rewards effectively move value from non-stakers to stakers, but nothing prevents most of the supply from being staked, especially with liquid staking derivatives.
> Staking is just trivial in comparison
I agree that staking is, but operating the node is not! Operating a validator is actually more demanding than operating a miner. For a miner, there is no disadvantage in being offline except for the opportunity cost. But a validator has a duty, and will be penalized for downtime. (Granted, the requirements on Ethereum are quite lax — on purpose, to make it easier for enthusiasts and other non-professionals to operate a node.) Operating a validator requires monitoring and maintenance like any other software. Your server will run out of disk space, your node will disconnect if you don’t update the node software in time, etc. Most validators in most of the PoS networks are operated by professional companies with dedicated SRE teams because of this.
The company that employs most of the Lido contributors is based in a region where the US has little influence. But aside from that, the Lido node operators (who operate the validators) consist of more than a dozen companies, registered in various countries, using servers in different locations. Diversity of jurisdictions is an explicit criterion for node operator selection. Possibly some of them could be forced to censor transactions, but I think it’s not the lowest hanging fruit (going after the client software developers might be a more impactful avenue, there are fewer of those than validators, though fortunately Ethereum has multiple client implementations).
But suppose somehow 99% of the blocks are produced by validators who censor certain actors. Then it depends a bit on how far-reaching the censorship is.
If validators refuse to include certain transactions in their blocks, but still accept other’s blocks for consensus, then I expect that blacklisted actors will find it more difficult and more expensive to get their transactions included, but it would still be possible. If they offer a juicy transaction fee, they will have to wait on average 50 blocks to get their transaction in, but then a validator will be more than happy to include it.
If validators refuse to include certain transactions in their blocks, and also refuse to vote on blocks that do for consensus, then they will be able to enforce their censorship. One way to think about this, is that the censorship has been built into the protocol, and the 1% of validators still willing to include the blacklisted transactions, are producing what the others consider invalid blocks. Consensus can tolerate 1/3 of the stake misbehaving.
99% is an extreme case though; if the censorship is limited to less than 1/3 of the stake, then the opposite happens. Validators who refuse to vote on certain blocks don’t fulfil their duty of voting, which incurs a penalty. If the validator is not allowed to vote on even a descendant of a block that contains a blacklisted transaction, then effectively it will be prevented from ever voting again, and its stake will slowly evaporate due to penalties.
An interesting case arises when censoring nodes control more than 1/3 of the stake, but less than 2/3. This could result in a liveness failure, where no blocks get finalized (because neither the censoring nor the non-censoring nodes can get the required 2/3 majority). This triggers an “inactivity leak”, where the stake of the misbehaving nodes gets destroyed, until there is less than 1/3 of it left, and consensus can be achieved again. Of course, who is “misbehaving” here depends on your point of view, and the situation is symmetric, so this would lead to the chain forking into one where the censors have a supermajority, and one where the non-censors have a supermajority. The side which had most stake will be the first to achieve consensus again.
(Because of this risk, there is an ongoing discussion in Lido about whether it should self-impose a limit to not control more than 1/3 of the stake. But it’s a tough situation, because the way it looks right now is that that stake would instead be controlled by centralized exchanges who offer staking services.)
Bitcoin and crypto use an obscene amount of energy and are basically impossible to ban. A working proof-of-stake system in a non-shitcoin will pile pressure on all cryptocurrencies to move to that system to use less energy.
ETA: A defense of the "rich history" of Görli is what finally got you to comment after 3 years?!
Obviously you wouldn't want to profit from that. How about donating your profits to a charity if you feel so strongly?
Ethereum price ~10 years ago, probably less than a dollar.
Ethereum price today, ~ $1900
Maybe I should be more clear, without ANY application or use for ANY crypto besides pump and dump schemes, ALL crypto, IMO, is a scam. Crypto has been a thing for 10 years, longer if you count egold and liberty cash (or whatever that was called).
And to clarify again, my eth has been locked up in "staking" for what 2 years now without me being able to sell it. I'm looking forward to offloading it all and reap my gains, doesn't change how I feel about it.
How can you sell your ETH in good conscience knowing that it's a scam? Wouldn't that make you a scammer?
There is no application nor will there ever be any application for crypto that cannot be done more efficiently elsewhere. It is no longer a currency so you can scratch that off the definition, there has been nothing but scams, going back to Mt Gox all the way upto this year of literally billions in theft. Why don't you address the ethics of the scams and thievery?
The only truly ethical thing to do would be to destroy all crypto.