Skip to content

LibraryConsensus2017Design paperCorpus record

ALGORAND: The Efficient and Democratic Ledger

Algorand. Silvio Micali.

Micali's ledger design: a proof-of-stake protocol that elects a small, unpredictable committee to certify each block, and replaces participants so a corruptor cannot find them in time.

Algorand picks a small, unpredictable committee for each step, lets that committee vote, and replaces it before an adversary can learn who to corrupt.

The five-minute read

Committees, not the whole network

Asking every holder to vote on every block is a broadcast storm. Algorand samples a committee whose votes stand for the stake, and it does this again for the next step.

The committee is secret until it speaks

A verifier locally computes a cryptographic sortition result. Nobody else knows they were chosen until the message, with its proof, is already on the wire.

Player replaceability

Once a step's message is out, that voter's power for the step is spent. Corrupting them afterwards does not let the adversary rewrite the step. The next committee is a new draw.

The adversary is assumed adaptive but not instant

The proof allows the adversary to corrupt players after seeing messages, as long as corruption is not faster than the step. That bound is the security claim. It is not a slogan about democracy.

Forks are not the steady state

The protocol is built to agree on one block with overwhelming probability, rather than to let forks race. Finality in the paper is a probability statement about the committee, not a social convention about six blocks.

One action, walked through

  1. Each online account holds a participation key and a stake weight.
  2. For a given round and step, the account runs cryptographic sortition against a shared seed and learns whether it has a vote, and of what weight.
  3. If selected, it gossips a signed vote with the sortition proof. Others can verify the proof without a private channel.
  4. A committee of proposers offers candidate blocks. A committee of voters reduces them until one block has a quorum.
  5. The seed for the next round is updated from the round's output so the next committee cannot be predicted far in advance.

The argument, unpacked

Secrecy has to last only one step

The design does not need anonymous accounts. It needs the adversary to learn a voter only when that voter's message is already useful to everyone. That is a narrower, more achievable secrecy. Systems that publish the committee in advance have dropped it.

Stake-weighted sampling can still be captured

A committee represents stake only if the draw is uniform and the seed is unbiased. A large holder who can predict or grind the seed can aim corruption at the people who will matter. Sortition is not a decoration on top of a weak beacon.

Democracy in the title is a stake democracy

Votes are weighted by stake, not by person. The paper is explicit about this. A marketing line about 'one user, one vote' is a different protocol.

What has to be true

  • Honest stake exceeds the paper's threshold, often two thirds in the Byzantine setting it argues.
  • The adversary cannot corrupt a newly revealed voter before the step completes.
  • Enough stake is online and participating. Offline stake does not vote, and the paper's liveness depends on participation.
  • The random seed is unpredictable and unbiasable within the round structure.

What happened after the paper

The Algorand network implemented the idea with participation keys, a relay topology, and later performance work. Those operational choices are not theorems in the 2017 paper. Committee size and timing parameters are where the proof meets the network.

What to check before you use the idea

  • Is the committee known before it votes?
  • What share of stake must be online for a round to complete?
  • How is the seed produced, and can the last proposer withhold it?
  • Are votes weighted by stake or by account?

Terms

Cryptographic sortition
A local lottery, proved to everyone else, that selects a voter with probability proportional to stake.
Player replaceability
The property that a voter matters only for the message they already sent. Later corruption cannot change that step.
Committee
The small stake-weighted sample whose votes decide a step, then is discarded.
Adaptive adversary
An attacker who can choose whom to corrupt as the protocol runs, not only at the start.

The problem the paper names

Classical Byzantine agreement is expensive if every holder talks to every other holder. Bitcoin-style longest chain is permissionless but slow to become confident. Algorand wants a committee that is large enough to represent stake and small enough to finish quickly, without publishing the committee in advance.

What the design proposes

  • Cryptographic sortition lets a holder learn privately, from their own key and a public seed, whether they were selected.
  • A verifier can check the selection proof after the message appears. Before that, the holder is not a target.
  • Player replaceability means the next step draws a new committee. Bribing the last one does not carry forward.

How the mechanism is specified

  • The ledger is a sequence of certified blocks, not a race of forks that the heaviest chain wins later.
  • Safety is argued from the stake-weighted honesty of the selected sets.
  • The 2017 systems paper by Gilad, Hemo, Micali, Vlachos and Zeldovich is the implementation companion, not a different project.

What this page does not treat as proven

  • Sortition only helps if the underlying stake and keys are what the paper assumes.
  • The paper is not a description of later Algorand product features or relay networks.
  • Committee designs still need an account of who can censor inclusion. Certification is not the same as open membership of every transaction.

Why a venture studio still reads it

The idea worth stealing, carefully, is replaceability: do not leave a standing set of signers who can be found and pressured. A venture that publishes its validator set on a webpage has not adopted this property.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.