LibraryConsensus2017Design paperCorpus record
ALGORAND: The Efficient and Democratic Ledger
Algorand. Silvio Micali.
Micali's ledger design: a proof-of-stake protocol that elects a small, unpredictable committee to certify each block, and replaces participants so a corruptor cannot find them in time.
Algorand picks a small, unpredictable committee for each step, lets that committee vote, and replaces it before an adversary can learn who to corrupt.
The five-minute read
Committees, not the whole network
Asking every holder to vote on every block is a broadcast storm. Algorand samples a committee whose votes stand for the stake, and it does this again for the next step.
The committee is secret until it speaks
A verifier locally computes a cryptographic sortition result. Nobody else knows they were chosen until the message, with its proof, is already on the wire.
Player replaceability
Once a step's message is out, that voter's power for the step is spent. Corrupting them afterwards does not let the adversary rewrite the step. The next committee is a new draw.
The adversary is assumed adaptive but not instant
The proof allows the adversary to corrupt players after seeing messages, as long as corruption is not faster than the step. That bound is the security claim. It is not a slogan about democracy.
Forks are not the steady state
The protocol is built to agree on one block with overwhelming probability, rather than to let forks race. Finality in the paper is a probability statement about the committee, not a social convention about six blocks.
One action, walked through
- Each online account holds a participation key and a stake weight.
- For a given round and step, the account runs cryptographic sortition against a shared seed and learns whether it has a vote, and of what weight.
- If selected, it gossips a signed vote with the sortition proof. Others can verify the proof without a private channel.
- A committee of proposers offers candidate blocks. A committee of voters reduces them until one block has a quorum.
- The seed for the next round is updated from the round's output so the next committee cannot be predicted far in advance.
The argument, unpacked
Secrecy has to last only one step
The design does not need anonymous accounts. It needs the adversary to learn a voter only when that voter's message is already useful to everyone. That is a narrower, more achievable secrecy. Systems that publish the committee in advance have dropped it.
Stake-weighted sampling can still be captured
A committee represents stake only if the draw is uniform and the seed is unbiased. A large holder who can predict or grind the seed can aim corruption at the people who will matter. Sortition is not a decoration on top of a weak beacon.
Democracy in the title is a stake democracy
Votes are weighted by stake, not by person. The paper is explicit about this. A marketing line about 'one user, one vote' is a different protocol.
What has to be true
- Honest stake exceeds the paper's threshold, often two thirds in the Byzantine setting it argues.
- The adversary cannot corrupt a newly revealed voter before the step completes.
- Enough stake is online and participating. Offline stake does not vote, and the paper's liveness depends on participation.
- The random seed is unpredictable and unbiasable within the round structure.
What happened after the paper
The Algorand network implemented the idea with participation keys, a relay topology, and later performance work. Those operational choices are not theorems in the 2017 paper. Committee size and timing parameters are where the proof meets the network.
What to check before you use the idea
- Is the committee known before it votes?
- What share of stake must be online for a round to complete?
- How is the seed produced, and can the last proposer withhold it?
- Are votes weighted by stake or by account?
Terms
- Cryptographic sortition
- A local lottery, proved to everyone else, that selects a voter with probability proportional to stake.
- Player replaceability
- The property that a voter matters only for the message they already sent. Later corruption cannot change that step.
- Committee
- The small stake-weighted sample whose votes decide a step, then is discarded.
- Adaptive adversary
- An attacker who can choose whom to corrupt as the protocol runs, not only at the start.
The problem the paper names
Classical Byzantine agreement is expensive if every holder talks to every other holder. Bitcoin-style longest chain is permissionless but slow to become confident. Algorand wants a committee that is large enough to represent stake and small enough to finish quickly, without publishing the committee in advance.
What the design proposes
- Cryptographic sortition lets a holder learn privately, from their own key and a public seed, whether they were selected.
- A verifier can check the selection proof after the message appears. Before that, the holder is not a target.
- Player replaceability means the next step draws a new committee. Bribing the last one does not carry forward.
How the mechanism is specified
- The ledger is a sequence of certified blocks, not a race of forks that the heaviest chain wins later.
- Safety is argued from the stake-weighted honesty of the selected sets.
- The 2017 systems paper by Gilad, Hemo, Micali, Vlachos and Zeldovich is the implementation companion, not a different project.
What this page does not treat as proven
- Sortition only helps if the underlying stake and keys are what the paper assumes.
- The paper is not a description of later Algorand product features or relay networks.
- Committee designs still need an account of who can censor inclusion. Certification is not the same as open membership of every transaction.
Why a venture studio still reads it
The idea worth stealing, carefully, is replaceability: do not leave a standing set of signers who can be found and pressured. A venture that publishes its validator set on a webpage has not adopted this property.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
