LibraryConsensus2016Design paperCorpus record
Bitcoin-NG: A Scalable Blockchain Protocol
Bitcoin-NG. Ittay Eyal, Adem Ercan Gencer, Emin Gün Sirer and Robbert van Renesse.
Separate the rare proof-of-work election from the frequent publication of transactions. Key blocks choose a leader. That leader's microblocks carry the transactions until the next key block.
Bitcoin-NG elects a leader rarely, with proof of work, and lets that leader publish many signed microblocks of transactions before the next election.
The five-minute read
Two kinds of block
A key block is mined. It chooses the leader and pays them. A microblock is signed by the leader and carries transactions. Only the key block resets who may speak.
Throughput leaves the puzzle
The puzzle interval can stay long enough to limit forks. Transactions per second then depend on how fast microblocks can be flooded and checked.
The next miner polices the last leader
The paper splits rewards so a leader who misbehaves can be punished by the following key block. That is an incentive, not a vote by users.
The epoch is a dictatorship
Inside one leader's window, ordering and censorship are that leader's choice. Short epochs shrink the window. They do not delete it.
One action, walked through
- Miners race to find a key block, as in Bitcoin.
- The winner signs microblocks that reference the key block and carry transactions.
- Nodes accept microblocks that chain back to the latest key block and carry a valid signature.
- Another miner finds the next key block. The previous leader's signing power ends.
- Fees are split between the leader who published the microblock and the miner of the next key block, on the paper's terms.
The argument, unpacked
Decoupling is the contribution
The paper's point is that leader election and transaction serialisation are different clocks. Any design that still does both inside one rare block has not used this idea.
Leader faults are concentrated
A dishonest leader can stuff or withhold microblocks until they are replaced. The damage is bounded by the epoch length only if the next key block actually arrives.
What has to be true
- Most hash power follows the protocol, including the rule about which microblocks to build on.
- Microblocks propagate faster than the key-block interval. Otherwise the decoupling was pointless.
- Leaders' keys are the keys that won the puzzle, not a committee glued on later.
- The heaviest key-block chain is what nodes follow. Microblocks do not outvote a key block.
What happened after the paper
Later high-throughput designs, including Solana's leader schedule, rhyme with the split between election and publication. They are not Bitcoin-NG. Bitcoin itself did not adopt microblocks. Cite the 2016 paper for the split, not for a live network.
What to check before you use the idea
- What event elects the leader, and how long do they serve?
- Can that leader publish transactions without a new puzzle?
- Who is paid if the leader censors, and who can replace them?
- Do observers treat a microblock as final before the next key block?
Terms
- Key block
- A mined block that elects the next leader.
- Microblock
- A signed batch of transactions from that leader, not itself a new election.
The problem the paper names
In Bitcoin, the same puzzle both elects a leader and caps how often transactions can be published. Shortening the block interval raises forks. Bitcoin-NG asks whether those two clocks have to be the same.
What the design proposes
- Key blocks are mined and decide who may speak.
- Microblocks are signed by that leader and can be frequent.
- Rewards are split so the next miner polices the previous leader.
How the mechanism is specified
- A key block names a public key. Microblocks under that key are valid until another key block appears.
- Transaction throughput is then limited by bandwidth and verification, not by the puzzle interval.
- A leader can still censor or reorder inside their epoch. The next key block is the check, not a vote of the users.
What this page does not treat as proven
- This is not Solana, and it is not proof of history. The election is still proof of work.
- A corrupt leader's epoch is real damage. The paper bounds it in fees, it does not erase it.
- The design does not hide transaction contents or stop a miner from preferring its own microblocks.
Why a venture studio still reads it
Use it when someone claims a chain is faster because blocks are smaller. Ask which event elects the leader, and what that leader can do alone before the next election.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
