Skip to content

LibraryConsensus2019Design paperCorpus record

HotStuff: BFT Consensus in the Lens of Blockchain

HotStuff. Maofan Yin, Dahlia Malkhi, Michael K. Reiter, Guy Golan Gueta and Ittai Abraham.

A three-phase BFT protocol whose communication is linear in the number of replicas, because a leader collects a threshold signature instead of everyone talking to everyone. Diem used a variant. The paper is not that network.

HotStuff commits a block once three successive quorum certificates build on it. A leader collects a threshold signature, so the cost grows linearly with the number of replicas, and a view change uses the same shape as an ordinary proposal.

The five-minute read

Linear, because of the leader

Replicas send votes to the leader, not to each other. The leader broadcasts one certificate. Without threshold signatures the vote is still linear inbound, and the certificate stops being small.

Three certificates

In the pipelined protocol a block rides under the next leaders' certificates. Commit is not a single round of applause. A diagram with one vote is a different protocol.

View change looks ordinary

The next leader speaks only if they carry the highest certificate. There is no separate mesh of blame messages. That is the practical difference from PBFT.

Responsiveness has a definition

After the network is stable, a correct leader can finish as fast as messages travel. It does not mean a silent leader is replaced instantly. The timeout is still there.

One action, walked through

  1. A leader proposes a block that extends the highest quorum certificate it knows.
  2. Replicas vote. The leader assembles a certificate and the next phase begins, often as the next block.
  3. A block that has three certificates on its chain commits.
  4. If the leader fails, replicas timeout and the next leader proposes, carrying the highest certificate they have seen.
  5. A client that needs finality waits for the commit certificate, not for the proposal.

The argument, unpacked

The leader is the product problem

Linearity is purchased by giving one replica the microphone. That replica can omit transactions until the view changes. Any HotStuff deployment is a statement about how often leaders rotate and who pays them.

Diem was a variant

The Libra/Diem chain used a HotStuff-family protocol with its own pacing and signature scheme. The academic paper does not describe Diem's validator politics, and Diem's shutdown does not refute the paper.

What has to be true

  • Fewer than one third of replicas are Byzantine.
  • After an unknown delay, messages between honest replicas arrive within a bound. That is partial synchrony.
  • Threshold signatures work, if the small-certificate claim is in play. A broken ceremony breaks the certificate.
  • Leaders eventually rotate to an honest replica. A fixed corrupt leader is a liveness failure.

What happened after the paper

Aptos, Diem, and other chains shipped HotStuff variants with different pacing, batching, and signature tools. Narwhal later argued that the leader should order certificates of data, not the data itself. Cite HotStuff for the three-phase linear commit, and cite the chain for everything it changed.

What to check before you use the idea

  • Is there a quorum certificate, and who aggregates it?
  • How many successive certificates commit a block?
  • How does a view change choose the parent?
  • How long can one leader censor before rotation?

Terms

Quorum certificate
A threshold signature, or an equivalent set of votes, that a quorum accepted a block.
Pipelining
Using the vote for the next block as one of the phases for the previous block.

The problem the paper names

PBFT's view change is expensive. HotStuff wants a view change that looks like the ordinary case, and a commit rule that stays responsive once messages are flowing.

What the design proposes

  • Prepare, pre-commit, commit, pipelined so one phase can serve the next block.
  • A leader aggregates votes into a quorum certificate.
  • The next leader needs that certificate, not a mesh of complaints.

How the mechanism is specified

  • A block commits when three successive quorum certificates build on it, in the pipelined presentation.
  • Linearity assumes a threshold signature. Without it, the leader still receives a linear number of votes, but the certificate is fat.
  • Responsiveness means the protocol moves at network speed after the network has settled, not that a leader cannot stall.

What this page does not treat as proven

  • The leader is still a choke point for censorship during their turn.
  • A known replica set is assumed. Stake-weighted election is extra machinery.
  • Diem, Aptos, and later chains changed parameters and networking. Cite the paper or cite the chain.

Why a venture studio still reads it

If a team says HotStuff, ask to see the quorum certificate and the view change. If the diagram is a complete graph of voters, it is a different protocol.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.