LibraryConsensus2017Design paperCorpus record
Ouroboros: A Provably Secure Proof-of-Stake Blockchain Protocol
Cardano. Aggelos Kiayias, Alexander Russell, Bernardo David, Roman Oliynykov.
The academic protocol Cardano's settlement layer is built around. It gives a proof-of-stake chain a stated security argument in a synchronous model, with stake electing slot leaders.
Ouroboros elects slot leaders from a stake distribution, and it argues that forging a chain still costs an adversary more stake than the honest majority, without burning energy on empty hashes.
The five-minute read
Proof of work buys a lottery with electricity
Bitcoin's leader is whoever finds a hash. Ouroboros wants the same kind of public lottery, but the tickets are stake, and the draw is a matter of record rather than of burned power.
Time is divided into slots and epochs
An epoch has a stake snapshot. Inside it, each slot has a leader who may extend the chain. Empty slots are allowed. The chain is the longest valid history under the stated rule.
The draw has to be unbiased
If the leader election can be grinded, a large stakeholder can keep re-rolling until they like the future. The paper's cryptographic work is there: a randomness beacon that the adversary cannot cheaply bias.
Stake is a moving target
Leaders are elected from a past snapshot, not from the stake that will exist after this block. That lag is what makes the distribution a fact instead of a value the current leader can rewrite.
The proof is about a model
Security is argued against a synchronous adversary who holds less than half the stake. Real networks drop messages, and later Ouroboros variants change the assumptions. Name the variant.
One action, walked through
- At the start of an epoch, the protocol fixes the stake distribution from a settled point in the past.
- A shared random seed for the epoch is derived from the previous epoch's output, under the paper's verifiable random function or coin-tossing construction.
- For each slot, every stakeholder can locally compute whether they are the leader. Others can check that claim.
- The leader publishes a block. Honest nodes adopt the chain that the fork rule selects.
- Rewards and the next snapshot update only after the epoch's rules say the history is stable.
The argument, unpacked
Why the snapshot lags
If the leader of this slot could move stake and immediately elect themselves again, the lottery would be circular. The paper freezes the electorate. Any implementation that elects from unconfirmed stake has left the proof.
Randomness is the whole game
A proof-of-stake chain that lets a proposer grind the seed will be captured by the grinder, even if they hold a minority. Ouroboros is useful because it treats biasable randomness as a break, not as a tuning issue.
Nothing-at-stake is a fork rule problem
If signing two forks is free, rational leaders sign both. The paper's security argument needs a rule that makes a second history unprofitable or punishable. A pitch that says 'we use Ouroboros' and then omits the fork choice is borrowing the name.
What has to be true
- Honest stake is a majority in the model the proof uses, and stake cannot be rented invisibly outside that model.
- Messages arrive within the slot bounds the protocol assumes. A quiet partition is a different theorem.
- The randomness mechanism matches the paper. A simpler hash of the previous block is not a substitute.
- Keys of elected leaders are online when their slot arrives, or a delegation scheme has been specified.
What happened after the paper
Cardano shipped Praos, Genesis and other descendants. Delegation, stake pools and the network's reward formula are later specifications. The 2017 paper is the first place the lottery-plus-snapshot argument is made carefully. It is not a description of today's node.
What to check before you use the idea
- Which Ouroboros variant is implemented, and which network assumption does its proof use?
- How far behind the tip is the stake snapshot?
- Can a proposer bias the next epoch's seed by withholding a block?
- What happens to a leader who signs two forks?
Terms
- Slot
- A unit of time that has at most one elected leader.
- Epoch
- A run of slots that share one stake snapshot and one random seed.
- Stake snapshot
- The distribution used to elect leaders, taken from a settled point so the current leader cannot rewrite the electorate.
- Grinding
- Re-rolling a leader-election seed until the future looks favourable. A proof-of-stake design has to make this expensive or impossible.
The problem the paper names
Early proof-of-stake proposals were often engineering sketches. Ouroboros asks for a protocol that says who may extend the chain, how randomness is produced, and which assumptions the security proof actually uses.
What the design proposes
- Time is divided into epochs and slots. A stakeholder is elected leader of a slot in proportion to stake.
- Leaders propose blocks. Honest majority of stake, not of hash power, is the assumption.
- Randomness for the next epoch is derived from the protocol rather than from an outside beacon that nobody accounts for.
How the mechanism is specified
- The paper works in a synchronous setting and says so. Network delay assumptions are part of the result.
- Stake distribution is taken from a settled earlier state so the current election cannot be rewritten cheaply.
- Follow-on papers (Praos, Genesis, and others) change the model. They are not this paper.
What this page does not treat as proven
- Publishing a proof about Ouroboros is not a statement about Cardano's market, clients or governance.
- The proof does not cover every later feature added around the settlement layer.
- Synchronous assumptions fail in messy networks. The paper's value is that it names them.
Why a venture studio still reads it
When a venture says 'we use proof of stake', ask which protocol, which honesty assumption, and which paper. Ouroboros is the example of a design that can be pointed at.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
