LibraryConsensus2018Design paperCorpus record
Ouroboros Praos: An Adaptively-Secure, Semi-synchronous Proof-of-Stake Protocol
Ouroboros Praos. Bernardo David, Peter Gaži, Aggelos Kiayias and Alexander Russell.
Praos hides who the slot leader is until they speak, and it tolerates a semi-synchronous delay, so an adaptive adversary cannot target the leader in advance.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
If a proof-of-stake chain publishes the next leader before the slot, it has given up the property this paper added.
The five-minute read
The defect
The first Ouroboros proof assumed a synchronous network and a stake distribution the adversary could not react to inside an epoch.
The rule
Praos hides who the slot leader is until they speak, and it tolerates a semi-synchronous delay, so an adaptive adversary cannot target the leader in advance.
How it is put together
Leaders are elected by a verifiable random function on the stake snapshot. The VRF output is private until the block is published. Empty slots are normal. The chain grows when someone speaks.
Where the claim stops
Praos is not the Cardano network's parameter page.
One action, walked through
- A party checks locally whether their key won the slot.
- They extend the chain the fork-choice rule prefers.
- Other parties verify the VRF and the stake that was allowed to win.
- Is the slot leader hidden until the block?
The argument, unpacked
Why it is still on the desk
If a proof-of-stake chain publishes the next leader before the slot, it has given up the property this paper added.
After the text
Cardano's later protocol lineage cites Praos. Delegation, rewards and governance are separate documents.
What has to be true
- Praos is not the Cardano network's parameter page.
- It does not set a yield.
- Adaptive security here is about rushing the leader, not about smart-contract bugs.
What happened after the paper
Cardano's later protocol lineage cites Praos. Delegation, rewards and governance are separate documents.
What to check before you use the idea
- Is the slot leader hidden until the block?
- What delay does semi-synchronous mean in this deployment?
- Which stake snapshot is the lottery run on?
Terms
- VRF
- A function only the key holder can evaluate, and anyone can check.
- Adaptive adversary
- One that can corrupt a party after seeing who must speak.
The problem the paper names
The first Ouroboros proof assumed a synchronous network and a stake distribution the adversary could not react to inside an epoch.
What the design proposes
- Leaders are elected by a verifiable random function on the stake snapshot.
- The VRF output is private until the block is published.
- Empty slots are normal. The chain grows when someone speaks.
How the mechanism is specified
- A party checks locally whether their key won the slot.
- They extend the chain the fork-choice rule prefers.
- Other parties verify the VRF and the stake that was allowed to win.
What this page does not treat as proven
- Praos is not the Cardano network's parameter page.
- It does not set a yield.
- Adaptive security here is about rushing the leader, not about smart-contract bugs.
Why a venture studio still reads it
If a proof-of-stake chain publishes the next leader before the slot, it has given up the property this paper added.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
