LibraryConsensus1999Design paperCorpus record
Practical Byzantine Fault Tolerance
PBFT. Miguel Castro and Barbara Liskov.
The paper that made a Byzantine quorum practical: a known set of replicas, three phases, and a view change when the leader is useless. Tendermint and HotStuff inherit the shape. Open membership is a different problem.
PBFT gets one answer from a known set of replicas of which fewer than one third may lie. A leader sequences requests. A quorum of two thirds plus one commits them. A view change fires the leader.
The five-minute read
The set is known
Replicas have identities before the protocol starts. PBFT does not discover who the voters are. A public chain that elects validators has to add that layer itself.
Three phases, one sequence number
Pre-prepare assigns the number. Prepare shows a quorum saw the same assignment. Commit shows a quorum is willing to execute it. Skip a phase and the intersection argument changes.
Quorums overlap in an honest replica
With 3f+1 replicas, any two quorums of 2f+1 share at least one honest node. That is why two committed values cannot both be true. The bound is one third, not a vibe about supermajorities.
View change is the protocol
If the leader censors or dies, a new view must carry forward anything that might have committed. A system that restarts from a snapshot without that proof is not PBFT.
One action, walked through
- A client sends a request to the leader, and eventually to the replicas if the leader is silent.
- The leader broadcasts a pre-prepare binding the request to a sequence number in this view.
- Replicas that accept it broadcast a prepare. A replica that sees 2f prepares broadcasts a commit.
- After 2f+1 commits, the replica executes and replies to the client.
- The client accepts when f+1 honest-looking replies match. A new view starts if this stalls.
The argument, unpacked
Safety does not wait for synchrony
The paper's safety holds even when messages are late. Liveness is what needs a period of timely delivery. Quoting PBFT for instant finality without saying which of those two you mean is how designs get oversold.
Permissioned is not an insult, it is the assumption
The theorem is about a fixed, authenticated set. Tendermint and HotStuff keep the quorum and change the messages. They do not turn the set into 'anyone with a coin'.
What has to be true
- Fewer than one third of replicas are Byzantine. A larger coalition can commit two values.
- Messages are eventually delivered when the network is in its good period. Safety does not use that. Liveness does.
- Replicas authenticate messages. A set that can be freely impersonated is not this protocol.
- The client waits for matching replies. A client that trusts the first answer has left the paper.
What happened after the paper
Tendermint, HotStuff, and the Diem-era protocols are descendants of this quorum shape, with different view changes and signature aggregation. A chain that markets BFT without a known validator set and a view-change story is using the adjective and not the paper.
What to check before you use the idea
- Is the replica set fixed, staked, or open?
- What is f, and what happens at f+1 faulty replicas?
- Does a view change preserve a request that already had a commit quorum?
- Does the client require f+1 matching replies?
Terms
- View
- One leader's turn. A view change is how the set fires that leader.
- Quorum
- 2f+1 replicas. Two quorums must intersect in an honest replica.
The problem the paper names
Lamport's Byzantine agreement was a proof, not a system that could run a replicated service. PBFT asks how a client gets one answer from replicas that may lie, without a synchrony assumption for safety.
What the design proposes
- Safety if fewer than one third of replicas are faulty.
- A leader orders requests. The others vote in pre-prepare, prepare, and commit.
- A view change elects a new leader without rolling back a committed request.
How the mechanism is specified
- A request is committed only after a quorum of 2f+1 replicas have agreed the same sequence number in the same view.
- Two quorums intersect in at least one honest replica, which is why the bound is one third and not one half.
- The paper assumes the replica set is known. It does not elect that set with mining or stake.
What this page does not treat as proven
- A permissioned quorum is not a public chain. Citing PBFT does not make a validator set open.
- Liveness still needs some period when messages get through. Safety does not.
- Later protocols cut the communication. They do not retire the quorum intersection argument.
Why a venture studio still reads it
When a pitch says Byzantine fault tolerance, ask whether the set of voters is known, who rotates the leader, and what a view change does to a request that already had a quorum.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
