LibraryConsensus2018Design paperCorpus record
Stake-Bleeding Attacks on Proof-of-Stake Blockchains
Stake bleeding. Peter Gaži, Aggelos Kiayias and Alexander Russell.
The paper shows a long-range style attack in which past stake keeps producing an alternative history unless the protocol makes that history obviously stale.
A reading of the public paper. Not a copy, not a benchmark, and not a claim about any later network.
If a design has no answer to stake that has already withdrawn, it has not answered this paper.
The five-minute read
The defect
A proof-of-stake history can be extended by an adversary who once held stake and keeps using it after the honest chain has moved on.
The proposal
The paper shows a long-range style attack in which past stake keeps producing an alternative history unless the protocol makes that history obviously stale.
Old keys are not burned by the passage of blocks alone.
A checkpoint or a key-evolving rule is a defence, not a slogan.
The bound
The paper is an attack, not a product.
One action, walked through
- Take stake that was valid in an old slot.
- Grow a private history that honest nodes who were offline cannot immediately reject.
- Compare that history with whatever rule the protocol uses to discount the past.
- What does a node that has been offline for a year accept?
The argument, unpacked
What the paper is for
If a design has no answer to stake that has already withdrawn, it has not answered this paper.
What happened after
Weak subjectivity and key-evolving signatures are later answers. They are not this attack paper.
What has to be true
- The paper is an attack, not a product.
- It does not say every proof-of-stake system is currently broken.
- A checkpoint taken from a website is a trust assumption. Name it.
What happened after the paper
Weak subjectivity and key-evolving signatures are later answers. They are not this attack paper.
What to check before you use the idea
- Can withdrawn stake still sign old slots?
- What does a node that has been offline for a year accept?
- Is the defence in the protocol or in a social checkpoint?
Terms
- Stake bleeding
- Old stake continuing to extend a history the honest chain has left.
- Long-range
- An alternative history built behind the current tip.
The problem the paper names
A proof-of-stake history can be extended by an adversary who once held stake and keeps using it after the honest chain has moved on.
What the design proposes
- Old keys are not burned by the passage of blocks alone.
- A checkpoint or a key-evolving rule is a defence, not a slogan.
- The attack is about history, not about a short reorg.
How the mechanism is specified
- Take stake that was valid in an old slot.
- Grow a private history that honest nodes who were offline cannot immediately reject.
- Compare that history with whatever rule the protocol uses to discount the past.
What this page does not treat as proven
- The paper is an attack, not a product.
- It does not say every proof-of-stake system is currently broken.
- A checkpoint taken from a website is a trust assumption. Name it.
Why a venture studio still reads it
If a design has no answer to stake that has already withdrawn, it has not answered this paper.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
