Skip to content

LibraryConsensus2014Design paperCorpus record

Tezos — a self-amending crypto-ledger

Tezos. L.M. Goodman.

Goodman's proposal for a ledger whose protocol can be amended by a defined on-ledger process, with stakeholders who bake blocks and who may delegate.

Tezos treats the rules of the ledger, including the rules for changing the rules, as something the stakeholders can amend on-chain, with a delay long enough to exit.

The five-minute read

The amendment is the feature

Most chains upgrade by a software flag day coordinated off to the side. Tezos proposes that a proposal, a vote, a test period and an adoption period are protocol steps.

Stakeholders vote, and bakers represent them

The paper's electorate is stake, exercised by delegates called bakers. A vote is not a poll of wallet downloads.

Time is a safety rail

Adoption is delayed on purpose. Someone who dislikes an amendment is supposed to have time to sell, fork, or leave before the rule binds them.

The seed protocol still has to be a chain

Self-amendment does not replace consensus. The paper also sketches a proof-of-stake block production story. Later Tenderbake and other revisions replaced that sketch.

Formal verification is a stated ambition

The paper wants the protocol, and contracts, to be amenable to proofs. That is a research programme sitting beside the voting mechanism, not a theorem that every later amendment is safe.

One action, walked through

  1. A baker submits a protocol amendment as a proposal hash.
  2. In the proposal period, stake-weighted votes select which proposal, if any, proceeds.
  3. A ballot period asks voters to accept or reject. The paper's thresholds are part of the design, not a default.
  4. A testing period runs the candidate so the network can watch it before it is sovereign.
  5. After the delay, the amendment becomes the protocol. Nodes that did not install the code simply stop understanding the chain.

The argument, unpacked

On-chain vote is not automatic legitimacy

A stake-weighted yes says that the bakers who showed up preferred this hash. It does not say the amendment is wise, that participation was broad, or that users read the diff. The paper's contribution is to make the procedure explicit. The political judgement stays outside.

The exit ramp is the moral core

The delay before adoption is what keeps an amendment from being a trap. If a later revision shortens that delay to the point that holders cannot react, the procedure has kept its name and dropped its protection.

Delegation concentrates the electorate

Bakers exist so that small holders do not have to be online. They also mean a few operators cast most of the votes. Any reading of Tezos governance that counts bakers as if they were users is miscounting.

What has to be true

  • Most stake that bothers to vote is not captured, and quorum rules are high enough to mean something.
  • Voters can obtain and review the protocol code behind a proposal hash. A vote on an unseen blob is only a vote on a blob.
  • The testing period is long enough to reveal a broken amendment, and short enough that the network still bothers to wait.
  • Client software is updated before adoption. The chain cannot run code the node does not have.

What happened after the paper

Tezos adopted a series of amendments through this procedure, and replaced its original consensus sketch with Tenderbake, a Byzantine fault tolerant finality layer. The 2014 paper predicts the existence of that kind of change. It does not describe Tenderbake.

What to check before you use the idea

  • What are the quorum and the supermajority, and who actually cast the last vote?
  • How long is the delay between a yes and the code becoming law?
  • Can a user see the amendment in source form, or only a hash?
  • Which consensus protocol is live now, as opposed to the one sketched in 2014?

Terms

Self-amendment
A protocol rule for replacing the protocol, including the voting rule itself, by an on-chain procedure.
Baker
A delegate who produces blocks and votes with stake assigned to them.
Proposal hash
The identifier of an amendment. The vote is about this identifier. The code is what it points at.
Adoption delay
The waiting period after a successful vote, meant to let dissenters leave before the new rule binds.

The problem the paper names

Forks that change the rules are political events coordinated off to the side. Tezos argues that the procedure for adopting a protocol change should itself be a protocol, so the ledger has a stated way to replace its own code.

What the design proposes

  • A shell distinguishes the consensus-relevant protocol from the governance process that can swap it.
  • Baking is the block production role. Delegation lets a holder assign rights without transferring ownership.
  • Formal specification is part of the pitch: amendments should be arguments about a mathematical object, not only about a client repository.

How the mechanism is specified

  • Stakeholders vote through a series of periods. The paper's process and the live governance process should not be assumed identical.
  • Security deposits and penalties are how the design makes baking expensive to abuse.
  • Self-amendment does not mean every social dispute fits in a vote. It means the rule-change path is explicit.

What this page does not treat as proven

  • The 2014 paper is not the current Tezos protocol hash.
  • Delegation creates representatives. The paper does not prove that representatives stay aligned with holders.
  • Formal methods reduce a class of bugs. They do not replace key management or an honest specification.

Why a venture studio still reads it

A venture that expects to change settlement rules after launch should show the amendment path before the first version, not after the first argument. That is the part worth taking from Tezos.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.