Skip to content

LibraryConsensus2017Design paperCorpus record

Thunderella: Blockchains with Optimistic Instant Confirmation

Thunderella. Rafael Pass and Elaine Shi.

A fast path and a slow path. If a large supermajority is honest and an accelerator proposes quickly, transactions confirm at network speed. If not, the protocol falls back to an underlying chain.

Thunderella confirms quickly only while a large supermajority and an accelerator behave. When that fails, it falls back to a slower underlying chain. The fast path is not the security bound.

The five-minute read

Two modes

The optimistic path needs more than three quarters honest and a live accelerator. The fallback is a conventional chain that keeps moving when the fast path cannot.

Instant means one round trip

Under those assumptions, a transaction can be acknowledged as fast as the committee can sign. That is a network-speed claim, not a claim about a user's wallet, a bridge, or a court.

The timeout is the design

Something has to notice that the fast path has stalled and switch. A product diagram that omits the switch has omitted the protocol.

Not Avalanche, not Tendermint

Avalanche samples. Tendermint commits with a two-thirds quorum in one mode. Thunderella's contribution is the pairing of an optimistic committee with a pessimistic chain.

One action, walked through

  1. A user sends a transaction to the accelerator.
  2. The accelerator proposes it to the committee.
  3. If more than three quarters acknowledge, the transaction is confirmed on the fast path.
  4. If acknowledgements do not arrive before the timeout, nodes stop treating the fast path as live.
  5. The underlying chain orders transactions and the protocol uses it to resume or to punish, on the paper's rules.

The argument, unpacked

Optimism is an assumption you can leave

The interesting failure is not a slow network. It is a committee that is only two-thirds honest, which would be enough for ordinary BFT and is not enough for this fast path. The fallback exists for that case.

Instant confirmation is easy to fake in a demo

A leader and a few servers can always acknowledge quickly. Thunderella's content is the condition under which that acknowledgement is safe, and the path that remains when the condition is false.

What has to be true

  • The fast path's honesty threshold is met. Below it, only the fallback is supposed to be safe.
  • The accelerator is live during optimistic periods. A censored accelerator is a fallback event, not a fatal bug, if the fallback exists.
  • The underlying chain has its own security assumption, which still has to be true.
  • Timeouts match real delay. A short timeout falls back forever. A long one stalls the optimistic claim.

What happened after the paper

Thunderella influenced how researchers talk about optimistic fast paths. It did not become a household network. Production chains that say instant finality usually mean a single BFT mode, which is a different bet: no fallback, because the quorum assumption is supposed to hold all the time.

What to check before you use the idea

  • What fraction must be honest on the fast path?
  • What is the underlying chain, and when is it used?
  • Who is the accelerator, and what if they censor?
  • How long is the timeout that triggers fallback?

Terms

Accelerator
The proposer the fast path relies on. If it is silent or corrupt, the protocol is supposed to leave the fast path.
Fallback
The slower chain that remains live when the optimistic committee does not.

The problem the paper names

Standard Nakamoto confirmation is slow because it has to tolerate a worst-case adversary all the time. Thunderella asks for instant confirmation only in the optimistic case, with a conservative chain underneath.

What the design proposes

  • An accelerator proposes.
  • A committee of more than three quarters acknowledges.
  • A fallback chain records enough to punish or to resume when the fast path fails.

How the mechanism is specified

  • The fast path is safe only under the larger honesty assumption. It is not the same bound as ordinary BFT.
  • A timeout moves the system onto the slow path. That timeout is the product decision hiding inside the paper.
  • Instant means one round trip under those assumptions, not a guarantee about a live deployment.

What this page does not treat as proven

  • The optimistic committee is not a marketing 'instant finality' badge.
  • Fallback has to be specified. A diagram with only the fast path is incomplete.
  • The paper is not Avalanche and not Tendermint.

Why a venture studio still reads it

Make the team point at the fallback. If they cannot say what confirms when the accelerator is censored, they have a demo.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.