LibraryConsensus2014Design paperCorpus record
Proof of Stake: How I Learned to Love Weak Subjectivity
Weak Subjectivity. Vitalik Buterin.
A node that has been offline longer than a known window must take a recent checkpoint from a source it already trusts. Inside the window, the protocol can defend itself.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.
The five-minute read
The defect
A proof-of-stake chain can be rewritten from genesis by an attacker who buys long-dead keys, because those keys cost nothing to use once the stake is withdrawn.
The rule
A node that has been offline longer than a known window must take a recent checkpoint from a source it already trusts. Inside the window, the protocol can defend itself.
How it is put together
The checkpoint is not a new consensus algorithm. The window is a social and economic parameter. Long-range attacks are the reason the window exists.
Where the claim stops
Weak subjectivity is not trustlessness from genesis for a new node.
One action, walked through
- Stay online, or sync often enough to stay inside the window.
- If you were gone too long, obtain a state from a client, a friend, or a checkpoint list.
- Then follow the fork-choice rule from that state.
- How long is the weak-subjectivity period?
The argument, unpacked
Why it is still on the desk
A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.
After the text
Ethereum's later consensus uses weak-subjectivity checkpoints in practice. The note is the argument, not the client.
What has to be true
- Weak subjectivity is not trustlessness from genesis for a new node.
- It is not a claim that checkpoints are incorruptible.
- The 2014 note is not the Ethereum consensus specification.
What happened after the paper
Ethereum's later consensus uses weak-subjectivity checkpoints in practice. The note is the argument, not the client.
What to check before you use the idea
- How long is the weak-subjectivity period?
- Where does a new node get the checkpoint?
- What stake-withdrawal rule makes old keys useless inside the window?
Terms
- Long-range attack
- Rewriting history with keys that are no longer bonded.
- Checkpoint
- A recent state a returning node agrees to start from.
The problem the paper names
A proof-of-stake chain can be rewritten from genesis by an attacker who buys long-dead keys, because those keys cost nothing to use once the stake is withdrawn.
What the design proposes
- The checkpoint is not a new consensus algorithm.
- The window is a social and economic parameter.
- Long-range attacks are the reason the window exists.
How the mechanism is specified
- Stay online, or sync often enough to stay inside the window.
- If you were gone too long, obtain a state from a client, a friend, or a checkpoint list.
- Then follow the fork-choice rule from that state.
What this page does not treat as proven
- Weak subjectivity is not trustlessness from genesis for a new node.
- It is not a claim that checkpoints are incorruptible.
- The 2014 note is not the Ethereum consensus specification.
Why a venture studio still reads it
A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
