Skip to content

LibraryConsensus2014Design paperCorpus record

Proof of Stake: How I Learned to Love Weak Subjectivity

Weak Subjectivity. Vitalik Buterin.

A node that has been offline longer than a known window must take a recent checkpoint from a source it already trusts. Inside the window, the protocol can defend itself.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.

The five-minute read

The defect

A proof-of-stake chain can be rewritten from genesis by an attacker who buys long-dead keys, because those keys cost nothing to use once the stake is withdrawn.

The rule

A node that has been offline longer than a known window must take a recent checkpoint from a source it already trusts. Inside the window, the protocol can defend itself.

How it is put together

The checkpoint is not a new consensus algorithm. The window is a social and economic parameter. Long-range attacks are the reason the window exists.

Where the claim stops

Weak subjectivity is not trustlessness from genesis for a new node.

One action, walked through

  1. Stay online, or sync often enough to stay inside the window.
  2. If you were gone too long, obtain a state from a client, a friend, or a checkpoint list.
  3. Then follow the fork-choice rule from that state.
  4. How long is the weak-subjectivity period?

The argument, unpacked

Why it is still on the desk

A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.

After the text

Ethereum's later consensus uses weak-subjectivity checkpoints in practice. The note is the argument, not the client.

What has to be true

  • Weak subjectivity is not trustlessness from genesis for a new node.
  • It is not a claim that checkpoints are incorruptible.
  • The 2014 note is not the Ethereum consensus specification.

What happened after the paper

Ethereum's later consensus uses weak-subjectivity checkpoints in practice. The note is the argument, not the client.

What to check before you use the idea

  • How long is the weak-subjectivity period?
  • Where does a new node get the checkpoint?
  • What stake-withdrawal rule makes old keys useless inside the window?

Terms

Long-range attack
Rewriting history with keys that are no longer bonded.
Checkpoint
A recent state a returning node agrees to start from.

The problem the paper names

A proof-of-stake chain can be rewritten from genesis by an attacker who buys long-dead keys, because those keys cost nothing to use once the stake is withdrawn.

What the design proposes

  • The checkpoint is not a new consensus algorithm.
  • The window is a social and economic parameter.
  • Long-range attacks are the reason the window exists.

How the mechanism is specified

  • Stay online, or sync often enough to stay inside the window.
  • If you were gone too long, obtain a state from a client, a friend, or a checkpoint list.
  • Then follow the fork-choice rule from that state.

What this page does not treat as proven

  • Weak subjectivity is not trustlessness from genesis for a new node.
  • It is not a claim that checkpoints are incorruptible.
  • The 2014 note is not the Ethereum consensus specification.

Why a venture studio still reads it

A wallet that syncs a proof-of-stake chain from genesis with no checkpoint has ignored the attack this note names.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.