Research

Too Late to Slash: Investigating Proof-of-Stake Economic Security

By LayerZeroSep 30, 20263 min read

Today we’re sharing a new paper challenging a common belief: slashing backs the security of proof-of-stake blockchains.

Slashing means validators caught cheating lose their stake. The argument for slashing is relatively straightforward: without it, validators can test whether enough others are willing to attack at no cost. Slashing is meant to remove that free option by making the act of coordinating an attack itself economically risky.

Our research questions that premise. We show how rational validators can determine whether enough others are willing to attack before producing any slashable evidence. If there aren’t enough participants, nothing happens. If there are, the coalition only equivocates once it is powerful enough to prevent the resulting punishment from being enforced.

Read the full paper on arXiv.


The argument for slashing

Consider an equivocation attack, where validators sign two conflicting blocks. Without slashing, a validator can sign both and see whether enough other validators join. If enough do, the attack succeeds. If they don’t, the validator loses nothing.

Slashing is intended to remove that free option. Signing both blocks creates public evidence of misbehavior, allowing the protocol to confiscate the validator’s stake. The assumption is that rational validators therefore won’t even try to find accomplices.

The risk of getting slashed is also why stake is often used to measure economic security. The usual reasoning is that an adversary only attacks consensus if the gain exceeds the stake at risk. So slashable stake can back applications of comparable value: the more that’s bonded, the more value the chain can safely secure.


Challenging the premise

Our paper challenges that assumption by separating coordination from equivocation. Validators first register their willingness to participate through a smart contract. Registration itself is not double signing and creates no slashable evidence. Once registration closes, the contract checks whether the participating validators have reached what the paper calls the monopoly threshold: enough consensus power to both finalize conflicting blocks and selectively censor transactions.

If the coalition is below the threshold, the attack is abandoned and nobody has done anything slashable. If the coalition reaches the threshold, the validators equivocate while censoring the transactions that would punish them, then withdraw their stake. The evidence only appears once the coalition is powerful enough to stop the punishment.

This is the key insight: algorithmic slashing relies on the consensus process that the attackers themselves control. Collateral works in the ordinary economy because the bank, not the borrower, seizes it. Here, the enforcer is the defendant. So slashing is only credible when it isn’t needed. Before a coalition strong enough to attack forms, the security is guaranteed by the fault tolerance of the protocol. Once such a coalition exists, it controls the process that would do the slashing. By then, it is too late to slash.

The paper formally proves that, under its model, the strategy forms an ex post Nash equilibrium: rational validators have no incentive to unilaterally deviate from the coordination strategy, even when they do not know in advance how many other validators are willing to participate.

Most importantly, the result holds for any positive gain from a successful attack, however small relative to the amount of bonded stake. This challenges the idea that increasing the amount of slashable capital necessarily increases economic security proportionally. If attackers can prevent the penalty from being enforced, the nominal value at risk is not the same thing as the amount an attacker actually stands to lose.

Read the full paper on arXiv.

Connect to our team

Start building