Proof of work vs proof of stake: how do blockchains agree on the next block?
Every public blockchain needs a way for strangers to agree on one history. Proof of work spends electricity to do it; proof of stake puts money up as collateral. Here is how each works and what the trade-offs are.

The short answer
Both decide who adds the next block. Proof of work makes miners race to solve a costly computing puzzle. Proof of stake has validators lock up coins as collateral that can be cut if they cheat. Bitcoin uses proof of work; Ethereum switched to proof of stake in 2022.
Key takeaways
- A consensus mechanism lets thousands of computers that do not trust each other agree on a single order of transactions.
- Proof of work makes block producers prove they spent computing effort; cheating means out-computing everyone else.
- Proof of stake makes block producers lock up coins; cheating can get that stake destroyed through penalties called slashing.
- Ethereum moved from proof of work to proof of stake on 15 September 2022, cutting its energy use by about 99.95% according to ethereum.org.
- Neither design is attack-proof: both can in theory be overpowered by someone who controls a majority of the key resource.
What problem do proof of work and proof of stake solve?
Digital money has an obvious weakness: a file can be copied. Without a referee, what stops someone from sending the same coin to two people? The Bitcoin paper calls this the double-spending problem, and its answer is a public, time-ordered record that everyone can check1. Our explainer on how a blockchain works covers that record. This page covers the harder question: who gets to write the next page?
The rule that answers it is called a consensus mechanism. NIST lists several, from proof of work and proof of stake to round robin and proof of authority2. Public cryptocurrencies mostly use the first two, because both let anyone take part without asking permission while making cheating expensive.
Figure · Two ways to make cheating expensive
Proof of work
- Miners spend electricity on puzzles
- Winner of the race adds the block
- Attack needs most of the computing power
Proof of stake
- Validators lock up coins as collateral
- Protocol picks who proposes the block
- Attack needs most of the staked coins
How does proof of work actually work?
In proof of work, computers called miners bundle waiting transactions into a candidate block and then search for a number, the nonce, that makes the block's hash meet a target. The Bitcoin paper describes this as finding a value whose SHA-256 hash begins with a required number of zero bits, by changing the nonce until one works1. ethereum.org calls this an intense race of trial and error3.
One round of mining, simplified
- 1
Build a block
The miner collects valid, unspent transactions into a candidate block1.
- 2
Guess
It changes the nonce and hashes the block again and again until the result meets the difficulty target1.
- 3
Broadcast
A miner that finds a valid result broadcasts the block, and other nodes accept it only if all its transactions are valid and unspent1.
- 4
Get paid
The block's first transaction creates new coins for its creator, and transaction fees can add to the reward1.
The network tunes the puzzle so blocks keep a steady pace. Bitcoin adjusts the difficulty every 2,016 blocks, aiming for about one block every ten minutes2; at that pace, 2,016 blocks take about 14 days. When two miners find blocks at once, nodes keep building on the longest chain1, and the shorter branch is abandoned.
Finality in proof of work is a matter of probability. Each new block on top of yours makes it harder to undo, and ethereum.org describes PoW finality in exactly those terms: the more blocks mined on top, the higher the confidence a transaction will not be reversed3.
How does proof of stake work?
Proof of stake replaces the electricity race with collateral. On Ethereum, anyone who wants to help run the chain as a validator deposits 32 ETH into a deposit contract and runs three pieces of software: an execution client, a consensus client and a validator client4.
Time is cut into slots of 12 seconds, grouped into epochs of 32 slots4, so one epoch lasts 6.4 minutes. In every slot, one validator is chosen at random to propose a block, and a randomly chosen committee of validators votes on it; each vote is called an attestation4.
Figure · One Ethereum slot, simplified
- 01Random pickone proposer per slot
- 02Block proposedwithin a 12-second slot
- 03Committee votesattestations
- 04Finalitytwo-thirds of stake agrees
Blocks become final, meaning they cannot change without enormous cost, once a pair of checkpoints gathers votes from validators holding at least two-thirds of all staked ETH4. Validators that break the rules can be slashed, losing part of their stake; the penalty grows when many validators are slashed around the same time4.
What are the main differences between proof of work and proof of stake?
Proof of work and proof of stake side by side
| Proof of work | Proof of stake | |
|---|---|---|
| Scarce resource | Computing power and electricity | Coins locked as collateral |
| Who produces blocks | Miners racing to solve a puzzle1 | Validators picked at random4 |
| Entry cost | Specialised hardware and energy3 | A stake (32 ETH for an Ethereum validator)4 |
| Finality | Probabilistic: more blocks, more certainty3 | Explicit checkpoints backed by two-thirds of stake4 |
| Penalty for cheating | Wasted electricity on rejected blocks | Slashing of the deposit4 |
| Majority attack needs | Over half the network's mining power3 | Over half of all staked coins4 |
Ethereum's documentation lists proof of work's strengths as neutrality (you need no coins to start), a long track record and relative simplicity, and its weaknesses as heavy energy use, costly specialist equipment and a tendency for mining to concentrate in large pools3. For proof of stake it highlights better energy efficiency, lower hardware requirements and reduced centralisation risk4.
NIST adds a caution about proof of stake: participants with more coins can stake more and so earn more, though buying a controlling majority is usually prohibitively expensive2.
What changed when Ethereum switched to proof of stake?
Ethereum launched in 20156 using proof of work3 and later ran a separate proof-of-stake chain, the Beacon Chain, alongside it from 1 December 20205. On 15 September 2022, in an upgrade called The Merge, the original chain was joined to the Beacon Chain and mining stopped; validators took over block production5.
Figure · Ethereum's road to proof of stake
- Jul 2015Ethereum launches (Frontier)
- Dec 2020Beacon Chain starts in parallel
- Sep 2022The Merge: mining ends
- Apr 2023Staking withdrawals enabled
- May 2025Pectra raises validator balance cap
The energy effect was large. ethereum.org estimates that miners were using about 70 TWh a year shortly before the switch3, and that The Merge cut Ethereum's energy consumption by about 99.95%5.
Note
Two common myths about The Merge
The 32 ETH deposit is the entry ticket, not a cap. The Pectra upgrade on 7 May 2025 raised the maximum effective balance a single validator can have to 2,048 ETH6.
What mistakes do beginners make when comparing the two?
Common beginner mistakes
Treating staking rewards as safe income
Validators that break the rules can be slashed4, and the coin you stake can still fall in price. Rewards do not protect you from either.
Assuming proof of stake cannot be attacked
An attacker with a majority of the staked coins could still cause harm4; the defence is cost, not impossibility.
Believing mining "creates" value
Mining secures the ledger and issues new coins under fixed rules. It says nothing about what those coins are worth.
Mixing up the network and the platform
Staking through an exchange adds the platform's own risks on top of the protocol's. Check who holds your coins; our guide to crypto custody explains why it matters.
Risk warning
Staking puts your coins at risk
Locking coins to earn staking rewards exposes you to slashing penalties, price swings and, if you use a third-party service, the risk that the service fails. Never stake money you cannot afford to lose, and read our risk disclosure first.
Frequently asked questions
Does Bitcoin use proof of work or proof of stake?
Is proof of stake more secure than proof of work?
Can I still mine ether?
No. Since The Merge in September 2022, mining is no longer how Ethereum blocks are produced; validators do that job5.
What is a 51% attack?
It is an attempt to control which blocks are accepted by holding a majority of the key resource: computing power in proof of work or staked funds in proof of stake. NIST lists it as a risk for both models2.
Do I need 32 ETH to earn staking rewards?
Running your own Ethereum validator requires a 32 ETH deposit4. Pooled and exchange services accept smaller amounts but add their own risks, so read their terms carefully.
The bottom line
Proof of work and proof of stake answer the same question, who adds the next block, with different costs: electricity and hardware on one side, locked-up coins on the other. Ethereum's 2022 switch showed that a large network can change models and cut energy use sharply. Neither model is attack-proof, and staking carries real financial risk.
Sources
- Bitcoin: A Peer-to-Peer Electronic Cash System — Satoshi Nakamoto (whitepaper hosted at bitcoin.org), 2008 Primary source
- NIST IR 8202: Blockchain Technology Overview — National Institute of Standards and Technology, U.S. Department of Commerce, 2018 Primary source
- Proof-of-work (PoW) — ethereum.org developer documentation Primary source
- Proof-of-stake (PoS) — ethereum.org developer documentation Primary source
- The Merge — ethereum.org Primary source
- The history of Ethereum (network upgrades) — ethereum.org Primary source
How we checked this page: every figure above links to the numbered source it came from. Spotted an error? Tell the desk — see our editorial policy.
Read next
Tech · ExplainerHow does a blockchain work, and why is it so hard to change?A blockchain is a shared record book that thousands of computers keep in sync without a boss. Here is how the pieces fit together, from a single transaction to a chain of blocks.Assets · ProfileWhat is Ethereum, and what is ether actually for?Ethereum is a shared computer as much as a payment network. This profile explains how it runs, how ether is created and destroyed, and where things have gone wrong.
Assets · ProfileWhat is Bitcoin, and how does it work without a bank in charge?Bitcoin was the first cryptocurrency and is still the reference point for the rest. This profile sticks to what its founding documents and official sources actually say.
Markets · ExplainerWhat is the Bitcoin halving, and why does it happen every 210,000 blocks?Every 210,000 blocks, the number of new bitcoin paid to miners is cut in half. The rule is a few lines of code, and it is the reason Bitcoin's supply schedule is known decades in advance.
Finance · ExplainerWho really holds your crypto? Custody, keys and wallets explainedWith crypto, whoever controls the private key controls the asset. Custody is the question of who holds that key, and the answer decides what you can lose, and to whom.
Tech · ExplainerWhat are layer 2 rollups, and how do optimistic and ZK rollups differ?Rollups move most of the work off Ethereum's main chain but still lean on it for security. Here is how the two main designs work and what each asks you to trust.