Finance · Fintech · Crypto — explained

Bitfolio

An independent explainer desk · No ads · No affiliate links

TechExplainer

Proof of work vs proof of stake: how do blockchains agree on the next block?

Every public blockchain needs a way for strangers to agree on one history. Proof of work spends electricity to do it; proof of stake puts money up as collateral. Here is how each works and what the trade-offs are.

Rows of cryptocurrency mining devices connected by tangled cables
Photo: “Icarus Bitcoin Mining rig” by Xiangfu, CC BY-SA 4.0, via commons.wikimedia.org · Edited: duotone, cropped.

The short answer

Both decide who adds the next block. Proof of work makes miners race to solve a costly computing puzzle. Proof of stake has validators lock up coins as collateral that can be cut if they cheat. Bitcoin uses proof of work; Ethereum switched to proof of stake in 2022.

Key takeaways

  1. A consensus mechanism lets thousands of computers that do not trust each other agree on a single order of transactions.
  2. Proof of work makes block producers prove they spent computing effort; cheating means out-computing everyone else.
  3. Proof of stake makes block producers lock up coins; cheating can get that stake destroyed through penalties called slashing.
  4. Ethereum moved from proof of work to proof of stake on 15 September 2022, cutting its energy use by about 99.95% according to ethereum.org.
  5. Neither design is attack-proof: both can in theory be overpowered by someone who controls a majority of the key resource.

What problem do proof of work and proof of stake solve?

Digital money has an obvious weakness: a file can be copied. Without a referee, what stops someone from sending the same coin to two people? The Bitcoin paper calls this the double-spending problem, and its answer is a public, time-ordered record that everyone can check1. Our explainer on how a blockchain works covers that record. This page covers the harder question: who gets to write the next page?

The rule that answers it is called a consensus mechanism. NIST lists several, from proof of work and proof of stake to round robin and proof of authority2. Public cryptocurrencies mostly use the first two, because both let anyone take part without asking permission while making cheating expensive.

Figure · Two ways to make cheating expensive

Two ways to make cheating expensiveProof of workMiners spend electricity on puzzlesWinner of the race adds the blockAttack needs most of the computing powerProof of stakeValidators lock up coins as collateralProtocol picks who proposes the blockAttack needs most of the staked coins

Proof of work

  • Miners spend electricity on puzzles
  • Winner of the race adds the block
  • Attack needs most of the computing power

Proof of stake

  • Validators lock up coins as collateral
  • Protocol picks who proposes the block
  • Attack needs most of the staked coins

How does proof of work actually work?

In proof of work, computers called miners bundle waiting transactions into a candidate block and then search for a number, the nonce, that makes the block's hash meet a target. The Bitcoin paper describes this as finding a value whose SHA-256 hash begins with a required number of zero bits, by changing the nonce until one works1. ethereum.org calls this an intense race of trial and error3.

One round of mining, simplified

  1. 1

    Build a block

    The miner collects valid, unspent transactions into a candidate block1.

  2. 2

    Guess

    It changes the nonce and hashes the block again and again until the result meets the difficulty target1.

  3. 3

    Broadcast

    A miner that finds a valid result broadcasts the block, and other nodes accept it only if all its transactions are valid and unspent1.

  4. 4

    Get paid

    The block's first transaction creates new coins for its creator, and transaction fees can add to the reward1.

The network tunes the puzzle so blocks keep a steady pace. Bitcoin adjusts the difficulty every 2,016 blocks, aiming for about one block every ten minutes2; at that pace, 2,016 blocks take about 14 days. When two miners find blocks at once, nodes keep building on the longest chain1, and the shorter branch is abandoned.

Finality in proof of work is a matter of probability. Each new block on top of yours makes it harder to undo, and ethereum.org describes PoW finality in exactly those terms: the more blocks mined on top, the higher the confidence a transaction will not be reversed3.

How does proof of stake work?

Proof of stake replaces the electricity race with collateral. On Ethereum, anyone who wants to help run the chain as a validator deposits 32 ETH into a deposit contract and runs three pieces of software: an execution client, a consensus client and a validator client4.

Time is cut into slots of 12 seconds, grouped into epochs of 32 slots4, so one epoch lasts 6.4 minutes. In every slot, one validator is chosen at random to propose a block, and a randomly chosen committee of validators votes on it; each vote is called an attestation4.

Figure · One Ethereum slot, simplified

One Ethereum slot, simplified01Random pickone proposer perslot02Block proposedwithin a 12-secondslot03Committee votesattestations04Finalitytwo-thirds of stakeagrees
  1. 01Random pickone proposer per slot
  2. 02Block proposedwithin a 12-second slot
  3. 03Committee votesattestations
  4. 04Finalitytwo-thirds of stake agrees
Source: [4]

Blocks become final, meaning they cannot change without enormous cost, once a pair of checkpoints gathers votes from validators holding at least two-thirds of all staked ETH4. Validators that break the rules can be slashed, losing part of their stake; the penalty grows when many validators are slashed around the same time4.

What are the main differences between proof of work and proof of stake?

Proof of work and proof of stake side by side

Proof of workProof of stake
Scarce resourceComputing power and electricityCoins locked as collateral
Who produces blocksMiners racing to solve a puzzle1Validators picked at random4
Entry costSpecialised hardware and energy3A stake (32 ETH for an Ethereum validator)4
FinalityProbabilistic: more blocks, more certainty3Explicit checkpoints backed by two-thirds of stake4
Penalty for cheatingWasted electricity on rejected blocksSlashing of the deposit4
Majority attack needsOver half the network's mining power3Over half of all staked coins4

Ethereum's documentation lists proof of work's strengths as neutrality (you need no coins to start), a long track record and relative simplicity, and its weaknesses as heavy energy use, costly specialist equipment and a tendency for mining to concentrate in large pools3. For proof of stake it highlights better energy efficiency, lower hardware requirements and reduced centralisation risk4.

NIST adds a caution about proof of stake: participants with more coins can stake more and so earn more, though buying a controlling majority is usually prohibitively expensive2.

What changed when Ethereum switched to proof of stake?

Ethereum launched in 20156 using proof of work3 and later ran a separate proof-of-stake chain, the Beacon Chain, alongside it from 1 December 20205. On 15 September 2022, in an upgrade called The Merge, the original chain was joined to the Beacon Chain and mining stopped; validators took over block production5.

Figure · Ethereum's road to proof of stake

Ethereum's road to proof of stakeJul 2015Ethereum launches(Frontier)Dec 2020Beacon Chainstarts in parallelSep 2022The Merge: miningendsApr 2023StakingwithdrawalsenabledMay 2025Pectra raisesvalidator balancecap
  1. Jul 2015Ethereum launches (Frontier)
  2. Dec 2020Beacon Chain starts in parallel
  3. Sep 2022The Merge: mining ends
  4. Apr 2023Staking withdrawals enabled
  5. May 2025Pectra raises validator balance cap

The energy effect was large. ethereum.org estimates that miners were using about 70 TWh a year shortly before the switch3, and that The Merge cut Ethereum's energy consumption by about 99.95%5.

Note

Two common myths about The Merge

The Merge did not lower transaction fees; ethereum.org says it was never intended to and did not significantly change network capacity5. It also did not let stakers withdraw their ETH. Withdrawals came later, with the Shanghai/Capella upgrade on 12 April 20236.

The 32 ETH deposit is the entry ticket, not a cap. The Pectra upgrade on 7 May 2025 raised the maximum effective balance a single validator can have to 2,048 ETH6.

What mistakes do beginners make when comparing the two?

Common beginner mistakes

  1. Treating staking rewards as safe income

    Validators that break the rules can be slashed4, and the coin you stake can still fall in price. Rewards do not protect you from either.

  2. Assuming proof of stake cannot be attacked

    An attacker with a majority of the staked coins could still cause harm4; the defence is cost, not impossibility.

  3. Believing mining "creates" value

    Mining secures the ledger and issues new coins under fixed rules. It says nothing about what those coins are worth.

  4. Mixing up the network and the platform

    Staking through an exchange adds the platform's own risks on top of the protocol's. Check who holds your coins; our guide to crypto custody explains why it matters.

Risk warning

Staking puts your coins at risk

Locking coins to earn staking rewards exposes you to slashing penalties, price swings and, if you use a third-party service, the risk that the service fails. Never stake money you cannot afford to lose, and read our risk disclosure first.

Frequently asked questions

Does Bitcoin use proof of work or proof of stake?

Bitcoin uses proof of work, as set out in its original paper1, with mining difficulty adjusted every 2,016 blocks2.

Is proof of stake more secure than proof of work?

They make attacks expensive in different ways. On Ethereum, reverting a finalised block would cost an attacker at least one-third of all staked ETH4, while a proof-of-work attacker needs most of the mining power3. Which is "more secure" depends on the threat being considered.

Can I still mine ether?

No. Since The Merge in September 2022, mining is no longer how Ethereum blocks are produced; validators do that job5.

What is a 51% attack?

It is an attempt to control which blocks are accepted by holding a majority of the key resource: computing power in proof of work or staked funds in proof of stake. NIST lists it as a risk for both models2.

Do I need 32 ETH to earn staking rewards?

Running your own Ethereum validator requires a 32 ETH deposit4. Pooled and exchange services accept smaller amounts but add their own risks, so read their terms carefully.

The bottom line

Proof of work and proof of stake answer the same question, who adds the next block, with different costs: electricity and hardware on one side, locked-up coins on the other. Ethereum's 2022 switch showed that a large network can change models and cut energy use sharply. Neither model is attack-proof, and staking carries real financial risk.

Sources

  1. Bitcoin: A Peer-to-Peer Electronic Cash System — Satoshi Nakamoto (whitepaper hosted at bitcoin.org), 2008 Primary source
  2. NIST IR 8202: Blockchain Technology Overview — National Institute of Standards and Technology, U.S. Department of Commerce, 2018 Primary source
  3. Proof-of-work (PoW) — ethereum.org developer documentation Primary source
  4. Proof-of-stake (PoS) — ethereum.org developer documentation Primary source
  5. The Merge — ethereum.org Primary source
  6. The history of Ethereum (network upgrades) — ethereum.org Primary source

How we checked this page: every figure above links to the numbered source it came from. Spotted an error? Tell the desk — see our editorial policy.

Read next