{"id":18083,"date":"2026-03-08T18:23:07","date_gmt":"2026-03-08T18:23:07","guid":{"rendered":"https:\/\/cryptoted.net\/index.php\/2026\/03\/08\/finalized-no-31-ethereum-foundation-blog\/"},"modified":"2026-03-08T18:23:07","modified_gmt":"2026-03-08T18:23:07","slug":"finalized-no-31-ethereum-foundation-blog","status":"publish","type":"post","link":"https:\/\/cryptoted.net\/index.php\/2026\/03\/08\/finalized-no-31-ethereum-foundation-blog\/","title":{"rendered":"Finalized no. 31 | Ethereum Foundation Blog"},"content":{"rendered":"<p> <br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/blog.ethereum.org\/images\/posts\/upload_4dae2a4ab4b6c89615b4b5c624c04b52.jpg\" \/><\/p>\n<div id=\"\">\n<p class=\"chakra-text css-gi02ar\">This issue of <em class=\"chakra-text css-0\">Finalized<\/em> is dedicated to the contextualization of a recently <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/arxiv.org\/abs\/2110.10086#\">published paper<\/a> describing three possible attacks on Ethereum&#8217;s proof-of-stake algorithm.<\/p>\n<p class=\"chakra-text css-gi02ar\">tl;dr<\/p>\n<blockquote class=\"chakra-code css-gk0tva\">\n<p class=\"chakra-text css-gi02ar\">These are serious attacks with a formally-analyzed, technically-simple mitigation. A fix will be rolled out prior to the Merge and <em class=\"chakra-text css-0\">will not<\/em> delay Merge timelines.<\/p>\n<\/blockquote>\n<h2 class=\"chakra-heading group css-1kpzc4q\" id=\"forkchoice-attacks-mitigations-and-timelines\" data-group=\"true\"><a class=\"chakra-link css-128fqrf\" aria-label=\"forkchoice attacks mitigations and timelines permalink\" href=\"#forkchoice-attacks-mitigations-and-timelines\"><svg viewbox=\"0 0 24 24\" focusable=\"false\" class=\"chakra-icon css-173jpr1\"><g fill=\"currentColor\"><path d=\"M10.458,18.374,7.721,21.11a2.853,2.853,0,0,1-3.942,0l-.892-.891a2.787,2.787,0,0,1,0-3.941l5.8-5.8a2.789,2.789,0,0,1,3.942,0l.893.892A1,1,0,0,0,14.94,9.952l-.893-.892a4.791,4.791,0,0,0-6.771,0l-5.8,5.8a4.787,4.787,0,0,0,0,6.77l.892.891a4.785,4.785,0,0,0,6.771,0l2.736-2.735a1,1,0,1,0-1.414-1.415Z\"\/><path d=\"M22.526,2.363l-.892-.892a4.8,4.8,0,0,0-6.77,0l-2.905,2.9a1,1,0,0,0,1.414,1.414l2.9-2.9a2.79,2.79,0,0,1,3.941,0l.893.893a2.786,2.786,0,0,1,0,3.942l-5.8,5.8a2.769,2.769,0,0,1-1.971.817h0a2.766,2.766,0,0,1-1.969-.816,1,1,0,1,0-1.415,1.412,4.751,4.751,0,0,0,3.384,1.4h0a4.752,4.752,0,0,0,3.385-1.4l5.8-5.8a4.786,4.786,0,0,0,0-6.771Z\"\/><\/g><\/svg><\/a>Forkchoice attacks, mitigations, and timelines<\/h2>\n<p class=\"chakra-text css-gi02ar\">There has recently been quite a bit of chatter around a newly <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/arxiv.org\/abs\/2110.10086#\">published paper<\/a> co-authored by a team at Stanford and some EF researchers. This paper made public three liveness and reorg attacks on the beacon chain&#8217;s consensus mechanism <em class=\"chakra-text css-0\">without<\/em> providing any mitigations or any contextualization of what this means for Ethereum&#8217;s coming Merge upgrade. The paper was released in an effort to better facilitate review and collaboration before introducing fixes on mainnet. It failed however to provide context on impact and mitigations. This left room for uncertainty in ensuing discussions.<\/p>\n<p class=\"chakra-text css-gi02ar\">Let&#8217;s get to the bottom of it.<\/p>\n<h3 class=\"chakra-heading group css-xuzltg\" id=\"yes-these-are-serious-attacks-\ufe0f\" data-group=\"true\"><a class=\"chakra-link css-128fqrf\" aria-label=\"yes these are serious attacks \ufe0f permalink\" href=\"#yes-these-are-serious-attacks-\ufe0f\"><svg viewbox=\"0 0 24 24\" focusable=\"false\" class=\"chakra-icon css-173jpr1\"><g fill=\"currentColor\"><path d=\"M10.458,18.374,7.721,21.11a2.853,2.853,0,0,1-3.942,0l-.892-.891a2.787,2.787,0,0,1,0-3.941l5.8-5.8a2.789,2.789,0,0,1,3.942,0l.893.892A1,1,0,0,0,14.94,9.952l-.893-.892a4.791,4.791,0,0,0-6.771,0l-5.8,5.8a4.787,4.787,0,0,0,0,6.77l.892.891a4.785,4.785,0,0,0,6.771,0l2.736-2.735a1,1,0,1,0-1.414-1.415Z\"\/><path d=\"M22.526,2.363l-.892-.892a4.8,4.8,0,0,0-6.77,0l-2.905,2.9a1,1,0,0,0,1.414,1.414l2.9-2.9a2.79,2.79,0,0,1,3.941,0l.893.893a2.786,2.786,0,0,1,0,3.942l-5.8,5.8a2.769,2.769,0,0,1-1.971.817h0a2.766,2.766,0,0,1-1.969-.816,1,1,0,1,0-1.415,1.412,4.751,4.751,0,0,0,3.384,1.4h0a4.752,4.752,0,0,0,3.385-1.4l5.8-5.8a4.786,4.786,0,0,0,0-6.771Z\"\/><\/g><\/svg><\/a>Yes, these are serious attacks \u2694\ufe0f<\/h3>\n<p class=\"chakra-text css-gi02ar\">First of all let us make clear, these are <em class=\"chakra-text css-0\">serious<\/em> issues that, if unmitigated, threaten the stability of the beacon chain. To that end, it is critical that fixes are put in place prior to the beacon chain taking over the security of Ethereum&#8217;s execution layer at the point of the Merge.<\/p>\n<h3 class=\"chakra-heading group css-xuzltg\" id=\"but-with-a-simple-fix\" data-group=\"true\"><a class=\"chakra-link css-128fqrf\" aria-label=\"but with a simple fix permalink\" href=\"#but-with-a-simple-fix\"><svg viewbox=\"0 0 24 24\" focusable=\"false\" class=\"chakra-icon css-173jpr1\"><g fill=\"currentColor\"><path d=\"M10.458,18.374,7.721,21.11a2.853,2.853,0,0,1-3.942,0l-.892-.891a2.787,2.787,0,0,1,0-3.941l5.8-5.8a2.789,2.789,0,0,1,3.942,0l.893.892A1,1,0,0,0,14.94,9.952l-.893-.892a4.791,4.791,0,0,0-6.771,0l-5.8,5.8a4.787,4.787,0,0,0,0,6.77l.892.891a4.785,4.785,0,0,0,6.771,0l2.736-2.735a1,1,0,1,0-1.414-1.415Z\"\/><path d=\"M22.526,2.363l-.892-.892a4.8,4.8,0,0,0-6.77,0l-2.905,2.9a1,1,0,0,0,1.414,1.414l2.9-2.9a2.79,2.79,0,0,1,3.941,0l.893.893a2.786,2.786,0,0,1,0,3.942l-5.8,5.8a2.769,2.769,0,0,1-1.971.817h0a2.766,2.766,0,0,1-1.969-.816,1,1,0,1,0-1.415,1.412,4.751,4.751,0,0,0,3.384,1.4h0a4.752,4.752,0,0,0,3.385-1.4l5.8-5.8a4.786,4.786,0,0,0,0-6.771Z\"\/><\/g><\/svg><\/a>But with a simple fix \ud83d\udee1<\/h3>\n<p class=\"chakra-text css-gi02ar\">The good news is that two simple fixes to the forkchoice have been proposed &#8212; &#8220;proposer boosting&#8221; and &#8220;proposer view synchronization&#8221;. Proposer boosting has been formally analyzed by Stanford researchers (write-up to follow shortly), has been <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/github.com\/ethereum\/consensus-specs\/pull\/2353\">spec&#8217;d since April<\/a>, and has even been <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/twitter.com\/ajsutton\/status\/1455052275949342725\">implemented<\/a> in at least one client. <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/ethresear.ch\/t\/change-fork-choice-rule-to-mitigate-balancing-and-reorging-attacks\/11127\">Proposer view synchronization<\/a> also looks promising but is earlier in its formal analysis. As of now, researchers expect proposer boosting to land in the specs due to it&#8217;s simplicity and maturity in analysis.<\/p>\n<p class=\"chakra-text css-gi02ar\">At a high level, the attacks from the paper are caused by an over-reliance on the signal from attestations \u2014 specifically for a small number of adversarial attestations to tip an honest view in one direction or another. This reliance is for a good reason &#8212; attestations almost entirely eliminate <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/twitter.com\/casparschwa\/status\/1454511850821931017\">ex post<\/a> block reorgs in the beacon chain &#8212; but these attacks demonstrate that this comes at a high cost &#8212; <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/twitter.com\/casparschwa\/status\/1454511850821931017\">ex ante<\/a> reorgs and other liveness attacks. Intuitively, the solutions mentioned above tune the balance of power between attestations and block proposals rather than living at one end of the extreme or the other.<\/p>\n<p class=\"chakra-text css-gi02ar\">Caspar did an excellent job succinctly explaining both the attacks and proposed fixes. Check out <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/twitter.com\/casparschwa\/status\/1454511836267692039\">this twitter thread<\/a> for the best tl;dr you&#8217;ll find.<\/p>\n<h3 class=\"chakra-heading group css-xuzltg\" id=\"and-what-about-the-merge\" data-group=\"true\"><a class=\"chakra-link css-128fqrf\" aria-label=\"and what about the merge permalink\" href=\"#and-what-about-the-merge\"><svg viewbox=\"0 0 24 24\" focusable=\"false\" class=\"chakra-icon css-173jpr1\"><g fill=\"currentColor\"><path d=\"M10.458,18.374,7.721,21.11a2.853,2.853,0,0,1-3.942,0l-.892-.891a2.787,2.787,0,0,1,0-3.941l5.8-5.8a2.789,2.789,0,0,1,3.942,0l.893.892A1,1,0,0,0,14.94,9.952l-.893-.892a4.791,4.791,0,0,0-6.771,0l-5.8,5.8a4.787,4.787,0,0,0,0,6.77l.892.891a4.785,4.785,0,0,0,6.771,0l2.736-2.735a1,1,0,1,0-1.414-1.415Z\"\/><path d=\"M22.526,2.363l-.892-.892a4.8,4.8,0,0,0-6.77,0l-2.905,2.9a1,1,0,0,0,1.414,1.414l2.9-2.9a2.79,2.79,0,0,1,3.941,0l.893.893a2.786,2.786,0,0,1,0,3.942l-5.8,5.8a2.769,2.769,0,0,1-1.971.817h0a2.766,2.766,0,0,1-1.969-.816,1,1,0,1,0-1.415,1.412,4.751,4.751,0,0,0,3.384,1.4h0a4.752,4.752,0,0,0,3.385-1.4l5.8-5.8a4.786,4.786,0,0,0,0-6.771Z\"\/><\/g><\/svg><\/a>And what about the Merge? \u26d3<\/h3>\n<p class=\"chakra-text css-gi02ar\">Ensuring a fix is in place before the Merge is an <strong>absolute must<\/strong>. But there is a fix, and it is simple to implement.<\/p>\n<p class=\"chakra-text css-gi02ar\">This fix targets only the forkchoice and is therefore congruous with the Merge specs as written today. Under normal conditions, the forkchoice is the exact same as it is now, but in the event of attack scenarios the fixed version helps provide chain stability. This means that rolling out a fix does <em class=\"chakra-text css-0\">not<\/em> introduce breaking changes or require a &#8220;hard fork&#8221;.<\/p>\n<p class=\"chakra-text css-gi02ar\">Researchers and developers expect that by the end of November, proposer boosting will be integrated formally into the consensus specs, and that it will be live on the Merge testnets by mid-January.<\/p>\n<p class=\"chakra-text css-gi02ar\"><em class=\"chakra-text css-0\">Lastly, I want to give a huge shoutout to Joachim Neu, Nusret Ta\u015f, and David Tse &#8212; members of the <a target=\"_blank\" rel=\"noopener\" class=\"chakra-link css-vezwxf\" href=\"https:\/\/tselab.stanford.edu\/\">Tse Lab<\/a> at Stanford &#8212; as they have been <strong>invaluable<\/strong> in not only identifying, but remedying, the critical issues discussed above<\/em> \ud83d\ude80<\/p>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/blog.ethereum.org\/en\/2021\/11\/02\/finalized-no-31\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This issue of Finalized is dedicated to the contextualization of a recently published paper describing three possible attacks on Ethereum&#8217;s proof-of-stake algorithm. tl;dr These are serious attacks with a formally-analyzed, technically-simple mitigation. A fix will be rolled out prior to the Merge and will not delay Merge timelines. Forkchoice attacks, mitigations, and timelines There has [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":17933,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"tdm_status":"","tdm_grid_status":"","footnotes":""},"categories":[24],"tags":[],"kronos_expire_date":[],"class_list":["post-18083","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ethereum"],"_links":{"self":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18083","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/comments?post=18083"}],"version-history":[{"count":0,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/posts\/18083\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media\/17933"}],"wp:attachment":[{"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/media?parent=18083"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/categories?post=18083"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/tags?post=18083"},{"taxonomy":"kronos_expire_date","embeddable":true,"href":"https:\/\/cryptoted.net\/index.php\/wp-json\/wp\/v2\/kronos_expire_date?post=18083"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}