This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

    • Learn more about this provideropens in a new window
      CookieConsentStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • Learn more about this provideropens in a new window
      bcookieUsed in order to detect spam and improve the website's security.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      li_gcStores the user's cookie consent state for the current domain
      Maximum Storage Duration: 180 daysType: HTTP Cookie
    • Learn more about this provideropens in a new window
      datadomeUsed in context with the website's BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • _pk_testcookie_domainThis cookie determines whether the browser accepts cookies.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • __cf_bm [x3]This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of their website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • Learn more about this provideropens in a new window
      lidcRegisters which server-cluster is serving the visitor. This is used in context with load balancing, in order to optimize user experience.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • Learn more about this provideropens in a new window
      guestRegisters data on visitors' website-behaviour. This is used for internal analysis and website optimization.
      Maximum Storage Duration: 1 monthType: HTTP Cookie
    • Learn more about this provideropens in a new window
      personalization_idThis cookie is set by Twitter - The cookie allows the visitor to share content from the website onto their Twitter profile.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
    • _pk_uidUsed by Piwik Analytics Platform to identify the visitor on repeat visits to the website.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      _pk_id#Collects statistics on the user's visits to the website, such as the number of visits, average time spent on the website and what pages have been read.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      _pk_ses#Used by Piwik Analytics Platform to track page requests from the visitor during the session.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • FPGSIDRegisters statistical data on users' behaviour on the website. Used for internal analytics by the website operator.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      FPIDRegisters statistical data on users' behaviour on the website. Used for internal analytics by the website operator.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      FPLCRegisters a unique ID that is used to generate statistical data on how the visitor uses the website.
      Maximum Storage Duration: 1 dayType: HTTP Cookie
    • _gaRegisters a unique ID that is used to generate statistical data on how the visitor uses the website.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
      _ga_#Used by Google Analytics to collect data on the number of times a user has visited the website as well as dates for the first and most recent visit.
      Maximum Storage Duration: 2 yearsType: HTTP Cookie
  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • Learn more about this provideropens in a new window

      Some of the data collected by this provider is for the purposes of personalization and measuring advertising effectiveness. The provider may use the IP Addresses for ads measurement and ads personalization.

      ads/ga-audiencesUsed by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor's online behaviour across websites.
      Maximum Storage Duration: SessionType: Pixel Tracker
    • Learn more about this provideropens in a new window
      userRefererDetermines how the user accessed the website. This information is used by the website operator in order to measure the efficiency of their marketing.
      Maximum Storage Duration: 1 monthType: HTTP Cookie
    • Learn more about this provideropens in a new window
      #:session-dataTracks the individual sessions on the website, allowing the website to compile statistical data from multiple visits. This data can also be used to create leads for marketing purposes.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      eng_mtTracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      t_gidThis cookie assigns a specific visitor ID, when the visitor interacts with ads or content from the website - this allows the website to target the visitor with similar ads or content.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      t_pt_gidCollects information on user preferences and/or interaction with web-campaign content - This is used on CRM-campaign-platform used by website owners for promoting events or products.
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      taboola global:user-idSets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers.
      Maximum Storage Duration: PersistentType: HTML Local Storage
      taboola_session_idThis cookie is used to collect information on a visitor. This information will become an ID string with information on a specific visitor – ID information strings can be used to target groups with similar preferences, or can be used by third-party domains or ad-exchanges.
      Maximum Storage Duration: SessionType: HTTP Cookie
    • Learn more about this provideropens in a new window
      1/i/adsct [x2]Collects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
      Maximum Storage Duration: SessionType: Pixel Tracker
      muc_adsCollects data on user behaviour and interaction in order to optimize the website and make advertisement on the website more relevant.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_idCollects data related to the user's visits to the website, such as the number of visits, average time spent on the website and which pages have been loaded, with the purpose of personalising and improving the Twitter service.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_id_adsCollects information on user behaviour on multiple websites. This information is used in order to optimize the relevance of advertisement on the website.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
      guest_id_marketingCollects information on user behaviour on multiple websites. This information is used in order to optimize the relevance of advertisement on the website.
      Maximum Storage Duration: 400 daysType: HTTP Cookie
    • _gcl_auUsed by Google AdSense for experimenting with advertisement efficiency across websites using their services.
      Maximum Storage Duration: 3 monthsType: HTTP Cookie
      _gcl_lsTracks the conversion rate between the user and the advertisement banners on the website - This serves to optimise the relevance of the advertisements on the website.
      Maximum Storage Duration: PersistentType: HTML Local Storage
    • pardot [x2]Used in context with Account-Based-Marketing (ABM). The cookie registers data such as IP-addresses, time spent on the website and page requests for the visit. This is used for retargeting of multiple users rooting from the same IP-addresses. ABM usually facilitates B2B marketing purposes.
      Maximum Storage Duration: SessionType: HTTP Cookie
  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • cs_analytics_ip_blockedPending
      Maximum Storage Duration: SessionType: HTTP Cookie
      user_tokenPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
    • _twpidPending
      Maximum Storage Duration: SessionType: HTTP Cookie
Cookie declaration last updated on 8/20/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
Image Staking and Protocol Security: The Backbone of Blockchain Safety

Staking and Protocol Security: The Backbone of Blockchain Safety

Timer8 min read

  • Technology

Consensus mechanisms play a crucial role in blockchain technology given its decentralised nature. They validate transactions, ensure the entire network shares the same ledger and protect against attacks by incentivising responsible behaviour among participants.

One of the most commonly used consensus mechanisms is proof of stake (PoS). This article explores PoS through the lens of Ethereum, the second-largest protocol by market capitalisation, and explains how it secures the network.

Basics of Blockchain Security

Three principles underpin blockchain security:

  • Immutability: nobody can change or modify transactions processed and recorded on a blockchain. Each block contains a hash- a fixed-length string created by a cryptographic algorithm- representing all of its transactions and those stored in the previous block.  

  • Decentralised: no single authority controls the network. Participants known as nodes are responsible for validating and keeping a record of transactions. Even if multiple nodes fail, the network can continue operating.   

  • Consensus: the whole network must agree on the latest state of the ledger, achieved using a consensus mechanism.

A PoS consensus mechanism requires nodes called validators to ‘stake’ (lock up in a smart contract) a specific amount of a protocol’s native token for the chance to be randomly selected to process the next block of transactions. The higher the size of a validator’s stake, the greater its odds of getting selected. Other nodes called attesters confirm the validity of each block.  

Ethereum switched from a proof of work (PoW) mechanism to PoS in September 2022. The main reason for the Merge, as the crypto community dubbed it, was to improve scalability and reduce the protocol’s energy consumption. The minimum stake for validators on Ethereum is 32 ether, and the network uses a random number generator algorithm to select a new validator every 12 seconds. 

Security Mechanisms in Ethereum 2.0

Ethereum incentivises good behaviour by paying block rewards, which validators earn for participating in the consensus mechanism and securing the network. They’re paid in proportion to the balance of a validator’s stake and come in two forms:   

  • The protocol pays consensus rewards to validators, attesters and ‘sync committees’ which ensure all nodes have the latest version of the ledger. These rewards are the primary source of newly issued ether.  

  • Validators earn execution rewards through transaction fees, known as gas fees, tips paid by users to encourage validators to include their transaction in the next block, and for fulfilling maximal extractable value requests to include, exclude or reorder transactions in a block.

Learn about Ethereum staking yields.

The protocol also penalises validators to discourage misbehaviour. Nodes pay minor penalties for being offline but more severe offences can lead to ‘slashing’, where a portion of a validator’s stake, starting at one ether, is removed from circulation or ‘burned’. These penalties can ultimately cost a validator its entire stake.

Three offences warrant slashing:  

  • Proposing and signing two different blocks in the same slot (the 12-second window during which a validator proposes a new block of transactions)

  • Attesting a block that contradicts the records held in an earlier block 

  • Attesting two different blocks for one slot

To discourage collusion, the network may impose a further penalty if a number of validators commit the same offense within a few days.

Enhancing Security in Ethereum 2.0

Two metrics used to measure a PoS mechanism’s decentralisation, and therefore its security, are validator numbers and the percentage of its native token’s total circulating supply that is staked (networks with a higher percentage are harder to hack). According to data analyst Dune, Ethereum has 1,074,669 validators (as of 10th of September 2024) and the number has steadily risen since the Merge. Dune also estimates that 28,07% of the circulating supply of ether is staked (as of 10th of September 2024).

Compared with other PoS blockchains, Ethereum is highly decentralised in terms of validator numbers, although it ranks low based on the percentage of native tokens staked.

PoS Blockchains Decentralisations MetricsAnother way Ethereum maintains security is by regularly updating the network. The latest upgrade, Dencun, which activated in March 2024, addressed scalability and efficiency. It implemented several Ethereum Improvement Proposals (EIPs), a key element of the protocol’s governance framework as community members submit, discuss and come to a consensus about their implementation. The most important of these proposals was EIP-4844, which introduced proto-danksharding, the first step in adding ‘blobs’ to blocks.

Ethereum also conducts regular audits to test the network’s security. It recently partnered with Web3 bug bounty platform Immunefi to offer a reward pool of over $500,000 to researchers who could detect weaknesses in the protocol.   

Addressing Common Misconceptions

One criticism levelled at PoS is that a few well-resourced validators can dominate the consensus mechanism, increasing the network’s centralisation. However, 32 ether is both Ethereum’s minimum and maximum stake. As a result, even the biggest participants, such as Lido (a staking pool accounting for 28,37% of ether staked as of 10th of September 2024) must set up multiple validators, which promotes decentralisation.

This cap also ensures an even distribution of rewards over time. Unlike bitcoin’s PoW consensus mechanism, which requires costly computing power, Ethereum’s PoS protocol is more of a level playing field. The barriers to entry in terms of computing resources are low, and validators receive rewards proportional to the cap, regardless of the size of their overall holdings. Furthermore, the rewards are based on a standard of performance that’s relatively easy to achieve: behaving responsibly (unpenalised validators have a better chance of getting selected) and maintaining uptime. 

Conclusion

Ethereum is the highest-profile PoS protocol, having transitioned from PoW in September 2022. Validators must stake 32 ether for the right to be randomly selected to process transactions. In return, they receive block rewards proportional to the value of their stake. The protocol also penalises bad behaviour.

Decentralisation is key to Ethereum’s security. Compared with rival PoS protocols, it ranks highly in the number of validators but relatively low in terms of the percentage of ether staked, two metrics for measuring decentralisation. Other ways Ethereum maintains security include regular network upgrades and audits. 

One of the main criticisms levelled at Ethereum is the potential centralisation caused by a few dominant validators. But the 32 ether cap serves as a counterbalance, while also ensuring a fair distribution of rewards.

Published onSept 10th, 2024

Writer
CoinShares Author Logo
CoinShares

Welcome to CoinShares

Personal Data

0102

When you visit CoinShares website, cookies enhance your experience. They help us to show you more relevant content. Some cookies are necessary for the site to work and will always be active. Blocking some types of cookies may impact your experience of the website and the services which we offer on our website.

We use cookies on our site to optimize our services. Learn more about our EU cookie policy or US cookie policy.

  • Necessary
    Question circle icon
  • Preferences
    Question circle icon
  • Statistical
    Question circle icon
  • Marketing
    Question circle icon

Don't invest unless you're prepared to lose all the money you invest. This is a high-risk investment, and you should not expect to be protected if something goes wrong. Take 2 mins to learn more. Approved by Archax 19/12/2025

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.