ZIP proposal: Proof of stake

I agree with @hdevalence.

Explicitly, in my role as a ZIP editor: I would love to see a developed version of this ZIP in a form that ECC and ZF could consider for adoption. We’ll need to develop the motivation, our assumptions about a staking ecosystem, our goals, and of course the (possibly novel!) economic and cryptographic mechanisms to achieve them.

Now, doffing the purple, star-spangled hat (h/t @mistfpga) of a ZIP editor for the sober black tricorn of the de facto ZF engineering roadmapper: despite this meeting the NU4 deadline, it seems unlikely to me that a design change of this size could happen in time for NU4. However, one way or another, by NU5 (~Q4 2020?) I think we’ll be in a solid position to evaluate a good PoS-for-Zcash design.

So we should try to have one by then! I’m definitely looking forward to investigating proof of stake for all kinds of reasons and 100% bless this endeavor. But I don’t think it’s time yet to adopt a specific ZIP for it.


Would be interested in contributing to the research and development, in the areas I’m familiar with.

I think compared to a a POS design this isn’t realy the case:

  • Limited hareware versus everybody can stake and secure the network.
  • Incentive to must sell ZEC with POW versus incentive to hold ZEC with POS.
  • Expensive electricity mining costs versus cheap POS staking costs.
  • Expensive hardware versus literally no hardware costs.
  • Middleman (Mining pools) in POW versus no middleman in POS.
  • Accumulating more hashpower (network centralization) in POS is rewarded as it makes it cheaper while accumulating more “POS” hashpower is sanctioned by making it more expensive.

I can not see a how POW is more straightforwarded in economics than a POS design and absolutly fail to see even one single economical benefit versus an alternative POS design.

True, it’s a battle tested, for some successfully for some it had an devastating outcome. Zcash is currently in the lucky position to be profitable and the top coin of it’s algo.

Just a reminder that the hourly attack cost on the Zcash network gets lower and lower, we are allready at $9,786 per hour for a 51% attack. If i remember right it was around $45,0000 15 months ago.

Taking the top 50 currencies by market cap there is only a handfull coins ~10 that use pure POW. ALL crypto projects that have driven us out from the Top 15 place we had in that rankings (we are currently #28) are POS projects. With every new successfull project being a POS design i doubt someone can really say it has not been around long enough.
Actually someone could say that the POW design has been around allready too long expect for BTC for which it makes perfect sense with an attack cost of nearly $1,000,000 per hour.

You mean after the dev fund has expired? (just kidding here). From an economical point of view it would have made most sense to use POS in the early stages to create an incentive to hold ZEC while the inflation is high IF someone wanted to create at least some incentive to hold ZEC and keep the price more stable instead of letting it fall endless. Of course creating later such incentive to hold will have an positive effect as well.

May main concern in waiting too long is simply competiton maybe outperformaing and overtaking us. I have zero doubt that at some point/time a lot of well established coins (no matter if POW/POS/whatever) will implent privacy featues. Once they begin to do this there will be even less incentive to hold ZEC. Someone should not forget that we are the top inflation coin for the next years as well.

@rebekah93, whist your zip seems straightforward, it is pretty complex the way it is written. Do you want to get this in for the NU4 deadline (I think you do?)

The foundation had commited to exploring this for a possible proof of work change sometime around October next year. However I haven’t seen any work releated to that done yet, except the foundation saying they wont do POS for 2 havlings yet (yes I am just as confused as you are)

ZIP’s are for the ECC - however I cannot hurt to put it in the mix to remind the foundation.

The key aspect of proof of work which at lot of people miss is that it is as much about securing the next work/processing transactions as it is about distributing coins to as many different people as possible (up to a certain point).

if POW is not doing its job in this regard and POS can be shown to be a better strategy for block distribution. I think it would get a lot of backers. - you don’t need to do this, but this is what it would take for that switch to happen before the next 2 halvingins (in my humble opinion)

Do you need any help fleshing out this proposal?



there are some interesting models/coins with pos in existence. imo however…

  • cost of attack is/was ovehyped problem. this was discussed as a major threat for years, yet still single digit number of valuable coins had been successfully attacked at given moment. it is indeed significant problem for abandoned coins. but living and strong networks are not static. they will retaliate. especially when a coin is a main player for it’s respected algo.
  • change of a whole nature of a coin is a huge mess to estimate benefits, losses, rewrite and rigorously test some codebase, etc. it can be researched/planned/considered when everything else is stable, valuation and media attention are flat, and not vice versa. didnt you see how “new blockchain to serve billions” mention/offer had immediate backfire after zcon1?
  • seems like almost everyone forgotten, that zcash has same inflation curve as btc. yeah, currently media sentiment is like “its overinflating”. but if this is a long game, and not just grab some situational clout with “we defeated inflation” (with completely wrecking coin’s fundamentals) - then it have to stay as is atm. its just one year till a far more significant inflation cut than btc will have with their next halvening.
  • if coins with strong fundamentals and “hard money” proposition have future at all, and not dystopian one as gambling tickers, including btc, then its much better for zcash with its strong idea, good fundamentals and absence of some technical and legacy problems, familiar to btc, to stay as is and polish all other primary and secondary issues till halvening, then reestimate where to go. instead of trying one more reckless leap of faith.
  • one of the merits of bitcoin’s success is that it survived all the disasters without jumping the horses on a full speed. zcash is not an utility token, it has similiar sov proposition. coin can not and will not be respected as a sov if it will bunnyhope following trends/trying to survive/aligning with some shoutouts.

These are for sure some valid points and argumens, but there are some other views and points as well:

I agree, and as we both said, as the top coin of a given algo it’s not a problem (yet). However, the cost of attack is an interesting measurement and i personally use it as some kind of libra.

  • If attack cost increases the network is more secure, more healthy, stronger.
  • If attack cost decreases the network gets more unsecure, more unhealthy, weaker.

I wouldn’t say it backfired but it caused huge confustion. The reason was in my opinion that it seems it was wrong published in media and second, the community wasn’t aware of anything like that. My pesonal opinion on this one is that it makes just sense. Why stick to a code that can’t be scaled, has very limited options for improvements, is far from perfect, outdated, slow, whatever? It just doesn’t make sense for me anyway, but that’s just my view. For Bitcoin it does, but than again, it’s Bitcoin, the only Bitcoin, we are an altcoin, an altcoin with 100’s of competitors.

It’s in my opinion ridiclous to compare and use the BTC inflation rate. Bitcoin used it without competition. There was no alternative coin, no competitor coin, no nothing. Nearly every supply curve would have worked for them. I actually would go as far as saying that even for BTC the curve was badly choosen, absolutly unfair and whatever not, but as a non BTC fan i don’t care too much about it.

As we have the same inflation it actually doesn’t matter If it’s POW or POS, the inflation would be the same. But POS at least would soften the effect of the inflation a bit and would give an incentive to hold ZEC, while POW does not have a single incentive to do so.

Sure, as you said, in the long game it gets leveled out and more attractive. I guess in 9 years it’s just ok to deal with the than way lower inflation. But funding and research happens with ZEC created bevor that. In generally if we take the ideal formula: more funds = more development, than the dev funds are in the worse possible time frame.

I like this argument most. It’s the most valid in my opinion and it’s an option for sure. But if we analyse it it contains some dangers in my opinion:

  • First, it’s Bitcoin like, another more or less copy & paste of Bitcoin to stay as much as possible “naturally”. It may work out, or may not work out, even for Bitcoin at some point.
  • Second, it might be too conservative. Competition with more aggresive, more innovative, more modern solutions might overtake Zcash overnight.
  • Third, maybe the most important one in my opinion. Adoption. Every POS design can involve the community more or less easy in staking, even more easy in future. While POW mining is literally a restiction for involving the community in this process. The best example is Zcash by switching form GPU to Asic mining, from 120k active adresses to some 25k, from an very active forum to a ghost town, from worldwider miners (with gpu) to some chinese and russian miners we even have no contact at all, neither someone from Zcash.

I would argue here, it’s because it’s competition less, because it’s the first comer, because it’s just that, Bitcoin. I’am pretty sure this will come some day to an end, there is no logic that this will continue forever. And the new winner or the coin that will replace BTC will not be a coin that is a tuned BTC but something more innovative, more useable, something that convinces the masses, something that’s easy and fast to use, something that doesn’t need special hardware, something that isn’t only for a few, something that combines the best what blockchain has to offer, something that is outstanding and not just old fashioned copy & paste. Does this sound like Zcash? No. But having Zcash one of the best teams it could be Zcash as it could be as well a total new player. In that case we more or less would have wasted huge amounts of funding for … nothing.

i agree that my comparisons with bitcoin are not bulletproof, because it was first-mover, different eras and markets. i’ve already noticed in my previous comments here some time ago that there are too significant discrepancies in an overal crypto environment and ecosystem between bitcoin and zcash early years, and that zcash can’t/couldnt afford to move as slow and stubborn as bitcoin could. in my last comment i wanted to place an accent, that to put more efforts to improve/finalize current model and to (re)build confidence - will have more benefits and more feasible to do reclaim/increase value of zcash, then to try to hop on different model like “lets throw away what we have and build from scratch, maybe it will work out”. again, we’re talking not about software, but about an asset. imho ofc, but i’d wanted to challenge founder’s vision of zcash, i’d just moved to another coin.)

p.s.: “lets throw away what we have and build from scratch, maybe it will work out” can actually work out with declining market in one single case. with venture capital backing and some reason to transfer value to new asset. like airdrop of new zstackedcash asset to zcash holders with initial price support of new asset. or without change of asset title, but anyway with price support period. without that, market will not apreciate pow>pos trantition in any organic way, except maybe for a very short period of time, depending on market cycle. but that’s a completely different story, not corellated with firm official position of zcash not to fall in complete dependence from third parties.

1 Like

I agree with Arktor. That miners selling coin is not a bad thing and that few people holding large number of coins maybe bad


Why does introducing proof of stake mean removing proof of work? The two can quite happily co-exist. Has any implementation for proof of stake been put forward, clone or not for the Zcash base?

1 Like

Nope. The Zcash community is basically waiting for Ethereum to implement their POS, learn from them (both the good and bad) and then decide after careful consideration.