Proof of work vs proof of stake
Every public blockchain needs a way for strangers to agree on one history. Bitcoin pays in electricity; Ethereum pays in locked-up coins.
Logos are trademarks of their respective owners, shown for identification only. Their use does not imply endorsement. Licences.

On this page
- Why does a blockchain need a consensus mechanism?
- How does proof of work choose the next block?
- How does proof of stake choose the next block?
- What are the key differences between proof of work and proof of stake?
- Why did Ethereum switch from proof of work to proof of stake?
- What mistakes do beginners make about proof of work and proof of stake?
- Questions readers ask
- Sources
- Proof of work and proof of stake are consensus mechanisms: rules that let thousands of computers agree on one shared ledger without a central referee.
- In proof of work, miners spend computing power and electricity hunting for a hash below a target; Bitcoin aims for one block about every 10 minutes.
- In proof of stake, validators lock up coins as collateral; on Ethereum each validator deposits 32 ETH and can lose part of it for provable misbehavior.
- Ethereum moved from proof of work to proof of stake on September 15, 2022; ethereum.org estimates its energy use fell by about 99.95%.
- Neither design is free of trade-offs: proof of work leans on hardware and energy, proof of stake on capital and more complex rules.
Both decide who adds the next block to a blockchain. Proof of work picks whoever first solves a costly computing puzzle, so security comes from spent electricity. Proof of stake picks validators who have locked up coins, so security comes from capital that can be destroyed if they cheat.
Why does a blockchain need a consensus mechanism?
A blockchain is a ledger copied across thousands of computers that do not know or trust each other. Anyone can broadcast a transaction, and anyone could try to broadcast a conflicting one — for example, spending the same coin twice. The network needs a rule for deciding which block of transactions gets added next, and for making that decision expensive to fake.
That rule is the consensus mechanism. It answers three questions: who is allowed to propose the next block, how everyone else checks it, and what an attacker would have to give up to rewrite history. Proof of work (PoW) and proof of stake (PoS) answer the third question in opposite ways. One makes cheating cost energy that has already been burned; the other makes cheating cost collateral that can be taken away.
How does proof of work choose the next block?
The Bitcoin whitepaper describes the process in six steps. New transactions are broadcast; each node gathers them into a candidate block; nodes race to find a valid proof of work; the winner broadcasts its block; others accept it only if every transaction is valid and unspent; and they show acceptance by building the next block on top of it.
The "work" is a guessing game. A miner repeatedly changes a small number in the block header, called a nonce, and runs the header through the SHA-256 hash function. A block counts only if the resulting hash is below a target set by the network. There is no shortcut: finding one means trying enormous numbers of guesses. Bitcoin Core sets the target spacing at 10 minutes and resets difficulty every 2,016 blocks so the average stays near that pace. We walk through the full process in how Bitcoin mining works.
Nodes follow the chain with the most accumulated work. To rewrite past blocks, an attacker would have to redo their work and then outpace everyone else, which the developer documentation says requires a majority of the network's hashing power.

How does proof of stake choose the next block?
Proof of stake replaces the guessing race with a lottery among people who have posted collateral. ethereum.org describes it as a way to prove that validators have put something of value into the network that can be destroyed if they act dishonestly.
On Ethereum, a validator deposits 32 ETH into a deposit contract and runs the required software. Time is cut into slots of 12 seconds and epochs of 32 slots. In each slot one validator is chosen at random to propose a block, and a randomly selected committee of other validators votes on, or "attests" to, whether it is valid. When validators holding at least two-thirds of all staked ETH vote for the same checkpoint pair, the earlier checkpoint becomes finalized — reversing it would require destroying a large amount of stake.
Validators who go offline lose small amounts; validators who sign contradictory messages can be slashed, meaning part of their deposit is destroyed and they are removed. ethereum.org notes slashing ranges from under 0.1% of a validator's balance in isolated cases to 100% when many validators misbehave together. For how ordinary holders take part, see what is staking.
What are the key differences between proof of work and proof of stake?
The table below compares the two designs as they run on Bitcoin and Ethereum today. Figures come from the Bitcoin Core source code, the Bitcoin developer guide and ethereum.org.
| Question | Proof of work (Bitcoin) | Proof of stake (Ethereum) |
|---|---|---|
| Who writes the next block? | The first miner to find a hash below the target | A validator picked at random for each 12-second slot |
| What does it cost to take part? | Mining hardware and electricity | 32 ETH locked per validator, plus a computer running the software |
| What does an attacker need? | A majority of network hash power to rewrite history reliably | 33% of stake to stall finality; 51% to steer the chain; 66% to finalize checkpoints alone |
| How is cheating punished? | Indirectly: wasted energy and a block other nodes reject | Directly: penalties and slashing of the deposit |
| When is a payment settled? | Probabilistically; each new block on top makes reversal harder | Explicit finality once two-thirds of stake confirm a checkpoint |
| Energy profile | High by design | ethereum.org estimates a 99.95% drop after the switch |
ethereum.org also lists PoW's strengths: anyone can start mining without owning the coin first, and the model has a long security record. Its weaknesses are heavy energy use, costly specialized equipment and the risk that mining pools concentrate power. Proof of stake has its own weak spot: stake can pile up with a few large providers, a risk ethereum.org itself flags on its staking pools page, warning that it creates conditions for censorship and single points of failure.
Why did Ethereum switch from proof of work to proof of stake?
Ethereum launched with proof of work. In December 2020 it started a separate proof-of-stake chain, the Beacon Chain, and ran the two side by side. On September 15, 2022, in an upgrade called The Merge, the original chain's transactions moved onto the proof-of-stake system and mining on Ethereum ended. ethereum.org estimates the network's energy consumption dropped by about 99.95%.
Bitcoin still uses proof of work, and the choice remains a live debate in crypto. Which trade-off is "better" depends on what you value — open entry and physical cost, or efficiency and explicit finality — and the blockchain trilemma explains why no design maximizes everything at once.

What mistakes do beginners make about proof of work and proof of stake?
- Thinking miners or validators can create any transaction they like. They choose the order and contents of a block, but every node checks the rules. A block with an invalid transaction is simply rejected.
- Assuming "51% attack" means the same thing in both systems. In PoW it is about hash power; in PoS the thresholds are about stake, and different shares enable different attacks (33%, 51%, 66%).
- Believing proof of stake means anyone holding coins earns rewards automatically. Rewards go to validators doing the work, and they carry penalties and slashing risk.
- Treating a single confirmation as final on a PoW chain. Settlement strengthens with each block added on top; services usually wait for several.
- Expecting a consensus change to make fees cheaper. The Merge shows it does not by itself.
Questions readers ask
Is proof of stake less secure than proof of work?
They secure the chain with different resources. PoW asks an attacker to out-compute the network; PoS asks an attacker to acquire and risk a large share of the staked coins, which can be destroyed by slashing. Each has its own attack models and trade-offs.
Does Bitcoin plan to move to proof of stake?
Bitcoin runs on proof of work, and its rules can only change if the network's users and node operators adopt new software. There is no adopted plan to switch.
Can I mine Ethereum today?
No. ethereum.org states that proof of work has been deprecated and Ethereum no longer uses it. Taking part in Ethereum's consensus now means staking ETH.
Do I need to run a node to understand either system?
No, but running one lets you verify the rules yourself. See what is a blockchain node.
Proof of work and proof of stake solve the same problem — agreeing on one history among strangers — by making cheating expensive in different currencies: burned energy or forfeitable collateral. Bitcoin chose the first, Ethereum switched to the second in 2022. Understanding which one a network uses tells you who controls block production and what an attacker would have to risk.
Sources
- Satoshi Nakamoto (bitcoin.org), Bitcoin: A Peer-to-Peer Electronic Cash System (2008)Primary source
- Bitcoin Project (developer.bitcoin.org), Bitcoin Developer Guide: Block Chain (2024)Primary source
- Bitcoin Core, Bitcoin Core source code: mainnet chain parameters (src/kernel/chainparams.cpp) (2026)Primary source
- ethereum.org, Proof-of-stake (PoS) (2025)Primary source
- ethereum.org, Proof-of-work (PoW) (2025)Primary source
- ethereum.org, The Merge (2025)Primary source
- ethereum.org, Pooled staking (2025)Primary source
Educational content only — not financial, investment, legal or tax advice. Crypto-assets are high-risk and you could lose all the money you put in. Rules differ by country; check with your national regulator. See our risk disclosure and editorial policy.



