RADIX WikiRADIX Wiki

Overview

Byzantine Fault Tolerance (BFT) is the property of a distributed system that enables it to reach consensus even when up to one-third of participating nodes are malicious, unresponsive, or sending conflicting information. The name comes from the Byzantine Generals Problem – a thought experiment about coordinating military strategy when some generals may be traitors.

All secure blockchain consensus protocols must be BFT. Radix's Cerberus is a BFT protocol specified to braid consensus across shards, so that fault tolerance and atomic composability survive sharding together. Mainnet runs it as a single unsharded instance, where the braiding machinery has nothing to braid.

The Byzantine Generals Problem

The concept was formalised in the 1982 paper The Byzantine Generals Problem by Leslie Lamport, Robert Shostak, and Marshall Pease. It frames distributed agreement as a group of generals besieging a city who can coordinate only by messenger: they must agree on a single plan of attack, yet some generals – or their messengers – may be traitors sending contradictory orders. A protocol is Byzantine fault tolerant if the loyal generals still reach the same decision despite this arbitrary, adversarial behaviour.

In a blockchain the "generals" are validator nodes and the "plan" is the ordering of transactions. A Byzantine fault is the strongest failure model: it covers not just crashed or slow nodes but nodes that actively lie, equivocate, or collude.

The One-Third Threshold

Classical BFT protocols tolerate faults among strictly fewer than one-third of participants – a system of 3f + 1 nodes stays safe and live with up to f Byzantine nodes. Below that bound the honest supermajority can always outvote any malicious faction and any two quorums are guaranteed to overlap in at least one honest node, which prevents two conflicting decisions from both being finalised.

This is why validator decentralisation matters: security rests on no single entity controlling a third of the effective voting weight. On Radix that weight is stake-weighted, so it tracks staked XRD rather than a raw node count.

Byzantine Fault Tolerance in Radix

Radix's Cerberus is a BFT protocol in the HotStuff family – a leader-based, partially-synchronous design that reaches finality in a linear message pattern. In its unsharded form Cerberus behaves like standard HotStuff; its stated innovation is braiding many parallel consensus instances so that a single transaction touching multiple shards is agreed atomically. The intent is to keep the classic one-third fault tolerance while preserving atomic composability across a sharded state space – the property most sharded designs give up.

That second half remains a specification. Mainnet runs one shard group covering the whole ledger, which the node’s own README describes as a variant implementation of the HotStuff BFT-style consensus, and the braided cross-shard protocol has never run in production on Radix or anywhere else. The Xi’an production candidate does not braid either: it commits per shard with a two-chain HotStuff-2 protocol, its lead developer having argued that braiding makes shards co-dependent for liveness. The one-third bound described above is the part that holds in every case; it is a property of the BFT family, not of braiding.

HydrateLast updated Sep 9, 2026v1.4.06 revisionsVerified Sep 9, 2026