RADIX WikiRADIX Wiki

The Honest Majority Assumption is a critical security premise that underlies Proof-of-Work (PoW) and Proof-of-Stake (PoS) Sybil defense mechanisms. The assumption states that at any given time, a majority of the mining or staking power in the network is controlled by honest participants who follow the protocol rules correctly.

Overview

In PoW blockchains like Bitcoin, the assumption is that honest miners controlling the majority of the network's collective hashing power will outpace any minority of malicious miners trying to revise the blockchain history. Similarly, in PoS blockchains, the assumption is that at least two-thirds of the staked cryptocurrency is controlled by honest validators who will refuse to validate conflicting blockchain histories.

This assumption allows the decentralized consensus mechanism to resist attacks and censorship attempts by any dishonest minority of participants. As long as the assumption holds true, the chain's canonical transaction history remains immutable and indisputable. However, if the assumption is violated and honest participants no longer control a majority of mining/staking power, malicious actors can begin disrupting consensus and the fundamental guarantees provided by the chain.

Assumption Details

The honest majority assumption is a fundamental security requirement for both Proof-of-Work (PoW) and Proof-of-Stake (PoS) consensus mechanisms used in blockchains:

Maintaining an honest majority among consensus participants is critical because it prevents adversaries from disrupting the decentralized consensus process. This enables key properties like censorship resistance, where no single entity can arbitrarily censor or reverse transactions, and immutability, where the blockchain's transaction history cannot be unilaterally rewritten. Violations of the honest majority undermine these security guarantees that make blockchains robust and decentralized.

Challenges to the assumption

Research has questioned both whether participants have a reason to behave honestly and whether an honest majority is enough.

Incentives. Formal analyses of Bitcoin conclude that it is secure if and only if most of its mining power is honest, without saying why real miners would behave that way. Christian Badertscher, Juan Garay, Ueli Maurer, Daniel Tschudi and Vassilis Zikas take up that question using rational protocol design, a framework that treats security as a game between the protocol's designer and an attacker trying to maximise its own payoff. They show that if miners are rewarded for adding blocks and pay for the computation they spend, the honest-majority assumption can be kept as a fallback or, for some applications, replaced by the assumption that miners want to maximise their revenue.

Selfish mining. Ittay Eyal and Emin Gün Sirer showed in 2013 that a majority is not enough, because Bitcoin's protocol is not incentive-compatible: it does not reward a miner for following it as written. A colluding pool can keep the blocks it finds private, extend its own branch in secret, and publish that branch when the public chain draws level, so that the honest miners' competing blocks are thrown away. The pool then earns more than its share of the mining power, rational miners prefer to join it, and it grows towards a majority. The attack works for a pool of any size under the protocol as it stood; the authors proposed a change that protects against pools with less than a quarter of the mining power.

Eclipse attacks. Mining power is not the only resource an attacker can use. Ethan Heilman, Alison Kendler, Aviv Zohar and Sharon Goldberg showed that an attacker controlling enough IP addresses can monopolise every connection to and from a victim Bitcoin node, so that the victim sees only what the attacker relays. An eclipsed node can then be used for double spends against payments it considers confirmed, for selfish mining, and to create adversarial forks of the chain. The authors reported their results to the Bitcoin developers in February 2015, and three of their countermeasures shipped in bitcoind 0.10.1.

The verifier's dilemma. An honest majority also has to check what it builds on. Loi Luu, Jason Teutsch, Raghav Kulkarni and Prateek Saxena showed that when a script or contract takes nontrivial computation to verify, the time a miner spends verifying is lost from the race to find the next block, so rational miners are well incentivised to accept blocks without validating them. They call this the verifier's dilemma, and describe attacks that exploit it either to waste honest miners' computation or to get incorrect script results accepted. The paper points to 4 July 2015, when large Bitcoin pools built on blocks containing invalid transactions without verifying them and forked the chain.

Long-range attacks on proof of stake. In proof of stake the majority is counted in stake, and a naive design lets an attacker rewrite history from far back. Vitalik Buterin described in 2014 how an attacker holding 1% of coins at or shortly after the genesis block could start a private chain from there: selected to produce only 1% of blocks, it could still produce 100 times as many and build a longer chain. He proposed two defences: clients reject chains whose timestamps run far ahead of their own clock, so that the attacking chain has to fit into the same span of time, where its small stake gives it a lower score; or the protocol requires a fixed share of all coins, such as 30%, to endorse blocks.

In Radix

Radix secures its network with delegated Proof of Stake: XRD holders stake to validator nodes, and consensus weight is proportional to stake. The honest-majority premise therefore reduces to an economic one – the bulk of staked XRD must sit behind validators that follow the protocol.

The Cerberus consensus that Radix runs is a Byzantine fault tolerant protocol, so its threshold is the classical BFT bound: the network preserves safety and liveness as long as fewer than one-third of the stake-weighted validators are Byzantine (equivalently, more than two-thirds are honest). This is a stronger, more explicit guarantee than the >50% margin a Nakamoto-style chain relies on, and it is the same one-third fault ceiling that Hyperscale preserves as it scales consensus across shard groups.

References

  1. Badertscher, Christian; Garay, Juan; Maurer, Ueli; Tschudi, Daniel and Zikas, Vassilis (2018). But Why Does It Work? A Rational Protocol Design Treatment of Bitcoin. EUROCRYPT 2018; revised version in the Cryptology ePrint Archive, 2018/138.
  2. Buterin, Vitalik (2014). Long-Range Attacks: The Serious Problem With Adaptive Proof of Work. Ethereum Foundation Blog.
  3. Eyal, Ittay and Sirer, Emin Gün (2013). Majority is not Enough: Bitcoin Mining is Vulnerable. Financial Cryptography 2014; preprint arXiv:1311.0243.
  4. Heilman, Ethan; Kendler, Alison; Zohar, Aviv and Goldberg, Sharon (2015). Eclipse Attacks on Bitcoin's Peer-to-Peer Network. 24th USENIX Security Symposium.
  5. Luu, Loi; Teutsch, Jason; Kulkarni, Raghav and Saxena, Prateek (2015). Demystifying Incentives in the Consensus Computer. 22nd ACM Conference on Computer and Communications Security (CCS 2015).

Further reading

  • Blockchain at Berkeley (2018). Game Theory and Attacks. Lecture 6 of the Fall 2018 Blockchain Fundamentals course, a recorded class on the game theory of mining and attacks on Bitcoin.
HydrateLast updated Sep 18, 2026v1.2.06 revisions