## BOX 1. Definitions — BOX 3. Selected Risks of Some Consensus Mechanisms

## Source details

**Canonical URL:** [BOX 1. Definitions — BOX 3. Selected Risks of Some Consensus Mechanisms](https://www.imf.org/-/media/files/publications/ftn063/2022/english/ftnea2022003.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/ftn063/2022/english/ftnea2022003.pdf.md)
- [Structured JSON version](/-/media/files/publications/ftn063/2022/english/ftnea2022003.pdf.json)

---

### Key definitions (from BOX 1)
- Distributed Ledger Technology (DLT): A set of technological solutions that enables a single, sequenced, standardized, and cryptographically secured record of activity to be safely distributed to, and acted upon by, a network of varied participants. This record can contain transactions, asset holdings, or identity data. Through nodes, DLT is used to maintain and share digital records instantaneously across a network of participants.
- Blockchain: DLT in its blockchain form was first used in Bitcoin to facilitate peer-to-peer payments without a central third party. Blockchain is a type of DLT that has a specific set of features, organizing its data in a chain of blocks. Each block contains data that are verified, validated, and then “chained” to the next block. Blockchain is a subset of DLT, and the Bitcoin Blockchain is a specific form of a blockchain.
- Consensus mechanisms: Consensus in distributed systems is ensuring that a state, value, or piece of information is correct and agreed on by most nodes. A consensus mechanism guarantees this effort is carried out fairly and independently of any interested party, or in the case of private permissioned networks, to achieve other objectives desired by the network (such as centralized control).
- 51 percent attack: An attack in which malicious actors gain control over 51 percent of nodes in a network
- Bali Fintech Agenda: A framework developed jointly with the World Bank to help authorities balance the benefits and risks of new technologies in financial services
- Hashrate: The speed of mining measured as the computational power per second used
- Mining pool: The pooling of resources by miners, who share their processing power over a network, to split the rewards
- Nodes: A DLT connection and communication point that can create, receive, send, and act on information
- On/off-ramps: Usually, centralized points of a crypto-asset ecosystem that allow fiat currencies to be exchanged for crypto assets—for example, trading platforms
- P2P protocol: Determines inter-node communication, including how blocks and transactions are exchanged
- Permissioned/closed networks: Networks in which only known actors with specific rights can validate existing records and add new ones
- Permissionless/open networks: Networks in which anyone is allowed to validate existing records and add new ones
- Private networks: Networks in which visibility is restricted to a subset of users
- Public networks: Networks in which all users can see records being added or changed
- Quorum: The number of nodes required to reach agreement
- Regulatory Sandbox: A controlled environment overseen by a regulatory authority that allows firms to test their innovative propositions with real consumers
- Sybil attack: An attempt to control a distributed network by creating multiple fake identities
- TechSprint: A technology-focused design sprint that brings together diverse participants to collaborate intensively over a short period of time on a software project

### Context, findings, and policy implications (from BOX 1)
- Increasing DLT use and benefits
  - DLT, including blockchains, is used in payments, issuing debt and equity, trade finance, and post-trade processes.
  - DLT has the potential to disintermediate markets, reduce costs, increase speed and efficiency, and create secure records of transparent, immutable, and auditable data and activity.
  - DLT can offer greater democratization of data as the data are distributed and control of the data is decentralized, and can improve financial inclusion, supply chain management, and record keeping.
- Current deployment and risks
  - Large-scale use of DLT in financial services is currently limited, but use cases are increasing in some jurisdictions.
  - Some DLT designs can create risks to the natural environment, consumers, market integrity, financial integrity, and financial stability.
  - When used at scale or in critical infrastructure that is not substitutable, DLT deployments can give rise to financial stability risks—for example, in a global stablecoin or a CBDC deployed using DLT.
- Consensus mechanisms and trade-offs
  - Consensus mechanisms underpin the effective operation of blockchains and ensure a single, consistent, and honest ledger.
  - Consensus mechanisms guarantee that a state, value, or piece of information is correct and agreed on by most nodes.
  - Different consensus mechanisms are designed to work best in public networks or private networks and deliver different outcomes (for example, prioritizing speed/efficiency versus security).
  - Examples: Within financial services, Proof-of-Work (PoW), Proof-of-Stake (PoS), and Delegated PoS (DPoS) are popular in public blockchains; pBFT, iBFT, and fBFT are popular in private blockchains; BigTech-created mechanisms (for example, DiemBFT) may enable rapid systemic adoption.
  - Supporting the Bitcoin Blockchain, PoW is the most popular consensus mechanism, but it consumes significant energy and can be slow and expensive during times of high network traffic; innovations such as the Lightning Network, side chains, and PoS aim to address some PoW issues but introduce other trade-offs (for example, probabilistic settlement).
  - pBFT, iBFT, fBFT, and DiemBFT offer immediate settlement but raise regulatory concerns about competition and conflict with decentralized network ideals.
- Regulatory guidance and considerations
  - The Bali Fintech Agenda (BFA) is a framework that aims to guide authorities in harnessing the benefits of new technologies in financial services while mitigating risks; the BFA is a framework composed of 12 policy elements.
  - Authorities should consider the pros and cons of different consensus mechanisms when deciding which designs can serve the regulated financial sector effectively and compliantly.
  - Authorities should consider whether a technology neutral approach can continue delivering mandates when diverse new technologies deliver different outcomes and may consider a more proactive approach to supporting or restricting certain technologies.
  - Authorities should consider upskilling supervisors to better supervise new technologies; international organizations have a role in sharing regulatory best practice where there might be a skills gap.
  - Approaches that can help authorities understand consensus mechanisms include TechSprints, regulatory sandboxes, and deeper public-private collaboration via formal reviews.
  - Consensus mechanisms should seek to be collaborative, egalitarian, interoperable, and inclusive, avoiding unnecessary barriers to entry and not favoring certain members over others while ensuring participants are “known” to protect financial integrity (through customer due diligence).
  - A good consensus mechanism should ensure robust network security, scalability, efficiency, and operational resilience to limit risks to market integrity and financial stability.

### Selected risks by type (from BOX 3)
- Consumer Protection
  - Some consensus mechanisms can lead to slow transaction times or high transaction costs, producing unexpected and unacceptable costs for vulnerable or technically illiterate consumers.
- Market Integrity
  - Less secure consensus mechanisms could enable fraudulent transactions (for example, via a 51 percent attack or a malicious leader node), potentially resulting in market manipulation and market abuse in financial markets.
- Financial Integrity
  - The pseudonymous nature of most DLT transactions can pose risks related to fraud, theft, money laundering, and terrorist financing. Although blockchains provide transparency, auditability, and immutability, end users and many market participants (such as nodes) are often not known, making sanctions or enforcement actions difficult to implement.
- Financial Stability
  - Private blockchains with permissioned access could allow a small network of entities (or a single entity) to gain market dominance, creating high barriers to entry, nonsubstitutability, and potential “too big to fail” risks.
  - If a crypto asset (such as a stablecoin or a CBDC) gains widespread adoption, failure of the underlying consensus mechanisms could generate risks to financial stability.

### Environmental and climate considerations (from BOX 3)
- Consensus mechanisms should not interfere with the global aim to transition to a low-carbon economy.
- Energy-intensive consensus methods present unacceptable risks to financial stability and society by exacerbating climate change.
- Example: total energy usage of Bitcoin mining is comparable to Poland at 140 Terrawatt-hour.
- The Swedish Finansinspektionen called for the European Union to ban PoW mining (Finansinspektionen 2021).
- Authorities should consider moving to less environmentally damaging methods of operating blockchains.

### Public vs Private blockchains: regulatory implications (from BOX 3)
- Public blockchains
  - Permissionless and decentralized; can remove reliance on single counterparties and democratize data transfer.
  - Larger public networks can be less susceptible to cyberattacks due to decentralization, but centralized points of risk can exist (for example, wallets and exchanges).
  - Supervision is more difficult because participants can be global or unknown, raising financial crime and consumer recourse issues.
- Private blockchains
  - Consist of a single or small number of entities with permissions for known participants; shift risk to network administrators.
  - Centralization creates vulnerability to operational, cyber, and default risk, but participants are more easily subject to regulation.
  - Known participants can ease oversight, though supervision challenges remain (for example, if participants are located offshore).
- Regulatory trade-offs
  - Immediate settlement (permissioned) may fit existing regulation better than probabilistic settlement (permissionless).
  - More open networks may limit barriers to entry but can slow transaction rates or create consumer protection and market integrity risks.

### Consensus mechanisms: descriptions, strengths/weaknesses, and regulatory considerations (from BOX 3)

- Proof-of-Work (PoW)
  - Mechanism: Nodes solve asymmetrical mathematical puzzles (“mining”) to produce new blocks; Bitcoin protocol targets a new block every 10 minutes.
  - Incentives: Block rewards and transaction fees incentivize participation. On the Bitcoin Blockchain, block rewards are halved every four years; from May 2020, the block reward fell from 12.5 Bitcoins to 6.25 Bitcoins.
  - Strengths and weaknesses:
    - PoW allows large numbers of nodes, increasing hashrate and security.
    - Consumes considerable energy due to brute-force computing.
    - Total energy usage example: 140 Terrawatt-hour (Bitcoin mining).
    - Can be slow and suffer low transaction throughput: Bitcoin processes approximately 7 transactions per second.
    - Comparators: Visa averages roughly 1,700 transactions per second.
    - Probabilistic settlement and forking complicate settlement finality.
    - Potential centralization via specialized hardware and mining pools; could raise “too big to fail” concerns.
  - Regulatory considerations:
    - PoW is secure and resilient but slow, energy intensive, and provides probabilistic settlement—making it likely unsuitable for many regulated financial services (for example, payments).
    - Supervisors should note decentralization can impede supervision due to unknown node identities.

- Proof-of-Stake (PoS)
  - Mechanism: Validators are randomly selected based on the amount token holders stake; selection probability increases with ownership.
  - Strengths and weaknesses:
    - Reduces energy consumption relative to PoW and preserves network security.
    - Limits the need to issue many new coins for incentives.
    - More expensive to carry out a 51 percent attack in a large PoS-based blockchain than in a large PoW-based one.
    - Higher transaction throughput than PoW, but settlement issues remain.
    - “Nothing at Stake” problem: validators may vote on multiple blocks to maximize rewards, increasing forks and settlement uncertainty. Some PoS models introduce monetary penalties for validators on blocks not included in the chain.
    - PoS can concentrate rewards among larger token holders, potentially creating centralization and exclusionary dynamics.
    - Staking locks tokens, potentially creating liquidity shortages and reduced transaction speed.
  - Regulatory considerations:
    - Authorities should consider sandboxing nascent PoS networks until they achieve sufficient scale.
    - Attention needed on network security, fairness, and risks from competing chains.

- Delegated Proof-of-Stake (DPoS)
  - Mechanism: Adds delegation and voting: stakeholders vote witnesses to validate blocks; witnesses can outsource validation work; rewards are shared between witnesses and stakeholders.
  - Strengths and weaknesses:
    - Energy savings, potentially greater decentralization, and faster transaction rates than PoW and PoS (witnesses are incentivized to act quickly to retain position).
    - If voter participation is low or stakes concentrated, risks of centralization and cartel-like behavior arise.
    - DPoS is relatively new and less tested; network-security risks, cartel behavior, and limited voter participation require regulatory attention.
  - Regulatory considerations:
    - If developed compliantly, DPoS can support regulated activities (for example, payments), but regulators must monitor centralization and security risks.

- Practical and Istanbul Byzantine Fault Tolerance (pBFT / iBFT)
  - Mechanism:
    - Designed for permissioned networks with partially trusted participants; nodes stake identity/reputation (Proof-of-Authority–type).
    - pBFT uses leader and backup nodes; consensus via message exchanges in four rounds (“views”); leaders can be changed after every view.
    - iBFT modifies pBFT: uses proposers and validators, allows validators to be added or removed, and produces blocks at regular intervals (including blocks with zero actions).
  - Strengths and weaknesses:
    - Works if fraudulent nodes do not exceed a third of nodes; security improves with more nodes, but message volume limits practical node count.
    - Immediate settlement and no forks (settlement finality).
    - Low energy consumption relative to PoW.
    - Can create centralized networks, barriers to entry, and reduced contestability—contrary to blockchain decentralization ideals.
    - Susceptible to Sybil attacks; a leader node could manipulate others.
  - Regulatory considerations:
    - pBFT/iBFT suits financial services where organizations represent nodes and operate within a governance system, but competition and entry barriers should be monitored.
    - Known participants facilitate regulation and supervision; immediate settlement aligns with existing regulatory frameworks.

- Federated Byzantine Fault Tolerance (fBFT)
  - Mechanism: Semi-trusted model relying on “quorum slices” or a Unique Node List; nodes choose whom they trust, creating quorum intersections that enable scalability.
  - Strengths and weaknesses:
    - Mixes known and unknown participants; immediate block finality and high transaction rates.
    - Potentially balances decentralization with efficiency; however, with scale, speed and trust can be compromised, potentially creating barriers to entry.
    - Greater risks to financial integrity than fully-known BFT mechanisms due to possible faulty or malicious nodes.
  - Regulatory considerations:
    - Authorities may need domestic and cross-border collaboration to mitigate financial stability risks while leveraging fBFT efficiency and scalability.

- DiemBFT
  - Mechanism:
    - Based on HotStuff protocol (which builds on pBFT) to increase speed and efficiency via a star communication model centered on leader nodes and unpredictable leader election.
    - Nodes in the Diem Network receive transactions from clients via a shared mempool; leaders propose blocks and follower nodes vote; a Quorum Certificate is formed upon majority vote.
  - Performance claims:
    - DiemBFT proposes to process 1,000 transactions at launch (contrast: Bitcoin processes approximately 7 transactions per second).
  - Strengths and weaknesses:
    - Faster transaction throughput and low cost potential; supports decentralized applications beyond stablecoin transfers.
    - Centralized network design for Diem: nodes must commit at least $10 million to join and have appropriate computing hardware; high sunk costs create barriers to entry and market contestability concerns.
    - Reliance on a few counterparties and leader nodes raises competition, data, and privacy issues.
  - Regulatory considerations:
    - Potential to become systemic payment infrastructure due to embedded userbases; requires extensive collaboration across financial and non-financial regulators (for example, competition authorities).

- Proof-of-Elapsed-Time (PoET)
  - Mechanism: Nodes generate random wait times; the node with the shortest wait time wins the new block. Nodes sleep during wait times to conserve energy. Intel provides a tool to generate and verify genuine random wait times.
  - Strengths and weaknesses:
    - Limits energy consumption, centralization of rewards, and resource locking; can maintain fairly high transaction rates.
    - Settlement remains probabilistic, raising concerns about meeting settlement finality requirements in some regulatory regimes.
    - Vulnerable to Sybil attacks; reliance on a third party (Intel) centralizes consensus control and challenges trustless objectives.
  - Regulatory considerations:
    - Authorities should assess security concerns’ impact on financial product provision and develop systems and controls for operational and cyber resilience.
    - Single-entity dependence (for example, Intel) may simplify regulation but complicate defining an effective financial regulatory perimeter.

### Comparative findings and key statistics (from BOX 3)
- Settlement finality
  - PoW, PoS/DPoS, PoET: Probabilistic
  - pBFT/iBFT, fBFT, DiemBFT: Immediate
- Transaction rates
  - PoW: Low (Bitcoin ~ 7 transactions per second)
  - PoS/DPoS: High
  - PoET: Medium
  - pBFT/iBFT, fBFT, DiemBFT: High
- Scalability and contestability (as presented)
  - PoW: Scalability High; Contestability High
  - PoS/DPoS: Scalability High; Contestability High
  - PoET: Scalability High; Contestability High
  - pBFT/iBFT: Scalability Low; Contestability Low
  - fBFT: Scalability High; Contestability Medium
  - DiemBFT: Scalability High; Contestability Low
- Environmental impact
  - PoW: High
  - PoS/DPoS: Medium
  - PoET, pBFT/iBFT, fBFT, DiemBFT: Low
- Security (as summarized)
  - PoW: High
  - PoS/DPoS: High
  - PoET: Medium
  - pBFT/iBFT, fBFT, DiemBFT: Medium
- Example numeric comparisons
  - Bitcoin block production target: every 10 minutes.
  - Bitcoin block reward halved from 12.5 Bitcoins to 6.25 Bitcoins (May 2020).
  - Bitcoin approximate throughput: 7 transactions per second.
  - Visa average throughput: roughly 1,700 transactions per second.
  - DiemBFT proposed throughput at launch: 1,000 transactions per second.
  - Bitcoin mining energy usage example: 140 Terrawatt-hour.
  - Diem node entry requirement (as described): at least $10 million commitment.

### Policy recommendations and supervisory actions (from BOX 3)
- Technology-agnostic regulatory approach
  - Authorities should be technology agnostic: determine whether consensus mechanisms are appropriate relative to the desired outcomes of a specific proposition while recognizing different technologies bring different risks.
- Supervisory capacity and collaboration
  - Supervisors should be upskilled; hire trained experts where possible to ask pertinent questions and make accurate risk-efficiency judgments.
  - International organizations (for example, the IMF) can provide technical assistance and share best practices.
  - Standard-setting bodies can develop global recommendations providing minimum requirements for consensus mechanisms when used in regulated financial entities.
- Public-private engagement and testing
  - Use “test and learn” approaches where DLT development is large: outreach, innovation hubs, sandboxes, and digital sandboxes to assess market-fit and regulatory alignment.
  - Short-term collaboration: joint events or commissioned surveys focused on consensus mechanisms.
  - Longer-term collaboration: joint research, experiments, testing, TechSprints, and supervised proof-of-concept programs.
- Regulatory focus areas
  - Assess settlement finality implications, especially for payments and custody.
  - Monitor centralization risks, barriers to entry, contestability, and “too big to fail” dynamics.
  - Consider environmental impacts; avoid supporting energy-intensive consensus mechanisms (for example, PoW) for regulated financial services.
  - Develop systems and controls for operational and cyber resilience (for example, aligning with BCBS Principles for Operational Resilience).
  - Coordinate across financial and non-financial regulators (for example, competition authorities) when networks could become systemic (for example, global stablecoins, large CBDCs, or BigTech-led systems).

*International Monetary Fund—Fintech Notes (excerpt: BOX 1. Definitions; BOX 3. Selected Risks of Some Consensus Mechanisms).*

### BOX 1. Definitions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

### BOX 1. Definitions

### Key definitions
- Distributed Ledger Technology (DLT): A set of technological solutions that enables a single, sequenced, standardized, and cryptographically secured record of activity to be safely distributed to, and acted upon by, a network of varied participants. This record can contain transactions, asset holdings, or identity data. Through nodes, DLT is used to maintain and share digital records instantaneously across a network of participants.
- Blockchain: DLT in its blockchain form was first used in Bitcoin to facilitate peer-to-peer payments without a central third party. Blockchain is a type of DLT that has a specific set of features, organizing its data in a chain of blocks. Each block contains data that are verified, validated, and then “chained” to the next block. Blockchain is a subset of DLT, and the Bitcoin Blockchain is a specific form of a blockchain.
- Consensus mechanisms: Consensus in distributed systems is ensuring that a state, value, or piece of information is correct and agreed on by most nodes. A consensus mechanism guarantees this effort is carried out fairly and independently of any interested party, or in the case of private permissioned networks, to achieve other objectives desired by the network (such as centralized control).
- 51 percent attack: An attack in which malicious actors gain control over 51 percent of nodes in a network
- Bali Fintech Agenda: A framework developed jointly with the World Bank to help authorities balance the benefits and risks of new technologies in financial services
- Hashrate: The speed of mining measured as the computational power per second used
- Mining pool: The pooling of resources by miners, who share their processing power over a network, to split the rewards
- Nodes: A DLT connection and communication point that can create, receive, send, and act on information
- On/off-ramps: Usually, centralized points of a crypto-asset ecosystem that allow fiat currencies to be exchanged for crypto assets—for example, trading platforms
- P2P protocol: Determines inter-node communication, including how blocks and transactions are exchanged
- Permissioned/closed networks: Networks in which only known actors with specific rights can validate existing records and add new ones
- Permissionless/open networks: Networks in which anyone is allowed to validate existing records and add new ones
- Private networks: Networks in which visibility is restricted to a subset of users
- Public networks: Networks in which all users can see records being added or changed
- Quorum: The number of nodes required to reach agreement
- Regulatory Sandbox: A controlled environment overseen by a regulatory authority that allows firms to test their innovative propositions with real consumers
- Sybil attack: An attempt to control a distributed network by creating multiple fake identities
- TechSprint: A technology-focused design sprint that brings together diverse participants to collaborate intensively over a short period of time on a software project

### Context, findings, and policy implications
- Increasing DLT use and benefits:
  - DLT, including blockchains, is used in payments, issuing debt and equity, trade finance, and post-trade processes.
  - DLT has the potential to disintermediate markets, reduce costs, increase speed and efficiency, and create secure records of transparent, immutable, and auditable data and activity.
  - DLT can offer greater democratization of data as the data are distributed and control of the data is decentralized, and can improve financial inclusion, supply chain management, and record keeping.
- Current deployment and risks:
  - Large-scale use of DLT in financial services is currently limited, but use cases are increasing in some jurisdictions.
  - Some DLT designs can create risks to the natural environment, consumers, market integrity, financial integrity, and financial stability.
  - When used at scale or in critical infrastructure that is not substitutable, DLT deployments can give rise to financial stability risks—for example, in a global stablecoin or a CBDC deployed using DLT.
- Consensus mechanisms and trade-offs:
  - Consensus mechanisms underpin the effective operation of blockchains and ensure a single, consistent, and honest ledger.
  - Consensus mechanisms guarantee that a state, value, or piece of information is correct and agreed on by most nodes.
  - Different consensus mechanisms are designed to work best in public networks or private networks and deliver different outcomes (for example, prioritizing speed/efficiency versus security).
  - Examples: Within financial services, Proof-of-Work (PoW), Proof-of-Stake (PoS), and Delegated PoS (DPoS) are popular in public blockchains; pBFT, iBFT, and fBFT are popular in private blockchains; BigTech-created mechanisms (for example, DiemBFT) may enable rapid systemic adoption.
  - Supporting the Bitcoin Blockchain, PoW is the most popular consensus mechanism, but it consumes significant energy and can be slow and expensive during times of high network traffic; innovations such as the Lightning Network, side chains, and PoS aim to address some PoW issues but introduce other trade-offs (for example, probabilistic settlement).
  - pBFT, iBFT, fBFT, and DiemBFT offer immediate settlement but raise regulatory concerns about competition and conflict with decentralized network ideals.
- Regulatory guidance and considerations:
  - The Bali Fintech Agenda (BFA) is a framework that aims to guide authorities in harnessing the benefits of new technologies in financial services while mitigating risks; the BFA is a framework composed of 12 policy elements.
  - Authorities should consider the pros and cons of different consensus mechanisms when deciding which designs can serve the regulated financial sector effectively and compliantly.
  - Authorities should consider whether a technology neutral approach can continue delivering mandates when diverse new technologies deliver different outcomes and may consider a more proactive approach to supporting or restricting certain technologies.
  - Authorities should consider upskilling supervisors to better supervise new technologies; international organizations have a role in sharing regulatory best practice where there might be a skills gap.
  - Approaches that can help authorities understand consensus mechanisms include TechSprints, regulatory sandboxes, and deeper public-private collaboration via formal reviews.
  - Consensus mechanisms should seek to be collaborative, egalitarian, interoperable, and inclusive, avoiding unnecessary barriers to entry and not favoring certain members over others while ensuring participants are “known” to protect financial integrity (through customer due diligence).
  - A good consensus mechanism should ensure robust network security, scalability, efficiency, and operational resilience to limit risks to market integrity and financial stability.

_International Monetary Fund—Fintech Notes (excerpt: BOX 1. Definitions)._

### BOX 3. Selected Risks of Some Consensus Mechanisms

### BOX 3. Selected Risks of Some Consensus Mechanisms

### Selected Risks by Type
- Consumer Protection
  - Some consensus mechanisms can lead to slow transaction times or high transaction costs, producing unexpected and unacceptable costs for vulnerable or technically illiterate consumers.
- Market Integrity
  - Less secure consensus mechanisms could enable fraudulent transactions (for example, via a 51 percent attack or a malicious leader node), potentially resulting in market manipulation and market abuse in financial markets.
- Financial Integrity
  - The pseudonymous nature of most DLT transactions can pose risks related to fraud, theft, money laundering, and terrorist financing. Although blockchains provide transparency, auditability, and immutability, end users and many market participants (such as nodes) are often not known, making sanctions or enforcement actions difficult to implement.
- Financial Stability
  - Private blockchains with permissioned access could allow a small network of entities (or a single entity) to gain market dominance, creating high barriers to entry, nonsubstitutability, and potential “too big to fail” risks.
  - If a crypto asset (such as a stablecoin or a CBDC) gains widespread adoption, failure of the underlying consensus mechanisms could generate risks to financial stability.

### Environmental and Climate Considerations
- Consensus mechanisms should not interfere with the global aim to transition to a low-carbon economy.
- Energy-intensive consensus methods present unacceptable risks to financial stability and society by exacerbating climate change.
- Example: total energy usage of Bitcoin mining is comparable to Poland at 140 Terrawatt-hour.
- The Swedish Finansinspektionen called for the European Union to ban PoW mining (Finansinspektionen 2021).
- Authorities should consider moving to less environmentally damaging methods of operating blockchains.

### Public vs Private Blockchains: Regulatory Implications
- Public blockchains
  - Permissionless and decentralized; can remove reliance on single counterparties and democratize data transfer.
  - Larger public networks can be less susceptible to cyberattacks due to decentralization, but centralized points of risk can exist (for example, wallets and exchanges).
  - Supervision is more difficult because participants can be global or unknown, raising financial crime and consumer recourse issues.
- Private blockchains
  - Consist of a single or small number of entities with permissions for known participants; shift risk to network administrators.
  - Centralization creates vulnerability to operational, cyber, and default risk, but participants are more easily subject to regulation.
  - Known participants can ease oversight, though supervision challenges remain (for example, if participants are located offshore).
- Regulatory trade-offs
  - Immediate settlement (permissioned) may fit existing regulation better than probabilistic settlement (permissionless).
  - More open networks may limit barriers to entry but can slow transaction rates or create consumer protection and market integrity risks.

### Consensus Mechanisms in Public Blockchains

- Common public-blockchain examples listed:
  - Proof-of-Work (PoW)
  - Proof-of-Stake (PoS)
  - Delegated Proof-of-Stake (DPoS)

Proof-of-Work (PoW)
- Mechanism
  - Nodes solve asymmetrical mathematical puzzles (“mining”) to produce new blocks; Bitcoin protocol targets a new block every 10 minutes.
  - Forking can occur when multiple nodes solve puzzles simultaneously; nodes eventually move to the longest chain.
- Incentives
  - Block rewards and transaction fees incentivize participation.
  - On the Bitcoin Blockchain, block rewards are halved every four years; from May 2020, the block reward fell from 12.5 Bitcoins to 6.25 Bitcoins.
- Strengths and weaknesses
  - PoW allows large numbers of nodes, increasing hashrate and security.
  - Consumes considerable energy due to brute-force computing.
  - Total energy usage example: 140 Terrawatt-hour (Bitcoin mining).
  - Can be slow and suffer low transaction throughput: Bitcoin processes approximately 7 transactions per second.
  - Comparators: Visa averages roughly 1,700 transactions per second.
  - Probabilistic settlement and forking complicate settlement finality.
  - Potential centralization via specialized hardware and mining pools; could raise “too big to fail” concerns.
- Regulatory considerations
  - PoW is secure and resilient but slow, energy intensive, and provides probabilistic settlement—making it likely unsuitable for many regulated financial services (for example, payments).
  - Supervisors should note decentralization can impede supervision due to unknown node identities.

Proof-of-Stake (PoS)
- Mechanism
  - Validators are randomly selected based on the amount token holders stake; selection probability increases with ownership.
- Strengths and weaknesses
  - Reduces energy consumption relative to PoW and preserves network security.
  - Limits the need to issue many new coins for incentives.
  - More expensive to carry out a 51 percent attack in a large PoS-based blockchain than in a large PoW-based one.
  - Higher transaction throughput than PoW, but settlement issues remain.
  - “Nothing at Stake” problem: validators may vote on multiple blocks to maximize rewards, increasing forks and settlement uncertainty. Some PoS models introduce monetary penalties for validators on blocks not included in the chain.
  - PoS can concentrate rewards among larger token holders, potentially creating centralization and exclusionary dynamics.
  - Staking locks tokens, potentially creating liquidity shortages and reduced transaction speed.
- Regulatory considerations
  - Authorities should consider sandboxing nascent PoS networks until they achieve sufficient scale.
  - Attention needed on network security, fairness, and risks from competing chains.

Delegated Proof-of-Stake (DPoS)
- Mechanism
  - Adds delegation and voting: stakeholders vote witnesses to validate blocks; witnesses can outsource validation work; rewards are shared between witnesses and stakeholders.
- Strengths and weaknesses
  - Energy savings, potentially greater decentralization, and faster transaction rates than PoW and PoS (witnesses are incentivized to act quickly to retain position).
  - If voter participation is low or stakes concentrated, risks of centralization and cartel-like behavior arise.
  - DPoS is relatively new and less tested; network-security risks, cartel behavior, and limited voter participation require regulatory attention.
- Regulatory considerations
  - If developed compliantly, DPoS can support regulated activities (for example, payments), but regulators must monitor centralization and security risks.

### Consensus Mechanisms in Private Blockchains

- Common private-blockchain examples listed:
  - Practical Byzantine Fault Tolerance (pBFT) / Istanbul BFT (iBFT)
  - Federated Byzantine Fault Tolerance (fBFT)
  - DiemBFT
  - Proof-of-Elapsed-Time (PoET)

Practical and Istanbul Byzantine Fault Tolerance (pBFT / iBFT)
- Mechanism
  - Designed for permissioned networks with partially trusted participants; nodes stake identity/reputation (Proof-of-Authority–type).
  - pBFT uses leader and backup nodes; consensus via message exchanges in four rounds (“views”); leaders can be changed after every view.
  - iBFT modifies pBFT: uses proposers and validators, allows validators to be added or removed, and produces blocks at regular intervals (including blocks with zero actions).
- Strengths and weaknesses
  - Works if fraudulent nodes do not exceed a third of nodes; security improves with more nodes, but message volume limits practical node count.
  - Immediate settlement and no forks (settlement finality).
  - Low energy consumption relative to PoW.
  - Can create centralized networks, barriers to entry, and reduced contestability—contrary to blockchain decentralization ideals.
  - Susceptible to Sybil attacks; a leader node could manipulate others.
- Regulatory considerations
  - pBFT/iBFT suits financial services where organizations represent nodes and operate within a governance system, but competition and entry barriers should be monitored.
  - Known participants facilitate regulation and supervision; immediate settlement aligns with existing regulatory frameworks.

Federated Byzantine Fault Tolerance (fBFT)
- Mechanism
  - Semi-trusted model relying on “quorum slices” or a Unique Node List; nodes choose whom they trust, creating quorum intersections that enable scalability.
- Strengths and weaknesses
  - Mixes known and unknown participants; immediate block finality and high transaction rates.
  - Potentially balances decentralization with efficiency; however, with scale, speed and trust can be compromised, potentially creating barriers to entry.
  - Greater risks to financial integrity than fully-known BFT mechanisms due to possible faulty or malicious nodes.
- Regulatory considerations
  - Authorities may need domestic and cross-border collaboration to mitigate financial stability risks while leveraging fBFT efficiency and scalability.

DiemBFT
- Mechanism
  - Based on HotStuff protocol (which builds on pBFT) to increase speed and efficiency via a star communication model centered on leader nodes and unpredictable leader election.
  - Nodes in the Diem Network receive transactions from clients via a shared mempool; leaders propose blocks and follower nodes vote; a Quorum Certificate is formed upon majority vote.
- Performance claims
  - DiemBFT proposes to process 1,000 transactions at launch (contrast: Bitcoin processes approximately 7 transactions per second).
- Strengths and weaknesses
  - Faster transaction throughput and low cost potential; supports decentralized applications beyond stablecoin transfers.
  - Centralized network design for Diem: nodes must commit at least $10 million to join and have appropriate computing hardware; high sunk costs create barriers to entry and market contestability concerns.
  - Reliance on a few counterparties and leader nodes raises competition, data, and privacy issues.
- Regulatory considerations
  - Potential to become systemic payment infrastructure due to embedded userbases; requires extensive collaboration across financial and non-financial regulators (for example, competition authorities).

Proof-of-Elapsed-Time (PoET)
- Mechanism
  - Nodes generate random wait times; the node with the shortest wait time wins the new block. Nodes sleep during wait times to conserve energy.
  - Intel provides a tool to generate and verify genuine random wait times.
- Strengths and weaknesses
  - Limits energy consumption, centralization of rewards, and resource locking; can maintain fairly high transaction rates.
  - Settlement remains probabilistic, raising concerns about meeting settlement finality requirements in some regulatory regimes.
  - Vulnerable to Sybil attacks; reliance on a third party (Intel) centralizes consensus control and challenges trustless objectives.
- Regulatory considerations
  - Authorities should assess security concerns’ impact on financial product provision and develop systems and controls for operational and cyber resilience.
  - Single-entity dependence (for example, Intel) may simplify regulation but complicate defining an effective financial regulatory perimeter.

### Comparative Findings and Key Statistics
- Settlement finality
  - PoW, PoS/DPoS, PoET: Probabilistic
  - pBFT/iBFT, fBFT, DiemBFT: Immediate
- Transaction rates
  - PoW: Low (Bitcoin ~ 7 transactions per second)
  - PoS/DPoS: High
  - PoET: Medium
  - pBFT/iBFT, fBFT, DiemBFT: High
- Scalability and contestability (as presented)
  - PoW: Scalability High; Contestability High
  - PoS/DPoS: Scalability High; Contestability High
  - PoET: Scalability High; Contestability High
  - pBFT/iBFT: Scalability Low; Contestability Low
  - fBFT: Scalability High; Contestability Medium
  - DiemBFT: Scalability High; Contestability Low
- Environmental impact
  - PoW: High
  - PoS/DPoS: Medium
  - PoET, pBFT/iBFT, fBFT, DiemBFT: Low
- Security (as summarized)
  - PoW: High
  - PoS/DPoS: High
  - PoET: Medium
  - pBFT/iBFT, fBFT, DiemBFT: Medium
- Example numeric comparisons
  - Bitcoin block production target: every 10 minutes.
  - Bitcoin block reward halved from 12.5 Bitcoins to 6.25 Bitcoins (May 2020).
  - Bitcoin approximate throughput: 7 transactions per second.
  - Visa average throughput: roughly 1,700 transactions per second.
  - DiemBFT proposed throughput at launch: 1,000 transactions per second.
  - Bitcoin mining energy usage example: 140 Terrawatt-hour.
  - Diem node entry requirement (as described): at least $10 million commitment.

### Policy Recommendations and Supervisory Actions
- Technology-agnostic regulatory approach
  - Authorities should be technology agnostic: determine whether consensus mechanisms are appropriate relative to the desired outcomes of a specific proposition while recognizing different technologies bring different risks.
- Supervisory capacity and collaboration
  - Supervisors should be upskilled; hire trained experts where possible to ask pertinent questions and make accurate risk-efficiency judgments.
  - International organizations (for example, the IMF) can provide technical assistance and share best practices.
  - Standard-setting bodies can develop global recommendations providing minimum requirements for consensus mechanisms when used in regulated financial entities.
- Public-private engagement and testing
  - Use “test and learn” approaches where DLT development is large: outreach, innovation hubs, sandboxes, and digital sandboxes to assess market-fit and regulatory alignment.
  - Short-term collaboration: joint events or commissioned surveys focused on consensus mechanisms.
  - Longer-term collaboration: joint research, experiments, testing, TechSprints, and supervised proof-of-concept programs.
- Regulatory focus areas
  - Assess settlement finality implications, especially for payments and custody.
  - Monitor centralization risks, barriers to entry, contestability, and “too big to fail” dynamics.
  - Consider environmental impacts; avoid supporting energy-intensive consensus mechanisms (for example, PoW) for regulated financial services.
  - Develop systems and controls for operational and cyber resilience (for example, aligning with BCBS Principles for Operational Resilience).
  - Coordinate across financial and non-financial regulators (for example, competition authorities) when networks could become systemic (for example, global stablecoins, large CBDCs, or BigTech-led systems).

*Source: BOX 3. Selected Risks of Some Consensus Mechanisms — Blockchain Consensus Mechanisms: A Primer for Supervisors (IMF Fintech Note content provided in source PDF).*

---


_Source: https://www.imf.org/-/media/files/publications/ftn063/2022/english/ftnea2022003.pdf_
