Proof of Work vs Proof of Stake: What's the Difference?
Proof of work and proof of stake are two ways a blockchain reaches agreement. Here is how each works, what each costs and the trade-offs.
By Christopher Cannucciari · Published

Key takeaways
- Proof of work and proof of stake are two methods for a network of strangers to agree on one ledger without a central authority.
- Proof of work makes participants spend computing power and electricity. Proof of stake makes them lock up coins as a deposit that can be taken away if they cheat.
- Bitcoin uses proof of work. Ethereum used proof of work until September 2022, when it switched to proof of stake.
- Each approach has trade-offs in energy use, hardware, wealth concentration and the assumptions its security rests on.
- Neither is declared better here. Which matters more depends on what you value in a network.
What problem do both solve?
Both mechanisms solve the same problem: deciding who gets to add the next block of transactions, and making it costly to cheat. A network with no central operator needs some rule that stops anyone from simply rewriting the ledger in their favor.
The common idea is to attach a real cost to cheating. A participant who plays honestly is rewarded, and one who tries to defraud the system loses something valuable. Proof of work and proof of stake differ in what that valuable thing is. In one it is energy already spent, and in the other it is capital put at risk. For the base mechanics of blocks and transactions, see How Does Bitcoin Work?.
How does proof of work work?
In proof of work, miners compete by repeatedly running a hash function until one of them finds a result below a target. Finding it takes huge numbers of guesses, but checking it takes a single calculation. The winner publishes the next block and collects the reward.
The cost is outside the system. Miners buy specialized machines and pay for electricity, and they only earn rewards if they follow the rules, because every node rejects invalid blocks and the work would be wasted. To rewrite old history, an attacker would have to redo the work for those blocks and then outpace the honest network. The details, including difficulty and hardware, are in Inside a Bitcoin Mining Operation.
An important property is that the work is anchored to the physical world. Nobody can create hash power from nothing, and your influence depends on the machines and power you can really bring. Another is that nothing needs to be locked up in advance: a new miner can join using only hardware and electricity, and the chain’s history can be verified from the first block by anyone.
How does proof of stake work?
In proof of stake, participants called validators lock up coins as a deposit, known as a stake. The protocol selects validators to propose and confirm blocks, and the chance of being chosen generally grows with the amount staked. Validators earn rewards for honest work.
The deterrent is the deposit. If a validator breaks the rules, for example by signing two conflicting versions of history, the protocol can destroy part of its stake in a penalty often called slashing. A validator that is simply offline can lose smaller amounts. So cheating has a direct cost paid in the network’s own asset.
Because no one has to run racing machines, a validator can operate on modest hardware. The cost shifts from electricity to capital: you need coins to stake, and that capital carries risk and cannot be used elsewhere while it is locked.
How do the two compare?
| Question | Proof of work | Proof of stake |
|---|---|---|
| What do you put up? | Hardware and electricity | Coins locked as a deposit |
| What is the penalty for cheating? | Wasted work and lost income | Part of the stake can be destroyed |
| Energy use | High, by design | Much lower |
| Who gets more influence? | Whoever has more computing power | Whoever has more stake |
| Joining the network | Buy or rent hardware | Acquire and lock coins |
| Network users | Bitcoin | Ethereum since 2022, among others |
This table is a simplification, and real networks add many details. But it captures the core difference: one anchors security in outside resources, and the other in the network’s own asset.
What about energy?
Energy is the most visible difference. Proof of work uses a large amount of electricity because the expense is the security. Proof of stake does not need that, so it uses a small fraction of it. When Ethereum made the switch in 2022, its energy use fell sharply, which is a widely reported result of the Merge.
Whether the energy cost of proof of work is acceptable is a values question as well as an engineering one. Critics point to emissions and local impacts. Supporters argue that miners seek cheap and often otherwise wasted power, and that the cost buys a security model with no insiders. These claims are covered further in the mining article linked above, and neither side’s headline numbers are settled.
What are the security assumptions?
Both systems assume that an attacker cannot gather enough of the scarce resource to take over. In proof of work, that resource is computing power. In proof of stake, it is staked coins. The attacks and defenses differ.
Proof of work. Controlling a majority of the hash power would let an attacker reorder recent blocks or block certain transactions, though not steal coins from addresses they do not control. Gathering that power would require a huge outlay and would be visible. The security budget is paid for continuously through rewards and fees.
Proof of stake. Controlling a large share of the stake could let an attacker disrupt the network, but doing so risks the attacker’s own coins through slashing, and the community may respond by changing the rules. Proof of stake also leans on social coordination more openly: a node that has been offline for a long time needs a recent trusted reference point to know which chain is correct, a property researchers call weak subjectivity.
These are different bets. One bets on physical cost and a long track record, and the other bets on carefully designed incentives and economic penalties. Both have run real networks, and both continue to be examined.
What are the common criticisms of each?
Fairness is easier when both sides are heard.
- Proof of work is criticized for energy use, for the concentration of hardware manufacturing among a few companies, and for the open question of whether fees alone can fund security once the subsidy ends. See What Is the Bitcoin Halving? for how the subsidy shrinks.
- Proof of stake is criticized because those with more coins earn more rewards and have more say, which some see as a tendency for wealth to compound. Critics also point to the reliance on rules and social coordination at the edges, and to the fact that the system’s security is measured in the same asset it protects.
Defenders of each answer these points. Proof of stake supporters note that anyone can stake and that slashing is a strong deterrent. Proof of work supporters note that mining is open to anyone with hardware and power, and that a purely digital deposit is not a physical cost. These are real debates among informed people.
Which networks use which?
Bitcoin uses proof of work and has since it launched in 2009. Ethereum, which launched in 2015, used proof of work at first and moved to proof of stake in September 2022 in a change known as the Merge. Other networks use one or the other, or variations on them. Both approaches have been tested in public by real networks holding real value, but that does not make either a recommendation. For a side-by-side of those two networks, see Bitcoin vs Ethereum.
How to think about the choice
Pick the question you care about. If you weigh a physical, outside-the-system cost and a long operating history, proof of work is the design that does this. If you weigh low energy use and a capital-based deterrent, proof of stake is. Neither answer is neutral, because each reflects a view about what makes money secure.
This article makes no judgment about which is better and no prediction about their future. If you are new to the topic, the Start Here path offers an ordered way into the basics before you compare designs.
Where to go next
- Inside a Bitcoin Mining Operation: proof of work in practice, with hardware and energy.
- Bitcoin vs Ethereum: how two networks with different consensus compare.
- What Is the Bitcoin Halving?: how the miner reward shrinks over time.
- How Does Bitcoin Work?: the transactions and blocks both systems order.
- Bitcoin’s Energy Use: What the Debate Is Really About: the arguments on both sides.
- What Is a Blockchain? Bitcoin’s Ledger Explained: the data structure behind Bitcoin.
Frequently asked questions
What is the difference between proof of work and proof of stake?
Proof of work makes participants spend computing power and electricity to earn the right to add a block. Proof of stake makes participants lock up coins as a deposit that can be penalized if they cheat. Both are ways to get a network to agree on one history without a central authority.
Does Bitcoin use proof of work or proof of stake?
Bitcoin uses proof of work and has since it launched in 2009. Ethereum originally used proof of work too, then switched to proof of stake in September 2022 in an upgrade known as the Merge.
Which one uses less energy?
Proof of stake uses far less electricity because it does not require machines to race to solve puzzles. Proof of work uses a lot of energy by design, since the cost is what secures it. Whether that cost is justified is a point on which supporters and critics disagree.
Is proof of stake more secure than proof of work?
Neither can be called simply more secure. They rely on different assumptions and face different kinds of attacks, and both have been running real networks. Each has trade-offs that researchers and users continue to debate.



