A few days ago, I saw someone in the validation community ask: “What if the chain keeps failing to pick a block?” At the time, I casually said, “Eventually someone will produce a block.” Now, thinking about it, that answer was a bit taken for granted.
Most people’s assumption about PoS chains is: as long as validators are online, consensus will eventually be reached—just maybe after waiting through a few more rounds. But the Dusk whitepaper states it very plainly: if the number of consecutive failed iterations reaches 16, the protocol will proactively disable the timeout mechanism and enter an “emergency mode.” At that point, two voting options—NoCandidate and NoQuorum—are directly disabled, meaning the committee is no longer allowed to effectively choose “nothing.”
There’s nothing particularly surprising about this design—it forces the system to keep moving forward. What really caught me off guard is the next part: in emergency mode, if even the maximum timeout across all iterations is exhausted and no candidate block can be selected, what happens then? The answer is: some provisioners can initiate an “Emergency Block Request” (EBR). As long as the group initiating the request holds the majority of the total stake on the network, they can directly produce an empty block containing no transactions—just to keep the chain progressing.
I didn’t originally intend to say it so bluntly, but in essence this is a legal pathway for the majority-staked side to bypass the normal block production process and keep the system alive by force.
Let’s look through the incentives: who benefits? The large holders with majority stake—in extreme cases, they can unilaterally decide whether the chain continues operating. That’s power. Who pays the cost? Ordinary users and small stakers—under these circumstances they have no say, and can only passively accept a “spinning” empty block until the system returns to normal. On the surface, it looks like a technical fail-safe. Dig deeper, and it’s actually about handing the “chain continuity” to the combined will of a small group of major stakeholders in the worst case.
The whitepaper doesn’t say whether this EBR mechanism has ever been triggered in real networks, nor does it provide an impact assessment of what it means for decentralization narratives—specifically, what effect “the majority-staked side jointly initiating empty blocks” has. That’s the part I haven’t found answers to so far.
A system design that “prevents complete shutdown” and “hands the decision power for a shutdown to the majority-staked side”—in extreme situations, these can be two sides of the same coin. Do you think this trade-off is reasonable? #dusk $DUSK @Dusk
Most people’s assumption about PoS chains is: as long as validators are online, consensus will eventually be reached—just maybe after waiting through a few more rounds. But the Dusk whitepaper states it very plainly: if the number of consecutive failed iterations reaches 16, the protocol will proactively disable the timeout mechanism and enter an “emergency mode.” At that point, two voting options—NoCandidate and NoQuorum—are directly disabled, meaning the committee is no longer allowed to effectively choose “nothing.”
There’s nothing particularly surprising about this design—it forces the system to keep moving forward. What really caught me off guard is the next part: in emergency mode, if even the maximum timeout across all iterations is exhausted and no candidate block can be selected, what happens then? The answer is: some provisioners can initiate an “Emergency Block Request” (EBR). As long as the group initiating the request holds the majority of the total stake on the network, they can directly produce an empty block containing no transactions—just to keep the chain progressing.
I didn’t originally intend to say it so bluntly, but in essence this is a legal pathway for the majority-staked side to bypass the normal block production process and keep the system alive by force.
Let’s look through the incentives: who benefits? The large holders with majority stake—in extreme cases, they can unilaterally decide whether the chain continues operating. That’s power. Who pays the cost? Ordinary users and small stakers—under these circumstances they have no say, and can only passively accept a “spinning” empty block until the system returns to normal. On the surface, it looks like a technical fail-safe. Dig deeper, and it’s actually about handing the “chain continuity” to the combined will of a small group of major stakeholders in the worst case.
The whitepaper doesn’t say whether this EBR mechanism has ever been triggered in real networks, nor does it provide an impact assessment of what it means for decentralization narratives—specifically, what effect “the majority-staked side jointly initiating empty blocks” has. That’s the part I haven’t found answers to so far.
A system design that “prevents complete shutdown” and “hands the decision power for a shutdown to the majority-staked side”—in extreme situations, these can be two sides of the same coin. Do you think this trade-off is reasonable? #dusk $DUSK @Dusk