I started looking at Dusk’s Emergency Mode after asking myself a simple question: what happens if most of the participants responsible for consensus suddenly go offline?
No attack. No malicious block.
Just not enough stake participation to reach agreement.
That’s what made @Dusk ’s Emergency Mode interesting to me.
At first, I assumed Emergency Mode was mainly about producing an emergency block. Looking closer, that isn’t really the point.
When one consensus iteration fails, Dusk doesn’t immediately close the door. Previous iterations can remain open while new ones begin, giving the remaining provisioners more chances to reach agreement.
But that creates a trade-off: keeping multiple iterations alive also creates the possibility of competing blocks.
That’s why Dusk prioritizes the lowest successful iteration.
And if participation remains insufficient, the Emergency Block Request (EBR) provides another recovery path. Once EBRs representing a majority of network stake are collected, an empty emergency block can be produced.
That block isn’t there to process transactions. Its purpose is to keep the chain moving and establish a fresh seed for another consensus attempt.
So Emergency Mode isn’t really about what happens when consensus succeeds. It’s about what the protocol does when the assumptions behind consensus stop holding.
That’s the deeper trade-off: preserving liveness is useful, but the recovery path has to remain deterministic when multiple outcomes are possible.
The question I’m left with is how well this recovery path holds up if degraded participation isn’t temporary, but persistent.
@Dusk $DUSK #dusk