Pith. sign in

REVIEW 4 major objections 5 minor 63 references

Censorship Resistance and Throughput with Multiple Concurrent Proposers

T0 review · 4 major / 5 minor · reviewed 2026-08-01 · deepseek-v4-flash

Pith's one-line read Multiple concurrent proposers can raise the cost of censoring a blockchain transaction roughly in proportion to their number, while a duplication-penalizing fee rule keeps throughput near its ceiling.

desk verdict Useful, clean model of MCP censorship resistance, but the headline scaling claims need a collusion caveat and the simulations need error bars. read the letter →

arxiv 2607.16995 v2 pith:SV4C5BAQ submitted 2026-07-18 cs.GT

classification cs.GT MSC 91A1091B26
keywords economiccensorshipresistancemultipleconcurrentproposerstransactionfeemechanismbriberyattackmixedNashequilibriumthroughputduplicationpenaltyblockchain
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper studies economically motivated censorship in blockchains, where an adversary bribes proposers to exclude a target transaction. It defines economic censorship resistance (eCR) as the adversary's expected cost of successful censorship divided by the user's expected payment for inclusion. It argues that single-proposer systems are structurally weak under this metric, and that splitting block production among multiple concurrent proposers can make censorship much more expensive—scaling roughly linearly with the number of proposers. The catch is duplicated transactions that eat throughput; the paper shows a duplication-penalizing fee mechanism navigates this trade-off best, dominating alternatives in both eCR and throughput on synthetic and empirical data.

What carries the argument

The engine is a symmetric mixed-Nash equilibrium over proposers' inclusion probabilities, computed by a one-dimensional bisection on the Lagrange multiplier lambda of a linear program. Admissible payoff functions—those where a transaction's marginal value to a proposer falls as more others include it—make the equilibrium unique, with each transaction included at probability determined by a common threshold lambda. A 'cut-and-paste' lemma then derives closed-form bribes: to censor a target transaction with probability s, the per-proposer bribe is the target transaction's marginal utility at the desired inclusion probability minus the equilibrium threshold of the game without it. The duplicati

What would settle it

Compute the same equilibrium under an adversary whose bribe is paid only if the target transaction is excluded; if the resulting eCR no longer grows linearly with the number of proposers (or drops to single-proposer levels), the paper's central scaling claim fails.

Watch

Extended reading notes

Core claim

The paper's central claim is that moving from one block proposer to multiple concurrent proposers, each building a sub-block from a shared mempool, converts a censorship bribe that costs only a few percent of the user's fee (single-proposer, with base-fee burn) into a bribe several times the user's fee, with the ratio growing linearly in the number of proposers. This holds under a 'duplication-penalizing' transaction fee mechanism, which pays a proposer a transaction's tip only when that transaction is included exactly once; the paper's equilibrium analysis finds this mechanism dominates even-split and collective fee sharing on both censorship resistance and throughput. The linear scaling su

Load-bearing premise

The result hinges on the bribe being public, unconditional, and identical for all proposers, and on proposers being rational and unable to collude; if bribes can be conditioned on success or proposers can collude, the cost of censorship drops substantially.

Editorial extensions

If this is right

  • If correct, MCP systems with duplication-penalizing TFM offer structural censorship resistance: an adversary must spend several times the user's fee even with significant base-fee burn, rather than a small fraction.
  • eCR grows roughly linearly with the number of proposers, so protocols can dial up censorship resistance by adding proposers without sacrificing much throughput after an initial duplication cost.
  • The duplication-penalizing TFM should be preferred over even-split or collective fee sharing in multi-proposer designs, based on both metrics across simulated Pareto and empirical block data.
  • The cut-and-paste bribe formula gives a practical way to compute censorship costs for any admissible TFM, requiring only a single equilibrium solve.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A natural stress test: the paper's model assumes an unconditional public bribe to every proposer. If an adversary can instead pay only upon successful censorship (a conditional bribe), the expected cost drops, so the linear scaling is likely an upper bound on resistance; extending the cut-and-paste method to conditional bribes could quantify the gap.
  • If proposers can collude, the many-proposer bribe burden collapses to a one-proposer negotiation; the paper notes this equivalence. Testing how much collusion is needed to restore weak censorship resistance would mark the practical limits of MCP.
  • The same equilibrium algorithm could be applied to intermediate two-tier tip schemes (between duplication-penalizing and even-split), suggesting a parameterized family where the optimal fee rule may be tunable per protocol.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. The paper studies economic censorship resistance (eCR) in multiple-concurrent-proposer (MCP) blockchains. It models n rational, non-colluding proposers who build sub-blocks from a shared mempool, facing an adversary that publicly offers an unconditional bribe to any proposer who excludes a target transaction. The paper defines eCR as the adversary's expected bribery cost divided by the user's expected payment, gives an LP-duality characterization of symmetric mixed equilibria for a class of admissible transaction fee mechanisms (TFMs), provides a one-dimensional bisection algorithm for computing these equilibria, and derives closed-form bribe formulas via a 'cut-and-paste' argument. It then compares three TFMs—duplication-penalizing, even-split, and collective—on synthetic Pareto-distributed bids and on empirical Ethereum tip data, concluding that MCP raises eCR substantially, that eCR scales roughly linearly with n, and that the duplication-penalizing TFM dominates the others in both eCR and throughput.

Significance. If the results hold, the paper makes a useful contribution to the growing literature on MCP and transaction fee mechanism design. The eCR definition is a clean, interpretable metric, and the equilibrium algorithm is efficient and applies to a broad family of TFMs. The cut-and-paste derivation of bribe costs is elegant and the core LP-duality arguments appear sound. The paper also ships an empirical validation on real Ethereum tip data, which is a valuable check. However, the headline quantitative claims—linear eCR scaling and TFM dominance—are simulation-based rather than theorem-based, and they depend on strong modeling assumptions (unconditional public bribes, no proposer collusion, exogenous tips). These caveats need to be stated more prominently, and at least one part of the empirical methodology is described in a way that is inconsistent with the model.

major comments (4)
  1. [§5.2, b* formula after Lemma 17] The closed-form bribe b* = u_c(p*_c) − λ^{−c} can be negative. This happens when the target's marginal value at the desired inclusion probability is below the post-cut equilibrium threshold, meaning the transaction is already censored with probability at least s even without any bribe. The paper does not define what eCR should be in that case (the bribery cost should be zero), nor does it state a nonnegativity condition. Since Definition 7 averages eCR over all mempool transactions and Section 6 reports aggregate curves, this omission can materially affect the plotted results. Please add a clamp or an explicit case distinction and state how negative b* is handled in the simulations.
  2. [§6.3, second paragraph] The empirical methodology says: 'we first solve for the baseline single-proposer equilibrium probabilities (p_i)_i under the relevant TFM. From these probabilities we compute throughput by taking the expected number of distinct transactions included by at least one of the n validators...' This is inconsistent with the n-proposer model of Sections 3–5. For n>1, each validator's sub-block capacity is B_B/n, and the relevant object is the n-proposer symmetric equilibrium, not the single-proposer equilibrium. If the code actually used the n-proposer equilibrium, the sentence should be rewritten to avoid describing it as single-proposer; if single-proposer probabilities were used for all n validators, the empirical validation does not test the model and the throughput/eCR numbers in Figure 6 are not the quantities defined in the paper.
  3. [Abstract and §7] The abstract and conclusion state as general findings that 'MCP systems enjoy much higher eCR than single proposer systems' and that 'eCR scales linearly with the number of validators' without the caveats that the adversary is restricted to public unconditional per-proposer bribes, that proposers are assumed not to collude, and that user tips are exogenous. Sections 1.1, 2, and 7 explicitly acknowledge that conditional bribes can be cheaper and that collusion is a natural threat. These qualifications should be carried through to the abstract and conclusion, and the linear-scaling claim should be labeled as a simulation-based observation rather than a proven structural result.
  4. [§6.1–§6.2, Figures 1–5] The principal quantitative claims—linear eCR scaling and dominance of the duplication-penalizing TFM—are supported only by Monte Carlo point estimates. No standard errors, confidence intervals, or statistical tests are reported for the 1000-trial averages, and no theorem establishes eCR growth in n. If these claims are central to the paper, the simulations should either be accompanied by uncertainty quantification or the claims should be explicitly framed as empirical observations over the chosen parameter grid.
minor comments (5)
  1. [§1.1] The parenthetical 'collusion is typically equivalent to a single proposer' is imprecise under the paper's unconditional per-proposer bribe: to censor the target, every proposer must exclude it, so the coalition still collects n per-proposer bribes. The equivalence holds more naturally for conditional bribes. Please clarify.
  2. [§6.3, first paragraph] The description 'single-proposer equilibrium probabilities' is confusing even if the intended meaning is 'baseline no-bribe equilibrium.' Please use consistent terminology.
  3. [§3, Definition 3] The transaction cost is defined conditional on inclusion in the final block. For the duplication-penalizing TFM, duplicated transactions are executed free of charge, so the denominator of eCR can be lowered by the TFM itself. This is acknowledged in Remark 1, but it would help to state explicitly in Definition 5 that eCR is not a measure of 'absolute' censorship cost but a ratio that depends on the TFM's fee extraction.
  4. [§5.2] The boundary handling for p*_c = 0 ('full censorship, s = 1') is described in one sentence. It may be worth stating the corresponding eCR formula explicitly, since s = 1 is used as a limiting case in the simulations.
  5. [§6, Figures] The figures would be easier to interpret with error bars or shaded confidence bands, especially because the claims are about dominance and scaling across n.

Circularity Check

0 steps flagged · score 1.0 of 10

No material circularity; the equilibrium and eCR derivations are self-contained, with only a mild definitional-normalization caveat.

full rationale

The central derivation chain is not circular. eCR (Definition 5) is explicitly defined as bribery cost (Definition 4) divided by transaction cost (Definition 3), and the paper then computes equilibria via a binary-search algorithm (Algorithm 1, supported by Property 1 and Theorem 13) and derives bribes via the cut-and-paste method (Lemma 17 and Section 5.2), producing closed forms like b* = u_c(p*_c) - lambda^{-c}. The linear-in-n scaling of eCR follows from the per-proposer bribe being O(1) under the duplication-penalizing TFM while the adversary must pay n proposers; this is a mathematical consequence of the model, not an input assumed in the conclusion. The one definitional-adjacent point is Remark 1: the eCR normalization rewards TFMs that lower expected user payments, and the paper explicitly acknowledges that duplicated transactions pay zero under the duplication-penalizing TFM, so part of that TFM's eCR advantage is a consequence of the chosen metric. This is a modeling choice rather than a derivational circularity. Self-citations such as [16] and [36] appear only in related-work or comparison contexts and are not load-bearing for the equilibrium, bribe, or scaling results. Assumptions like non-colluding proposers (Section 1.1) and unconditional public bribes (Section 3) are stated limitations, not circular inputs.

Assumptions & free parameters 4 free parameters · 7 assumptions · 0 invented entities

The model rests on a small set of standard game-theory tools plus the domain choices listed above (no collusion, public unconditional bribes, exogenous tips, shared mempool, and the eCR normalization). Simulation parameters (Pareto shape, burn multiple, target probability, block sizes) are inputs, not fitted to the conclusions. No new physical or postulated entities are introduced.

free parameters (4)
  • Pareto bid distribution (scale=1, shape alpha=2.5) = scale=1, alpha=2.5
    Synthetic bid baseline in Section 6.1; chosen to mimic heavy-tailed fees, not derived from the model.
  • Burn multiple beta / average tip = 4 and 8.7
    Burn levels in Section 6.1 and Figure 3; 8.7 is taken from an Ethereum Jan-2026 base-fee/tip ratio, not a model output.
  • Target censorship probability s = 0.9 (baseline)
    Adversary goal in Definition 4 and Section 6; varied in Figure 5; eCR values depend on it.
  • Mempool size m and block size B = m=250, B=200
    Baseline congestion in Section 6.1; varied in Figure 4; affects throughput and eCR levels.
assumptions (7)
  • domain assumption Proposers are rational and do not collude
    Section 1.1: 'proposers are rational, do not collude (collusion is typically equivalent to a single proposer)'. If they collude, the MCP bribe burden collapses to the single-proposer case.
  • domain assumption The bribe is public, unconditional, and identical for all proposers
    Section 3: 'adversary offers an unconditional bribe of b to all proposers who do not include t_c' and it is common knowledge. Conditional bribes would be cheaper (Sections 2 and 7).
  • domain assumption User tips are exogenous and users do not strategically respond
    Section 3, Remark 1: 'tips as exogenous'; user-side equilibrium and user-proposer collusion are left to future work.
  • domain assumption Proposers share a common mempool; no private order flow in the base model
    Section 3 assumes a shared mempool; Section 7 lists private order flow as an unmodeled extension.
  • domain assumption eCR is defined as bribery cost divided by expected user payment conditional on inclusion
    Definitions 3-5. This normalization is a modeling choice that can inflate the duplication-penalizing TFM, since duplicated transactions pay zero (Remark 1 acknowledges lower expected user payments).
  • domain assumption Each proposer submits exactly ell = B/n transactions; m > ell
    Section 3: 'Each proposer submits a sub-block of at most ell := B/n'; Section 4 assumes m > ell throughout.
  • standard math Standard LP duality, binomial identities, and Jensen's inequality
    Used in Property 1, Examples 9-11, and the equilibrium theorems.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Censorship Resistance and Throughput with Multiple Concurrent Proposers." pith.science (2026). https://pith.science/paper/SV4C5BAQ

@misc{pith2026260716995,
  author       = {Pith},
  title        = {Pith review of: Censorship Resistance and Throughput with Multiple Concurrent Proposers},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/SV4C5BAQ}},
  note         = {Machine review of arXiv:2607.16995}
}
abstract

Censorship resistance is the defining advantage of blockchains over their centralized counterparts. Yet block proposers censor transactions for many reasons, from legal consequences to economic incentives. We study economically-incentivized censorship, modeled by an adversary who bribes proposers to exclude a target transaction, and define the economic censorship resistance (eCR) of a transaction as the adversary's expected cost of successful censorship divided by the user's expected payment for inclusion. Single-proposer systems are structurally weak by this measure: under a first-price auction the adversary need only match the user's bid, and fee burning pushes eCR to a few percent of what the user pays. We therefore turn to multiple concurrent proposers (MCP), where block capacity is divided among $n$ proposers and the block is the union of their sub-blocks. While MCP can substantially increase the cost of censorship by requiring the adversary to bribe many proposers, it also introduces transaction duplication, reducing throughput. The resulting trade-off depends critically on the transaction fee mechanism (TFM), which determines how fees are shared among competing proposers. We create a game theoretic model where validators construct blocks from a shared mempool, subject to an adversary's bribery attempt. We provide an algorithm that solves for the mixed equilibrium of a given mempool, which is characterized by the probability of including each transaction. This algorithm works for a wide class of TFMs, and allows us to calculate the expected throughput and censorship resistance for any bid distribution. We then use simulations to show how the eCR and throughput vary as the number of proposers increases. We compare three TFMs, finding that the duplication-penalizing TFM dominates the others across many settings. We also validate our findings with empirical Ethereum data.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

63 extracted references · 4 linked inside Pith

  1. [1]

    arXiv preprint arXiv:1807.04938 , year =

    Buchman, Ethan and Kwon, Jae and Milosevic, Zarko , title =. arXiv preprint arXiv:1807.04938 , year =

  2. [2]

    and Resnick, Max , title =

    Fox, Elijah and Pai, Mallesh M. and Resnick, Max , title =. 5th Conference on Advances in Financial Technologies (AFT 2023) , series =. 2023 , doi =

  3. [3]

    Cho, Brian and Spiegelman, Alexander , title =

  4. [4]

    arXiv , volume =

    Sedna: Sharding transactions in multiple concurrent proposer blockchains , author =. arXiv , volume =

  5. [5]

    2019 , eprint=

    The latest gossip on BFT consensus , author=. 2019 , eprint=

  6. [6]

    2025 , note =

    Censorship.pics , organization =. 2025 , note =

  7. [7]

    2019 , howpublished =

    The RedBelly Network Whitepaper , author =. 2019 , howpublished =

  8. [8]

    2017 , howpublished =

    Filecoin: A Decentralized Storage Network , author =. 2017 , howpublished =

Show all 63 references
  1. [9]

    2020 , howpublished =

    The Hedera Hashgraph Consensus Algorithm , author =. 2020 , howpublished =

  2. [10]

    2020 , howpublished =

    Avalanche Consensus Protocol , author =. 2020 , howpublished =

  3. [11]

    2022 , howpublished =

    Mysten Labs , title =. 2022 , howpublished =

  4. [12]

    2025 , howpublished =

    Mysten Labs , title =. 2025 , howpublished =

  5. [13]

    2025 , howpublished =

  6. [14]

    2025 , url =

    Pranav Garimidi and Joachim Neu and Max Resnick , title =. 2025 , url =

  7. [15]

    2025 , month =

    Alpenglow: A Consensus Protocol for a High-Performance Proof of Stake Blockchain , author =. 2025 , month =

  8. [16]

    arXiv preprint arXiv:2502.20692 , year =

    MonadBFT: Fast, Responsive, Fork-Resistant Streamlined Consensus , author =. arXiv preprint arXiv:2502.20692 , year =

  9. [17]

    arXiv preprint arXiv:2508.12173 , year =

    Carry the Tail in Consensus Protocols , author =. arXiv preprint arXiv:2508.12173 , year =

  10. [18]

    and Gueta, Guy Golan and Abraham, Ittai , booktitle =

    Yin, Maofan and Malkhi, Dahlia and Reiter, Michael K. and Gueta, Guy Golan and Abraham, Ittai , booktitle =. HotStuff: BFT Consensus with Linearity and Responsiveness , year =. doi:10.1145/3293611.3331591 , pages =

  11. [19]

    2023 , url =

    Dahlia Malkhi and Kartik Nayak , title =. 2023 , url =

  12. [20]

    2021 , eprint=

    Mir-BFT: High-Throughput Robust BFT for Decentralized Networks , author=. 2021 , eprint=

  13. [21]

    2022 , url =

    Nicolas Alhaddad and Sourav Das and Sisi Duan and Ling Ren and Mayank Varia and Zhuolun Xiang and Haibin Zhang , title =. 2022 , url =

  14. [22]

    2016 , isbn =

    Miller, Andrew and Xia, Yu and Croman, Kyle and Shi, Elaine and Song, Dawn , title =. 2016 , isbn =. doi:10.1145/2976749.2978399 , booktitle =

  15. [23]

    19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22) , year =

    Lei Yang and Seo Jin Park and Mohammad Alizadeh and Sreeram Kannan and David Tse , title =. 19th USENIX Symposium on Networked Systems Design and Implementation (NSDI 22) , year =

  16. [24]

    2023 , eprint=

    BigDipper: A hyperscale BFT system with short term censorship resistance , author=. 2023 , eprint=

  17. [25]

    Bullshark:

    Spiegelman, Alexander and Giridharan, Neil and Sonnino, Alberto and Kokoris-Kogias, Lefteris , month = nov, year =. Bullshark:. Proceedings of the 2022. doi:10.1145/3548606.3559361 , urldate =

  18. [26]

    Mysticeti:

    Babel, Kushal and Chursin, Andrey and Danezis, George and Kokoris-Kogias, Lefteris and Sonnino, Alberto , month = feb, year =. Mysticeti:. doi:10.48550/arXiv.2310.14821 , urldate =

  19. [27]

    Flashbots Report: System Requirements, Existing and New Solutions, and Their Efficiency , author =

  20. [28]

    Wadhwa, Sarisht and Ma, Julian and Thiery, Thomas and Monnot, Barnabe and Zanolini, Luca and Zhang, Fan and Nayak, Kartik , year =

  21. [29]

    2024 , note =

    Fork-Choice Enforced Inclusion Lists (FOCIL) , author =. 2024 , note =

  22. [30]

    Gate.io , author =

    Braid:. Gate.io , author =

  23. [31]

    Neu, Joachim and Sridhar, Srivatsan and Yang, Lei and Tse, David , year =. Optimal

  24. [32]

    Bonneau, Joseph and Bünz, Benedikt and Christ, Miranda and Efron, Yuval , year =. How

  25. [33]

    BRICS Report Series , volume =

    Balls and Bins: A Study in Negative Dependence , author =. BRICS Report Series , volume =

  26. [34]

    The Annals of Statistics , pages=

    Negative association of random variables with applications , author=. The Annals of Statistics , pages=. 1983 , publisher=

  27. [35]

    J. L. Doob , journal =. Regularity Properties of Certain Families of Chance Variables , urldate =

  28. [36]

    2025 , note =

    Multiple Proposer Transaction Fee Mechanism Design: Robust Incentives Against Censorship and Bribery , author =. 2025 , note =. doi:10.48550/arXiv.2505.13751 , url =. 2505.13751 , archivePrefix =

  29. [37]

    Proceedings of the 33rd ACM Web Conference (WWW ’24) , year =

    Blockchain Censorship , author =. Proceedings of the 33rd ACM Web Conference (WWW ’24) , year =. doi:10.1145/3589334.3645431 , publisher =

  30. [38]

    Proceedings of the 2023 ACM Internet Measurement Conference (IMC '23) , year =

    Ethereum's Proposer-Builder Separation: Promises and Realities , author =. Proceedings of the 2023 ACM Internet Measurement Conference (IMC '23) , year =. doi:10.1145/3618257.3624824 , publisher =

  31. [39]

    CoRR , volume =

    Roughgarden, Tim , title =. CoRR , volume =. 2021 , url =

  32. [40]

    Karakostas, Dimitris and Kiayias, Aggelos and Zacharias, Thomas , title =. Proc. of CCS 2024 , pages =. 2024 , doi =

  33. [41]

    IEEE Europe

    Winzer, Fredrik and Herd, Benjamin and Faust, Sebastian , title =. IEEE Europe. Symposium on Security and Privacy Workshops (EuroSP Workshops) 2019 , pages =. 2019 , publisher =

  34. [42]

    Computer Security – ESORICS 2020, Proceedings, Part II , series =

    Sun, Hanyi and Ruan, Na and Su, Chunhua , title =. Computer Security – ESORICS 2020, Proceedings, Part II , series =. 2020 , editor =

  35. [43]

    2024 , howpublished =

    Financial Censorship , author =. 2024 , howpublished =

  36. [44]

    Financial Cryptography 2018 Workshops , editor =

    McCorry, Patrick and Hicks, Alex and Meiklejohn, Sarah , title =. Financial Cryptography 2018 Workshops , editor =. 2019 , publisher =

  37. [45]

    Gai, Fangyu and Niu, Jianyu and Beschastnikh, Ivan and Feng, Chen and Wang, Sheng , title =. Proc. of IEEE ICDE 2023 , pages =. 2023 , publisher =

  38. [46]

    and Mamageishvili, Akaki and Sudakov, Benny , title =

    Berger, Ben and Felten, Edward W. and Mamageishvili, Akaki and Sudakov, Benny , title =. Proceedings of the 26th ACM Conference on Economics and Computation , pages =. 2025 , isbn =. doi:10.1145/3736252.3742611 , abstract =

  39. [47]

    CoRR , volume =

    Alpos, Orestis and David, Bernardo and Kamarinakis, Nikolas and Zindros, Dionysis , title =. CoRR , volume =. 2025 , url =

  40. [48]

    2025 , eprint=

    Transaction Fee Mechanism Design for Leaderless Blockchain Protocols , author=. 2025 , eprint=

  41. [49]

    Proceedings of the 2023 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA) , pages =

    Chung, Hao and Shi, Elaine , title =. Proceedings of the 2023 Annual ACM-SIAM Symposium on Discrete Algorithms (SODA) , pages =. 2023 , doi =

  42. [50]

    and Kiayias, Aggelos and Leonardos, Nikos , title =

    Garay, Juan A. and Kiayias, Aggelos and Leonardos, Nikos , title =. Advances in Cryptology -- EUROCRYPT 2015 , series =. 2015 , doi =

  43. [51]

    Financial Cryptography and Data Security -- FC 2016 International Workshops (BITCOIN) , series =

    Bonneau, Joseph , title =. Financial Cryptography and Data Security -- FC 2016 International Workshops (BITCOIN) , series =

  44. [52]

    Proceedings of the Seventeenth European Conference on Computer Systems (EuroSys '22) , pages =

    Danezis, George and Kokoris-Kogias, Lefteris and Sonnino, Alberto and Spiegelman, Alexander , title =. Proceedings of the Seventeenth European Conference on Computer Systems (EuroSys '22) , pages =. 2022 , doi =

  45. [53]

    2021 , note =

    Buterin, Vitalik , title =. 2021 , note =

  46. [54]

    2022 , note =

    D'Amato, Francesco , title =. 2022 , note =

  47. [55]

    2023 , note =

    Neuder, Mike and Buterin, Vitalik and D'Amato, Francesco and Tsao, Terence and. 2023 , note =

  48. [56]

    2023 , note =

    Buterin, Vitalik and Neuder, Mike , title =. 2023 , note =

  49. [57]

    The more, the less censored: Committee-enforced Inclusion Sets (

    Thiery, Thomas and D'Amato, Francesco and Monnot, Barnab. The more, the less censored: Committee-enforced Inclusion Sets (. 2024 , note =

  50. [58]

    2024 , note =

    Thiery, Thomas and D'Amato, Francesco and others , title =. 2024 , note =

  51. [59]

    2026 , url =

    Elsheimy, Fatima and Kaklamanis, Ioannis and Wadhwa, Sarisht and Papamanthou, Charalampos and Zhang, Fan , title =. 2026 , url =

  52. [60]

    2025 , url =

    Abraham, Ittai and Efron, Yuval and Ren, Ling , title =. 2025 , url =

  53. [61]

    Proceedings of the 46th IEEE Symposium on Security and Privacy (S&P) , publisher =

    Yang, Sen and Nayak, Kartik and Zhang, Fan , title =. Proceedings of the 46th IEEE Symposium on Security and Privacy (S&P) , publisher =. 2025 , url =

  54. [62]

    Proceedings of the ACM Web Conference 2025 (WWW '25) , publisher =

    Wang, Shuzheng and Huang, Yue and Zhang, Wenqin and Huang, Yuming and Wang, Xuechao and Tang, Jing , title =. Proceedings of the ACM Web Conference 2025 (WWW '25) , publisher =. 2025 , doi =

  55. [63]

    2025 , url =

    Alpos, Orestis and Heimbach, Lioba and Nayak, Kartik and Wadhwa, Sarisht , title =. 2025 , url =

Pith tools

Reviewed August 1, 2026 · model on record in the stance chip above.