Docs Xyz — Running an Ethereum proof-of-stake | docs.zstake.xyz

Docs Xyz — Running an Ethereum proof-of-stake | docs.zstake.xyz

Double Signing, Surround Votes and Slashing

Only two offences slash a validator — a double sign and a surround vote — and both are provable on-chain; ordinary downtime is not among them.

Exactly two offences slash a validator. The first is a double sign: two conflicting attestations for the same slot. The second is a surround vote, an attestation whose range brackets one of the validator's earlier votes. Both are provable from the signed messages themselves.

The minimum forfeit is 1/64 of the stake — 0.5 ETH on a 32 ETH validator — and a quadratic penalty is added on top, so the real cost exceeds that floor. A 2-epoch exit is queued behind the penalty.

Everything else is a mistake, not a crime. Missing attestations on both sides of a slot is not by itself a slashable offence; it forfeits the rewards those attestations would have earned and nothing more.

The signature mark of this site, drawn as a plate

On narrow screens, swipe or scroll the plate sideways.

The duty schedule explains why honest mistakes are common and slashing is rare. Each validator attests once per epoch, and 8,192 slots divided by 32 slots per committee gives 256 committees per epoch — the network spreads the work so that no single slot depends on a single validator.

Downtime has its own, separate consequence. Past the weak subjectivity period — about 27 hours, one epoch — a returning client cannot resolve the canonical chain from the fork choice alone and must resynchronise from a checkpoint before attesting again.

And a validator that simply stops attesting does not get to sit at zero: it bleeds balance until its effective balance falls to 32 ETH, at which point it is queued for exit automatically.

  • Slashable: two conflicting attestations for the same slot.
  • Slashable: a surround vote bracketing an earlier vote.
  • Not slashable: missed attestations, even on both sides of a slot.
  • Not slashable: being offline — but past one epoch the client must resync from a checkpoint.

Further reading