# kaal:claim:3125822-034

**Claim.** A proof of stake lottery on this architecture is vulnerable because the seed of the pseudorandom generator that names the next block author is partly controlled by the current block author, which lets an attacker capture all block creation by routing authorship to their own Sybil accounts; the proposed remedy is to derive the seed from a hash of the previous block's validation information.

**Type.** failure  **Support.** argued

**Holds when.**

- applies to the proof of stake block author lottery

**Source quote.**

> The seed for the generator that determines the next block author is partially controlled by the current block author, which opens the possibility of gaming the system by controlling all block creation by sending authorship to your own Sybil accounts.

**From.** Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, *Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A* (2018), 7.4.1 Example: Proof of stake, page 34

**Cite as.** Craig Calcaterra, Wulf A. Kaal, Vlad Andrei, Blockchain Infrastructure for Measuring Domain Specific Reputation in Autonomous Decentralized and A (2018). SSRN: https://ssrn.com/abstract=3125822

**Verify.** sha256 of source PDF `d4d0bbaa3260968226186131d60e6d64a53e904d94e4295c61fd17042f1191ef` at https://raw.githubusercontent.com/wulfkaal/Academic-Papers/main/papers/pdf/Calcaterra%20et%20al.%20-%202018%20-%20Blockchain%20Infrastructure%20for%20Measuring%20Domain%20Specific%20Reputation%20in%20Autonomous%20Decentralized%20and%20A.pdf

**Failure mode.** block author seed capture  (family: consensus-and-protocol-attack)

**Topics.** consensus-and-security

**Keywords.** sybil-attack, randomness, proof-of-stake, block-authorship

**Canonical form.** This markdown file is the canonical hashed representation of the claim. Its sha256 is the content hash used for attestation.
