EOPcoin

A Sybil-resistant blockchain powered by absolutely anonymous evidence of personhood rather than energy expenditure or locked wealth.

White paper

Executive Summary

EOPcoin is a blockchain based on the idea that the wealth of evidence of personhood (EoP), which is becoming easily available in digital form due to emerging projects like zkPass and zkPassport, can provide a new basis for blockchain consensus. The implementation (in progress) is based on Ethereum, so it inherits Ethereum’s smart contract functionality and leverages its stake-related code—but replaces stake with information-theoretic “weights” that are derived from items of evidence of personhood.

A wide variety of types of EoP can be used, from passports to electric company accounts. Two key aspects of EOPcoin are its incorporation of techniques for non-rebindability and privacy. Non-rebindability is essential to an EoP-based consensus mechanism so that the same EoP isn’t used over and over by being bound to different accounts. Privacy is also essential, and EOPcoin’s is secure even against cryptographic brute force attacks at a level that could be carried out by a government trying to determine whether one of its passport holders has registered, even using its access to all the data associated with that passport. The EOPcoin sub-project which has those properties is called ASGARD (Anonymous Sybil-Resistant Gatekeeping Architecture with Issuer-Resistant Nullifier Derivation). As far as we can tell after extensive searches, there is no publicly known algorithm with those properties that works in a decentralized setting. (ASGARD will be public soon.)

When operating on a scale similar to Bitcoin’s and Ethereum’s, EOPcoin aims for at least a similar degree of security. But this is done without requiring more hardware capabilities than those of millions of home PCs being sold annually, and without the need for high energy bills or staking—the latter of which can be costly because it requires foregoing other investment opportunities.

Security is based on the amount of EoP added by each node operator. Unlike other blockchains that use EoP for gateway purposes, node operators can add as much EoP as they want (from different sources) and collect more profit from issuance and transaction fees for each item they add. Each item also makes the blockchain itself more secure.

EOPcoin’s inherent Sybil resistance enables it to target the same opportunities as World (formerly WorldCoin) without requiring iris scans. Iris scan technology is appropriate in many parts of the world, but first-world countries already have an enormous amount of digital identity information readily available that can be used instead. EOPcoin is a better match in those countries. World has 18 million verified users and a $1 billion market cap, with integrations in progress with companies like Tinder and Zoom, underscoring the need for Sybil resistance. EOPcoin, with similar integrations, can enable people to fully register directly in those apps, which is impossible for World due to its scanning requirement.

EOPcoin has pending patents on its core enabling concepts, including ASGARD.

Introduction

Like Bitcoin and Ethereum, EOPcoin is a blockchain that will enable transactions, and like Ethereum, it will also provide for smart contracts because it is based on Ethereum’s source code.

Payments are made for running transactions and smart contracts, and those payments are distributed to node operators. Also, new coins are issued, and those, too, are distributed to node operators.

So, like Bitcoin and Ethereum, EOPcoin is a blockchain through which node operators can earn rewards.

However, it has an entirely different basis for security from Bitcoin and Ethereum, with the result that it does not require special hardware, large-scale energy consumption, or stake.

Its innate Sybil resistance makes it a good support for applications that benefit from that, enabling it to compete with World (formerly WorldCoin). While using digital persona credentials for Sybil resistance, it also has a uniquely high level of privacy; even the issuer of a credential cannot discover whether the person it represents has registered.

The problem

We first look at the currently dominant blockchains to see where we can solve existing problems.

Bitcoin and proof-of-work

In this section, we will consider whether Bitcoin’s security is as impregnable as many people think it is. We are doing so not to claim that Bitcoin isn’t secure, but to begin to discuss why EOPcoin may be able to achieve a similar or higher level of security. In the Security section of this paper, we will discuss how it avoids the challenges mentioned here.

Bitcoin leverages billions of dollars worth of hardware and an energy expenditure equal to that of a mid-sized country. The security of a proof-of-work blockchain like Bitcoin depends on the amount of hardware and energy required to launch a 51% attack. To achieve Bitcoin’s level of security, individual personal computer owners are “priced out” of participation, leading to centralization.

This centralizing effect is so strong that .1% of Bitcoin miners, about 50 of them, control close to 50% of the mining power.[1] This is because, according to a paper from the National Bureau of Economic Research:

mining centralization arises from core aspects of the Bitcoin mining protocol, and is not a temporary aberration.[2]

It can have the following effect, according to an article in the Communications of the ACM:

The currency stops being decentralized and becomes controlled by the colluding group. Such a group can, for example, prohibit certain transactions, or all of them.[3]

Ethereum and proof-of-stake

Ethereum uses hundreds of billions of dollars worth of stake for its security. The more stake, the more secure any proof-of-stake (PoS) blockchain is, because of “slashing”: stakers taking part in an attack can potentially lose 100% of their stake.

But staking has to compete with other possible investments; if people choose not to invest in stake, blockchains which depend on such investments will lose their source of security.

A working paper from the United States Office of Financial Research discusses how Ethereum’s security depends on stake. It models the risk that, if staking ETH becomes unattractive, the motivation to stake may go down. Therefore, there may be less security, making ETH a worse investment, making staking in it still less attractive.[4]

BlackRock’s Jay Jacobs and Robbie Mitchnick wrote:

Ethereum staking offers the potential to earn modest rewards … but should only be considered after deciding to add exposure to ETH.[5]

But given that Ethereum is down more than 60% from its high, it may be worth asking how many people will continue to make that exposure decision.

As with Bitcoin, we are not claiming Ethereum is a poor investment, and we acknowledge that many members of the relevant communities would contest the quotes provided above. We are only pointing out that there is potential for an alternative blockchain foundation, founded on a very different basis, to have security advantages.

Expense of PoW and PoS

To earn rewards on a PoW blockchain, one needs to pay for the electricity and hardware. And to earn rewards on a PoS blockchain, one needs to put one’s capital on-chain rather than investing it elsewhere. This is an opportunity cost. Since 2024, the returns for staking on Ethereum have been less than those from 3-month T-bills, and they have not been keeping up with inflation this year.

So, while rewards are earned, there is a cost to those rewards. If EOPcoin were to eventually reach a similar scale of growth, it could reward transaction fees and issuance to node operators without those associated costs.

Summary

We propose that EOPcoin could compete with Bitcoin and Ethereum in terms of security if it reaches their scale, and that node operators could be more profitable with EOPcoin at that point. Additionally, it has commercial opportunities due to its intrinsic Sybil resistance, as explored in the section "The commercial potential for EOPcoin."

The threshold for viability

EOPcoin is based on the proposition that evidence of personhood (EoP) can be used instead of work or stake to enable blockchain security. The primary questions are: how well can we leverage EoP for security, compared to how well, for example, Bitcoin leverages billions of dollars worth of hardware and an energy expenditure equal to that of a mid-sized country, and Ethereum leverages hundreds of billions of dollars worth of stake? Can it be done in a way that makes EOPcoin at least as secure as those blockchains, without requiring such resources?

There is a threshold of security potential, below which EOPcoin is not viable, and above which it is. We propose that the threshold is reached when its design enables it to achieve, when operating at a scale similar to Bitcoin’s or Ethereum’s, at least a similar level of security.

Our goal is to use every available lever that has potential for enabling us to reach that threshold.

Reaching the threshold

The levers we have available for reaching the viability threshold are discussed in the following sections.

We also note that various combinations of these aspects are patent-pending.

EOPcoin security grows as the average amount of EoP per person rises.

The first lever is to maximize the ability of security to grow as more EoP is added.

There are existing blockchains where the security grows as each person is added, where each person adds their own EoP. Examples include Humanode, Idena, and Duniter. But the security added to those projects is limited by the number of people added.

As far as we have been able to determine, EOPcoin is unique in that it benefits not only from the EoP associated with the number of people, but also from how much EoP each person brings.

Motivating people to add multiple EoPs.

On EOPcoin, people earn rewards for each EoP they are associated with. So the motivations of the individual person and the needs of the blockchain as a whole are aligned. The more EoP a person adds, the greater their rewards and the more secure the blockchain as a whole is.

Motivating people to add particularly fraud-resistant EoPs

EOPcoin assigns greater rewards for EoPs that are more fraud-resistant. This motivates people to add stronger EoPs. But it doesn't discourage people from adding EoPs that are less fraud-resistant, because those can add up to reach the value of more secure ones. (A key to that is not allowing more than one EoP per person per source.)

Using information theory to maximize the impact each EoP has on security

EOPcoin assigns different weights to EoPs from each source based on how fraud-resistant the EOPcoin community agrees the source’s EoPs are. These weights determine how often the related validators are randomly chosen for committee assignments and block proposing.

Obviously, sources that are more fraud-resistant should receive higher weights because they have more influence on blockchain processing. But the question is, how do we determine how much weight to give?

Ultimately, the weights must be based on human intuition because there are no real-world measurements to determine them. We don’t know how often sources of EoP, such as the United States government, might be the source of fraudulent EoPs to be used in attacks against EOPcoin when EOPcoin isn’t yet in operation and there have been, and may never be, serious attacks. And yet, we know that such attacks are not inconceivable, if, for instance, the right government employees are bribed with large sums of money provided by China and promised safe relocation before the effects of the fraud are felt. And of course, such corruption would be far easier in the case of college IDs.

But despite the fact that we can’t measure what the probabilities are, it’s intuitively clear that there are actual underlying probabilities, whether we know them or not.

And it’s intuitively clear that if we can somehow assign weights that are most meaningfully reflective of the underlying probabilities, that will be better for security than if we assign random weights, even if they are greater for sources we think are less likely to be affected by fraud.

Let’s assume we can meaningfully estimate a probability for fraud (exactly what that probability represents will be defined below). Of course, our guesses won’t be accurate, but it seems intuitively clear that they will be significantly better than random.

Now we will present EOPcoin’s method for computing weights from probabilities.

First: we assume the condition of an attack.

Further, we assume a user, \(u_1\), two sources of EoPs, \(s_1\) and \(s_2\), and two EoPs the user has received from the sources, \(e_{1,1}\) and \(e_{1,2}\).

And further, we define the probability \(p(e_{a,b})\) as the probability that source \(s_b\) has been corrupted by whoever is running the attack. So, for example, \(p(e_{1,2})\) is that probability for source \(s_2\).

We note that corrupting the source of an identity document is not the only way to attack. For instance, for a passport, we would use zkPassport or equivalent software to read the passport’s RFID chip and create a digital, cryptographically verifiable attestation of having a passport. It might be that that intermediate software is the point of attack.

But for the sake of discussion, we are calling the entire path, including intermediate software, the “source” of the EoP which ultimately appears on-chain. This is realistic to the extent that EOPcoin gives different sources their own unique paths. For instance, EOPcoin can be designed to allow only zkPassport to read passports. In the end, there may be some fudging in the paths where different sources do have some path aspects in common. And we make one more simplifying assumption: given an attack, whether one source has been corrupted tells us nothing about whether another has been — the paths are sufficiently separate, and success on one path is not taken as evidence of an attacker capable of defeating others.

These simplifications mean there isn’t 100% accuracy in the analysis. But it doesn’t have to be rigorously perfect, because this is not a theorem; it’s a real-world project with all the messiness that entails. Economics commonly uses simplifying assumptions that are not 100% accurate, but those assumptions can still be useful. The world does not always correspond perfectly to simple mathematical models, and so, simplifying assumptions are common, and the models are nevertheless found to be useful in many, many circumstances. In our case, our calculations must be sufficiently accurate to optimize our use of EoP to the point where the network becomes viable. That is our only real goal.

It’s important to notice the role that conditioning on the attack plays here. If the probabilities weren’t conditional on the assumption of an attack, then \(e_{1,2}\) being fraudulent would indicate the existence of an attack we weren’t already assuming, and that would make it more likely that \(e_{1,1}\) was also fraudulent. So the assumed condition of an attack is essential for independence. That condition, together with the simplifying assumption we made above, is what lets us treat the events that \(e_{1,1}\) and \(e_{1,2}\) are fraudulent as conditionally independent given an attack: learning that \(e_{1,2}\) is fraudulent does not change the conditional probability that \(e_{1,1}\) is fraudulent. For brevity, we’ll simply refer to these conditional probabilities as probabilities.

Now suppose we have another user, \(u_2\), who has only one EoP, from a third source, \(s_3\). And further, suppose that \(s_3\) is sufficiently more secure that its probability of corruption equals the joint probability that both \(s_1\) and \(s_2\) are corrupted. In other words, because independent probabilities are multiplied to compute a joint probability, we have: $$ p(e_{1,1})p(e_{1,2})=p(e_{2,3}) $$ But we need a way of computing the weight of an EoP that can be substituted for work or stake. In particular, since EOPcoin is based on Ethereum source code, we want to be able to substitute weight for stake.

We have said that the likelihood that \(s_1\) and \(s_2\) are both corrupted is exactly the same as for \(s_3\) alone. So a user who has added EoPs from both \(s_1\) and \(s_2\) has added the same amount of security to the network as one who added only \(s_3\) and should therefore be rewarded the same way.

So the rewards user \(u_1\) receives from the validator associated with \(e_{1,1}\), plus the rewards that the user receives from \(e_{1,2}\), should be the same as \(u_2\) receives for \(e_{2,3}\). In other words, if the function calculating the weight is \(w\), we have: $$ w(e_{1,1})+w(e_{1,2})=w(e_{2,3}) $$ We used the two-subscript notation in the examples above because we were discussing specific users and sources, but in general, we can say that for any EoPs \(e_1\), \(e_2\), and \(e_3\) for which:

\[p(e_{1})p(e_{2})=p(e_{3})\]

we should have $$ w(e_{1})+w(e_{2})=w(e_{3}) $$

Also, since smaller values of \(p\) are associated with greater weights \(w\), and probabilities are between 0 and 1, we have $$ 0<p(e_1)<p(e_2)\le1 \implies w(e_1)>w(e_2) $$ There is exactly one way of calculating \(w\) that has those properties: $$ w(e)=-\log_b(p(e)) $$ for some base \(b>1\). In information theory, this logarithmic calculation on a probability creates “self-information”, a.k.a. “surprisal”. If the base \(b\) is 2, the units of the calculated weights are called “bits of information”.

So we can say that each EoP carries a certain number of bits of information. We could use the number of bits of information as the weight, but for reasons of convenience (such as to bring them to the same magnitude as stake when using EoP software that hardcodes certain limits), we can also multiply them by a constant to derive the weight with no effect on the underlying reasoning.

Sybil resistance

The term “Sybil resistance” comes from a 1973 book about a woman with multiple personality disorder. It relates to the fact that for many applications, an attacker can cause various kinds of problems by creating online identities which seem to represent separate people, but which are actually under the control of just one person.

In many cases, the ultimate sources of EoP have built-in Sybil resistance. For instance, the US government doesn’t normally supply more than one simultaneous passport for the same person (although it does under certain special circumstances). And LinkedIn makes a good-faith effort to prevent the same person from creating a new account within 365 days of another one, and zkPass can enable a verifiable attestation for use by EOPcoin to be generated from a LinkedIn account. (EOPcoin can limit the time period for which a LinkedIn-based attestation is valid, mitigating that risk; but getting a new account involves deactivating one’s old one, and losing its connections, so it’s a sacrifice few people would be willing to make just to get some extra EOPcoin income.)

In fact, EOPcoin only accepts sources that have built-in Sybil resistance.

It’s important to note that, while very determined individuals can often find ways to obtain more than one EOPcoin account using the same EoP source, this is not an attack that poses a significant threat to the network. It’s too small-scale. One can imagine an attack by a nation-state whose passports are used, and in which huge numbers of fake passports are created by that nation-state and fake accounts placed on the system using them, but that is a different kind of attack, which EOPcoin has specific mechanisms to make impossible, discussed elsewhere in the Security section of this document.

Privacy

Using zkPassport with a passport, or zkPass with an account such as LinkedIn or Coinbase, results in a verifiable attestation with privacy built-in. (There are other ways, such as zkemail, but we are focusing on two for simplicity.) An outsider with access to the attestation, but not to the data that was used in forming it, cannot determine the person who is its subject.

However, there are two remaining issues.

  1. EOPcoin may have reason to use an attestation that isn’t as private as the ones mentioned above.
  2. It may be that the entity that is the source of the information used in creating an attestation for a particular person wants to identify that particular person’s account, or at least know whether they’ve registered.

For that purpose, we have developed a technology we call ASGARD (Anonymous Sybil-Resistant Gatekeeping Architecture with Issuer-Resistant Nullifier Derivation).

ASGARD makes it so that, even in a decentralized context such as the EOPcoin blockchain, and even if an attacker knows the information that is associated with a given person and used as input, they cannot link it with a particular account on-chain or the actions taken by that account.

But at the same time, ASGARD ensures that the same attestation cannot be used more than once on an ASGARD-using system to create an account. (A property we call non-rebindability.)

This non-discoverability is true even of the account issuer that knows all of the information going into a zkPass or zkPassport attestation and can therefore generate the same attestation themselves using the open-source code behind those projects. So, even the US government would be unable to know that a person who has registered with their passport has registered.

It’s worth mentioning that ASGARD is patent-pending, with us as the sole inventor and assignee. We don’t claim that another way can’t be created to achieve the same goals: non-rebindability together with absolute privacy, even from the issuer of a credential, even to the point of them not being able to discern whether the person has registered. But we have searched using the best means available to us, and have not been able to find an alternative that is currently available.

Security

Attacks based on a malicious entity having too much of the underlying resource

EOPcoin has a different primary attack vector than those applicable to Bitcoin and Ethereum.

A 51% attack occurs when an entity controls more than half of the network’s hash rate. It can do so unbeknownst to the network as a whole and suddenly put forth its version of the blockchain, which may show funds as unspent that have been spent on the main chain, enabling them to be spent again because this malicious chain has suddenly become the most-work chain.

In EOPcoin, there isn’t work and therefore no opportunity for such an attack.

In a PoS blockchain powered by a variant of Byzantine consensus, such as Ethereum, there is a possibility that an entity such as a nation-state could add enough stake to the network that it controls more than 33.3% of the total. That would enable the attacker to prevent finalization.

In contrast, EOPcoin is structured such that people register their EoPs before they are used for consensus or other actions. This enables the network to automatically detect and prevent an attack.

Suppose the government of China were to issue a huge number of fake passports, and use zkPassport to create attestations which can be added to EOPcoin.

EOPcoin node software continuously monitors the counts of EoPs from every source. Long before one source has enough EoPs on-chain that validators relying on EoPs from that source could become a threat, those validators are automatically disallowed from any consensus activity.

This is a resistance to attack that Bitcoin and Ethereum have no equivalent for, because the source of hashing power or stake is not supplied for such chains.

Centralization-based attacks

We discussed the dangers of centralization for proof-of-work and proof-of-stake chains in the "The problem" section near the top of this paper. They have forces that lead to centralization and commensurate risk.

EOPcoin’s reliance on evidence-of-personhood instead of work or stake provides a strong contrast. It does not require the specialized hardware or extremely high energy consumption that puts Bitcoin mining beyond the reach of ordinary PC users. And it doesn’t require stake which can be slashed, which is a motivation for using staking pools where they trust that slashing won't occur.

It can run on millions of PCs, Macs, etc. being sold annually, and over time, the proportion of such hardware being able to run it will increase until pretty much any home computer can do so. And it can be run without risking staked capital.

So, we expect that EOPcoin, if it were to eventually achieve prominence at a similar level to the existing major blockchains, would be far more decentralized.

Punishment for malicious actions

If a user's node software is altered such that it violates the blockchain rules, the EoP is deactivated and can never be reactivated. But unlike Ethereum slashing, which punishes users by destroying (burning) a portion of their staked funds, the main point of EoPcoin's deactivation of EoP is that it cannot be used to enable any future rule-breaking.

Other practical differences between EOPcoin, Bitcoin and Ethereum

Hardware requirements

Bitcoin mining is considered to be out of the reach of average home computer users because it depends on expensive hardware called ASICs (Application-Specific Integrated Circuits).

In contrast, hardware requirements for EOPcoin are the same as Ethereum’s for a particular level of transaction activity and stored history. At launch, EOPcoin will require far less than Ethereum because of the much shorter history and far lower rate of transactions. But if we were to assume parity with Ethereum on those axes, it’s worth noting that Ethereum can run on a Raspberry Pi that costs less than $700 today, and considering trends in price decreases for memory and SSDs, will probably cost less than $350 in 5 years in inflation-adjusted dollars, with continued decreases after that.

Moreover, millions of home computers sold every year can run EOPcoin without requiring any extra hardware at all.

Energy use

Bitcoin uses as much energy as a medium-sized country. EOPcoin will use as much electricity as a typical awake home computer, around $7 per month. But an appropriate Raspberry Pi configuration uses an amount closer to $2 per month.

Financial opportunity cost

As discussed above, Ethereum’s security is based on buying ETH and committing it as stake. Money committed as stake can’t be invested elsewhere. Returns for staking are typically less than for 3-month treasury bills, and so far in 2026, they’re less than inflation.

For people who feel that ETH’s price will rise, and who therefore want to invest in ETH for that reason, it’s definitely a good idea to stake much or all of that ETH so that there is income from this speculative asset. But without such assumed price rises, the question of whether it will be viewed as a good investment for non-speculators is worth asking, and it seems fair to wonder about the implications of such questions for the future of Ethereum security, given that the price of ETH today is down by about 67% from its high at the time of this writing.

The commercial potential for EOPcoin

We have already discussed EOPcoin's potential relative to Bitcoin and Ethereum purely as a blockchain.

Now we will focus on its potential as a Sybil-resistant blockchain, which opens up many doors. We will discuss this by using World (formerly WorldCoin) as an example.

World relies on a biometric identity, where people’s eyes are scanned by a hardware device called an Orb. It is currently hard for most people in the US to access them. One can get an account without an iris scan, but the privileges one earns by doing so are constrained until a scan occurs. It is also possible to use passports, obtaining somewhat limited benefits compared to a scan-based account.

However, World is not a blockchain. It is based on smart contracts living on Ethereum, relying wholly on Ethereum for security. If the WLD coin (and/or other coins that rely on Ethereum) were to rival Ethereum's in total value, it would be a threat to Ethereum because it would rely on the security provided by Ethereum's stake, without contributing to that security.

EOPcoin is a blockchain that, in the long term, has potential to compete with Bitcoin and Ethereum. It can even use World’s Proof of Human credential as a type of EoP contributing to a piece of its security, which Ethereum cannot do.

Like EOPcoin, World provides Sybil resistance, in World’s case, through its iris scans. It is possible for irises to give different scan results, resulting in different identities, in the event of accidents or illness affecting the iris, but this is rare.

Today, there are 18 million verified humans on World, and WLD has a market cap of more than $1 billion. It is integrated with Tinder. It has joint efforts with Zoom and DocuSign.

But we will make the following assertion: in first-world countries, which are very rich in credentials like passports, LinkedIn accounts, bank accounts, utility bill relationships, etc., all of which can be turned into credentials usable by EOPcoin through means such as zkPass, zkPassport, etc., EOPcoin can serve all the same purposes while being a better fit.

Since it doesn’t rely on another blockchain for security, the potential market capitalization of EOPcoin’s native coin could be on a scale similar to that of BTC or ETH.

Like World, it provides the Sybil resistance that is leading to all the integrations mentioned above, but it doesn’t require an iris scan. People can join anytime they want from their own home with no need for extra hardware. They can earn money by running their own consensus nodes on much of the home computer hardware being sold today.

It can be used for Sybil resistance on Tinder, DocuSign, etc., etc. Unlike World, it can be integrated with such products and services in such a way that people could sign up immediately, in the course of their interactions with those services, because no iris scan is required.

We believe World provides strong evidence of EOPcoin’s potential to play a major role.

Summary

We have discussed how EOPcoin compares to existing blockchain technology and used World as an example of its potential to integrate with many applications that need Sybil resistance.

It has the potential, in the long term, to have similar (or possibly even greater) security than existing blockchains.

It has a number of patent-pending aspects.

We propose that EOPcoin is a worthy project for pre-seed funding.


  1. Igor Makarov and Antoinette Schoar, “Blockchain Analysis of the Bitcoin Market,” NBER Working Paper no. 29396 (Cambridge, MA: National Bureau of Economic Research, October 2021), doi:10.3386/w29396. ↩︎

  2. Nick Arnosti and S. Matthew Weinberg, “Bitcoin: A Natural Oligopoly,” Management Science 68, no. 7 (July 2022): 4755–4771, doi:10.1287/mnsc.2021.4095. ↩︎

  3. Ittay Eyal and Emin Gün Sirer, “Majority Is Not Enough: Bitcoin Mining Is Vulnerable,” Communications of the ACM 61, no. 7 (July 2018): 95–102, doi:10.1145/3212998. ↩︎

  4. Samuel Hempel, Gregory Phelan, and Thomas Ruchti, “Does Lock-Up Lead to Stability? Implications for Runs in the Proof-of-Stake Protocol,” Office of Financial Research Working Paper No. 24-08, October 31, 2024. ↩︎

  5. Jay Jacobs and Robbie Mitchnick, “Ethereum Staking Explained: Risks, Rewards, and How It Works,” iShares by BlackRock, March 12, 2026, accessed July 21, 2026. ↩︎

The problem

Blockchains have few ways to recognize legitimate participation.

  1. 01

    Participation is narrowly defined.

    Many blockchain systems base participation primarily on computational expenditure or owned and locked capital.

  2. 02

    Identity solutions answer only part of the question.

    Proof of personhood can establish that someone is a unique human, but that is different from allowing a protocol to recognize multiple forms of evidence and determine how each should affect eligibility, influence, or rewards.

  3. 03

    Existing evidence cannot simply be published.

    Governments, banks, employers, universities, and licensing bodies already maintain useful evidence, but placing those records directly on a public ledger would create privacy and reuse problems.

Project roadmap

Roadmap

Seven implementation milestones, presented in the order the work is being advanced.

  1. 01

    Design information-theoretically principled approach for deriving a weight from an item of evidence of personhood

    Complete
  2. 02

    Identify solutions to non-reuse of EoP for Sybil resistance

    Complete
  3. 03

    File patent applications

    Complete
  4. 04

    Modify the source code of an Ethereum client to use the weight instead of stake for rewards

    Complete
  5. 05

    Run the blockchain locally

    Complete
  6. 06

    Enable the blockchain nodes to operate remotely

    Pending
  7. 07

    Package the node software to be easy to install

    Pending