Arxium

How a block becomes final, and what happens when someone cheats

The consensus rules, the penalties and the open gaps, written from the code the validators run.

Three levels of done

LevelWhat it meansCan it be undone?
ProvisionalA valid block is accepted at once, served to peers and voted on. It can still be unwound, because it sits above the finalized line.Yes, until it is finalized
FinalizedValidators holding two thirds of voting power have signed the same block. From here it cannot be reversed.No
SettledA finalized block whose 12-hour challenge window closed with no upheld dispute. This is the line wallets treat as done.No, and the challenge window has closed

The rules validators follow

Two thirds must agree

With 3f+1 validators, up to f can be faulty. A block is final only with a quorum of 2f+1 by voting power, which on the devnet is 6,667 of 10,000.

It halts rather than forks

If a network split leaves neither side a quorum, nothing is finalized or produced until it heals. The provisional tip can change; the finalized chain cannot.

One vote per round

A validator signs at most one prevote and one precommit per round, and follows lock rules so it can't vote against a block it has helped lock.

Signatures belong to one chain

Every signed action and block is bound to the chain's genesis hash, so it can't be replayed on another network.

When a validator misbehaves

The faultWhat happens

Signing two different blocks or votes at the same height

Slashed and removed from the set. The signed evidence is public.

Executing a block to a different result than the proposer

The validator submits a dispute. Settlement below that block pauses until governance resolves it.

Missing its turn to propose

A quorum can time the round out, and the next validator in the rotation takes over.

Unbonding takes 14 days, longer than the challenge window, so a validator can’t leave before a fault is caught. Faults leave signed evidence that Arx Verify checks in your browser, without a node.

What isn’t done yet

We list the gaps so you don’t have to find them.

  • The devnet is a test network and can be reset. It makes no promise about the permanence of state.
  • Zero-knowledge proving keys come from a devnet-only setup, not a public ceremony, so private-claim proofs are for testing integrations.
  • Programmable-account policies still need an independent circuit audit before they are released.
  • There are no smart contracts. Assets and accounts use fixed, reviewed protocol circuits.