The consensus rules, the penalties and the open gaps, written from the code the validators run.
| Level | What it means | Can it be undone? |
|---|---|---|
| Provisional | A valid block is accepted at once, served to peers and voted on. It can still be unwound, because it sits above the finalized line. | Yes, until it is finalized |
| Finalized | Validators holding two thirds of voting power have signed the same block. From here it cannot be reversed. | No |
| Settled | A finalized block whose 12-hour challenge window closed with no upheld dispute. This is the line wallets treat as done. | No, and the challenge window has closed |
With 3f+1 validators, up to f can be faulty. A block is final only with a quorum of 2f+1 by voting power, which on the devnet is 6,667 of 10,000.
If a network split leaves neither side a quorum, nothing is finalized or produced until it heals. The provisional tip can change; the finalized chain cannot.
A validator signs at most one prevote and one precommit per round, and follows lock rules so it can't vote against a block it has helped lock.
Every signed action and block is bound to the chain's genesis hash, so it can't be replayed on another network.
Signing two different blocks or votes at the same height
Slashed and removed from the set. The signed evidence is public.
Executing a block to a different result than the proposer
The validator submits a dispute. Settlement below that block pauses until governance resolves it.
Missing its turn to propose
A quorum can time the round out, and the next validator in the rotation takes over.
Unbonding takes 14 days, longer than the challenge window, so a validator can’t leave before a fault is caught. Faults leave signed evidence that Arx Verify checks in your browser, without a node.
We list the gaps so you don’t have to find them.