Draft

EIP Draft: Tapered Issuance Burn

An EIP-formatted draft proposing a tapered issuance burn, deducted per validator duty and tapered linearly with the staking ratio, phased in over an 18-month transition that temporarily raises the base reward factor so yields fall gradually rather than at once. Under this proposal, issuance no longer incentivises stake growth beyond a 50% staking ratio, while leaving Ethereum’s existing reward curve — including BASE_REWARD_FACTOR — unchanged once the transition completes.
Published

July 14, 2026

Modified

July 23, 2026

eip: <to be assigned>
title: Tapered Issuance Burn
description: Remove the issuance incentive for stake growth beyond a 50% staking ratio by deducting and burning a linearly-tapered fraction of idealised validator rewards, phased in over an 18-month transition that temporarily raises the base reward factor to soften the yield reduction
author: pintail (@pintail-xyz), pa7x1 (@pa7x1), Jérôme de Tychey (@jdetychey), Justin Drake (@justindrake), Ladislaus von Daniels (@ladidan)
discussions-to: <to be assigned>
status: Draft
type: Standards Track
category: Core
created: 2026-07-14

Abstract

This EIP introduces a tapered issuance burn: at each epoch boundary a deduction is applied to each validator for its assigned duties in that epoch (attestation, block proposal, and sync committee participation), and the deducted ETH is burned. Each deduction is sized as a fraction of the idealised reward for the duty. The burn fraction is zero when the staking ratio is zero and rises to 100% at a fixed saturation balance, tapering linearly in between. In aggregate, the deductions burn a tapered fraction of consensus issuance that grows with the staking ratio, so the net staking yield declines as more ETH is staked. This removes the yield floor implicit in the current curve, letting the staking market settle at an equilibrium yield set according to the risk premium that stakers demand. For a positive yield, that equilibrium is reached at a staking ratio below 50%, beyond which the issuance mechanism no longer incentivises further stake growth.

Given the current staking ratio, applying the burn at the fork without any other change would result in an immediate reduction in yield for stakers. To enable a smooth adjustment, the reduction is phased in over an 18-month transition. This is done by temporarily raising the BASE_REWARD_FACTOR, which scales rewards, penalties, and the corresponding issuance burn together. As a result, net yield begins close to today’s level and transitions smoothly back to today’s reward curve, with tapered issuance burn applied, and the balance between micro-incentives preserved throughout. The taper’s shape, however, is in full effect from activation: from day one the issuance mechanism no longer rewards growth in the staking ratio beyond 50%, allowing the market to settle at its equilibrium yield.

Motivation

The choice between staking and simply holding ETH is made on the gap between the yields the two options offer and the risks each carries.1 For staking these include liquidity, slashing, operational, and regulatory risks; liquid staking exchanges some of these for risks attaching to the token issuer, whether smart-contract and governance risks for on-chain protocols or counterparty risk for a centralised provider. Stake is therefore expected to keep flowing in for as long as the net incentive to stake, given by the nominal yield, exceeds the premium the marginal staker demands for bearing those risks. The staking market reaches equilibrium only if the nominal yield falls to the level of the staking risk premium. This risk premium is trending down owing to the maturity of staking setups at the infrastructure, smartcontract and software level. Furthermore, the credibility of slashing is negatively impacted by large amounts of ETH at stake, further weighing on the staking risk premium.

Under the current issuance curve there is no point at which the incentive to stake switches off: the yield falls only as \(1/\sqrt{f}\) in the staking ratio \(f\) and never drops below roughly 1.5%, even with all ETH staked. Whether stake growth halts short of 100% therefore rests entirely on the marginal staker’s risk premium staying above this yield floor; however, the protocol neither observes nor controls this premium. There is reason to think the premium may continue to fall: as the staking ecosystem matures, trusted low-friction custodians such as ETF providers emerge, and tooling and liquid staking reduce the costs and risks that justify it. Meanwhile, since issuance increases with staking ratio, dilution costs to unstaked ETH holders increase, adding greater incentive to stake to avoid this dilution.

A drift toward a very high staking ratio is undesirable for two distinct reasons, which correspond to the two goals of this proposal: preserving Ethereum’s security and resistance to capture, and protecting ETH’s role as money.2

Security, neutrality, and resistance to capture

Beyond a certain level, additional stake makes Ethereum less secure, not more: the marginal contribution of new stake to economic security falls as the ratio rises, while several risks compound. As an ever-larger share of the ETH supply is held by custodians and staking providers rather than its owners, the social layer is deprived of its ability to hold large operators to account, while the most independent of validators, solo stakers, are forced out.

  • Stake concentration leads to moral hazard. A large operator that misbehaves can degrade consensus for its own gain, and its delegators bear the loss if slashing follows. This is a risk that should be priced by delegators, increasing the effective cost of delegated staking. But when enough of the supply is exposed to a single outcome, the holders with most to lose are also the best resourced and best organised to coordinate a fork reversing it; The DAO rescue demonstrated that the social layer may override protocol rules if a sufficient proportion of ETH is at risk of loss. A dominant operator could therefore come to be treated as “too big to fail”. The resulting moral hazard compounds: anticipating rescue rather than ruin, delegators stop demanding compensation for tail risk, the discount makes the largest operators cheaper to stake with, and stake concentrates further still.
  • The social layer loses its backstop. Meanwhile, a fork that should happen becomes much harder to coordinate: “social slashing” of a colluding coalition can only succeed if the wider economy coordinates on the forked chain. Since most ETH holders cannot run validators themselves, the incentive toward universal staking pushes most of the supply into custody with a handful of exchanges, ETFs, and staking service providers. With the owners of ETH no longer in full control of it (“not your keys, not your coins”), the credibility of a fork which implements social slashing, and therefore its deterrent effect, is diminished. The same concentration decides which coalition can coordinate: an operator’s clients can, everyone else cannot.
  • Solo stakers are forced out. Dilution erodes everyone’s real return as the ratio climbs, but solo stakers, who in most jurisdictions pay income tax on their nominal yield, cross into negative dilution-adjusted returns well before large operators and liquid staking token (LST) holders do. Once the most independent and uncorrelated participants have exited, there is no mechanism to bring them back, and the validator set slides toward a concentrated state, more vulnerable to capture.

The consequence of the above trends is the capture of both the validator set and the ETH supply by a small group who are at much greater risk of coercion, undermining core Ethereum properties of neutrality and censorship resistance.

ETH as money

Issuance is yield paid on the staked base, and under the current curve the ETH issued per year grows without bound as the staking ratio rises. This excess issuance operates as a continuous dilution tax on holders of unstaked ETH, eroding the scarcity and monetary premium that underpin ETH’s value as money and forcing on every holder an artificial choice: accept dilution, or take on the costs and risks of staking merely to avoid it.

At high staking ratios the damage is compounded. Yield-bearing LSTs and other staking derivatives come to dominate raw ETH as collateral and medium of exchange within the Ethereum economy, displacing the most neutral, permissionless, trustless asset available with intermediated claims on staking providers. For a staking provider this displacement is a rational profit-maximising strategy pursued by embedding the derivative across every layer and application until it, rather than ETH, is the ecosystem’s working money. The costs of that substitution are concrete: if ETH is progressively displaced as the reserve asset, liquidity fragments across competing derivatives and slippage rises on decentralised exchanges, while every application that settles in a staking derivative inherits its issuer’s smart-contract, counterparty, and governance risk.

By moderating issuance, each staking derivative faces stronger competition from non-staked ETH, promoting a trustless asset at the foundation of the ecosystem. This reduces the risk that the social layer becomes co-dependent on an outside organization, its issued derivative of ETH, and its governance processes. Without that mitigation, applications that power the money could gain outsized influence over applications that use the money, making Ethereum a less desirable blockchain to build and develop on.

Bounding issuance-driven stake growth keeps issuance itself bounded. Under this proposal it peaks at a staking ratio of roughly 20% and falls beyond it, settling at at the ratio where yield is equal to the compensation stakers require for the costs and risks they bear — complementing the fee burn of EIP-1559 on the supply side of the ledger and protecting the central monetary role of unstaked ETH.

Restoring an equilibrium

This EIP proposes the minimal change needed to ensure that the issuance mechanism no longer drives stake growth beyond a 50% staking ratio: after computing rewards exactly as today, deduct from each validator a fraction of the idealised reward for each assigned duty — destroying the deducted ETH — with that fraction tapering linearly in the staking ratio up to a fixed saturation point. Because the post-burn issuance yield falls to zero at the 50% saturation ratio, it crosses any positive risk premium at some ratio strictly below 50%, giving the staking market an equilibrium wherever the market sets that premium.

The two goals are served by different aspects of this change. The security and capture-resistance goal is met by the shape of the tapered curve: with net issuance yield falling to zero at 50%, issuance no longer rewards staking beyond that ratio. The ETH-as-money goal is served additionally by the level of issuance — bounding it well below today’s trajectory, so that holders of ETH do not overpay for security through dilution.

Because the shape and the level are controlled independently, the two goals are realised on different timescales. To avoid a sharp fall in yield at the fork, the reduction is phased in over an 18-month transition, during which the effective base reward factor decays from twice its current value back to today’s, limiting the impact on existing stakers at activation. The tapered shape is nonetheless in full effect from the moment the transition begins: from day one the issuance mechanism no longer rewards growth in the staking ratio beyond 50%, so the market has an equilibrium below that point and the security goal is achieved immediately. The transition scales only the overall level of issuance, which declines to its permanent low as the transition elapses; the ETH-as-money goal therefore strengthens across the transition and reaches full strength once it completes.

Specification

Let \(D\) denote get_total_active_balance(state) in Gwei, and let SATURATION_BALANCE (Gwei, \(D_\text{sat}\)) be a fixed constant set at the hard fork to approximately half the ETH supply. Define the burn fraction

\[b = \left(\frac{D}{D_\text{sat}}\right)^{3/2}, \qquad \text{clamped to } b \le 1.\]

For each validator duty, a deduction of \(b\) times the idealised reward for that duty is applied (via decrease_balance) to every validator assigned the duty, immediately after rewards and penalties are applied for the epoch; the deducted ETH is destroyed. The deduction is a function of effective balance and total active balance only — it is charged whether or not the duty was performed.

BASE_REWARD_FACTOR itself is left unchanged at its current value of 64. The only modification to the existing rewards machinery is temporary: to avoid a sudden drop in yield when the burn activates, get_base_reward_per_increment reads a time-varying effective base reward factor that starts at TRANSITION_BASE_REWARD_FACTOR (128) and decays linearly to BASE_REWARD_FACTOR (64) over TRANSITION_DURATION_EPOCHS (≈ 18 months). Because both rewards and the burn’s reference rewards derive from get_base_reward_per_increment, this elevation scales the whole schedule — rewards, penalties, and burn — uniformly, so the balance between them is preserved. Once the transition completes the effective factor is permanently 64, and process_rewards_and_penalties behaves exactly as it does today.

Constants

BASE_REWARD_FACTOR is left unchanged at uint64(64). The following constants are added:

Name Value Notes
SATURATION_BALANCE Gwei(60_250_000 * 10**9) Total active balance \(D_\text{sat}\) at which the burn fraction reaches 100%; set at the hard fork to approximately half the current ETH supply
TRANSITION_BASE_REWARD_FACTOR uint64(128) Effective base reward factor at the start of the transition — twice BASE_REWARD_FACTOR — decaying linearly to BASE_REWARD_FACTOR over the transition
TRANSITION_START_EPOCH Epoch(...) Epoch at which the transition begins; set at the hard fork to the activation epoch
TRANSITION_DURATION_EPOCHS Epoch(123_300) Transition length; \(123{,}300 = 548 \times 225\) epochs \(\approx 18\) months (225 epochs per day)

Helper functions

get_issuance_burn applies the burn fraction to a reward. It is expressed as the cube of a square-root ratio so that it can be computed as three successive uint64 multiply-divides, keeping every intermediate value within uint64 — consistent with the rest of the reward machinery, which never forms a value wider than 64 bits. The two square roots are computed once per epoch by the caller and passed in.

def get_issuance_burn(reward: Gwei, sqrt_active: uint64, sqrt_sat: uint64) -> Gwei:
    # reward * (sqrt_active / sqrt_sat)**3 == reward * (D / SATURATION_BALANCE)**(3/2)
    burn = uint64(reward)
    for _ in range(3):
        burn = burn * sqrt_active // sqrt_sat
    return Gwei(burn)

This EIP also relies on two lookups not present in the current specification: get_beacon_proposer_index_at_slot (the existing get_beacon_proposer_index generalised to an arbitrary slot in the epoch) and get_validator_index_by_pubkey (a pubkey→index lookup, which clients already maintain as a cache).

The base reward factor transition

get_base_reward_factor returns the effective base reward factor for an epoch: TRANSITION_BASE_REWARD_FACTOR at the start of the transition, decaying linearly to BASE_REWARD_FACTOR over TRANSITION_DURATION_EPOCHS, and permanently BASE_REWARD_FACTOR thereafter.

def get_base_reward_factor(epoch: Epoch) -> uint64:
    # Elevated during the transition to cushion the yield reduction, decaying
    # linearly from TRANSITION_BASE_REWARD_FACTOR at TRANSITION_START_EPOCH to
    # BASE_REWARD_FACTOR after TRANSITION_DURATION_EPOCHS. Permanently
    # BASE_REWARD_FACTOR — today's value — once the transition completes.
    if epoch <= TRANSITION_START_EPOCH:
        return TRANSITION_BASE_REWARD_FACTOR
    elapsed = epoch - TRANSITION_START_EPOCH
    if elapsed >= TRANSITION_DURATION_EPOCHS:
        return BASE_REWARD_FACTOR
    remaining = TRANSITION_DURATION_EPOCHS - elapsed
    boost = TRANSITION_BASE_REWARD_FACTOR - BASE_REWARD_FACTOR
    return BASE_REWARD_FACTOR + uint64(boost) * uint64(remaining) // uint64(TRANSITION_DURATION_EPOCHS)

get_base_reward_per_increment is modified to use this factor in place of the BASE_REWARD_FACTOR constant; this is the sole change to the existing rewards machinery, and it reverts to today’s behaviour once the transition completes:

def get_base_reward_per_increment(state: BeaconState) -> Gwei:
    factor = get_base_reward_factor(get_current_epoch(state))
    return Gwei(
        EFFECTIVE_BALANCE_INCREMENT * factor // integer_squareroot(get_total_active_balance(state))
    )

Beacon chain state transition

A new step, process_issuance_burn, is added to process_epoch immediately after process_rewards_and_penalties and before process_effective_balance_updates. Running it there means effective balances still hold the epoch’s values, so the proposer burn below charges exactly the proposers that were selected during the epoch. The burn is applied per duty, in three passes:

  • Attestation burn — a burn of \(b\) times the ideal attestation reward, applied to every active validator;
  • Proposer burn — a burn of \(b\) times an equal share of the epoch’s ideal proposer reward, charged to each of the 32 proposers;
  • Sync committee burn — a burn of \(b\) times the ideal sync committee reward for the epoch, charged to each of the 512 sync committee members.

Splitting the burn by duty, rather than applying a single uniform per-validator deduction, keeps the variance between validators low despite the rare duties of proposal and sync committee participation. The burn reads base from get_base_reward_per_increment, so during the transition it scales with the elevated effective factor automatically; the step below needs no further change.

def process_issuance_burn(state: BeaconState) -> None:
    # Clamping sqrt_active to sqrt_sat keeps the burn fraction at or below 1.
    sqrt_sat = integer_squareroot(SATURATION_BALANCE)
    sqrt_active = min(integer_squareroot(get_total_active_balance(state)), sqrt_sat)
    increment = EFFECTIVE_BALANCE_INCREMENT
    base = get_base_reward_per_increment(state)
    epoch = get_current_epoch(state)

    # 1. Attestation burn — every active validator.
    attest_weight = TIMELY_SOURCE_WEIGHT + TIMELY_TARGET_WEIGHT + TIMELY_HEAD_WEIGHT
    for index in get_active_validator_indices(state, epoch):
        n = state.validators[index].effective_balance // increment
        attest_reward = Gwei(n * base * attest_weight // WEIGHT_DENOMINATOR)
        burn = get_issuance_burn(attest_reward, sqrt_active, sqrt_sat)
        decrease_balance(state, index, burn)

    # 2. Proposer burn — the 32 proposers of the epoch.
    n_total = get_total_active_balance(state) // increment
    ideal_proposer_reward = Gwei(
        n_total * base * PROPOSER_WEIGHT // WEIGHT_DENOMINATOR // SLOTS_PER_EPOCH
    )
    proposer_burn = get_issuance_burn(
        ideal_proposer_reward, sqrt_active, sqrt_sat
    )
    start_slot = compute_start_slot_at_epoch(epoch)
    for slot in range(start_slot, start_slot + SLOTS_PER_EPOCH):
        proposer = get_beacon_proposer_index_at_slot(state, Slot(slot))
        decrease_balance(state, proposer, proposer_burn)

    # 3. Sync committee burn — the 512 sync committee members.
    for pubkey in state.current_sync_committee.pubkeys:
        index = get_validator_index_by_pubkey(state, pubkey)
        n = state.validators[index].effective_balance // increment
        sync_reward = Gwei(n * base * SYNC_REWARD_WEIGHT // WEIGHT_DENOMINATOR)
        burn = get_issuance_burn(sync_reward, sqrt_active, sqrt_sat)
        decrease_balance(state, index, burn)

The dominant new cost is one O(1)-per-validator deduction (the attestation burn) — foldable into the existing rewards/penalties pass — plus two fixed passes over the 32 proposers and 512 sync committee members.

Rationale

Deriving the burn fraction

Expressed as a function of the staking ratio \(f = D/S\) (with \(S\) the total ETH supply), the current consensus-layer yield is

\[y(f) = \frac{B\,E}{\sqrt{f\,S}},\]

with BASE_REWARD_FACTOR \(B\) and epochs per year \(E\). Issuance is the yield paid on the staked fraction, \(i(f) = B\,E\sqrt{f/S}\). The burn fraction derived below is independent of \(B\): it scales the reward whatever its magnitude. The permanent policy uses today’s \(B = 64\); during the transition \(B\) is temporarily elevated, which lifts \(y(f)\) uniformly without changing \(b(f)\).

The goal is to subtract from the yield a term that is zero at \(f = 0\) and grows linearly to cancel the yield entirely at a saturation ratio \(f_\text{sat}\), so that the net yield reaches zero there:

\[\tilde y(f) = \begin{cases} y(f) - \dfrac{f}{f_\text{sat}}\,y(f_\text{sat}) & f \le f_\text{sat} \\ 0 & f > f_\text{sat} \end{cases}\]

Figure 1: Consensus layer net yield under the current curve and under the tapered issuance burn in its permanent (post-transition) state, both with BASE_REWARD_FACTOR at today’s value of 64. The tapered curve reaches zero at the 50% saturation ratio.

Writing \(\tilde y(f) = (1 - b(f))\,y(f)\) and solving for the burn fraction \(b(f)\) that reproduces this linear taper gives

\[b(f) = \left(\frac{f}{f_\text{sat}}\right)^{3/2}.\]

The exponent of \(3/2\) rather than \(1\) follows from the reward curve’s \(f^{-1/2}\) shape: the absolute deduction needed is linear in \(f\), but expressed as a fraction of a reward that itself scales as \(f^{-1/2}\), it picks up an extra half power. With \(f_\text{sat} = 50\%\), the resulting issuance curve

\[\tilde i(f) = \begin{cases} f\,\tilde y(f) & f \le f_\text{sat} \\ 0 & f > f_\text{sat} \end{cases}\]

no longer runs away with \(f\): it rises, peaks at \(f^* = 2^{-7/3} \approx 19.8\%\), and falls back to zero at \(f_\text{sat}\).

Figure 2: Annual ETH issuance under the current curve and under the tapered issuance burn in its permanent (post-transition) state, both with BASE_REWARD_FACTOR at today’s value of 64. The tapered curve peaks at \(f^* = 2^{-7/3} \approx 19.8\%\) and falls to zero at \(f = \tfrac{1}{2}\).

The transition period

Imposed in full at the fork, the burn would cut the net yield at today’s staking ratio (\(f \approx 33\%\)) by more than half, from about 2.6% to 1.2% — a dramatic change for existing stakers, and one that would be expected to trigger a substantial exit of stake on activation. Rather than reach that curve immediately, or change BASE_REWARD_FACTOR permanently, the proposal phases the reduction in over 18 months. At activation the effective base reward factor is 128 (twice today’s value), lifting the whole net yield curve so that it crosses the current curve at \(f \approx 31\%\), close to today’s ratio: stakers see a yield very close to what they receive now. Over the following 18 months the effective factor decays linearly to 64, and the net yield slides down to the permanent tapered curve. The fork itself therefore changes yields very little; the reduction arrives gradually, giving stakers time to adjust.

The 18-month figure is the length of the transition measured from activation, but the effective window for participants to adjust is longer. A hard fork is generally scheduled for inclusion (SFI) six months or more before it goes live, and this proposal — including the transition’s start and end points — is fully specified and predictable from that moment. Adding that lead time to the 18-month decay gives ecosystem participants on the order of two years, from the change becoming certain to yields reaching their permanent level, in which to take account of it and respond — whether that means solo stakers reassessing their position, providers adjusting their offerings, or applications adapting to the new issuance path.

Figure 3: Net yield (left) and annual issuance (right) as the tapered issuance burn phases in, driven together by a single control. Drag the slider or press play to sweep the 18-month transition: at month 0 the effective base reward factor is 128, so net yield starts close to today’s; by month 18 it has decayed to 64 and both curves reach their permanent shape. Throughout, net yield falls to zero at the 50% saturation ratio.

Because the effective factor multiplies get_base_reward_per_increment, it scales rewards, penalties, and the burn’s reference rewards together, so the balance between micro-incentives is preserved throughout the transition — and the schedule is left exactly as it is today once the transition completes.

Phasing the change in this way does not defer the security benefit. The burn fraction reaches 100% at the saturation balance whatever the base reward factor, so from the first epoch after activation the issuance mechanism no longer rewards growth in the staking ratio beyond 50%: the market can settle at an equilibrium below that point at once, and the security and capture-resistance goal is met immediately. What the transition phases in is only the level of issuance — and with it the full benefit to ETH’s role as money, which arrives as the effective factor completes its decay to 64.

The transition does not reintroduce runaway issuance. The permanent (post-transition) issuance peaks at \(f^* \approx 19.8\%\) — at roughly 0.5% of supply per year — and falls to zero at 50%, sitting below the current curve, which grows without bound in stake and reaches about 1.5% of supply per year with all ETH staked. During the transition, issuance begins near today’s level and declines toward that curve.

Why a burn, and not a change to the reward curve

An alternative route to lower issuance would be to redesign the reward curve itself, and proposals for this exist.3 This EIP nonetheless prefers a burn, for three reasons.

  • A single parameter, with a natural value. Reward curves engineered to exhibit several desirable properties at once (a cap on total issuance, a yield floor, a target ratio) tend to introduce several new parameters, each of which must be set and defended. The burn introduces exactly one, SATURATION_BALANCE, and its value has a natural focal point: half the ETH supply. (The permanent policy adds only this one constant and leaves BASE_REWARD_FACTOR untouched; the transition parameters are temporary, and fall away once it completes.)
  • A market-determined yield. In a workable reward curve, rewards and penalties must remain matched: schedules that taper rewards to zero while retaining penalties to compel participation are vulnerable to griefing attacks. With matched incentives, a performing validator always earns a positive yield, so any reshaped reward curve without burn still imposes a floor on the yield, and stake growth stops only if the market’s risk premium happens to sit above that floor. A deduction removes the floor: the staking ratio settles at the point where the yield meets the premium stakers demand, so the equilibrium yield is set by the market rather than by the shape of the curve.
  • Micro-incentives at full strength. Reaching a low yield by scaling the reward and penalty schedule down weakens the per-duty incentives for correct and timely participation. With substantial execution-layer income and MEV available, consensus rewards and penalties must remain large relative to the external incentives to misbehave (through block-timing games or reorgs, for example), or chain stability is put at risk. The burn leaves the entire schedule at its current magnitude — indeed, during the transition the elevated base reward factor temporarily strengthens it — and nets macro yield off afterwards.

Why the deducted ETH is burned rather than redirected

Any redirection of the deducted ETH, whether to other validators, a treasury, or any other recipient, would leave total issuance unchanged and so defeat the proposal’s monetary purpose, while creating a new claimant whose incentives must be analysed and whose share can be lobbied over. Burning the ETH, as established by the base-fee burn of EIP-1559,4 is the credibly neutral alternative: the value removed accrues pro rata to all ETH holders.

Why the deduction is computed from idealised rather than actual rewards

Each deduction is sized from the idealised reward for a duty, not from the reward the validator actually earned. This leaves every micro-incentive exactly as strong as it is today. If the deduction scaled with the reward actually earned, each duty’s marginal payoff would be multiplied by \((1-b)\), progressively weakening the incentive to perform duties correctly. Computed from the idealised reward instead, the deduction is fixed with respect to the validator’s behaviour in the epoch: performing a duty improves a validator’s balance by exactly as much as it does under current rules.

Why the saturation point is expressed as a fixed balance

The protocol observes get_total_active_balance(state) directly but has no notion of total ETH supply, so \(f\) itself is not something the state transition can compute. SATURATION_BALANCE fixes \(D_\text{sat} = f_\text{sat}\,S\) as a constant at the hard fork, using the supply at that time. Because SATURATION_BALANCE does not track the live supply, the effective saturation ratio will drift slowly as supply changes through ongoing issuance and burning after the fork. This drift is expected to be small over any reasonable time horizon, and could be eliminated by a future EIP that makes the protocol aware of total supply, allowing \(D_\text{sat}\) to be recovered from \(f_\text{sat}\,S\) directly.

Why the burn is split by duty

Applying \(b\) as a single, uniform per-validator deduction each epoch would be simpler to specify, but every validator only proposes and joins a sync committee rarely. A uniform deduction sized to also cover those infrequent, larger rewards would exceed a typical epoch’s attestation reward as the burn fraction grows, leaving even a perfectly performing validator with a negative balance change in every epoch spent waiting for a rare duty assignment. Allocating the deduction by assigned duty avoids this: a validator that performs its attestation duties is never pushed into a negative balance change merely for lack of a proposal or sync-committee assignment, and each deduction stays proportionate to the reward on offer at each opportunity.5

Backwards Compatibility

This EIP introduces a backwards-incompatible change to the consensus-layer state transition and must be accompanied by a hard fork. No changes are required to the execution layer or to existing on-chain contracts.

Test Cases

Test vectors are not yet included in this draft. On progressing toward implementation, test cases would be added to the epoch_processing test suite in the consensus-specs repository,6 following the existing format for process_rewards_and_penalties, covering: zero active balance below saturation, active balance at and above SATURATION_BALANCE, the boundary behaviour of get_issuance_burn at sqrt_active == sqrt_sat, and the value of get_base_reward_factor at the transition boundaries (TRANSITION_START_EPOCH, its midpoint, and TRANSITION_START_EPOCH + TRANSITION_DURATION_EPOCHS).

Reference Implementation

The Python in the Specification section constitutes the reference implementation, in the same style used throughout the beacon chain consensus specification. No client implementation exists yet, as this is presented here as a draft for discussion.

Security Considerations

Incentive compatibility. The burn fraction \(b(f)\) is a deterministic, publicly computable function of total active balance, and applies identically to every validator. No validator or coalition can shift a larger share onto another, nor reduce its own, so it introduces no new griefing or discrimination vector. Because each deduction is computed from the idealised duty reward rather than the reward actually earned, it is independent of the validator’s behaviour within the epoch, leaving every marginal performance incentive intact; during the transition the elevated base reward factor scales the reward and penalty schedule up together, preserving the balance between them, and once the transition completes the schedule is exactly as it is today. And because \(b(f) \le 1\) for all \(f\) (clamped via sqrt_active = min(..., sqrt_sat)), no deduction ever exceeds the idealised reward it is derived from: a validator performing its duties correctly retains a non-negative net reward for the epoch, and the burn cannot by itself drive aggregate net issuance negative.

Effect on economic security. This EIP deliberately results in a lower equilibrium quantity of stake than the current curve. In proof-of-stake with slashing, the cost of attack is set by the stock of slashable stake an attacker must acquire and forfeit, and at any staking ratio in the tens of percent that stock remains vast relative to any plausible attack reward. Nor does economic security increase monotonically with stake: as set out in the Motivation, beyond a certain level the accompanying concentration of stake and supply makes the network less secure, not more. To the extent the proposal protects ETH’s monetary premium, it also supports the real value of the stake securing the chain.

Computational cost. The additional per-epoch cost is one O(1) deduction per active validator (foldable into the existing rewards/penalties pass) plus two fixed-size passes over the 32 proposers and 512 sync committee members, so this EIP does not introduce a new DoS surface. get_validator_index_by_pubkey, used for the sync committee burn, should reuse the same pubkey→index cache clients already maintain for sync committee processing, rather than a linear scan.

Constant drift. As noted in Rationale, SATURATION_BALANCE is fixed at the fork and does not track live supply, so the effective saturation ratio will drift slowly over time. This drift changes only the location of the equilibrium point, not any safety property of the mechanism, and is not expected to be security-relevant on the timescale of a single fork’s lifetime.