Breakthroughs in Blockchain Economics#
“It is not from the benevolence of the butcher, the brewer, or the baker that we expect our dinner, but from their regard to their own interest.” – Adam Smith, The Wealth of Nations, 1776
Cryptography makes cheating detectable; incentives make honesty the best course. A blockchain pays the miners and validators who secure it, sells its scarce block space to the users who want it, and hosts markets whose prices and ordering can be exploited. Breakthroughs in Consensus covers two incentive attacks on consensus itself, selfish mining and nothing at stake; Breakthroughs in Smart Contracts covers the flash loan as a contract. This chronology follows the economics: the game theory and auction theory the field borrowed, how block rewards and fees pay for security, how fee markets price block space, how decentralized exchanges and stablecoins work, and how the order of transactions became a market of its own.
The models in blockchainkit.economics are pure functions and small
seeded simulations; the stablecoin, the exchange and the lender are
contracts on World.
Exact conventions and model boundaries lists where they depart from deployed systems.
1960 – Schelling’s Focal Points: Coordinating without Communicating#
In The Strategy of Conflict, Schelling asked people to choose where and when to meet a stranger in New York without any way to agree in advance. Any place and time is an equilibrium: if both choose it, neither gains by switching. Yet most chose the same one, noon at Grand Central Station. A focal point is an equilibrium that stands out, by convention, uniqueness or salience, and players reach it because each expects the others to.
To see why salience matters, suppose each of \(k\) players picks the salient option with probability \(s\), and otherwise picks uniformly among all \(n\) options, the salient one included. The salient option is then chosen with probability \(s + (1-s)/n\) and each other one with \((1-s)/n\), so all players coincide with probability
Without salience, \(P = n^{1-k}\), and each extra player divides the chance of agreement by \(n\). With salience, each extra player multiplies it by only about \(s + (1-s)/n\), so a strongly salient answer keeps even a large group coordinated. Blockchain oracles and voting games rely on the truth being that salient answer.
Implementation: blockchainkit.economics.systems.coordination.coordination_probability()
and blockchainkit.economics.systems.coordination.play_coordination().
Salience is a single probability shared by every player; Schelling’s
experiments measured it rather than assuming it.
References: T. C. Schelling, The Strategy of Conflict, Harvard University Press (1960), chapter 3.
Schelling’s focal points: coordinating without communicating (1960)
1961 – Vickrey’s Second-Price Auction and Truthful Bidding#
In a sealed-bid first-price auction, the winner pays its bid. Bidding one’s true value then guarantees zero profit, so every bidder shades its bid below its value by an amount that depends on what it guesses the others will bid. Vickrey charged the winner the second-highest bid instead. A bid then decides only whether one wins, never the price, and the bidder with value \(v_i\) has utility
Bidding the true value \(b_i = v_i\) wins exactly when the price \(\max_{j \ne i} b_j\) is below \(v_i\), that is, exactly when winning is profitable. Bidding more adds only wins at a price above \(v_i\), which lose money; bidding less gives up only wins at a price below \(v_i\), which would have made money. So truthful bidding is optimal whatever the others do: it is a dominant strategy. Mechanisms that make honest reporting optimal are the template for fee mechanisms and builder auctions on blockchains.
Implementation: blockchainkit.economics.systems.auctions.second_price_auction()
and blockchainkit.economics.systems.auctions.first_price_auction(),
whose AuctionResult reports each
bidder’s utility. Bids are sealed by fiat; on a public blockchain they must
be hidden by commit-reveal or encryption, or the auction is not sealed at
all.
References: W. Vickrey, Counterspeculation, auctions, and competitive sealed tenders, The Journal of Finance 16(1), 8–37 (1961). DOI.
Vickrey’s second-price auction: truthful bidding (1961)
1981 – Myerson’s Optimal Auctions and Revenue Equivalence#
Myerson asked which auction maximizes the seller’s expected revenue, when each bidder’s value is private and drawn from a distribution \(F\) with density \(f\). A seller cannot charge each bidder its value, because a bidder would then pretend to value the item less; to keep bidders honest, it must leave each one an information rent. Myerson accounted for this rent by replacing each value with its virtual value,
and showed that expected revenue equals the expected virtual value of the winner. Maximizing revenue therefore means selling to the bidder with the highest virtual value, and not selling at all when every virtual value is negative. For identical bidders whose virtual value rises with their value, that is a second-price auction with the reserve price \(\varphi^{-1}(0)\), which is \(h/2\) for values uniform on \([0, h]\). The same identity gives revenue equivalence: two auctions that allocate the item to the same bidders, and in which a bidder with the lowest possible value pays nothing, raise the same expected revenue. A first-price auction with shaded bids thus earns what a second-price one earns with truthful bids. Blockchain fee mechanisms, from EIP-1559’s base fee to builder auctions, are analyzed with these tools.
Implementation: blockchainkit.economics.systems.auctions.virtual_value(),
blockchainkit.economics.systems.auctions.optimal_reserve(),
blockchainkit.economics.systems.auctions.equilibrium_bid(),
blockchainkit.economics.systems.auctions.expected_revenue() and
blockchainkit.economics.systems.auctions.simulate_revenue(). Values
are independent and uniform on \([0, h]\), the case with closed forms;
Myerson’s result covers any regular distribution.
References: R. B. Myerson, Optimal auction design, Mathematics of Operations Research 6(1), 58–73 (1981). DOI.
Myerson’s optimal auction and revenue equivalence (1981)
2003 – Hanson’s Logarithmic Market Scoring Rule#
A prediction market pays 1 per share of the outcome that happens. A trader who believes an outcome has probability \(p\) buys its shares while they cost less than \(p\), so prices read as the market’s probabilities. But thin markets have empty order books, and a trader with information finds nobody to trade with. Hanson proposed an automated market maker that always quotes a price. It tracks the shares \(q_i\) sold of each of \(n\) outcomes and charges each trade the change in the cost function \(C\), whose derivatives are the prices:
The prices are positive and sum to one, like probabilities. The market maker starts at \(C(0) = b \ln n\) and finally pays \(q_w\) for the winning outcome \(w\); since \(C(q) \ge q_w\), the traders have paid it \(C(q) - C(0) \ge q_w - b \ln n\). Its loss is therefore at most \(b \ln n\), a bounded subsidy that buys information, with the liquidity parameter \(b\) setting how far each trade moves the price. On-chain prediction markets adopted it, and it is the ancestor of the formula-priced pools of decentralized exchanges.
Implementation: blockchainkit.economics.systems.lmsr.lmsr_cost(),
blockchainkit.economics.systems.lmsr.lmsr_prices(),
blockchainkit.economics.systems.lmsr.lmsr_trade() and
blockchainkit.economics.systems.lmsr.lmsr_max_loss(), in floating
point; a contract would use fixed-point arithmetic, for which the
exponential is costly.
References: R. Hanson, Combinatorial information market design, Information Systems Frontiers 5(1), 107–119 (2003).
2008 – Nakamoto’s Incentive: Block Rewards and Fees#
Section 6 of the Bitcoin paper pays the creator of each block in new coins and in the fees of its transactions. The reward distributes the currency, pays for the work that secures the chain, and, Nakamoto argued, keeps even a powerful miner honest: it “ought to find it more profitable to play by the rules.”
The argument compares two uses of the same hashrate. An attacker pays a merchant \(V\), and the merchant waits for \(z\) confirmations; meanwhile the attacker mines a private chain without the payment, which takes about \(m = z + 1\) blocks to overtake the public one. Mined honestly, those blocks earn \(mR\) for a reward \(R\) per block. In the attack they earn nothing unless the private chain wins, with the whitepaper’s catch-up probability \(P_z\); if it does, the attacker keeps \(V\) as well as its blocks’ rewards, of which a fraction \(d\) has lost its worth because the attack shook confidence in the coin. Attacking pays when
A small miner rarely catches up, so \(P_z\) is tiny and only a payment worth many blocks tempts it. A majority miner always catches up, \(P_z = 1\), and the condition becomes \(V > d\, m R\): it is deterred only by the loss \(d\) on “the validity of his own wealth.”
Implementation: blockchainkit.economics.systems.rewards.block_reward()
and blockchainkit.economics.systems.rewards.double_spend_incentive(),
using attacker_success_probability().
The comparison counts the attacker’s own blocks, not time, and ignores
propagation delay and the cost of the hardware.
References: S. Nakamoto, Bitcoin: A peer-to-peer electronic cash system (2008), sections 6 and 11.
Nakamoto’s incentive: block rewards and fees (2008)
2009 – Fixed Supply and the Halving Schedule#
The first Bitcoin release set the monetary policy in code. The block at height \(h\) creates
so the subsidy halves every 210,000 blocks, about every four years at ten minutes a block. Each period issues half as many coins as the one before, so the total approaches the geometric sum \(210\,000 \times 50 \times (1 + \tfrac12 + \tfrac14 + \cdots) = 21\) million coins. The floor drops fractions of a satoshi at every halving, so the total falls slightly short: the subsidy, \(5 \times 10^9\) satoshis at first, reaches zero at the 33rd halving, around 2140, with 20,999,999.9769 coins issued. A fixed, predictable supply was a deliberate contrast with central-bank money; it also means that miners must eventually be paid by fees alone.
Implementation: blockchainkit.economics.systems.rewards.block_subsidy(),
the logic of Bitcoin Core’s GetBlockSubsidy, and
blockchainkit.economics.systems.rewards.issued_supply(), which counts
the genesis block’s 50 coins although Bitcoin can never spend them.
References: S. Nakamoto, Bitcoin v0.1 source code, main.cpp,
GetBlockValue (January 2009); Bitcoin Core, validation.cpp,
GetBlockSubsidy.
2014 – SchellingCoin and Decentralized Oracles#
Contracts cannot see the world, so prices and outcomes must be reported to them. Buterin’s SchellingCoin asks many reporters, each with a deposit \(D\), publishes the median report, and pays those whose report \(r_i\) lies between the lower and upper quartiles of all reports:
A reporter is paid for agreeing with the others, so its best report is the one it expects the others to make. Each reporter knows the truth, and expects the others to know it, so the truth is the focal point: if everyone else reports it, reporting it too is best. The scheme is only as honest as its majority. A cartel that reports one false value is paid once it exceeds a quarter of the reports, since its value then reaches the quartile; above half it sets the median; and above three quarters it pushes the honest reports outside the quartiles and takes their deposits. Buterin’s later P + epsilon attack showed that even a bribe that is never paid can move the focal point: promise reporters of a false answer a reward if that answer loses, and reporting it becomes the safer choice for each, so it wins and the promise costs nothing. UMA’s and Kleros’s dispute resolution build on the same idea.
Implementation: blockchainkit.economics.systems.oracles.schelling_round(),
which settles one round; there are no rounds over time, no commit-reveal of
reports, and no token whose value depends on the oracle’s honesty.
References: V. Buterin, SchellingCoin: a minimal-trust universal data feed, Ethereum Blog (March 2014); V. Buterin, The P + epsilon attack, Ethereum Blog (January 2015).
2016 – Carlsten et al.: the Instability of Bitcoin without the Block Reward#
Once the subsidy is gone, a block earns only the fees it collects. Fees arrive at a steady rate while blocks arrive at random, so a block’s reward is proportional to the time since the last one, and a block found right after another holds almost nothing. Carlsten, Kalodner, Weinberg and Narayanan showed two consequences. First, \(t\) seconds after a block, the next one is worth \(S + ft\) for a subsidy \(S\) and a fee rate \(f\). While that is less than \(c\), what a miner spends on electricity per block it expects to find, mining loses money, so miners pause for a mining gap of
seconds, which is zero while the subsidy covers the cost. Second, a miner can fork the tip instead of extending it, re-mining its height to claim the tip’s fees as well as the pending ones. If the tip claimed more fees than remain in the mempool, the fork offers more; by undercutting, claiming only part of the fees and leaving the rest for the next block, the miner makes its fork the more lucrative branch for other miners to build on. They also showed that selfish mining becomes profitable for arbitrarily small miners.
Implementation: blockchainkit.economics.systems.fee_only.simulate_block_rewards(),
blockchainkit.economics.systems.fee_only.mining_gap() and
blockchainkit.economics.systems.fee_only.undercutting_payoffs(). The
undercutting model is a one-shot comparison in which other miners follow
the more lucrative branch; the paper simulates repeated play with learning
miners.
References: M. Carlsten, H. Kalodner, S. M. Weinberg and A. Narayanan, On the instability of Bitcoin without the block reward, Proc. ACM CCS 2016, 154–167 (2016).
The instability of Bitcoin without the block reward (Carlsten et al. 2016)
2016 – Kiayias et al.: Mining Games and When Honest Mining Is an Equilibrium#
Kiayias, Koutsoupias, Kyropoulou and Tselekounis modeled mining as a stochastic game in which miners choose which block to extend and when to publish. When every miner’s hashrate is small, honest mining is a best response to honest mining; a large miner gains by deviating, and other equilibria arise. The same year, Sapirshtein, Sompolinsky and Zohar computed a miner’s best deviation exactly. A miner with a share \(\alpha\) of the hashrate chooses, in each state \((a, h)\) given by the lengths of its private branch and of the public one, whether to publish, wait or give up; \(\gamma\) is the fraction of the other miners that build on its block when two branches tie. Over all strategies \(\pi\), its best long-run share of the blocks in the chain is
A ratio is hard to optimize directly, but a share above \(\rho\) is achievable exactly when some strategy makes the per-block reward \(r_\text{miner} - \rho (r_\text{miner} + r_\text{others})\) positive on average, which is an ordinary Markov decision problem; bisection on \(\rho\) then finds \(\rho^*\). Mining honestly earns \(\alpha\), so honest mining is an equilibrium exactly when \(\rho^* = \alpha\). With \(\gamma = 0\), ties going to honest blocks, that holds up to about \(\alpha = 0.33\).
Implementation: blockchainkit.economics.systems.mining_games.optimal_mining_revenue()
and blockchainkit.economics.systems.mining_games.honest_mining_is_equilibrium(),
by relative value iteration. Both branches are capped at max_lead
blocks, which can only underestimate the best deviation; the full games
of Kiayias et al., with several strategic miners, are not modeled.
References: A. Kiayias, E. Koutsoupias, M. Kyropoulou and Y. Tselekounis, Blockchain mining games, Proc. ACM EC 2016, 365–382 (2016), arXiv:1607.02420; A. Sapirshtein, Y. Sompolinsky and A. Zohar, Optimal selfish mining strategies in Bitcoin, Financial Cryptography 2016, LNCS 9603, 515–532 (2017).
Mining games: when honest mining is an equilibrium (Kiayias et al. 2016)
2017 – MakerDAO’s Dai: a Collateralized Stablecoin and Liquidation#
A stablecoin aims at a fixed price. Dai, launched in December 2017, is backed by ether locked in contracts rather than dollars in a bank. A user locks ether in a vault (then a collateralized debt position) and draws newly minted Dai, as long as
at the price reported by an oracle. If a fall in the price breaks this inequality, anyone may liquidate the vault: repay its debt, which burns that Dai, and take collateral worth the debt plus a 13% penalty. The margin is what keeps every Dai backed. At the moment of liquidation the vault holds collateral worth 1.5 times its debt, more than the 1.13 times the liquidator takes, and the price can fall by a third before the collateral is worth less than the debt. Dai becomes undercollateralized only if the price falls faster than liquidations can follow, as on 12 March 2020, when congestion let some liquidators win collateral for almost nothing.
Implementation: blockchainkit.economics.systems.lending.VaultEngine,
Stablecoin and
PriceFeed, with
Single-Collateral Dai’s 150% ratio and 13% penalty. The liquidator buys the
collateral at the oracle price instead of in an auction, and there is no
stability fee, savings rate or governance.
References: The Maker Team, The Dai stablecoin system (December 2017).
MakerDAO’s Dai: a collateralized stablecoin and liquidation (2017)
2018 – Uniswap’s Constant-Product Market Maker and Impermanent Loss#
An order book needs market makers who post and cancel orders constantly, which is too expensive on chain, where every update is a paid transaction. Uniswap, launched in November 2018, replaced it with a pool of two tokens whose reserves \(x\) and \(y\) keep their product constant. A trader who pays in \(\Delta x\) has 0.3% kept as a fee and takes out the \(\Delta y\) that restores the product:
The pool’s price is the ratio \(p = y/x\), and every trade moves it: the more of a token is bought, the scarcer and dearer it becomes, so no trade can empty the pool. Anyone can deposit both tokens and earn the fees, but bears impermanent loss. When the market price moves by a factor \(r\), arbitrageurs trade the pool to the new price, buying from it the token that rose. With the product fixed, \(x = \sqrt{xy/p}\) and \(y = \sqrt{xy\,p}\), so the deposit’s value \(px + y = 2\sqrt{xy\,p}\) grows by a factor \(\sqrt{r}\), while holding the two tokens grows by \((1 + r)/2\). The ratio \(2\sqrt{r}/(1+r)\) is at most one, with equality only at \(r = 1\). The loss is impermanent because it vanishes if the price returns. Uniswap V2 (2020) added a price oracle that reads the price before the first trade of each block. A transaction moves the price only after that reading, so no single transaction can move the oracle.
Implementation: blockchainkit.economics.systems.amm.amount_out()
(V2’s getAmountOut), blockchainkit.economics.systems.amm.impermanent_loss()
and the contract blockchainkit.economics.systems.amm.ConstantProductPool,
whose previous_price()
stores the price before a block’s first trade rather than V2’s
time-weighted accumulator. Shares are not tokens, and no liquidity is
locked at the first deposit.
References: H. Adams, Uniswap whitepaper (November 2018); H. Adams, N. Zinsmeister and D. Robinson, Uniswap v2 core (March 2020).
Uniswap’s constant-product market maker and impermanent loss (2018)
2019 – Flash Boys 2.0: Front-Running and Priority Gas Auctions#
Daian et al. watched arbitrage bots on decentralized exchanges compete for the same opportunity by repeatedly replacing their pending transaction with one paying a higher fee, in a priority gas auction: miners order transactions by fee, so the highest bid is executed first and takes the opportunity. Each replacement must raise the fee by at least a fraction \(\beta\). Bots that all value the opportunity at \(V\) keep outbidding each other while a raise still leaves a profit, and stop at a price whose next raise would exceed \(V\): \((1 + \beta)\,\text{price} > V\). The winner therefore keeps
and the rest goes in fees to whoever orders the block. They called this value miner extractable value (MEV). When a past block holds more MEV than the reward for a new one, a miner gains by forking the chain to re-mine that block and capture it, a threat to consensus itself.
Implementation: blockchainkit.economics.systems.ordering.priority_gas_auction(),
in which bots respond one at a time with the minimum raise; real bots
raced on latency, mempool visibility and gas estimates.
References: P. Daian, S. Goldfeder, T. Kell, Y. Li, X. Zhao, I. Bentov, L. Breidenbach and A. Juels, Flash Boys 2.0: frontrunning, transaction reordering, and consensus instability in decentralized exchanges, IEEE Symposium on Security and Privacy 2020 (2019), arXiv:1904.05234.
Flash Boys 2.0: priority gas auctions and front-running (Daian et al. 2019)
2020 – Flash Loans and Oracle Manipulation: the bZx Attacks#
In February 2020, two attacks on the bZx lending protocol took flash loans, used them to move a decentralized exchange’s spot price within one transaction, and exploited protocols that trusted that price. A flash loan must be repaid in the same transaction, so it needs no collateral, and anyone can briefly command a large sum.
In its simplest form, the attacker flash-borrows \(U\) dollars and spends them on a token from a constant-product pool holding \(x\) tokens and \(y\) dollars. The purchase leaves \(y + U\) dollars and \(xy/(y+U)\) tokens in the pool, so the attacker receives \(xU/(y+U)\) tokens and the spot price rises to \((y+U)^2/(xy)\). At that price the tokens bought appear worth \(U(y + U)/y\), more than the \(U\) they cost. Deposited with a lender that reads the spot price and demands 150% collateral, they borrow
The attacker repays the flash loan from the new loan and keeps the difference, and the lender is left holding tokens worth far less than it lent once the price recovers. A price recorded before the transaction, like Uniswap V2’s, cannot be moved this way.
Implementation: blockchainkit.economics.systems.lending.OracleLender,
reading ConstantProductPool’s
spot price or its price before the block, attacked by
OracleAttacker with
FlashLender. The model
reduces the second attack to its mechanism; the first combined a margin
trade on bZx with the manipulated price, across several protocols.
References: K. Qin, L. Zhou, B. Livshits and A. Gervais, Attacking the DeFi ecosystem with flash loans for fun and profit, Financial Cryptography 2021, LNCS 12674, 3–32 (2021). DOI.
Flash loans and oracle manipulation: the bZx attacks (2020)
2020 – EIP-1559’s Base Fee and Burn, with Roughgarden’s Analysis#
Bitcoin sells block space by a first-price auction, and Ethereum did until the London upgrade of August 2021. As Vickrey’s analysis predicts, users must guess how much to shade their bids, no bid is obviously right, and prices swing with demand. EIP-1559 instead sets a protocol price per unit of gas, the base fee \(b_t\). After each block it moves by up to an eighth, up when the block used more gas \(g_t\) than the target \(g^*\), half the block’s capacity, and down when it used less:
Every transaction pays the base fee, which is burned, plus a tip to the producer. Because the price is posted rather than bid, Roughgarden’s analysis showed that, outside sudden rises in demand, bidding the base fee plus a small tip is optimal for users. Because the base fee is burned, a producer gains nothing by raising it with fake transactions, and a myopic producer has no reason to deviate from including the highest tips; nor can users and producers profit from an off-chain deal that skips the base fee, since it goes to neither of them.
Implementation: blockchainkit.economics.systems.fee_market.next_base_fee(),
the specification’s integer update, and
blockchainkit.economics.systems.fee_market.simulate_fee_market(),
which runs a mempool through either mechanism. Every transaction is a
transfer of 21,000 gas, values are uniform, and first-price bidders shade
by a fixed fraction rather than strategically.
References: V. Buterin, E. Conner, R. Dudley, M. Slipper, I. Norden and A. Bakhta, EIP-1559: fee market change for ETH 1.0 chain (2019); T. Roughgarden, Transaction fee mechanism design for the Ethereum blockchain: an economic analysis of EIP-1559 (December 2020), arXiv:2012.00854.
EIP-1559: a base fee, burned (2021), and Roughgarden’s analysis (2020)
2021 – Sandwich Attacks on Decentralized Exchanges#
A swap waits in the public mempool before it is mined, where anyone can see it. A sandwich attacker buys the same token just before it, which raises the price the victim pays, and sells just after, at the price the victim’s purchase pushed up further. The victim’s only protection is its slippage tolerance \(s\): its swap reverts if it would receive less than a fraction \(1 - s\) of the output quoted before the attack. A larger front-run \(a\) moves the price more and earns the attacker more, but the victim’s output \(\text{out}_\text{victim}(a)\) falls as \(a\) grows, and the attacker gets nothing if the victim’s swap reverts. So the attacker maximizes its profit over the front-runs that keep
which for a large victim trade means the largest front-run allowed. The attacker also pays the pool’s fee twice, so a trade too small to move the price by more than those two fees is not worth attacking.
Zhou, Qin, Torres, Le and Gervais derived this optimal attack, measured sandwiches on Uniswap, and showed that a looser tolerance hands more of each trade to the attacker. Private transaction relays and batch auctions are among the responses.
Implementation: blockchainkit.economics.systems.ordering.sandwich_profit()
and blockchainkit.economics.systems.ordering.sandwich_attack(), which
bounds the front-run by bisection and maximizes the profit by ternary
search; the attacker is assumed to control the order of the three
transactions and to hold the capital.
References: L. Zhou, K. Qin, C. F. Torres, D. V. Le and A. Gervais, High-frequency trading on decentralized on-chain exchanges, IEEE Symposium on Security and Privacy 2021 (2021), arXiv:2009.14021.
Sandwich attacks on decentralized exchanges (Zhou et al. 2021)
2022 – Proposer-Builder Separation and MEV-Boost#
Extracting MEV takes searchers, order flow and infrastructure. A validator that has them earns more per unit of stake than one that does not, so stakers move to it, and MEV pushes proof of stake toward a few large operators. Proposer-builder separation lets specialized builders assemble blocks and bid for each slot, while the proposer, any validator, only signs the best bid. A block holds fees \(f\) and an MEV opportunity \(M\), of which builder \(b\) can capture a fraction \(\sigma_b\), so it values the block at \(v_b = f + \sigma_b M\). In a second-price auction builders bid these values, and the proposer receives the runner-up’s, or what it could build itself if that is more:
This bound does not depend on the proposer’s own skill. With two or more capable builders, \(\sigma_{(2)}\) is close to one, so a solo staker earns about as much per slot as a professional operator. Flashbots’ MEV-Boost ran the auction outside the protocol from Ethereum’s move to proof of stake in September 2022, through relays that both builders and proposers must trust; enshrining it in the protocol remains open.
Implementation: blockchainkit.economics.systems.pbs.simulate_pbs(),
which picks proposers with StakeSampler
and sells each slot by
second_price_auction().
MEV-Boost’s auction is first-price with open bids through relays; with
many builders the price approaches the runner-up’s value either way.
References: V. Buterin, Proposer/block builder separation-friendly fee market designs, ethresear.ch (June 2021); Flashbots, MEV-Boost (2022).