CoW Protocol (COW) sustainability report
| Name | BlockNodes SAS |
| Relevant legal entity identifier | 969500PZJWT3TD1SUI59 |
| Name of the crypto-asset | CoW Protocol |
| Beginning of the period to which the disclosure relates | 2025-09-27 |
| End of the period to which the disclosure relates | 2026-09-27 |
| Energy consumption | 1310.76311 kWh/a |
Consensus Mechanism
CoW Protocol is present on the following networks: Arbitrum, Base, Binance Smart Chain, Ethereum, Polygon, Gnosis Chain.
Arbitrum One does not run a consensus algorithm or a validator set of its own. It is an optimistic rollup: transactions are executed off Ethereum, while Ethereum holds the canonical record and provides final settlement. A sequencer accepts transactions, orders them on a first-come basis and executes them under the chain's state-transition rules, producing blocks roughly four times a second and giving users an immediate local confirmation. The ordered transactions are compressed and published to Ethereum in batches. Because that input data sits on the settlement layer, anyone running the node software can replay it and arrive at the same Layer 2 state without trusting the operator.
Agreement about what that state is happens on Ethereum. Validators post assertions — claims about the rollup's resulting state — to contracts on the settlement layer. Since early 2025 the chain has used a dispute protocol that made validation permissionless, so any party may post an assertion or challenge one rather than only an approved list of operators. Conflicting claims are resolved by an interactive process that narrows the disagreement down to a single step of execution, which Ethereum then adjudicates directly. The protocol is designed so that disputes conclude within a bounded period no matter how many adversaries join them, and so that a single honest participant is enough to defend the correct state. Once the challenge window has passed without a successful dispute, the assertion is confirmed and withdrawals that depend on it become executable through the canonical bridge.
Two qualifications matter for an accurate picture. Ordering is still performed by a single sequencer operated by the chain's development company, so transaction ordering is not decentralized today; censorship is bounded rather than impossible, because a user can submit a transaction to a queue contract on Ethereum and force its inclusion once a defined delay has elapsed. Separately, a security council retains powers over the contracts, which keeps the arrangement short of full trust-minimization. Security therefore rests on Ethereum's proof-of-stake consensus combined with the rollup's fraud-proof mechanism, not on a validator set belonging to the chain itself.
Base is a Layer 2 network that executes transactions away from the Ethereum chain and settles them on it. It runs no consensus protocol of its own and has no validator set of its own. Agreement about which Base transactions occurred, and in what order, is ultimately established by the data and the state commitments the network publishes to Ethereum, which are secured by Ethereum's proof-of-stake consensus.
Ordering and execution on the Layer 2 are carried out by a single sequencer, operated by the company that launched the network. It receives transactions, places them into blocks at a fixed cadence and returns a result to the user straight away; those blocks are then compressed and posted to Ethereum in batches, alongside commitments to the state they produce. Once a batch sits inside a finalized Ethereum block, the ordering it encodes is as hard to reverse as Ethereum itself. Users are not wholly dependent on the sequencer for access: a transaction can instead be submitted through a contract on Ethereum, and the rules by which the Layer 2 chain is derived oblige it to be included, which bounds how far the sequencer can censor.
Base is an optimistic rollup, built on the shared OP Stack codebase and part of the Superchain group of networks that use it. State commitments are accepted as correct unless disputed. Anyone may propose one and anyone may challenge one within a dispute window, by playing an interactive game on Ethereum that narrows the disagreement down to a single step of execution, which an Ethereum contract then settles by running that step itself. Both sides post bonds, so an untrue claim and a frivolous challenge are each expensive. Permissionless fault proofs have run on the main network since late 2024, and a multi-party security council with a supermajority threshold governs changes to the contracts; together these place the network at the intermediate tier of the rollup maturity scale commonly used to compare such systems. A withdrawal to Ethereum cannot complete until the dispute window for the relevant commitment has elapsed. Decentralizing the sequencer itself remains outstanding work.
BNB Smart Chain, the programmable chain of BNB Chain and formerly styled Binance Smart Chain, reaches agreement through Proof of Staked Authority, a design that borrows stake-weighted election from delegated proof of stake and rotating, permissioned block production from proof of authority. Bonded stake decides who may produce blocks rather than who wins any individual slot. The network keeps an active set of forty-five operators, ranked by the amount of the native asset bonded to them through self-delegation and through delegation from holders. The twenty-one highest-ranked form the cabinet tier and the next twenty-four are candidates, with everyone below inactive and producing nothing. Rankings are recomputed once a day, so membership of the set turns over on a daily cycle rather than per block.
Within each epoch a consensus group of twenty-one is drawn from the active set, weighted heavily toward the cabinet tier, and those operators take turns proposing in a fixed rotation. Turn length and epoch length are protocol parameters that have been retuned repeatedly as block intervals shortened: successive upgrades cut the interval from three seconds to 1.5, then to 0.75 in mid-2025, and to 0.45 seconds in January 2026. A separate voting layer sits above the rotation, in which validators sign attestations on recent blocks; once enough signatures accumulate a block is treated as final, giving deterministic finality in roughly a second. Should that voting layer stall, the chain falls back to confirmation by accumulated depth, which takes minutes rather than seconds.
Security rests on an honest supermajority of a deliberately small elected set, backed by on-chain penalty logic. A slashing contract watches for double signing, for contradictory attestations in the fast-finality vote, and for repeated failure to produce during an assigned turn. Consequences range from temporary jailing and lost rewards through to removal from the set and forfeiture of part of a validator's own bonded stake. The trade-off is deliberate: a compact, frequently re-elected validator set buys very short block intervals and cheap execution, at the cost of the broader operator base that larger validator sets provide.
Ethereum reaches agreement through proof of stake, adopted in September 2022 when the original mining-based chain was retired in favor of a validator-driven consensus layer. The protocol family is usually referred to as Gasper. A fork-choice rule named LMD-GHOST selects the head of the chain by following the branch carrying the greatest accumulated weight of validator votes, while a separate finality gadget, Casper FFG, periodically justifies and then finalizes checkpoints, so that reversing them would require destroying an enormous quantity of bonded value.
Time is divided into slots of twelve seconds, and thirty-two slots form an epoch. For each slot the protocol pseudo-randomly designates one active validator to assemble and publish a block, and assigns the rest to committees that vote on what they believe is the correct head and the correct checkpoints. Under healthy conditions a checkpoint becomes final two epochs after it is proposed, a little under thirteen minutes, after which everything beneath it is treated as settled.
Joining the validator set requires a deposit of no fewer than 32 units of the native asset. Since the protocol upgrade of May 2025 a single validator may hold a far larger balance, up to 2,048 units, and earn on the whole of it, which lets an operator running many minimum-sized validators consolidate them into fewer; the activation floor itself did not change. Entry and exit are rate-limited by a queue measured in staked weight rather than in validator headcount, which bounds how fast the composition of the set can turn over.
Security rests on voting power being bonded. A validator that signs contradictory messages can be proved to have done so and is penalized, and the size of that penalty scales with how much other stake was penalized at the same time, so a coordinated attack is punished far more severely than an isolated fault. Should the chain stop finalizing altogether, a separate mechanism gradually erodes the balances of validators that are not participating until the remainder again represents a large enough majority to finalize. Upgrades during 2024 and 2025 changed how large data payloads are distributed and sampled between nodes, without altering this underlying agreement process.
Polygon PoS is an EVM-compatible proof-of-stake network that runs its own validator set and anchors itself to Ethereum by posting periodic checkpoints there. It should not be confused with the other chains that have carried the Polygon name: the zero-knowledge rollup operated under that brand was shut down in 2026, and chains built with Polygon's development kit are independent networks with their own validators. Polygon PoS executes transactions and holds its own transaction data, so it is a sidechain or commit-chain rather than a rollup inheriting Ethereum's execution and data-availability guarantees.
The architecture splits into two node layers that every validator runs together. The execution layer, derived from Go Ethereum, assembles transactions into blocks. The consensus layer coordinates the validator set, tracks staking and finalizes checkpoints; it was rebuilt in 2025 on the Cosmos SDK and CometBFT, which brought checkpoint-based finality down from a wait of one to two minutes to a matter of seconds and capped how deeply the chain may reorganize. At intervals the consensus layer gathers the blocks produced since the last checkpoint into a Merkle tree and submits the root to contracts on Ethereum, where it becomes the reference point for bridge withdrawals.
Staking itself lives on Ethereum. Validators bond the network's native asset, POL, which replaced MATIC in the migration that began in 2024 and now serves as both the staking asset and the gas asset, into contracts on Ethereum mainnet; holders delegate through share-based pools in the same contracts. The active set is capped, so entry requires displacing an incumbent by stake.
Block production changed materially with the Rio upgrade in late 2025. Rather than rotating producers by stake-weighted draw over short intervals, validators now vote, with voting power weighted by stake, to elect the producer or producers for a span. Because a single elected producer builds the span, competing chain tips largely disappear and reorganizations are eliminated. The same upgrade introduced witness-based verification, letting a validator check a block against a supplied witness instead of holding full state, which lowers the storage burden of participating.
Gnosis Chain is a proof of stake network with its own validator set and its own genesis, secured entirely by that validator set rather than by any other chain. It began as a proof of authority sidechain, and in December 2022 a separately bootstrapped consensus chain merged with the existing execution chain, replacing the authority set with staking. Since then the architecture mirrors Ethereum's: every participant runs two pieces of software, an execution client that processes transactions and maintains state, and a consensus client that votes on and orders the blocks. The same independent client implementations used on Ethereum are used here with adjusted parameters, which keeps the network from depending on a single codebase. It is not a rollup and not a layer two; the bridges connecting it to Ethereum move assets but carry no part of the ordering or validation of its blocks.
Time is divided into five second slots grouped into epochs of sixteen slots, giving an epoch of roughly eighty seconds. For each slot the protocol pseudorandomly assigns one validator to build a block and a committee of others to attest to what they see, with the assignment derived from an on chain randomness accumulator so that upcoming duties are hard to predict or target. The fork choice rule follows the branch carrying the greatest weight of recent attestations, and a separate finality mechanism operates on epoch boundaries: when a supermajority of the staked balance attests across two successive epochs, the earlier one is finalized and can no longer be reverted without the destruction of a large fraction of all stake.
The distinctive parameter is the size of a validator deposit, an order of magnitude smaller in relative terms than Ethereum's, which has produced an unusually large and widely distributed set of validating keys. A later upgrade allowed a single validator to hold a much larger effective balance, letting operators consolidate many keys into one. The network has also deployed an optional encrypted transaction pool, in which threshold cryptography keeps transaction contents hidden from the block builder until ordering is already fixed.
Incentive Mechanisms and Applicable Fees
CoW Protocol is present on the following networks: Arbitrum, Base, Binance Smart Chain, Ethereum, Polygon, Gnosis Chain.
Fees on Arbitrum One are paid in the settlement layer's native asset and split into two economic components. The execution component prices computation and state access on Layer 2 through a base fee that a control loop raises and lowers with demand, in the style of Ethereum's own fee market. The data component covers the cost of publishing compressed batches to Ethereum. A transaction's share of that component is estimated from how many bytes it adds to a compressed batch, so how well its data compresses matters as much as its size, and the fixed cost of a posting is spread over everything in the batch rather than falling on one transaction. Since Ethereum opened a dedicated data space for rollups, batches are posted there and priced by that space's separate fee market. Both components are converted into a single unit, so a user sees one price rather than two.
Payments flow to several places. The party that posts batches is reimbursed from collected fees, with the data price adjusted over time so that reimbursement tracks what was actually spent. Remaining Layer 2 revenue accrues to protocol-controlled accounts — one covering baseline infrastructure, another collecting congestion revenue — which governance directs, rather than being burned. A portion of ordering rights is also sold: a sealed-bid auction awards a short-lived priority lane for a round lasting under a minute, and the proceeds go to an account that chain governance designates. Contracts compiled to WebAssembly run alongside EVM contracts and are metered on their own resource unit.
There is no staking, delegation, issuance or slashing at this layer. The equivalent penalty is a bond: participants that assert or challenge state must lock collateral, and a party that loses a dispute forfeits it, with part compensating the honest side, so an incorrect claim carries a direct cost. Beneath the rollup, Ethereum's own incentives apply to the data it posts — the base fee there is burned and the priority fee goes to the block proposer. There is no recurring storage rent; state is paid for when it is written.
Base has no native protocol asset, no staking and no issuance. Nothing is minted to reward participation and there is no validator or delegation system on the Layer 2. Fees are denominated and paid in ether, the same asset used on the settlement layer.
What a user pays has two parts, and they behave quite differently. The first is the cost of executing the transaction on the Layer 2, metered in gas exactly as on Ethereum and priced by an equivalent algorithmic base fee that moves with how full recent Layer 2 blocks have been, plus an optional tip. Because Layer 2 block space is plentiful, this component is usually very small and fairly stable. The second is a charge for the cost of publishing that transaction's data to Ethereum. It is assessed per transaction from the compressed byte size of the transaction and the prevailing price of settlement-layer data space, and it is collected when the transaction is processed even though the actual posting happens later, in a batch shared with many others. This second component typically dominates the total and is why Layer 2 costs track conditions on Ethereum.
Since Ethereum opened a dedicated market for rollup data in 2024, the network posts its batches into that market rather than as ordinary transaction data. Those data fees are priced independently of execution and are destroyed rather than paid to anyone, which cut this component sharply. A December 2025 change on the settlement layer raised the available data capacity while introducing a floor that ties the minimum data price to ordinary execution costs, so the charge no longer falls to almost nothing whenever demand for data space is light.
Fees collected on the Layer 2 accrue to the entity operating the sequencer, funding the cost of running it and of settling to Ethereum, with a portion shared with the collective that stewards the shared codebase. The other economic mechanism at work is the dispute system: participants who propose or challenge a state commitment post bonds that are forfeited if they are shown to be wrong, which funds honest challenges and makes dishonest claims costly.
BNB Smart Chain pays for its own security out of transaction fees rather than out of new issuance. The native asset carries no protocol-level block subsidy, so every reward reaching a validator or a delegator originates in gas paid by users. When a block is finalized the proposer's collected fees are routed into system contracts and split three ways. A governed fraction is sent to an unspendable address and permanently removed from supply, a slice accumulates in a reward vault used for network-wide purposes such as paying for fast-finality attestations, and the balance sits in the validator-set contract until it is distributed, on a daily cycle, to active validators and the holders who delegated to them.
Participation is staking-based. An operator must self-delegate a substantial amount of the native asset before it can be considered for the active set, and holders may bond additional stake to any validator to lift its ranking. Delegators receive their proportional share of whatever the validator earns, after the commission that validator sets for itself, and only the forty-five ranked operators earn at all: stake bonded to an inactive validator yields nothing. Unbonding is subject to a waiting period, so stake cannot be pulled out the instant misbehavior comes to light.
Penalties are graduated. Missing assigned turns or going offline for a sustained stretch triggers jailing, during which the validator produces nothing and earns nothing. Double signing and contradictory attestations in the finality vote are treated far more severely and can cost the validator a portion of its own bonded stake alongside ejection from the set.
Users face a conventional gas-metered fee model inherited from the Ethereum virtual machine. Each operation carries a gas cost, the sender chooses a gas price, and the total is charged in the native asset. There is no separate storage rent, so the cost of persisting state is bundled into execution gas, and deploying or calling a contract is priced purely by the computation and storage it consumes. The minimum acceptable gas price is a coordinated parameter that operators and infrastructure providers have revised downward several times, keeping ordinary transfers and contract calls inexpensive in absolute terms.
Payment inside the protocol flows to validators, the only participants the consensus layer compensates directly. A validator earns newly issued units of the network's native asset for voting promptly and correctly on the head of the chain and on the checkpoints being justified, for serving its turn in the committee that signs headers for light clients, and, when selected to propose, for the block itself. The proposer additionally keeps the priority portion of the fees in that block, together with whatever it receives from the separate market through which many proposers outsource block assembly. There is no delegation inside the consensus rules: stake is either operated directly or entrusted to an operator through arrangements that sit outside the protocol.
Users pay for execution in gas, metered per operation, with writes to persistent state priced far above arithmetic. Every transaction carries a base fee per unit of gas that the protocol sets algorithmically from how full recent blocks have been, and that amount is destroyed rather than paid to anyone, so sustained demand withdraws native asset from circulation. On top of it a user adds a voluntary tip, which goes to the proposer and governs how quickly the transaction is picked up. Data posted on behalf of Layer 2 networks is priced in a second, independent market whose fee is likewise destroyed; a December 2025 upgrade tied the floor of that market to ordinary execution costs so it cannot collapse to a negligible level, and capped the gas any one transaction may consume.
Penalties mirror the rewards. Failing to vote, or voting late or incorrectly, costs a validator roughly what correct behavior would have earned it. Provable equivocation is treated far more harshly: the offender is scheduled for ejection, forfeits part of its balance immediately, and later incurs an additional correlated penalty computed from how much other stake was penalized nearby in time. Prolonged absence while the chain is failing to finalize drains balances until finality can resume. Stakers may take out accumulated rewards without leaving the set, and since 2025 may also trigger a full exit from the execution layer rather than only from the consensus client.
Validators on Polygon PoS are paid for two distinct jobs: producing and executing blocks on the chain itself, and signing the checkpoints submitted to Ethereum. Rewards are distributed per checkpoint, funded by protocol issuance of the native asset together with an allocation of transaction fees, and they are apportioned by stake and by how reliably each validator signed. Because the staking contracts sit on Ethereum, a validator's operating costs include Ethereum gas for checkpoint submission and for staking transactions, a meaningful expense that chain-local fee models do not capture.
Delegation works through validator-specific share pools. A holder exchanges the native asset for shares in a chosen validator, and as rewards accrue the redemption value of each share rises, so returns appear as appreciation of the share rather than as separate payments. Validators take a commission before the remainder flows to their delegators. Stake withdrawn from a validator remains locked for a defined number of checkpoints before it can be moved out, while switching between validators carries no such delay.
The penalty structure is weighted toward lost income. The staking contracts define consequences for double-signing and for sustained unavailability, but in normal operation the dominant economic pressure on a validator is forfeited reward: missed checkpoint signatures and poor block-production uptime reduce what a validator and its delegators earn. The producer election introduced by the Rio upgrade also redistributes fee income, including value captured from transaction ordering, toward validators that are not currently producing, so that supporting the chain stays worthwhile for the rest of the set.
Users pay fees in the native asset under a base-fee-plus-tip model. The base fee moves with how full recent blocks have been and is routed to a burn path, while the optional tip goes to the producer. A 2026 protocol change made that base-fee destination configurable in order to fund a time-limited program that recycles fees for one narrow category of activity, with ordinary transactions continuing to follow the burn path. There is no storage rent, and contract deployment and execution are charged purely as metered gas on the resources they consume.
Validators are paid from two separate streams. Consensus duties — attesting to blocks, serving on the synchronization committee and proposing when selected — are rewarded in the staking asset, issued by the protocol and accruing to the withdrawal address the operator nominated when depositing. Execution duties pay in the network's gas asset: when a validator proposes, it receives the priority tips attached to the transactions it includes, together with any value it captures from how it orders them. The issuance rate is not fixed. It is a function of the total balance staked, so the reward for each validator falls as the active set grows, and the design targets a level of security rather than a headline yield.
The penalty structure is symmetric with the reward structure. A validator that misses an attestation, or attests to the wrong thing, loses roughly what it would have earned for getting it right, so ordinary downtime is a small recurring cost rather than a catastrophe. If the chain fails to finalize for an extended period, a progressively steeper drain applies to validators that are not attesting, shrinking their balances until the participating remainder regains a supermajority. Provable equivocation is punished far more severely: proposing two blocks for one slot, or casting votes that contradict each other, costs part of the balance immediately, forces exit from the validator set, and carries an additional penalty scaled to how many other validators were caught doing the same thing over the same period, so coordinated attacks are punished far harder than isolated mistakes. Exiting voluntarily is also rate limited by a queue.
Users pay in the gas asset, a stable value token minted on this chain when a dollar denominated stablecoin is locked in the native bridge on Ethereum, which makes transaction costs predictable in fiat terms. Each transaction carries a base component, priced algorithmically from recent block fullness and never paid to the proposer, and an optional tip that is. Contract execution is metered in gas, and stored data carries no recurring rent.
Energy consumption sources and methodologies
CoW Protocol is present on the following networks: Arbitrum, Base, Binance Smart Chain, Ethereum, Polygon, Gnosis Chain.
The consumption attributed to Arbitrum One has two parts, and they are estimated in different ways. The first is the chain's own infrastructure: the machines running the sequencer and the batch-posting process, the validators that track state assertions and would take part in a dispute, and the broader population of full, archive and RPC nodes that other participants operate. The second is the share of Ethereum's consumption that belongs to the rollup, because settlement and data availability happen there. Ethereum's validators do work on the rollup's behalf whenever a batch is posted, and a proportion of their consumption is apportioned to the chain according to how much of the settlement layer's capacity those postings occupy. Ethereum publishes its own account of how that figure is arrived at (Ethereum energy consumption).
Since nothing here is mined, the first part is estimated by counting machines rather than by modeling operator profitability. The size of the node population is approximated from network crawlers, peer discovery and publicly listed endpoints. A representative hardware specification is inferred from what the client software states it needs to stay in sync — processor class, memory, fast storage and bandwidth — and the electricity that specification draws is taken from controlled measurement of equivalent machines, both under load and idling. The total is the aggregate across the estimated population including idle draw, because nodes run continuously whether or not blocks are full. Dispute participation is episodic and contributes little in normal operation. A fraction of the network total is then attributed to an individual asset in proportion to observed on-chain activity involving it.
These are estimates rather than meter readings, and the limits should be read as part of the figure. Node counts are lower bounds, because machines behind private networks cannot be discovered. The hardware mix is inferred from stated software requirements rather than surveyed from operators. Where the evidence runs out, the assumption chosen is the one more likely to overstate consumption than to understate it, and figures are revised as observation improves.
The estimate for this network has two components, and they are constructed differently.
The first is the network's own infrastructure. This is a small and largely identifiable set of machines rather than a large permissionless population: the sequencer that orders and executes transactions, the batching service that compresses and submits data to the settlement layer, the service that publishes state commitments, and the replica and archive nodes that third parties operate to serve applications and to independently check what the sequencer produced. The number of independent replicas is estimated from crawlers of the Layer 2 peer-to-peer network and from public information about node operators and infrastructure providers. Hardware profiles are inferred from the published requirements of the node software, which for a high-throughput rollup are materially heavier than for an ordinary chain, and per-device power draw comes from measurement on representative equipment under controlled laboratory conditions, counting idle draw as well as load. The fault-proof machinery adds little in normal operation, since the interactive dispute game runs only when a commitment is actually challenged rather than continuously.
The second component is the share of the settlement layer's consumption that this network causes. That layer is Ethereum, whose own consumption is estimated from its validator population using the node-level method described for that network. A portion is attributed here in proportion to what this network occupies there, principally the data space its batches consume, alongside the gas used by its commitment and dispute contracts. Because the settlement layer's consumption is driven by a continuously running validator set rather than by throughput, this attributed share is modest next to the Layer 2's own footprint, but it is included so that settlement is not treated as free.
Both components are estimates built on public observation and stated software requirements, not metered readings. The replica population is the least observable part and the largest source of uncertainty. Where evidence is thin, the assumptions used are those more likely to overstate impact than understate it, and figures are revised as observation improves. The settlement layer publishes its own account of its energy profile at Ethereum energy consumption.
The energy figure for BNB Smart Chain is built upward from the node population rather than downward from operator revenue, which is the appropriate treatment for a staked network where block production is not a computational race. Nothing about the fee model or the value of the native asset determines how much hardware is deployed: the size of the validator set is fixed by protocol, and the wider population of non-validating nodes is driven by demand for chain access.
The estimate has three inputs. The first is the number of machines. The elected validator set is known from the chain itself, while the surrounding population of full and archive nodes is approximated from peer-discovery crawls, public node listings and network scans, all of which observe only nodes willing to accept inbound connections and therefore tend toward undercounting. The second input is a representative hardware profile per node, inferred from the client software's published requirements, which on this chain are demanding relative to slower networks of the same family, since sub-second block intervals and rapid state growth push operators toward high core counts, large memory and fast solid-state storage. The third is the electrical draw of such a machine, taken from measurement of comparable configurations on the bench, both under sustained load and at idle, because a validator idles between its assigned turns and that baseline draw is a real part of the total. Aggregating the per-machine figure across the estimated population, with an allowance for the overhead of the facilities housing it, gives the network total.
Several qualifications belong with the result. It is a modeled estimate resting on observed node counts and stated software requirements, not metered consumption at the socket. Where evidence is thin, the assumptions chosen lean toward overstating rather than understating consumption. Figures are revised as crawler coverage and hardware information improve. Finally, apportioning a share of the network total to any single asset issued on the chain is done from observed on-chain transfer volumes, which measures how heavily an asset is used rather than the energy it uniquely causes.
The figure reported for this network is assembled machine by machine, treating the computers that run the protocol as the thing that draws electricity. The starting point is an estimate of how many independent nodes are operating, built from crawlers that walk the peer-to-peer layer and record every peer they can reach, supplemented by public listings of infrastructure and staking providers and by the protocol's own visible record of how much stake is active and how it is spread across operators.
A representative hardware profile is then inferred for those machines. The client software publishes what it requires in processor, memory and disk terms, and operators have little reason to provision far beyond that, so the profile is derived from those stated requirements rather than from a survey of individual operators. Power draw for the resulting device classes comes from measurement on representative equipment under controlled laboratory conditions, capturing both the load validating places on a machine and the draw of a machine that is powered on but momentarily idle, which for a network of this kind accounts for a large share of the total. Multiplying measured per-device draw across the estimated population over the reporting period yields the network figure. Where a disclosure concerns one of the many assets issued on this network rather than the network itself, a portion of the network total is assigned to it in proportion to observed on-chain transfer volumes.
The limits deserve stating plainly. The node count records what is reachable, not a census, and machines behind restrictive network configurations are missed. The hardware profile is a reasoned inference from published software requirements, not a record of what any particular operator bought. Nothing here is metered at the wall. Where the evidence runs out, the assumptions chosen are those that push the estimate upward rather than downward, so the result is more likely to overstate consumption than to understate it, and it is revised as observation improves. The network's own account of its energy profile is published at Ethereum energy consumption.
Polygon PoS is a staked network, so its consumption is modeled from the machines that run it rather than from mining economics. Two components are added together. The first is the chain's own infrastructure: every validator operates a paired execution and consensus process, which in practice means a heavier machine than a single-process chain of comparable throughput would need, plus the wider population of full and archive nodes serving applications and data consumers. The second is a share of Ethereum's consumption, because the checkpoint and staking transactions that give Polygon PoS its anchor are executed by Ethereum's validators; that share is apportioned by the gas those transactions consume as a fraction of total Ethereum gas.
For the chain's own component, the node count is estimated from peer-discovery crawls, public node listings and the validator set recorded on chain, with the understanding that crawls see only nodes willing to accept connections. A representative hardware profile is inferred from the published requirements for running both node processes, and the electrical draw of such a configuration is taken from measurement of comparable machines, at load and at idle, since a validator's hardware draws power continuously regardless of whether it is currently producing. Aggregating across the estimated population, with an allowance for the overhead of the facilities housing it, gives the chain-local total.
The usual qualifications apply and matter here. The node population and the hardware behind it are inferred from public observation and stated software requirements, not metered. Where evidence is incomplete, the assumptions used err toward a higher figure rather than a lower one. The estimate is revised as observation improves. The gas-based apportionment of Ethereum's consumption is a convention rather than a physical measurement, since Ethereum's validators would run whether or not the checkpoints were posted. And where a share of the network total is attributed to an individual asset issued on the chain, that attribution is made from observed on-chain transfer volumes, which reflects how heavily an asset is used rather than the energy it uniquely causes.
The reported consumption is an estimate constructed from the machines running the network, not a measured quantity. The first step is to size the physical node population, using network crawlers, peer discovery traffic and information operators publish themselves. One feature of this network makes that step unusually error prone and worth stating plainly: because the deposit required for a single validator is small, the number of validating keys is very large, and a single physical machine can run hundreds of them behind one consensus client. Counting keys would therefore overstate the hardware enormously. The estimate counts machines, and treats the key count as evidence about participation rather than about equipment.
The second step is to characterize those machines. Every participant runs an execution client and a consensus client, usually on the same host, and the hardware profile is inferred from the processor, memory and storage specifications those clients publish as their requirements, mapped onto server and workstation configurations that satisfy them. Power draw for such configurations comes from laboratory measurement taken both under load and at rest. The period total aggregates that draw across the estimated set, idle time included, since a synchronized node consumes power whether or not it is presently doing anything.
The result carries the limits of its inputs. Node counts and hardware profiles are inferred from public observation and stated requirements rather than from an inventory, and this network's mix spans everything from rented cloud instances to small machines run at home, which have quite different efficiency characteristics. Where evidence is thin the assumptions chosen are the ones more likely to overstate the footprint than to understate it, and figures are revised as the observed picture sharpens. Client efficiency and hardware requirements also change across protocol upgrades, so estimates from different periods are not strictly comparable.
Key energy sources and methodologies
CoW Protocol is present on the following networks: Arbitrum, Base, Binance Smart Chain, Ethereum, Polygon, Gnosis Chain.
The renewable share is derived geographically, starting from where the machines that keep the chain running actually sit: the servers hosting the sequencer and the batch poster, the validators that participate in the dispute protocol, and the wider population of full and archive nodes. Their locations are inferred from publicly observable network information — the addresses reachable peers announce, hosting and autonomous-system registries, and public node listings — which yields a country-level distribution rather than a precise address for any individual machine. Much of this infrastructure is hosted with commercial cloud and colocation providers, so the region a provider operates a facility in stands in where a single host cannot be placed more precisely. Where the chain's own distribution is too sparse to observe with confidence, the pattern seen on networks of similar shape — alike in how participants are paid and in the class of hardware they run — fills the gap.
The same exercise is applied to the settlement layer, because the portion of Ethereum's consumption attributed to the rollup carries the geographic profile of Ethereum's validator set rather than that of the rollup's own machines. The two distributions are combined, weighted by how much estimated consumption each accounts for.
Country weights are then matched against published statistics on how much of each country's electricity comes from renewable sources, drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy. The result is a consumption-weighted average across the estimated footprint. It is not a statement about what any operator has contracted for: power purchase agreements, on-site generation and renewable certificates are invisible in network data and are not assumed.
Energy intensity is expressed marginally, as the additional electricity associated with one more transaction on top of the infrastructure already running. Because the cost of operating a node is largely fixed and barely responds to how full a block is, that marginal figure is small and moves inversely with throughput, which is why it should not be read as a per-transaction share of the total.
The renewable share reported for this network is a weighted average of the electricity mixes of the grids its infrastructure draws on, assembled in two steps: establish where the machines are, then attach regional generation statistics to those places.
Locating them is easier for some parts of the network than others. The sequencing, batching and commitment services run in identifiable data center regions, and the hosting regions an operator uses are publicly observable. The wider population of replica and archive nodes is inferred as it would be for any peer-to-peer network, from the addresses peers advertise so that others can reach them, collected by crawlers and supplemented by public directories of infrastructure providers. Resolving a single address to a country is unreliable, but in aggregate these resolutions describe a distribution well enough to weight against. Where the observable sample is too thin, the geographic spread of a structurally comparable network is used in its place, chosen because its operators face similar hosting economics rather than because it runs similar software. The same exercise is carried out for the settlement layer, because part of the figure reported here is an attributed share of Ethereum's consumption, and Ethereum's validator population is spread quite differently from a rollup's concentrated operator infrastructure. The two distributions are weighted by their respective contributions to consumption and combined.
Each location is then matched to published statistics on how electricity is generated in that country or region, and the renewable proportion is the consumption-weighted share falling in regions supplied by renewable generation. Grid averages are used throughout, because the actual supply arrangements of individual hosting facilities are not observable; a facility on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is a marginal figure rather than an average: the additional electricity attributable to one further transaction on the network as it currently runs. Because most of the infrastructure runs continuously whether or not it is busy, that marginal quantity is much smaller than dividing total consumption by the transaction count would suggest. The generation statistics come from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share reported for BNB Smart Chain follows from where its machines physically run, so the method begins with locating them. Node addresses visible through peer discovery and public network observation are resolved to hosting providers, autonomous systems and countries, producing an approximate geographic distribution of the validator and full-node population. Where that observation is too sparse to stand on its own, the distribution of a network with a comparable staking design and operator economics is substituted, on the reasoning that similar incentives attract similar operators into similar hosting markets.
That distribution is then matched against national electricity statistics. Each country's share of generation coming from renewable sources is taken from Share of electricity generated by renewables, compiled and processed by Our World in Data from Ember's yearly electricity datasets and the Energy Institute's Statistical Review of World Energy. Weighting those country-level shares by the portion of estimated node capacity sitting in each gives a single renewable percentage for the network.
Energy intensity is a separate quantity and is defined marginally: the additional electricity associated with one further transaction being processed, rather than the annual total divided by the transaction count. On a chain that produces blocks on a fixed schedule whether or not they are full, the marginal figure is far smaller than a simple average would suggest, and the two should not be used interchangeably.
Three limits are worth stating plainly. An observed hosting location identifies a grid but not a procurement arrangement, so an operator buying renewable power on a carbon-heavy grid is indistinguishable from one that is not. Cloud and proxy infrastructure can place a node's apparent location away from the hardware actually running it. And national annual averages smooth over the hourly and seasonal variation in generation mix that a continuously running machine actually draws from.
The renewable share reported here is a weighted average of grid mixes rather than a record of what any operator actually buys. It is produced in two steps: establish where the infrastructure sits, then attach regional electricity statistics to those places.
Location is inferred from what the network exposes publicly. Nodes advertise network addresses in order to be reachable by peers, and those addresses resolve to a country accurately enough to describe an aggregate distribution, even though any single resolution may be wrong. Crawlers of the peer-to-peer layer and public directories of hosting and staking infrastructure supply the input. Where the observable sample is too thin or too skewed to stand for the whole population, the geographic spread of a structurally similar network is substituted, chosen because its participants face comparable hardware costs and comparable pressures over where to site machines, on the reasoning that operators respond to the same commercial forces even where the software differs.
Each location is then matched to published statistics on how electricity in that country or region is generated. The renewable proportion for the network is the consumption-weighted share falling in regions where generation is renewable. Grid averages are used because the alternative, knowing each operator's actual supply contract, is not observable; an operator on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.
Energy intensity is reported on a different basis from total consumption. It is a marginal quantity: the additional electricity attributable to processing one further transaction on the network as it currently runs. For a network whose consumption is driven by a validator set that operates continuously regardless of how busy the chain is, that marginal figure is small, and it is not the total divided by the transaction count. The generation statistics are drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.
The renewable share attributed to Polygon PoS depends on where its infrastructure physically sits, so the method begins with geolocation. Nodes visible through peer discovery and public network observation are resolved to hosting providers, autonomous systems and countries, giving an approximate map of where validator and full-node capacity is concentrated. Coverage is never complete; where it is too thin to be relied on, the geographic distribution of a network with a similar staking design and operator economics is used as a proxy. The same exercise applies to the portion of Ethereum's footprint brought in through checkpointing, using Ethereum's own observed node distribution.
Those locations are then matched to national electricity statistics. Each country's share of generation from renewable sources comes from Share of electricity generated by renewables, compiled and processed by Our World in Data from Ember's yearly electricity datasets and the Energy Institute's Statistical Review of World Energy. Weighting the country-level shares by the estimated node capacity in each produces a single renewable figure for the network.
Energy intensity is reported as a marginal quantity: the extra electricity associated with processing one more transaction, not the annual total divided by the number of transactions. On a chain whose validators run continuously and produce blocks on a schedule, that marginal figure is much smaller than a simple average would suggest, and the two are not interchangeable.
The limitations are inherent to the approach. An observed hosting location identifies a grid, not a power purchase agreement, so an operator sourcing renewable electricity on a carbon-heavy grid is invisible to the method. Cloud hosting and proxying can misplace a node relative to the hardware actually running it. Annual national averages cannot capture the hourly and seasonal swings in generation mix that continuously running machines draw from. And the borrowed share of Ethereum's footprint carries whatever geographic error is present in Ethereum's own distribution.
The renewable proportion is inferred from where the network's machines appear to sit and from how the electricity in those places is generated. Locations are approximated from publicly observable network data: the addresses seen during peer discovery and in crawler output, resolved to country or region rather than to a street. This network is a relatively favorable case for that method, because its low participation threshold has drawn in a wide and internationally dispersed set of operators, many of them running a single machine rather than renting capacity in a handful of large data centers. It remains an approximation. Operators behind hosting providers, relays or privacy services are attributed to the wrong place or not observed at all, and where the picture is too incomplete to support a distribution the geographic spread of a structurally comparable network is used to fill the gap.
The resulting distribution is weighted against published electricity statistics. For each region, the proportion of generation coming from renewable sources is taken from Share of electricity generated by renewables, compiled by Our World in Data from Ember and from the Energy Institute's Statistical Review of World Energy, and applied to the consumption assigned to that region. Summing across regions produces a weighted renewable share for the network. The assumption behind it is that every node draws from its local grid at that grid's average mix, which neither credits an operator on a certified renewable supply contract nor penalizes one on a dirtier local supply, since neither arrangement is visible in network data.
Energy intensity is reported as the marginal energy associated with one further transaction rather than as a period total divided by a transaction count. On a network whose nodes draw essentially the same power across a wide range of block fullness, the incremental figure describes the actual cost of additional usage, while an average would move with how busy the chain happened to be.
Key GHG sources and methodologies
CoW Protocol is present on the following networks: Arbitrum, Base, Binance Smart Chain, Ethereum, Polygon, Gnosis Chain.
Emissions are derived from the energy estimate rather than measured at the source. The geographic distribution built for the renewable calculation — sequencer and batch-posting infrastructure, dispute-protocol validators, full nodes, and the share of Ethereum's validator set attributed to settlement — is reused, and each country's slice of estimated electricity is multiplied by the average carbon intensity of that country's grid. Grid figures are drawn from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy and made available under a Creative Commons BY 4.0 license. Regional totals are summed to give a network figure, and a fraction of that figure is attributed to an individual asset in proportion to observed on-chain activity.
The two scopes are treated separately. Scope 1 covers combustion that the operators themselves control — on-site generators, fuel burned directly on their premises. For a chain whose infrastructure sits in commercial data centers this is ordinarily zero or negligible, and it is reported as such unless direct fuel use is known. Scope 2 is the substantive figure: the emissions embodied in the grid electricity that infrastructure draws. It is computed on a location basis, using the average intensity of the grid a machine draws from, rather than on a market basis reflecting supply contracts or certificates, because supplier-level information cannot be observed from the network. Emissions embodied in manufacturing the hardware or building the facilities that house it fall outside this boundary.
Greenhouse gas intensity is stated marginally, as the additional emissions associated with one more transaction. Two limits are worth stating plainly. Grid intensity statistics are annual national averages, so they miss the hourly and sub-national variation any specific facility experiences, and a data center on a dedicated low-carbon supply will be represented by its country's average. And the figure inherits every uncertainty in the energy and location estimates beneath it; where those rest on assumption, the assumption chosen is the one more likely to overstate the result.
Emissions are not measured directly. They are derived by attaching a carbon intensity to each unit of electricity the network is estimated to consume, across both parts of its footprint: the machines the network operates itself, and the share of the settlement layer's consumption attributed to the data and commitments it posts there.
The geographic step repeats the one used for the renewable share. The hosting regions of the sequencing and batching infrastructure are publicly observable; the wider set of replica and archive nodes is located from the addresses peers advertise, collected by crawlers and public directories. Where observation is too sparse to characterize the population, the spread of a structurally comparable network is used in its place. The settlement layer's validator population is located separately, because it is distributed quite differently, and the two are weighted by how much consumption each accounts for. Each region is then assigned a carbon intensity, the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the total.
Two scopes are distinguished. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For infrastructure that consists of ordinary servers in commercial data centers drawing from public grids, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the purchased electricity, and is where essentially the whole footprint sits. Emissions from manufacturing and transporting the hardware fall outside this boundary.
Greenhouse gas intensity follows the marginal logic used for energy intensity: the additional emissions attributable to one further transaction, not an average spread across all of them. It inherits the uncertainty of both the consumption estimate and the grid averages. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Emissions for BNB Smart Chain are derived from the same geographic picture used for the energy mix, then converted using regional carbon factors. Node locations are approximated from peer-discovery data, public network observation and hosting attribution, and where coverage is insufficient the distribution of a structurally similar staked network stands in. Each location carries the carbon intensity of its national grid, drawn from Carbon intensity of electricity generation, processed by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy and published under a CC BY 4.0 license. Multiplying the electricity attributed to each region by that region's grams of carbon dioxide equivalent per kilowatt-hour, and summing across regions, gives the annual emissions figure.
The split between scopes matters for interpretation. Scope 1 covers emissions from sources the network's operators control directly, such as on-site fuel combustion, which for a population of general-purpose servers in rented facility space is generally negligible and is reported as such. Scope 2 covers the indirect emissions embodied in the electricity those machines purchase from the grid, and that is where effectively the whole footprint sits. Emissions upstream of operation, in the manufacture and eventual disposal of the hardware, fall outside this accounting boundary.
Greenhouse-gas intensity mirrors the energy definition: the incremental emissions associated with one additional transaction, not the annual total divided by throughput.
Uncertainty in the emissions figure compounds the uncertainty in the two inputs behind it. Any error in the estimated electricity total propagates directly into the result, and the geographic attribution adds error of its own, since grid carbon intensity varies by more than an order of magnitude between countries and a misplaced share of node capacity moves the answer substantially. Annual national averages also mask the hourly variation in grid intensity to which a machine running around the clock is fully exposed.
Emissions are derived from the consumption estimate rather than measured, by attaching a carbon intensity to each unit of electricity the network is estimated to draw and summing across the network.
The geographic step repeats the one used for the renewable share. Node locations are inferred from publicly observable network data, principally the addresses peers advertise so that others can connect to them, gathered by crawlers and supplemented by public information about where staking and hosting infrastructure is operated. Where that observation is too sparse to characterize the whole population, the distribution of a comparable network stands in for it, selected because its participants face similar operating economics rather than because its software resembles this one. Each region is assigned a carbon intensity, meaning the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the network total.
The reporting separates two scopes. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For a network of this kind, whose participants overwhelmingly run ordinary servers connected to a public grid, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the electricity purchased to run that infrastructure, and that is where essentially the whole footprint sits. Emissions further up the supply chain, such as those from manufacturing and shipping the hardware, fall outside this boundary.
Greenhouse gas intensity follows the same marginal logic as energy intensity: it expresses the additional emissions attributable to one further transaction rather than an average spread across all of them. Because it inherits both the consumption estimate and the grid averages, its uncertainty combines theirs. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.
Emissions attributed to Polygon PoS rest on the same geographic work as the renewable share, with regional carbon factors applied in place of renewable percentages. Validator and full-node locations are approximated from peer discovery, public network observation and hosting attribution, and a comparable network's distribution stands in wherever direct observation is too sparse. The share of Ethereum's footprint brought in through checkpointing is located the same way, against Ethereum's own node distribution. Each location is paired with the carbon intensity of its national grid, taken from Carbon intensity of electricity generation, processed by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy, and made available under a CC BY 4.0 license. Multiplying regional electricity by regional grams of carbon dioxide equivalent per kilowatt-hour, then summing, yields the annual total.
Scope matters to how the result should be read. Scope 1 captures emissions from sources under the direct control of the network's operators, such as fuel burned on site, which for servers in rented facility space is generally negligible and reported as such. Scope 2 captures the indirect emissions embodied in purchased electricity, and that is where essentially the entire footprint falls. Manufacture and disposal of the hardware sit outside the boundary of this accounting.
Greenhouse-gas intensity is defined marginally, as the incremental emissions associated with one additional transaction rather than the annual total spread across throughput.
The error bars on the emissions figure inherit those on the electricity estimate and add to them. Grid carbon intensity differs by more than an order of magnitude between countries, so a misallocated share of node capacity shifts the result considerably, and annual national averages hide the hourly swings in intensity that machines running around the clock experience in full.
Emissions figures are derived from the estimated electricity consumption of the network combined with the carbon content of the supply in the places where its machines run. The geographic starting point is the same as for the energy assessment: node locations approximated from addresses seen in peer discovery and crawler output, resolved to region, with the distribution of a structurally comparable network substituted wherever direct observation is too sparse to be relied upon.
Each region is then assigned a carbon intensity for its electricity, in emissions per unit generated, drawn from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and from the Energy Institute's Statistical Review of World Energy and made available under the Creative Commons Attribution 4.0 license. Applying each region's intensity to the consumption attributed to it and summing across regions gives the network total for the period.
The division between reported scopes follows from what running this network involves. Scope one covers emissions from sources the operators control directly, which would mean combustion on their own premises; validating produces none, and standby generation is neither material nor observable at this level, so the figure is reported at or close to zero. Scope two covers the emissions embodied in the electricity bought to run the machines, and effectively the entire footprint falls there. Because regional averages are used, the estimate is insensitive to the individual supply contracts of particular operators, which is a known limitation rather than a claim about them. It is also worth noting that the residential share of this network's operators is supplied at the household rather than the industrial tariff mix, though both are represented in the same regional average.
Greenhouse gas intensity is expressed as the marginal emissions attributable to one additional transaction, consistent with the treatment of energy intensity, because the infrastructure emits at much the same rate irrespective of how full the blocks it is producing happen to be.