Ethena (ENA) sustainability report

NameBlockNodes SAS
Relevant legal entity identifier969500PZJWT3TD1SUI59
Name of the crypto-assetEthena
Beginning of the period to which the disclosure relates2025-09-27
End of the period to which the disclosure relates2026-09-27
Energy consumption4889.65058 kWh/a

Consensus Mechanism

Ethena is present on the following networks: Arbitrum, Avalanche, Base, Ethereum, Kava, Optimism, Solana, Toncoin, Zksync.

Arbitrum One does not run a consensus algorithm or a validator set of its own. It is an optimistic rollup: transactions are executed off Ethereum, while Ethereum holds the canonical record and provides final settlement. A sequencer accepts transactions, orders them on a first-come basis and executes them under the chain's state-transition rules, producing blocks roughly four times a second and giving users an immediate local confirmation. The ordered transactions are compressed and published to Ethereum in batches. Because that input data sits on the settlement layer, anyone running the node software can replay it and arrive at the same Layer 2 state without trusting the operator.

Agreement about what that state is happens on Ethereum. Validators post assertions — claims about the rollup's resulting state — to contracts on the settlement layer. Since early 2025 the chain has used a dispute protocol that made validation permissionless, so any party may post an assertion or challenge one rather than only an approved list of operators. Conflicting claims are resolved by an interactive process that narrows the disagreement down to a single step of execution, which Ethereum then adjudicates directly. The protocol is designed so that disputes conclude within a bounded period no matter how many adversaries join them, and so that a single honest participant is enough to defend the correct state. Once the challenge window has passed without a successful dispute, the assertion is confirmed and withdrawals that depend on it become executable through the canonical bridge.

Two qualifications matter for an accurate picture. Ordering is still performed by a single sequencer operated by the chain's development company, so transaction ordering is not decentralized today; censorship is bounded rather than impossible, because a user can submit a transaction to a queue contract on Ethereum and force its inclusion once a defined delay has elapsed. Separately, a security council retains powers over the contracts, which keeps the arrangement short of full trust-minimization. Security therefore rests on Ethereum's proof-of-stake consensus combined with the rollup's fraud-proof mechanism, not on a validator set belonging to the chain itself.

Avalanche's Primary Network is not a single chain but three, each specialized and all validated by the same set of operators. The contract chain hosts smart-contract execution in an Ethereum-compatible environment and is where most applications and issued assets live. The exchange chain handles asset creation and transfers. The platform chain tracks the validator set, staking, and the registration of the sovereign networks that run alongside the Primary Network.

Agreement across all three comes from the Snow family of protocols, which reaches consensus through repeated randomized sampling rather than through the round-based voting of classical Byzantine fault tolerant designs. There is no leader gathering votes from the entire validator set. Instead each node repeatedly asks a small random sample of validators what they currently prefer, adopts whichever answer carries a sufficient majority of that sample, and accepts a decision once it has seen enough consecutive samples agree. Because a node queries a fixed-size sample rather than everyone, the messaging load per node barely grows as the validator set grows, which is what allows the set to be large without consensus becoming the constraint.

Snowman is the variant used for linearly ordered chains, and Snowman++ layers a proposer schedule over it: block-building windows are assigned to proposers in proportion to stake, with production opening more widely if a designated proposer fails to act, which limits contention without introducing a fixed committee. Sampling remains the voting mechanism throughout. An earlier design in which the exchange chain ordered transactions as a directed acyclic graph was retired in 2023 when that chain was linearized, and the whole Primary Network now runs on the same linear engine.

Acceptance is fast, typically under a second, and once a decision is accepted the protocol treats it as irreversible. Formally the guarantee is probabilistic: sampling parameters can drive the chance of two conflicting decisions both being accepted arbitrarily close to zero, but not to exactly zero, which is a different kind of statement from the deterministic finality a quorum-certificate protocol offers. Validators join the Primary Network by bonding the native asset for a chosen term, holders may delegate to them, and the protocol does not slash bonded principal.

Base is a Layer 2 network that executes transactions away from the Ethereum chain and settles them on it. It runs no consensus protocol of its own and has no validator set of its own. Agreement about which Base transactions occurred, and in what order, is ultimately established by the data and the state commitments the network publishes to Ethereum, which are secured by Ethereum's proof-of-stake consensus.

Ordering and execution on the Layer 2 are carried out by a single sequencer, operated by the company that launched the network. It receives transactions, places them into blocks at a fixed cadence and returns a result to the user straight away; those blocks are then compressed and posted to Ethereum in batches, alongside commitments to the state they produce. Once a batch sits inside a finalized Ethereum block, the ordering it encodes is as hard to reverse as Ethereum itself. Users are not wholly dependent on the sequencer for access: a transaction can instead be submitted through a contract on Ethereum, and the rules by which the Layer 2 chain is derived oblige it to be included, which bounds how far the sequencer can censor.

Base is an optimistic rollup, built on the shared OP Stack codebase and part of the Superchain group of networks that use it. State commitments are accepted as correct unless disputed. Anyone may propose one and anyone may challenge one within a dispute window, by playing an interactive game on Ethereum that narrows the disagreement down to a single step of execution, which an Ethereum contract then settles by running that step itself. Both sides post bonds, so an untrue claim and a frivolous challenge are each expensive. Permissionless fault proofs have run on the main network since late 2024, and a multi-party security council with a supermajority threshold governs changes to the contracts; together these place the network at the intermediate tier of the rollup maturity scale commonly used to compare such systems. A withdrawal to Ethereum cannot complete until the dispute window for the relevant commitment has elapsed. Decentralizing the sequencer itself remains outstanding work.

Ethereum reaches agreement through proof of stake, adopted in September 2022 when the original mining-based chain was retired in favor of a validator-driven consensus layer. The protocol family is usually referred to as Gasper. A fork-choice rule named LMD-GHOST selects the head of the chain by following the branch carrying the greatest accumulated weight of validator votes, while a separate finality gadget, Casper FFG, periodically justifies and then finalizes checkpoints, so that reversing them would require destroying an enormous quantity of bonded value.

Time is divided into slots of twelve seconds, and thirty-two slots form an epoch. For each slot the protocol pseudo-randomly designates one active validator to assemble and publish a block, and assigns the rest to committees that vote on what they believe is the correct head and the correct checkpoints. Under healthy conditions a checkpoint becomes final two epochs after it is proposed, a little under thirteen minutes, after which everything beneath it is treated as settled.

Joining the validator set requires a deposit of no fewer than 32 units of the native asset. Since the protocol upgrade of May 2025 a single validator may hold a far larger balance, up to 2,048 units, and earn on the whole of it, which lets an operator running many minimum-sized validators consolidate them into fewer; the activation floor itself did not change. Entry and exit are rate-limited by a queue measured in staked weight rather than in validator headcount, which bounds how fast the composition of the set can turn over.

Security rests on voting power being bonded. A validator that signs contradictory messages can be proved to have done so and is penalized, and the size of that penalty scales with how much other stake was penalized at the same time, so a coordinated attack is punished far more severely than an isolated fault. Should the chain stop finalizing altogether, a separate mechanism gradually erodes the balances of validators that are not participating until the remainder again represents a large enough majority to finalize. Upgrades during 2024 and 2025 changed how large data payloads are distributed and sampled between nodes, without altering this underlying agreement process.

Kava is a layer 1 network built with the Cosmos SDK that reaches agreement through CometBFT, the Byzantine-fault-tolerant engine previously released under the Tendermint Core name. The design is proof of stake: voting power is allocated in proportion to the quantity of the network's native asset bonded to each validator, either committed by the operator directly or delegated to it by other holders, and only the hundred highest-weighted operators sit in the active set that produces blocks at any given height.

What separates this network from a conventional single-environment chain is its co-chain arrangement. One validator set and one consensus process secure two execution environments that sit side by side: an Ethereum-compatible environment in which Solidity contracts run, and a Cosmos SDK environment whose state changes are typed module messages rather than contract bytecode and which speaks the Inter-Blockchain Communication protocol to other Cosmos networks. A translator component moves value and calls between the two. Because both environments advance inside the same block, they share a single transaction ordering and a single security budget, rather than being separate chains joined by a bridge.

Block production follows the round structure usual to this consensus family. A proposer is drawn for each height with a frequency weighted by bonded stake, and the remaining validators move through a pre-vote and then a pre-commit round. Once more than two thirds of voting power has pre-committed, the block is committed and treated as final at that moment; there is no confirmation depth to wait out and no reorganization of committed history while fewer than one third of voting power behaves adversarially. On the Ethereum-compatible side blocks arrive roughly every six seconds and are final at the first block. Accountability is economic: operators that sign conflicting blocks at the same height, or that miss too large a share of recent blocks, forfeit part of their bonded stake and are excluded from the active set until they are reinstated.

OP Mainnet operates no validator set and no consensus algorithm of its own. It is an optimistic rollup: blocks are produced away from Ethereum, but the canonical history and final settlement live on Ethereum. A sequencer accepts transactions, orders them and produces Layer 2 blocks on a two-second cadence, which is what gives users a fast confirmation. The ordered transaction data is compressed and published to Ethereum in batches, and every node derives the canonical chain by reading that data back from the settlement layer. Deriving the chain from Ethereum rather than from the sequencer's word is what makes the arrangement verifiable: anyone holding the published data can recompute the same state independently.

Correctness is enforced after the fact. Claims about the chain's output state are posted to a dispute-game contract on Ethereum, and since the fault-proof system was opened to the public in mid-2024 anyone may post such a claim or dispute one, with no allowlist involved. A challenge proceeds as a bisection game in which the two sides repeatedly narrow their disagreement until a single step of execution remains; that step is then executed inside a deterministic fault-proof machine on Ethereum, which settles the matter on-chain. Both sides lock bonds and the loser forfeits. A claim that survives a challenge window of roughly a week is treated as final for the purpose of withdrawing assets to Ethereum.

Two limits belong in any accurate description. Sequencing rests with a single operator, so ordering is centralized in practice; censorship is constrained rather than prevented, because a transaction can be deposited through a contract on Ethereum and must then be included in the chain. And a guardian role, alongside a security council, retains emergency powers, including pausing withdrawals and returning the dispute system to a permissioned mode should it fail — a deliberate safeguard that nonetheless keeps the chain short of full trust-minimization. Ultimate security comes from Ethereum's proof-of-stake consensus, whose validators finalize the data the rollup depends on.

Solana runs a proof-of-stake network in which the right to produce a block is allocated in proportion to the quantity of the native asset staked to each validator. What sets the design apart is that ordering is established before agreement is sought. A designated leader runs a sequential hash chain, each output feeding the next input, so the chain cannot be computed faster than a fixed number of steps and a transaction's position within it is evidence of when that transaction was received. This construction, called proof of history, spares validators from negotiating timestamps with one another and lets the rest of the protocol treat the order of events as already settled.

Leadership is not auctioned block by block. At the start of each epoch, which runs for roughly two days, a schedule is derived deterministically from the active stake distribution and assigns every short slot in the epoch to a named validator. Slots follow one another a few hundred milliseconds apart. The scheduled leader gathers transactions, executes them and streams the resulting block to the rest of the set in small fragments relayed through a tree structure rather than pushed to every peer at once. Receiving validators replay the block independently and publish votes for the fork they consider canonical.

Fork choice weights those votes by stake, and each vote commits a validator to its chosen fork for a period that doubles with every further confirmation, so abandoning a block grows steadily more costly. A block that a supermajority of stake has voted on is treated as confirmed within about a second, and it is locked in permanently once enough additional confirmations accumulate, which takes on the order of ten seconds. Safety rests on the assumption that participants acting dishonestly control less than a third of staked value. A revision of the voting layer, approved in a stake-weighted validator vote, is being activated on the main network in stages; it retains stake-weighted validation and the existing block distribution scheme while replacing the incremental lockout rule with direct voting that settles in one or two rounds.

TON is not a single chain but a hierarchy of them secured by one Byzantine fault tolerant proof-of-stake validator set. At the top sits the masterchain, which carries the protocol configuration, the current validator set and hash references to the latest state of everything beneath it. Below it are workchains, each able to define its own rules, of which one general-purpose chain is in operation. Each workchain is in turn divided into shardchains, and that division is dynamic: the count is always a power of two, a shardchain splits in two when its load grows and the halves merge back when it falls, and an account's address prefix decides which shard holds it at any moment. Describing this as a single-chain network would misstate it, as would treating the shards as independent chains, since the masterchain commits them all.

Agreement is reached by two layered protocols. The lower layer, Catchain, gives a validator group a signed, hash-linked message graph with dependency information, so broadcasts are reliably delivered and any attempt to fork is detectable. A block consensus protocol runs on top of it to agree the next block. Validators are partitioned into groups, each assigned to a shard or to the masterchain for a term, and a group's agreement is safe as long as fewer than a third of its members behave maliciously.

Selection runs through an election contract on the masterchain rather than a continuous ranking. Candidates submit an application carrying their keys and a stake in the native asset; applications clearing a configured minimum are ordered by stake and the set is taken down to a configured maximum, with a cap limiting how much weight any single large stake can carry relative to the smallest accepted. Terms are fixed-length rounds, after which a fresh election seats a new set, and a departing validator's stake stays frozen for a further period so that misconduct discovered late can still be answered for. Contracts interact only by asynchronous messages, which is what allows work to cross shard boundaries as they split and merge.

zkSync Era is a validity rollup on Ethereum — the family commonly called zero-knowledge rollups — and it runs neither a consensus algorithm nor a validator set of its own. A sequencer receives transactions, orders them and executes them against the chain's state, returning a confirmation within a second or two. Blocks are grouped into batches, and each batch passes through three stages on Ethereum: the resulting data is committed, a cryptographic proof that the batch executed correctly is submitted and checked by a verifier contract, and the state transition is then applied on the settlement layer.

What separates this design from an optimistic rollup is that correctness is established before the fact rather than assumed and disputed afterwards. Once a proof verifies on Ethereum, the batch is known to have followed the protocol's rules, so there is no fraud proof, no challenger role and no week-long challenge window standing between a withdrawal and settlement; the wait is instead however long producing and verifying a proof takes. Proving is carried out by dedicated proving infrastructure, not by ordinary users. Proofs are built recursively, with many small proofs aggregated into one, and the final proof is compact enough to verify cheaply on Ethereum. The proving stack has been replaced more than once as the technology matured; the current generation proves execution of the chain's state-transition program itself, which brings proving close to real time and removes the need to maintain a separate circuit description mirroring the same logic.

Data availability rests on Ethereum. The chain publishes compressed differences in state — what changed as a result of a batch, rather than every transaction in it — into the dedicated data space Ethereum provides for rollups, which is sufficient for an independent party to reconstruct the chain. Two limits apply here as they do across comparable networks: sequencing is performed by a single operator, and the contracts are upgradeable through a governance process with timelocks and an emergency path rather than being fixed.

Incentive Mechanisms and Applicable Fees

Ethena is present on the following networks: Arbitrum, Avalanche, Base, Ethereum, Kava, Optimism, Solana, Toncoin, Zksync.

Fees on Arbitrum One are paid in the settlement layer's native asset and split into two economic components. The execution component prices computation and state access on Layer 2 through a base fee that a control loop raises and lowers with demand, in the style of Ethereum's own fee market. The data component covers the cost of publishing compressed batches to Ethereum. A transaction's share of that component is estimated from how many bytes it adds to a compressed batch, so how well its data compresses matters as much as its size, and the fixed cost of a posting is spread over everything in the batch rather than falling on one transaction. Since Ethereum opened a dedicated data space for rollups, batches are posted there and priced by that space's separate fee market. Both components are converted into a single unit, so a user sees one price rather than two.

Payments flow to several places. The party that posts batches is reimbursed from collected fees, with the data price adjusted over time so that reimbursement tracks what was actually spent. Remaining Layer 2 revenue accrues to protocol-controlled accounts — one covering baseline infrastructure, another collecting congestion revenue — which governance directs, rather than being burned. A portion of ordering rights is also sold: a sealed-bid auction awards a short-lived priority lane for a round lasting under a minute, and the proceeds go to an account that chain governance designates. Contracts compiled to WebAssembly run alongside EVM contracts and are metered on their own resource unit.

There is no staking, delegation, issuance or slashing at this layer. The equivalent penalty is a bond: participants that assert or challenge state must lock collateral, and a party that loses a dispute forfeits it, with part compensating the honest side, so an incorrect claim carries a direct cost. Beneath the rollup, Ethereum's own incentives apply to the data it posts — the base fee there is burned and the priority fee goes to the block proposer. There is no recurring storage rent; state is paid for when it is written.

Validators on the Primary Network are compensated out of protocol issuance under a capped supply schedule rather than out of user fees. An operator bonds a minimum amount of the native asset for a chosen staking term and is paid at the end of that term provided it met the uptime requirement. A validator's effective weight is capped relative to its own bonded stake, which limits how much delegated stake any single operator can concentrate. Holders who do not run infrastructure may delegate to a validator for a term and receive the reward net of the fee that validator charges.

The enforcement model is unusual in that bonded principal is not slashed. A validator that fails to meet the uptime threshold simply does not receive its reward for that period and gets its stake back, so the penalty is forfeited income rather than confiscated capital. The most recent protocol upgrade reworked these terms considerably: the minimum staking term was shortened from two weeks to two days, staking terms can now renew automatically with rewards compounded at a chosen ratio, the uptime threshold required to earn a reward was raised for newly started validations, and the average rate at which rewards are issued was reduced.

Sovereign networks running alongside the Primary Network are funded differently. Since the late-2024 upgrade that separated them, their validators no longer need to bond a large stake and validate the Primary Network as well; instead they pay a continuous fee to the platform chain that adjusts with the number of active such validators relative to a target, rising when the population exceeds it and easing when it falls short.

Users of the contract chain pay a base fee plus an optional tip, priced dynamically in the style of Ethereum's fee market. The distinguishing feature is that the fee is burned rather than paid to the block producer, so transaction activity reduces supply and offsets issuance instead of rewarding validators directly. The minimum base fee has been lowered by upgrade and is now a floor that validators adjust collectively rather than a hard-coded constant. The exchange and platform chains likewise price their operations dynamically, and those fees are burned as well. There is no storage rent.

Base has no native protocol asset, no staking and no issuance. Nothing is minted to reward participation and there is no validator or delegation system on the Layer 2. Fees are denominated and paid in ether, the same asset used on the settlement layer.

What a user pays has two parts, and they behave quite differently. The first is the cost of executing the transaction on the Layer 2, metered in gas exactly as on Ethereum and priced by an equivalent algorithmic base fee that moves with how full recent Layer 2 blocks have been, plus an optional tip. Because Layer 2 block space is plentiful, this component is usually very small and fairly stable. The second is a charge for the cost of publishing that transaction's data to Ethereum. It is assessed per transaction from the compressed byte size of the transaction and the prevailing price of settlement-layer data space, and it is collected when the transaction is processed even though the actual posting happens later, in a batch shared with many others. This second component typically dominates the total and is why Layer 2 costs track conditions on Ethereum.

Since Ethereum opened a dedicated market for rollup data in 2024, the network posts its batches into that market rather than as ordinary transaction data. Those data fees are priced independently of execution and are destroyed rather than paid to anyone, which cut this component sharply. A December 2025 change on the settlement layer raised the available data capacity while introducing a floor that ties the minimum data price to ordinary execution costs, so the charge no longer falls to almost nothing whenever demand for data space is light.

Fees collected on the Layer 2 accrue to the entity operating the sequencer, funding the cost of running it and of settling to Ethereum, with a portion shared with the collective that stewards the shared codebase. The other economic mechanism at work is the dispute system: participants who propose or challenge a state commitment post bonds that are forfeited if they are shown to be wrong, which funds honest challenges and makes dishonest claims costly.

Payment inside the protocol flows to validators, the only participants the consensus layer compensates directly. A validator earns newly issued units of the network's native asset for voting promptly and correctly on the head of the chain and on the checkpoints being justified, for serving its turn in the committee that signs headers for light clients, and, when selected to propose, for the block itself. The proposer additionally keeps the priority portion of the fees in that block, together with whatever it receives from the separate market through which many proposers outsource block assembly. There is no delegation inside the consensus rules: stake is either operated directly or entrusted to an operator through arrangements that sit outside the protocol.

Users pay for execution in gas, metered per operation, with writes to persistent state priced far above arithmetic. Every transaction carries a base fee per unit of gas that the protocol sets algorithmically from how full recent blocks have been, and that amount is destroyed rather than paid to anyone, so sustained demand withdraws native asset from circulation. On top of it a user adds a voluntary tip, which goes to the proposer and governs how quickly the transaction is picked up. Data posted on behalf of Layer 2 networks is priced in a second, independent market whose fee is likewise destroyed; a December 2025 upgrade tied the floor of that market to ordinary execution costs so it cannot collapse to a negligible level, and capped the gas any one transaction may consume.

Penalties mirror the rewards. Failing to vote, or voting late or incorrectly, costs a validator roughly what correct behavior would have earned it. Provable equivocation is treated far more harshly: the offender is scheduled for ejection, forfeits part of its balance immediately, and later incurs an additional correlated penalty computed from how much other stake was penalized nearby in time. Prolonged absence while the chain is failing to finalize drains balances until finality can resume. Stakers may take out accumulated rewards without leaving the set, and since 2025 may also trigger a full exit from the execution layer rather than only from the consensus client.

Validators and the holders who delegate to them are the paid participants. Fee revenue from each block is spread across the active set in proportion to voting power, with an additional share to the proposer, and each operator passes on what remains to its delegators after deducting a commission rate it sets and publishes. Delegation lets holders contribute stake weight without running infrastructure, and it carries the matching downside: stake delegated to a penalized operator is reduced alongside the operator's own.

The material change in how all this is funded is that the protocol no longer issues new units to pay for security. Emissions were switched off at the start of 2024, the last inflationary issuance having been minted in the final block of 2023, and the protocol retains no mechanism to create further supply — only to destroy it. Rewards consequently come from two places: transaction fees collected in the ordinary course, and distributions out of a community-controlled on-chain treasury whose balance was set aside rather than printed. Ecosystem incentive programs that were once paid from new issuance are funded the same way, with governance deciding allocations and deciding whether any surplus is retired or redeployed. The reward budget is therefore a finite and governed pool rather than an open-ended subsidy, and the security of the network rests on fee revenue over the long run.

Users pay for execution in gas, denominated in the network's native asset on both co-chains. Contract execution in the Ethereum-compatible environment is metered per operation on the familiar opcode schedule, so computation, storage writes and contract deployment cost in proportion to the work they impose on every node; module messages on the Cosmos side are metered on an equivalent gas basis. Validators enforce a minimum acceptable gas price, and transactions offering more than that floor are ordered ahead of those that do not. Penalties form the counterweight: a fraction of bonded stake is confiscated for equivocation, a smaller penalty and temporary exclusion from the set apply to sustained unavailability, and stake withdrawn from bonding stays exposed through an unbonding period before it becomes transferable.

Transactions are paid for in the settlement layer's native asset, and the amount splits in two. The execution component prices computation and state access on Layer 2 through a base fee that adjusts with demand plus an optional priority fee, and it is small because the work happens away from Ethereum. The data component covers publishing the transaction's data to Ethereum so the chain can be reconstructed, and it usually dominates. Since Ethereum introduced a dedicated data space for rollups, batches are posted there instead of as ordinary call data, and the pricing function reads both Ethereum's ordinary base fee and the separate fee for that data space — each relayed onto Layer 2 by a system contract every block — scaled by two parameters the chain operator can tune. What a transaction pays is proportional to its compressed size, estimated with a compression function, so the cost of a posting is apportioned across the transactions in the batch rather than charged to whichever one happens to trigger it.

There is no staking, delegation or reward issuance at this layer, and consequently no slashing. The sequencer's incentive is the margin between the fees it collects and what it spends publishing data to Ethereum, which gives it a direct reason to batch efficiently. Net of those costs, the surplus from this chain is directed to the collective treasury that funds protocol development and public-goods programs, and other chains built on the same software contribute a defined share of their own revenue on the same basis. Participants in the proof system are paid differently: bonds locked in a dispute are forfeited by the losing side to the winner, so challenging an incorrect claim is rewarded while posting one is expensive.

Deploying and calling smart contracts is charged on the resources consumed, on the same basis as on Ethereum, and there is no recurring storage rent — state is paid for when it is written. Underneath, the data the chain posts is subject to Ethereum's own rules, where the base fee is burned and the priority fee goes to the block proposer.

Two streams of payment reach validators. The protocol issues new units of the native asset on a defined schedule and distributes them at the close of every epoch to validators and to the stake delegated to them, in proportion both to that stake and to the voting credits the validator actually accrued over the epoch; an operator that missed its slots or stopped voting accrues fewer credits and receives a correspondingly smaller share. Holders who do not wish to run hardware delegate through a stake account to an operator of their choice, retain control of that account, and receive the reward net of whatever commission the operator has set. Delegated stake becomes active and inactive only at epoch boundaries, so capital committed to securing the network cannot be pulled out on demand.

Users pay a fixed base fee for every signature a transaction carries. Half of that amount is destroyed and half is paid to the validator that produced the block. A transaction may attach an optional priority fee, quoted per unit of requested compute, which under a protocol change adopted in 2025 goes in full to the block producer; this is the mechanism that rations capacity when demand exceeds what a slot can hold. Program execution is metered in compute units against a per-transaction ceiling, so the cost of a contract call tracks the work it requests rather than a flat tariff.

Storage is charged once, not continuously. An account has to hold a minimum balance scaled to the number of bytes it occupies in order to be exempt from rent, and that balance is a refundable deposit rather than a fee: closing the account returns it. Recurring rent collection has been switched off at the protocol level and rent-paying accounts can no longer be created, so ongoing storage charges do not form part of the fee model as it now stands.

Staked assets are not confiscated by the protocol. No implemented mechanism automatically destroys a validator's stake for equivocation or for being offline; the cost of downtime is forgone reward set against operating expense, including the fees an operator pays to submit its own votes. A scheme to record provable duplicate-block violations on chain, as groundwork for any future economic penalty, is still at proposal stage and would not itself remove stake.

Validators are paid from two sources. New units of the native asset are issued with each block, with a masterchain block carrying a larger subsidy than a block of the general-purpose workchain, and the subsidy for a shard is divided among the shardchains that result when it splits. On top of that, the fees collected during a validation round accumulate in the election contract. When a round closes and the frozen stakes are released, the contract distributes rewards in proportion to stake, so payment reaches a validator only after its term has ended and the window for complaints has passed. The minimum stake for a seat is high, so holders wanting to participate with less generally do so through nomination and staking pool contracts, which aggregate deposits behind an operator and return rewards after a commission.

Punishment is deliberate rather than automatic. There is no mechanism that confiscates stake the instant a fault occurs. Instead, a validator that failed to produce the blocks it was assigned can be reported by another validator, who constructs a proof of the omission, proposes a fine scaled to its severity and files it with the election contract; the validators of the current round then vote on the complaint, and if it is upheld the fine is deducted from the frozen stake of the accused. Most of what is taken is destroyed rather than redistributed.

Users pay several distinct fees rather than one. Storage is genuine rent: a contract accrues a charge for every second it occupies space, priced by the cells and bits it holds, settled whenever it is next touched, and a contract that exhausts its balance is frozen and eventually removed. Computation is metered in gas, forwarding fees pay for delivering messages between contracts and across shards with the charge split between the sending and receiving shards' validators, and further components cover inbound external messages and outbound actions. All of these prices are set in on-chain configuration parameters that validators change by vote, not by an auction among users, so costs are stable rather than demand-driven. Half of the fees collected are sent to an unspendable address and destroyed; validators keep the other half.

Fees on zkSync Era are denominated in the settlement layer's native asset and cover three costs rather than two. The first is executing the transaction on Layer 2. The second is publishing data to Ethereum: because the chain posts compressed state differences instead of full transaction data, a transaction's share of that cost turns on how many storage slots it touches and whether others in the same batch touch the same ones — repeated writes to one slot within a batch collapse into a single published change, so activity concentrated on the same state costs less than its raw size implies. The third is proving. Generating a validity proof consumes real computation on specialized hardware, and verifying it on Ethereum costs a fixed amount per batch however many transactions that batch contains, so both are spread across the batch and both reward filling batches fully.

The incentive structure follows from that. The operator running the sequencer and the proving infrastructure is paid out of collected fees and is out of pocket if those fees fail to cover data publication and proof verification, which ties its revenue to keeping batches full and published data compact. There is no staking, delegation, issuance or slashing at this layer, because the chain does not select block producers economically and so has no stake to penalize. What protects users instead is the proof itself — an invalid state transition simply cannot be verified on Ethereum — together with a queue on the settlement layer that gives users a route around a sequencer unwilling to include them.

Two further features shape what users actually pay. Account abstraction is part of the protocol rather than bolted on, so a contract can sponsor another account's fees or accept payment in a different asset while settlement still happens in the native one. And there is no recurring storage rent: state is paid for when it is written, through the data component of the fee, rather than carried as an ongoing charge against whoever wrote it.

Energy consumption sources and methodologies

Ethena is present on the following networks: Arbitrum, Avalanche, Base, Ethereum, Kava, Optimism, Solana, Toncoin, Zksync.

The consumption attributed to Arbitrum One has two parts, and they are estimated in different ways. The first is the chain's own infrastructure: the machines running the sequencer and the batch-posting process, the validators that track state assertions and would take part in a dispute, and the broader population of full, archive and RPC nodes that other participants operate. The second is the share of Ethereum's consumption that belongs to the rollup, because settlement and data availability happen there. Ethereum's validators do work on the rollup's behalf whenever a batch is posted, and a proportion of their consumption is apportioned to the chain according to how much of the settlement layer's capacity those postings occupy. Ethereum publishes its own account of how that figure is arrived at (Ethereum energy consumption).

Since nothing here is mined, the first part is estimated by counting machines rather than by modeling operator profitability. The size of the node population is approximated from network crawlers, peer discovery and publicly listed endpoints. A representative hardware specification is inferred from what the client software states it needs to stay in sync — processor class, memory, fast storage and bandwidth — and the electricity that specification draws is taken from controlled measurement of equivalent machines, both under load and idling. The total is the aggregate across the estimated population including idle draw, because nodes run continuously whether or not blocks are full. Dispute participation is episodic and contributes little in normal operation. A fraction of the network total is then attributed to an individual asset in proportion to observed on-chain activity involving it.

These are estimates rather than meter readings, and the limits should be read as part of the figure. Node counts are lower bounds, because machines behind private networks cannot be discovered. The hardware mix is inferred from stated software requirements rather than surveyed from operators. Where the evidence runs out, the assumption chosen is the one more likely to overstate consumption than to understate it, and figures are revised as observation improves.

Avalanche is a staked network, so its energy estimate is assembled from the machines that participate rather than from hardware economics driven by block rewards. One structural feature shapes the calculation: a single Primary Network validator runs one node that validates the contract chain, the exchange chain and the platform chain together. The three are therefore not summed as though they were three independent populations, which would count the same hardware three times; the footprint is modeled against one node population serving all of them.

The estimate combines three inputs. The validator set is read directly from the platform chain, which makes the consensus-participating population unusually well observed compared with networks where it has to be inferred. The surrounding population of non-validating full and archive nodes, run by applications, data services and trading venues, is approximated from peer-discovery crawls and public listings, which see only nodes that accept inbound connections and so tend to undercount. A representative hardware profile is then inferred from the published requirements for the node software, and the power draw of such a configuration is taken from measurement of comparable machines under sustained load and at idle, since a validator draws power continuously whether or not it is currently proposing.

The result carries qualifications that should be read as part of the figure rather than as footnotes to it. Node counts and hardware profiles are inferred from public observation and stated requirements, not metered at the socket. Where evidence is missing, the assumptions chosen are the ones more likely to overstate consumption than to understate it. Estimates are revised as crawler coverage and hardware information improve. Sovereign networks that maintain their own validator sets are accounted for separately from the Primary Network rather than folded into it. And where a share of the total is attributed to an individual asset issued on the chain, that share is derived from observed on-chain transfer volumes, which measures how heavily an asset is used rather than the energy it uniquely causes.

The estimate for this network has two components, and they are constructed differently.

The first is the network's own infrastructure. This is a small and largely identifiable set of machines rather than a large permissionless population: the sequencer that orders and executes transactions, the batching service that compresses and submits data to the settlement layer, the service that publishes state commitments, and the replica and archive nodes that third parties operate to serve applications and to independently check what the sequencer produced. The number of independent replicas is estimated from crawlers of the Layer 2 peer-to-peer network and from public information about node operators and infrastructure providers. Hardware profiles are inferred from the published requirements of the node software, which for a high-throughput rollup are materially heavier than for an ordinary chain, and per-device power draw comes from measurement on representative equipment under controlled laboratory conditions, counting idle draw as well as load. The fault-proof machinery adds little in normal operation, since the interactive dispute game runs only when a commitment is actually challenged rather than continuously.

The second component is the share of the settlement layer's consumption that this network causes. That layer is Ethereum, whose own consumption is estimated from its validator population using the node-level method described for that network. A portion is attributed here in proportion to what this network occupies there, principally the data space its batches consume, alongside the gas used by its commitment and dispute contracts. Because the settlement layer's consumption is driven by a continuously running validator set rather than by throughput, this attributed share is modest next to the Layer 2's own footprint, but it is included so that settlement is not treated as free.

Both components are estimates built on public observation and stated software requirements, not metered readings. The replica population is the least observable part and the largest source of uncertainty. Where evidence is thin, the assumptions used are those more likely to overstate impact than understate it, and figures are revised as observation improves. The settlement layer publishes its own account of its energy profile at Ethereum energy consumption.

The figure reported for this network is assembled machine by machine, treating the computers that run the protocol as the thing that draws electricity. The starting point is an estimate of how many independent nodes are operating, built from crawlers that walk the peer-to-peer layer and record every peer they can reach, supplemented by public listings of infrastructure and staking providers and by the protocol's own visible record of how much stake is active and how it is spread across operators.

A representative hardware profile is then inferred for those machines. The client software publishes what it requires in processor, memory and disk terms, and operators have little reason to provision far beyond that, so the profile is derived from those stated requirements rather than from a survey of individual operators. Power draw for the resulting device classes comes from measurement on representative equipment under controlled laboratory conditions, capturing both the load validating places on a machine and the draw of a machine that is powered on but momentarily idle, which for a network of this kind accounts for a large share of the total. Multiplying measured per-device draw across the estimated population over the reporting period yields the network figure. Where a disclosure concerns one of the many assets issued on this network rather than the network itself, a portion of the network total is assigned to it in proportion to observed on-chain transfer volumes.

The limits deserve stating plainly. The node count records what is reachable, not a census, and machines behind restrictive network configurations are missed. The hardware profile is a reasoned inference from published software requirements, not a record of what any particular operator bought. Nothing here is metered at the wall. Where the evidence runs out, the assumptions chosen are those that push the estimate upward rather than downward, so the result is more likely to overstate consumption than to understate it, and it is revised as observation improves. The network's own account of its energy profile is published at Ethereum energy consumption.

The figure is built from the network's node population rather than from any metered reading taken across the network, which is the appropriate treatment for a stake-weighted Byzantine-fault-tolerant chain where the right to produce a block is not won by computational effort. The estimation approach used here begins by establishing how many machines take part. The active and standby validator set is enumerated from public chain state, and the wider population of full, archive and public endpoint nodes is approximated using network crawlers alongside publicly listed infrastructure. A representative hardware profile is then inferred from the specifications the client software states for running a node that can keep pace with the chain, and the electrical draw of machines matching that profile comes from laboratory measurement, recorded both under load and at rest. Aggregating that draw across the estimated population over the reporting period, with idle hours counted rather than assumed away, gives the network total.

The co-chain arrangement matters to this calculation. Since one validator set and one consensus process advance both the Ethereum-compatible and the Cosmos-side environments inside the same block, there is no second node population to add for the contract environment. Counting the validator and node set once captures both, and treating the two environments as though they were distinct networks would double the result.

Several limits should be read alongside the output. The node count and the hardware mix are inferences drawn from public observation and from stated software specifications, not readings taken from the machines themselves, and operators are under no obligation to disclose what they run. Where the evidence is thin, the assumptions chosen sit at the cautious end, so the result is likelier to overstate consumption than to understate it. Figures are restated as observation of the node population improves or as client specifications change. Where an asset is issued across more than one network, the portion attributed to each is derived from observed on-chain transfer volumes rather than divided evenly between them.

Two distinct things are being estimated, and conflating them is the usual source of error. The first is the electricity drawn by the chain's own infrastructure: the sequencer, the process that publishes batches, the challenger software that watches state claims and would contest an invalid one, and the population of nodes that other participants run, each of which pairs a consensus client deriving the chain from Ethereum with an execution client replaying it. The second is the portion of Ethereum's own consumption that belongs to the rollup, since every batch it posts occupies capacity that the settlement layer's validators pay to provide. That portion is apportioned by how much of Ethereum's resources the chain's postings take up. Ethereum publishes its own description of how its consumption is estimated (Ethereum energy consumption).

Nothing in this design is mined, so the chain's own side is estimated at the level of individual machines rather than through the economics of hardware competition. The node population is approximated from crawlers, peer discovery and publicly advertised endpoints. A representative machine specification is inferred from what the client software states it requires to keep pace with the chain, and the power that specification draws is taken from controlled measurement of comparable hardware, recorded both under load and at rest. The network total is the aggregate across the estimated population, including idle draw, since these machines run continuously. From that total, a fraction is assigned to an individual asset according to observed on-chain activity involving it.

The honest caveats belong with the number. The node count is a floor rather than a census, because machines behind private networks are not visible to a crawler. The hardware profile comes from stated requirements, not from a survey of what operators actually bought. And where evidence is thin, the assumption taken is the one that produces the larger figure rather than the smaller one. Estimates are revised as observation of the network improves.

The figure reported for this network is assembled from the machines that run it rather than inferred from any single aggregate quantity. The starting point is a count of active nodes, put together from network crawlers, publicly reachable cluster and gossip information, and data operators choose to publish. That population is then divided by role, because a validator taking part in voting, a machine that only replays the ledger, and the infrastructure that answers application requests do not draw comparable amounts of power.

Each role is matched to a representative hardware profile derived from the resources the client software is documented to need. Requirements here are heavy by the standards of proof-of-stake systems, running to many processor cores, large memory and fast solid-state storage, and the profiles reflect that rather than assuming commodity equipment. Electrical draw per profile is taken from controlled bench measurement of equivalent devices, capturing both the load imposed by processing and the draw of a machine that is powered up but idle, since a node consumes electricity continuously whether or not it is producing a block. Multiplying profiles by the estimated population across the hours of the reporting period gives consumption for the network as a whole. Where a figure is attributed to one asset issued on the network rather than to the network itself, the share is taken from observed on-chain transfer activity for that asset.

The output is an estimate and should be read as one. The node count rests on what is visible from outside, and operators are under no obligation to be visible; the hardware mix is inferred from stated requirements rather than surveyed; and facility overheads such as cooling and power conversion are approximated rather than metered. Where the evidence does not settle a question, the assumption adopted is the one more likely to overstate consumption than understate it, and figures are restated as observation improves or as protocol changes alter the work a node must perform. The network's own climate reporting is published at Solana Climate Dashboard.

The figure reported for this network is an estimate constructed from the machines that run it, not a metered reading. It begins with the population of participating nodes and works upward from the power each is expected to draw.

Establishing that population takes account of the network's structure. The validator set is elected on-chain for fixed terms and its size and membership can therefore be read directly from publicly observable network data at any point in a round, but validators are only part of the picture. They are partitioned into groups covering the masterchain and each shardchain, and the number of shardchains changes as load causes them to split and merge, so the work carried per machine is not constant across a reporting period. Beyond consensus, the network depends on nodes that keep full or partial history and on the query-serving infrastructure that applications rely on; those are estimated from peer discovery, published operator information and automated crawling, since they are not enumerated on-chain.

The second input is per-machine draw. A representative hardware profile is inferred from the resources the node software states it needs, covering processor, memory, disk and bandwidth, and power consumption is attributed from laboratory measurement of equipment matching that profile. The minimum stake for a seat is substantial and terms are contested, so validator infrastructure is assumed to be server-grade and continuously online; draw is counted on that basis, idle time included, and multiplied across the estimated population.

The limits are worth stating plainly. Both the count and the hardware mix are inferences from public observation and from stated requirements rather than from surveys or meters. The supporting non-consensus infrastructure is the least observable component, and the shifting shard count adds variability that a snapshot does not capture. Where evidence is missing, assumptions are chosen so that the impact is more likely to be overstated than understated, and the estimate is revised as observation of the network improves and as its topology changes.

The estimate combines two sources of consumption. One is the chain's own infrastructure, which has a component most rollups lack: alongside the sequencer, the process that publishes data to Ethereum, and the full and archive nodes that applications and infrastructure providers run, there is a proving fleet. Generating validity proofs is genuine computation on servers with high core counts and accelerator hardware, run continuously as batches arrive, and it is a material line in the total rather than a rounding error. The other source is the share of Ethereum's consumption attributable to the rollup, since every batch commitment and every proof verification consumes capacity that the settlement layer's validators pay to provide; that share is apportioned by how much of Ethereum's resources those postings occupy. Ethereum publishes its own account of how its consumption is estimated (Ethereum energy consumption).

Because nothing is mined, the chain's own side is assessed machine by machine. The node population is approximated from crawlers, peer discovery and published endpoints. Representative hardware is inferred from what the client software states it needs, and for the proving side from what the proving implementation documents as its requirements, which are considerably heavier. Power draw for each profile comes from controlled measurement of equivalent equipment under load and at idle, and the network total aggregates across the estimated population including idle draw. A fraction of that total is then attributed to an individual asset according to observed on-chain activity involving it.

The caveats are the substance of the method, not a disclaimer attached to it. Node counts are floors, since machines on private networks cannot be discovered. Proving capacity is particularly hard to observe from outside, because it is operated privately rather than announced to peers, so its size is inferred from proof cadence and stated hardware requirements. Where evidence is missing, assumptions are chosen that are more likely to overstate consumption than understate it, and figures are revised as observation improves.

Key energy sources and methodologies

Ethena is present on the following networks: Arbitrum, Avalanche, Base, Ethereum, Kava, Optimism, Solana, Toncoin, Zksync.

The renewable share is derived geographically, starting from where the machines that keep the chain running actually sit: the servers hosting the sequencer and the batch poster, the validators that participate in the dispute protocol, and the wider population of full and archive nodes. Their locations are inferred from publicly observable network information — the addresses reachable peers announce, hosting and autonomous-system registries, and public node listings — which yields a country-level distribution rather than a precise address for any individual machine. Much of this infrastructure is hosted with commercial cloud and colocation providers, so the region a provider operates a facility in stands in where a single host cannot be placed more precisely. Where the chain's own distribution is too sparse to observe with confidence, the pattern seen on networks of similar shape — alike in how participants are paid and in the class of hardware they run — fills the gap.

The same exercise is applied to the settlement layer, because the portion of Ethereum's consumption attributed to the rollup carries the geographic profile of Ethereum's validator set rather than that of the rollup's own machines. The two distributions are combined, weighted by how much estimated consumption each accounts for.

Country weights are then matched against published statistics on how much of each country's electricity comes from renewable sources, drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy. The result is a consumption-weighted average across the estimated footprint. It is not a statement about what any operator has contracted for: power purchase agreements, on-site generation and renewable certificates are invisible in network data and are not assumed.

Energy intensity is expressed marginally, as the additional electricity associated with one more transaction on top of the infrastructure already running. Because the cost of operating a node is largely fixed and barely responds to how full a block is, that marginal figure is small and moves inversely with throughput, which is why it should not be read as a per-transaction share of the total.

Establishing a renewable share for Avalanche is first a question of geography, because the same hardware draws very different electricity depending on which grid it sits on. The validator set is enumerated from the platform chain, and the network addresses behind those validators, together with the wider set of nodes seen through peer discovery and public network observation, are resolved to hosting providers, autonomous systems and countries. That yields an approximate map of where node capacity is concentrated. Where the mapping is too incomplete to support a result, the observed distribution of a network with comparable staking economics is used in its place.

The map is then joined to national electricity statistics. Each country's share of generation from renewable sources is taken from Share of electricity generated by renewables, compiled and processed by Our World in Data from Ember's yearly electricity datasets and the Energy Institute's Statistical Review of World Energy. Weighting country-level shares by the estimated node capacity located in each gives one renewable percentage for the network as a whole.

Energy intensity is a marginal measure rather than an average: the additional electricity associated with one further transaction being processed. Because validators run continuously and blocks are produced on a schedule regardless of how full they are, the marginal figure is considerably lower than the annual total divided by transaction count, and the two answer different questions.

Several limits constrain what the renewable percentage can mean. Hosting location reveals a grid but not a contract, so operators procuring renewable electricity on a carbon-heavy grid are not distinguished from those that are not. Cloud regions and proxied connections can place a node's apparent location away from its actual hardware. Annual national averages flatten the hourly and seasonal movement in generation mix. And validator infrastructure is concentrated in a relatively small number of hosting markets, so the result is sensitive to how a handful of large operators are located.

The renewable share reported for this network is a weighted average of the electricity mixes of the grids its infrastructure draws on, assembled in two steps: establish where the machines are, then attach regional generation statistics to those places.

Locating them is easier for some parts of the network than others. The sequencing, batching and commitment services run in identifiable data center regions, and the hosting regions an operator uses are publicly observable. The wider population of replica and archive nodes is inferred as it would be for any peer-to-peer network, from the addresses peers advertise so that others can reach them, collected by crawlers and supplemented by public directories of infrastructure providers. Resolving a single address to a country is unreliable, but in aggregate these resolutions describe a distribution well enough to weight against. Where the observable sample is too thin, the geographic spread of a structurally comparable network is used in its place, chosen because its operators face similar hosting economics rather than because it runs similar software. The same exercise is carried out for the settlement layer, because part of the figure reported here is an attributed share of Ethereum's consumption, and Ethereum's validator population is spread quite differently from a rollup's concentrated operator infrastructure. The two distributions are weighted by their respective contributions to consumption and combined.

Each location is then matched to published statistics on how electricity is generated in that country or region, and the renewable proportion is the consumption-weighted share falling in regions supplied by renewable generation. Grid averages are used throughout, because the actual supply arrangements of individual hosting facilities are not observable; a facility on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.

Energy intensity is a marginal figure rather than an average: the additional electricity attributable to one further transaction on the network as it currently runs. Because most of the infrastructure runs continuously whether or not it is busy, that marginal quantity is much smaller than dividing total consumption by the transaction count would suggest. The generation statistics come from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.

The renewable share reported here is a weighted average of grid mixes rather than a record of what any operator actually buys. It is produced in two steps: establish where the infrastructure sits, then attach regional electricity statistics to those places.

Location is inferred from what the network exposes publicly. Nodes advertise network addresses in order to be reachable by peers, and those addresses resolve to a country accurately enough to describe an aggregate distribution, even though any single resolution may be wrong. Crawlers of the peer-to-peer layer and public directories of hosting and staking infrastructure supply the input. Where the observable sample is too thin or too skewed to stand for the whole population, the geographic spread of a structurally similar network is substituted, chosen because its participants face comparable hardware costs and comparable pressures over where to site machines, on the reasoning that operators respond to the same commercial forces even where the software differs.

Each location is then matched to published statistics on how electricity in that country or region is generated. The renewable proportion for the network is the consumption-weighted share falling in regions where generation is renewable. Grid averages are used because the alternative, knowing each operator's actual supply contract, is not observable; an operator on a dedicated renewable supply and one drawing ordinary grid power in the same country are treated alike.

Energy intensity is reported on a different basis from total consumption. It is a marginal quantity: the additional electricity attributable to processing one further transaction on the network as it currently runs. For a network whose consumption is driven by a validator set that operates continuously regardless of how busy the chain is, that marginal figure is small, and it is not the total divided by the transaction count. The generation statistics are drawn from Share of electricity generated by renewables, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy.

The renewable share is derived geographically. Node locations are inferred from publicly observable network data — the addresses peers advertise, the hosting ranges those addresses fall within, and operator disclosures that are already public — and each located node is assigned to the electricity grid of the region it sits in. Aggregating those assignments produces a weighted picture of which grids the network's infrastructure actually draws on, which is the input the renewable calculation needs.

Coverage is never complete. A meaningful share of nodes sits behind hosting arrangements or privacy configurations that reveal nothing dependable about physical location. The co-chain arrangement does not complicate this, because the same machines serve both execution environments and so are located once. Where a network's own geographic spread cannot be observed to a usable standard, the spread of a structurally similar network is substituted as a stand-in — one chosen for a comparable validator economy, a comparable cost of entry for node operators, and therefore a comparable hosting pattern. That substitution is a source of uncertainty in its own right and is applied only to the portion that cannot be resolved directly.

Grid assignments are then matched against published statistics on how electricity is generated in each region, yielding the proportion of the network's electricity that comes from renewable generation. Those statistics are taken from Share of electricity generated by renewables, compiled by Our World in Data from Ember and from the Energy Institute's Statistical Review of World Energy.

Energy intensity is a separate quantity and should not be read as a per-transaction bill. It is defined at the margin: the additional electricity drawn as a consequence of one further transaction being processed, given the infrastructure already running. On a network of this kind, where validators run continuously and commit blocks on a fixed cadence whether or not demand is present, that marginal quantity is small next to the standing consumption, and it moves inversely with throughput — the busier the network, the lower the intensity attributed to each transaction.

Establishing a renewable share begins with location rather than with energy. The infrastructure in question is the sequencing and batch-publishing servers, the challenger nodes that watch the dispute system, and the wider set of full and archive nodes run by applications, bridges and infrastructure providers. Where those machines sit is inferred from publicly observable network information — announced peer addresses resolved against hosting and autonomous-system registries, and public listings of node operators — which supports a country-level picture rather than a precise location for any one machine. Because much of this runs on rented cloud capacity, the region a provider states for a facility is used in place of a finer-grained address. Where the chain's own sample is too thin to support a distribution, the pattern observed on networks built along similar lines, with comparable participant roles and hardware classes, substitutes for the missing portion.

The settlement layer is handled separately and then combined. The share of Ethereum's consumption attributed to the rollup takes on the geographic profile of Ethereum's validator population, which is distributed differently from the rollup's own servers, so the two distributions are weighted by their respective contributions to estimated consumption before being merged.

Those country weights are applied to published figures for the renewable proportion of each country's electricity generation, taken from Share of electricity generated by renewables, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy. What comes out is a consumption-weighted average across the inferred footprint, reflecting the grids the infrastructure most likely draws on. It does not capture procurement: renewable supply contracts, certificates and behind-the-meter generation cannot be seen in network data and are not credited.

Energy intensity here means a marginal quantity — the extra electricity associated with one further transaction, given the infrastructure already running. Node and sequencer power draw barely varies with how full a block is, so this marginal figure is small and falls as throughput rises. It is not the network total divided by the transaction count, and the two should not be compared.

The renewable share is derived geographically. Node locations are inferred from what the network exposes about itself: addresses observable through crawlers and public cluster information, resolved to a country or region. Coverage is never complete, because operators may sit behind hosting providers or relays that obscure where the hardware physically sits. Where the geographic spread of this network cannot be observed directly, the distribution of a structurally similar network stands in as a proxy, chosen because its validator economics and agreement protocol place comparable demands on operators and therefore tend to attract them to comparable locations.

Each located node is then assigned the generation mix of the grid that serves it. Those regional mixes come from Share of electricity generated by renewables, compiled by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy. Weighting each region's renewable share by the estimated consumption sitting in that region produces a network-wide proportion. The result describes the grids the infrastructure draws from, not contractual purchases: an operator buying renewable certificates is not treated differently from a neighbor on the same grid, because that distinction cannot be observed from outside.

Energy intensity is reported separately and means something narrower than total consumption divided by transaction count. It is the marginal quantity of energy associated with processing one further transaction. That distinction matters for a network of this type, where validators run continuously at close to constant power regardless of how full the blocks are, so the incremental energy attached to an additional transaction is small while the standing consumption of the validator set is not. Both the renewable share and the intensity figure therefore move with two separate things: the composition and location of the node population, and the grid statistics for the years covered, which are themselves restated as national reporting is revised.

The renewable share attributed to this network is derived from where its machines physically sit, not from any claim about the electricity its operators procure. Placement is inferred from publicly observable network data: the addresses nodes announce to their peers, information operators publish about themselves, and the hosting providers and data-center address ranges those addresses belong to, gathered by automated crawling of the peer network.

Two features of this network shape that exercise. The validator set turns over at the end of each election round, so the population being located is not the same from one term to the next and has to be observed repeatedly rather than fixed once. And because validators are grouped across a masterchain and a shifting number of shardchains, the geographic weighting reflects where machines are rather than which chain a given machine happened to serve. Coverage is still incomplete, since some operators sit behind relays or cloud infrastructure that conceals the underlying site. Where the observed spread is too thin to rely on, the distribution of a structurally similar network is substituted, chosen because its participants face comparable incentives and carry comparable duties and can be expected to cluster in broadly the same regions.

Each located machine is then matched to the grid that serves it, and the renewable proportion of that grid's generation is applied, weighted by the share of estimated consumption in each region. The outcome is a consumption-weighted renewable share for the network, which changes when operators move and when national generation mixes change from year to year.

Energy intensity is reported alongside it with a narrow meaning: the marginal energy associated with one further transaction. Because almost all of the consumption is the fixed cost of keeping elected validators online, rather than anything that scales with throughput, this marginal figure falls as activity rises and should not be read as an average cost per transaction. Grid statistics come from Share of electricity generated by renewables, compiled by Our World in Data with major processing from Ember and from the Energy Institute's Statistical Review of World Energy.

Working out a renewable share is a question of geography before it is a question of energy. The relevant infrastructure is the sequencing and data-publishing servers, the proving fleet, and the full and archive nodes operated by applications, bridges and infrastructure providers. Locations are inferred from what the network exposes publicly — peer addresses resolved against hosting and autonomous-system registries, and published operator endpoints — giving a country-level distribution rather than a fixed address for any one machine. Since much of this capacity is rented from cloud and colocation providers, the region a provider assigns to a facility stands in where nothing finer is available. The proving fleet is the hardest part to place, because it is run privately and does not announce itself to peers; where it cannot be located directly, the distribution of comparable computation-heavy infrastructure is used in its place. The same substitution applies more generally: where the chain's own sample is too thin, the pattern seen on networks of similar design fills the gap.

The settlement layer is treated on its own terms. The portion of Ethereum's consumption attributed to the rollup follows the geography of Ethereum's validator population, not of the rollup's servers, so the two distributions are weighted by their shares of estimated consumption and then combined.

Those country weights are applied to published figures for the renewable proportion of national electricity generation, taken from Share of electricity generated by renewables, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy. The output is a consumption-weighted average across the inferred footprint. Procurement is outside what this can see: renewable supply contracts, certificates and on-site generation leave no trace in network data and are not credited.

Energy intensity is a marginal measure — the additional electricity associated with one further transaction on top of infrastructure that is already running. Sequencing and node power draw barely move with block occupancy, and proving cost is amortized across a batch, so the marginal figure is small and declines as batches fill.

Key GHG sources and methodologies

Ethena is present on the following networks: Arbitrum, Avalanche, Base, Ethereum, Kava, Optimism, Solana, Toncoin, Zksync.

Emissions are derived from the energy estimate rather than measured at the source. The geographic distribution built for the renewable calculation — sequencer and batch-posting infrastructure, dispute-protocol validators, full nodes, and the share of Ethereum's validator set attributed to settlement — is reused, and each country's slice of estimated electricity is multiplied by the average carbon intensity of that country's grid. Grid figures are drawn from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy and made available under a Creative Commons BY 4.0 license. Regional totals are summed to give a network figure, and a fraction of that figure is attributed to an individual asset in proportion to observed on-chain activity.

The two scopes are treated separately. Scope 1 covers combustion that the operators themselves control — on-site generators, fuel burned directly on their premises. For a chain whose infrastructure sits in commercial data centers this is ordinarily zero or negligible, and it is reported as such unless direct fuel use is known. Scope 2 is the substantive figure: the emissions embodied in the grid electricity that infrastructure draws. It is computed on a location basis, using the average intensity of the grid a machine draws from, rather than on a market basis reflecting supply contracts or certificates, because supplier-level information cannot be observed from the network. Emissions embodied in manufacturing the hardware or building the facilities that house it fall outside this boundary.

Greenhouse gas intensity is stated marginally, as the additional emissions associated with one more transaction. Two limits are worth stating plainly. Grid intensity statistics are annual national averages, so they miss the hourly and sub-national variation any specific facility experiences, and a data center on a dedicated low-carbon supply will be represented by its country's average. And the figure inherits every uncertainty in the energy and location estimates beneath it; where those rest on assumption, the assumption chosen is the one more likely to overstate the result.

The emissions estimate for Avalanche reuses the geographic work behind the renewable share and substitutes carbon factors for renewable percentages. The validator set enumerated from the platform chain, together with the nodes observed through peer discovery and public network data, is resolved to countries; where that resolution is too sparse, the distribution of a network with comparable staking economics stands in. Each country is then paired with the carbon intensity of its electricity, taken from Carbon intensity of electricity generation, processed by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy and published under a CC BY 4.0 license. The estimated electricity in each region, multiplied by that region's grams of carbon dioxide equivalent per kilowatt-hour and summed across regions, gives the annual emissions figure.

Reporting separates two scopes. Scope 1 covers emissions from sources the operators control directly, such as fuel burned on site for power or heat; for a population of servers hosted in rented facility space this is generally negligible and is reported accordingly. Scope 2 covers the indirect emissions embodied in the electricity those machines buy from their grids, which is where effectively the entire footprint of a staked network falls. Hardware manufacture and end-of-life disposal lie outside the boundary of this accounting.

Greenhouse-gas intensity follows the same marginal logic used for energy: the incremental emissions associated with one more transaction, not the annual total divided by throughput.

Uncertainty accumulates across the two steps. Whatever error exists in the electricity estimate passes straight through into emissions, and the geographic step adds its own, since national grid intensities span more than an order of magnitude and shifting a large operator from one country to another visibly moves the answer. Annual averages also conceal the hourly variation in grid intensity that continuously running machines are exposed to in full.

Emissions are not measured directly. They are derived by attaching a carbon intensity to each unit of electricity the network is estimated to consume, across both parts of its footprint: the machines the network operates itself, and the share of the settlement layer's consumption attributed to the data and commitments it posts there.

The geographic step repeats the one used for the renewable share. The hosting regions of the sequencing and batching infrastructure are publicly observable; the wider set of replica and archive nodes is located from the addresses peers advertise, collected by crawlers and public directories. Where observation is too sparse to characterize the population, the spread of a structurally comparable network is used in its place. The settlement layer's validator population is located separately, because it is distributed quite differently, and the two are weighted by how much consumption each accounts for. Each region is then assigned a carbon intensity, the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the total.

Two scopes are distinguished. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For infrastructure that consists of ordinary servers in commercial data centers drawing from public grids, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the purchased electricity, and is where essentially the whole footprint sits. Emissions from manufacturing and transporting the hardware fall outside this boundary.

Greenhouse gas intensity follows the marginal logic used for energy intensity: the additional emissions attributable to one further transaction, not an average spread across all of them. It inherits the uncertainty of both the consumption estimate and the grid averages. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.

Emissions are derived from the consumption estimate rather than measured, by attaching a carbon intensity to each unit of electricity the network is estimated to draw and summing across the network.

The geographic step repeats the one used for the renewable share. Node locations are inferred from publicly observable network data, principally the addresses peers advertise so that others can connect to them, gathered by crawlers and supplemented by public information about where staking and hosting infrastructure is operated. Where that observation is too sparse to characterize the whole population, the distribution of a comparable network stands in for it, selected because its participants face similar operating economics rather than because its software resembles this one. Each region is assigned a carbon intensity, meaning the average greenhouse gas released per unit of electricity generated on that grid, expressed in carbon dioxide equivalent so that methane and the other gases are counted on a common basis. Estimated consumption in a region multiplied by that region's intensity, summed across regions, gives the network total.

The reporting separates two scopes. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site in a generator. For a network of this kind, whose participants overwhelmingly run ordinary servers connected to a public grid, there is generally nothing in that category, and it is reported as such rather than left out. Scope 2 covers the indirect emissions embodied in the electricity purchased to run that infrastructure, and that is where essentially the whole footprint sits. Emissions further up the supply chain, such as those from manufacturing and shipping the hardware, fall outside this boundary.

Greenhouse gas intensity follows the same marginal logic as energy intensity: it expresses the additional emissions attributable to one further transaction rather than an average spread across all of them. Because it inherits both the consumption estimate and the grid averages, its uncertainty combines theirs. Carbon intensities are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's electricity datasets and the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.

Emissions are derived from the same geographic work that supports the energy figures, applied against a different coefficient. Once the node population has been located and assigned to regional grids, each assignment is matched to the carbon intensity of electricity generation in that region — the mass of carbon dioxide equivalent released per unit of electricity delivered — and the network's estimated consumption is apportioned across those regions and converted. Regional variation is wide enough that two networks consuming identical amounts of electricity can differ substantially in emissions, which is why locating the infrastructure carries as much weight in the result as sizing its draw.

The two scopes are treated differently. Scope 1 covers emissions from sources the operators control directly, such as fuel burned on site for backup generation, and for a network of this design it is negligible or zero, since validators run commodity servers on purchased electricity rather than any combustion process of their own. Scope 2 covers the indirect emissions embodied in that purchased electricity and accounts for effectively the whole of the result. Where a node's location cannot be established with confidence, the regional profile of a structurally comparable network stands in for it, and that substitution carries into the emissions result exactly as it does into the energy one.

Carbon intensity coefficients are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy and published under the Creative Commons Attribution 4.0 license.

Greenhouse gas intensity mirrors the definition used for energy intensity: the additional emissions attributable to one further transaction beyond those already being processed, rather than total emissions divided by a transaction count. Because the infrastructure runs continuously regardless of load, that marginal quantity is modest and falls as utilization rises. Results are restated when regional grid statistics are updated or when better observation of the node population becomes available, and the direction of any assumption made under uncertainty favors the higher estimate.

The emissions figures are computed from the energy estimate, not observed directly. The geographic breakdown assembled for the renewable share — sequencing and batch-publishing servers, challenger and full nodes, and the slice of Ethereum's validator population attributed to settlement — is carried over, and each country's portion of estimated electricity is multiplied by that country's average grid carbon intensity. The intensity figures come from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy and released under a Creative Commons BY 4.0 license. Country results are summed into a network total, from which a share is attributed to an individual asset in line with observed on-chain activity.

Scope 1 and scope 2 describe different things and are reported separately. Scope 1 is direct combustion under the operators' own control — fuel burned on site, standby generation. For infrastructure hosted in commercial data centers there is normally nothing material to report here, and it is stated as zero or negligible rather than estimated upward. Scope 2 carries the weight: it is the indirect emissions embodied in purchased electricity. The calculation is location-based, applying the average intensity of the grid serving each region, because a market-based calculation would need supplier contracts and certificates that are not observable from outside. Embodied emissions from manufacturing servers or constructing the facilities they occupy are not in scope.

Greenhouse gas intensity is reported as the marginal emissions of one additional transaction, consistent with how energy intensity is treated. The main uncertainties should be read alongside the number. National annual averages smooth away the hourly swings and regional differences a real facility experiences. Every assumption in the underlying energy and location estimates propagates through to the emissions figure. And where a choice between plausible assumptions has to be made, the one producing the higher result is preferred, so these figures are better understood as a conservative ceiling than as a precise measurement.

Emissions are derived from the same geographic picture used for energy sources, applied to a different set of grid statistics. Node locations are inferred from addresses observable through crawlers and public cluster information and resolved to a region; where direct observation falls short, the geographic distribution of a structurally comparable network is substituted, selected on the basis that its incentive design and agreement protocol impose similar operating demands.

Each region is then paired with a carbon intensity for its electricity, taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember's yearly electricity data and the Energy Institute's Statistical Review of World Energy and made available under the CC BY 4.0 licence. Multiplying the electricity estimated to be consumed in a region by that region's carbon intensity, and summing across regions, gives the emissions attributable to running the network.

The disclosure separates two scopes. Scope 1 covers emissions from sources the operators of the infrastructure control directly, such as fuel burned on site; for a network of this kind, whose nodes are ordinary servers in rented facilities, this is normally nil or immaterial, and a zero figure reflects the absence of such sources rather than an omission. Scope 2 covers the indirect emissions embodied in the electricity those machines purchase, and is where essentially the whole footprint of this network falls.

Greenhouse gas intensity follows the same marginal logic as its energy counterpart: it expresses the emissions associated with one additional transaction rather than an average obtained by dividing an annual total by throughput. Because validators consume electricity at a fairly steady rate whether or not blocks are full, the marginal figure is small and is not a proxy for the footprint of the network as a whole. Both the absolute emissions and the intensity figure are sensitive to the grid statistics underlying them, which are revised as national energy reporting is updated.

Emissions are derived by combining the network's estimated electricity use with the carbon content of the grids that supply it. The energy total is first apportioned geographically, using the same picture built for the energy analysis: node addresses observed on the peer network, operator information published openly, and the hosting ranges those addresses resolve to. Because the validator set is re-elected at the end of each round, that apportionment is rebuilt over the reporting period rather than taken from a single observation. Where placement cannot be resolved, the distribution of a structurally comparable network is used instead, selected for similar incentives and similar validation duties rather than for similar size.

Each portion of consumption is then multiplied by the carbon intensity of the grid serving its region, expressed as emissions per unit of electricity generated, and the parts are summed. The result therefore depends as much on where operators host as on how much electricity the network draws, and it shifts year to year as national generation mixes change and as the elected set turns over.

Two scopes are reported separately. Scope 1 covers emissions from sources the operators control directly, such as fuel burned on site; for infrastructure of this kind it is effectively nil, because the machines are commodity servers drawing grid power in facilities run by third parties. Scope 2 covers the indirect emissions embodied in the electricity purchased to run that infrastructure, and it accounts for essentially the entire footprint. Emissions from manufacturing the hardware and from building and cooling the facilities housing it fall outside both scopes and are not included.

GHG intensity is the marginal quantity: the emissions attributable to one additional transaction. As with energy, most of the total is a fixed cost incurred whether or not the network is busy, so intensity declines as usage rises and is not an average. Carbon intensity values come from Carbon intensity of electricity generation, compiled by Our World in Data with major processing from Ember and from the Energy Institute's Statistical Review of World Energy, and made available under the CC BY 4.0 license.

Emissions are derived from the energy estimate rather than measured. The geographic breakdown used for the renewable share — sequencing and data-publishing servers, the proving fleet, full nodes, and the portion of Ethereum's validator population attributed to settlement — is reused, and each country's share of estimated electricity is multiplied by the average carbon intensity of that country's grid. Those intensity figures are taken from Carbon intensity of electricity generation, compiled by Our World in Data from Ember and the Energy Institute's Statistical Review of World Energy and published under a Creative Commons BY 4.0 license. Country-level results are summed into a network total, and a fraction of that total is attributed to an individual asset in proportion to observed on-chain activity.

The scopes are separated deliberately. Scope 1 covers emissions from sources the operators directly control, meaning fuel burned on their own premises. Infrastructure hosted in commercial data centers normally has nothing material here, and it is reported as zero or negligible rather than inflated by guesswork. Scope 2 is where the figure sits: the indirect emissions embodied in the electricity purchased to run sequencing, proving and node hardware. It is calculated on a location basis, applying the average intensity of the grid serving each region, since a market-based figure would require supply contracts and certificates that are not observable from network data. Emissions embodied in manufacturing the hardware — which for accelerator-heavy proving equipment is not trivial — and in constructing the facilities that host it fall outside this boundary and are not included.

Greenhouse gas intensity is expressed as the marginal emissions of one more transaction, mirroring the treatment of energy intensity. Three limits should be read with the figure: national annual averages conceal hourly and regional variation in real grids; every uncertainty in the energy and location estimates carries through; and where assumptions must be chosen, the more conservative one is taken, so the result is better understood as an upper bound than as a precise quantity.