Overview
Proof of personhood (PoP) is a means of resisting malicious attacks on peer-to-peer networks, particularly attacks that use multiple fake identities, otherwise known as a Sybil attack. Decentralized online platforms are particularly vulnerable to such attacks by their very nature, as notionally democratic and responsive to large voting blocks. In PoP, each unique human participant obtains one equal unit of voting power, and any associated rewards.
The term is used in Cryptocurrency and Blockchains as a parallel to proof of work, proof of stake, and other consensus mechanisms which attempt to distribute voting power and rewards to participants proportionately to an investment of resources.
1 source for this section
Background
The problem of Sybil attacks using many virtual identities has been recognized for decades as a fundamental challenge for distributed systems that expect each human user to have only one account or identity. CAPTCHAs attempt to rate-limit automated Sybil attacks by using automated Turing tests to distinguish humans from machines creating accounts or requesting services.
Even when successful in this goal, however, CAPTCHAs allow one human to obtain multiple accounts or shares of a resource simply by solving multiple CAPTCHAs in succession, and thus do not satisfy the one-per-person goal in PoP. Aside from CAPTCHAs allowing people to obtain multiple users, there are additional complications. Many users who are visually impaired or have learning disabilities may struggle to complete the puzzles. Additionally, some recently developed AI has succeeded in solving the CAPTCHA issue.
Distributed systems could require users to authenticate using strong identities verified by a government or trusted third party, using an identity verification service or self-sovereign identity system for example, but strong identification requirements conflict with privacy and anonymity, and increase barriers to entry. One approach proposed to create anonymous but one-per-person credentials for use in distributed systems is pseudonym parties, in which participants gather periodically at in-person events and leverage the fact that humans can physically be in only one place at a time.
In 2014, Vitalik Buterin proposed the problem of creating a "unique identity system" for cryptocurrencies, which would give each human user one and only one anti-Sybil participation token.^([non-primary source needed]) In 2017, the term "proof of personhood" was proposed for an approach based on pseudonym parties.
7 sources for this section
- 1Proof of personhood — Wikipedia, revision 1375991898
- 2Douceur, John R (2002). "The Sybil Attack". Peer-to-Peer Systems. Lecture Notes in Computer Science. Vol. 2429. pp. 251–60. doi:10.1007/3-540-45748-8_24. ISBN 978-3-540-44179-3.
- 3"What is CAPTCHA? | IBM". www.ibm.com. Archived from the original on 2023-07-12. Retrieved 2023-07-12.
Approaches
A variety of approaches to implementing proof of personhood have been proposed, some in experimental deployment.
In-person events
The approach originally proposed by Borge et al. was to use in-person pseudonym parties as a basis to create anonymous one-per-person tokens periodically without requiring any form of identity verification. The encointer project adapts this approach by asking participants to meet in small groups simultaneously at randomly-chosen places, to verify each other's physical presence.
One drawback of this approach is the inconvenience to participants of going to designated physical locations at specific times, especially for participants with conflicting responsibilities at those times. Another issue is the challenge of organizing federated pseudonym parties in multiple locations simultaneously while allowing each group to verify that all other groups are organized honestly without inflating the number of digital credentials they issue.
4 sources for this section
- 1Proof of personhood — Wikipedia, revision 1375991898
- 5Ford, Bryan; Strauss, Jacob (1 April 2008). An Offline Foundation for Online Accountable Pseudonyms. 1st Workshop on Social Network Systems - SocialNets '08. pp. 31–6. doi:10.1145/1435497.1435503. ISBN 978-1-60558-124-8. Archived from the original on 30 October 2020. Retrieved 28 October 2020.
- 7Maria Borge; Eleftherios Kokoris-Kogias; Philipp Jovanovic; Linus Gasser; Nicolas Gailly; Bryan Ford (29 April 2017). Proof-of-Personhood: Redemocratizing Permissionless Cryptocurrencies. IEEE Security & Privacy on the Blockchain (IEEE S&B). doi:10.1109/EuroSPW.2017.46.
- 9Brenzikofer, Alain (14 January 2020). "encointer - An Ecological, Egalitarian and Private Cryptocurrency and Self-Sovereign Identity System" (PDF). GitHub. Archived (PDF) from the original on 4 October 2021. Retrieved 28 October 2020.
Social networks
Another approach, related to the PGP Web of Trust, relies on users forming a social network to verify and attest to each other's identities. UniqueID incorporates biometric verification into the social network approach.
One criticism of the social network approach is that there is no straightforward way for a participant to verify that a social connection has not created other Sybil identities connected to and verified by other, disjoint sets of social contacts. A related challenge is that Sybil detection based on graph analysis make certain assumptions about the behavior of a Sybil attacker, and it is not clear that real-world social networks satisfy these assumptions.
Finally, graph-based Sybil detection algorithms tend to be able to detect only large, densely-clustered groups of Sybil nodes in a social network, leaving small-scale attacks difficult or impossible to distinguish by graph structure alone from legitimate users' connectivity structures.
4 sources for this section
- 1Proof of personhood — Wikipedia, revision 1375991898
- 10Gal Shahaf; Ehud Shapiro; Nimrod Talmon (October 2020). Genuine Personal Identifiers and Mutual Sureties for Sybil-Resilient Community Growth. International Conference on Social Informatics. arXiv:1904.09630. doi:10.1007/978-3-030-60975-7_24. Archived from the original on 2023-02-16. Retrieved 2020-10-28.
- 11Mohammad-Javad Hajialikhani; Mohammad-Mahdi Jahanara (20 June 2018). "UniqueID: Decentralized Proof-of-Unique-Human". arXiv:1806.07583 [cs.CR].
- 12Bimal Viswanath; Ansley Post; Krishna Phani Gummadi; Alan E Mislove (August 2010). "An analysis of social network-based Sybil defenses". ACM SIGCOMM Computer Communication Review. 40 (4): 363–374. doi:10.1145/1851275.1851226. Archived from the original on 2020-10-31. Retrieved 2020-10-28.
The source notesEvidence & further reading12 sources
- Proof of personhood — Wikipedia, revision 1375991898 Wikipedia contributors · Reference source · accessed 2026-09-22
- Douceur, John R (2002). "The Sybil Attack". Peer-to-Peer Systems. Lecture Notes in Computer Science. Vol. 2429. pp. 251–60. doi:10.1007/3-540-45748-8_24. ISBN 978-3-540-44179-3. archive.org · Reference source · link imported 2026-09-22
- "What is CAPTCHA? | IBM". www.ibm.com. Archived from the original on 2023-07-12. Retrieved 2023-07-12. ibm.com · Reference source · link imported 2026-09-22
- Rodríguez, C. (2023). "Digital Identity Systems and Human Rights: A Legal Framework for Trust and Security". Legal Studies in the Digital Age. Retrieved March 12, 2026. jlsda.com · Reference source · link imported 2026-09-22
- Ford, Bryan; Strauss, Jacob (1 April 2008). An Offline Foundation for Online Accountable Pseudonyms. 1st Workshop on Social Network Systems - SocialNets '08. pp. 31–6. doi:10.1145/1435497.1435503. ISBN 978-1-60558-124-8. Archived from the original on 30 October 2020. Retrieved 28 October 2020. dl.acm.org · Reference source · link imported 2026-09-22
- Buterin, Vitalik (25 Aug 2014). "Problems". GitHub. Archived from the original on 23 November 2020. Retrieved 28 October 2020. github.com · Reference source · link imported 2026-09-22
- Maria Borge; Eleftherios Kokoris-Kogias; Philipp Jovanovic; Linus Gasser; Nicolas Gailly; Bryan Ford (29 April 2017). Proof-of-Personhood: Redemocratizing Permissionless Cryptocurrencies. IEEE Security & Privacy on the Blockchain (IEEE S&B). doi:10.1109/EuroSPW.2017.46.