You're twelve minutes into reading about Ethereum finality and you keep hitting the same number: two-thirds. It's in every explainer, usually without ceremony, as if the threshold arrived fully formed from the sky.

It didn't. Casper the Friendly Finality Gadget (Casper FFG) requires attestations from validators holding at least two-thirds of total staked ETH before a checkpoint can be justified, and then a second two-thirds supermajority before it can be finalized. Not a simple majority. Not three-quarters. Two-thirds, specifically, because a 40-year-old theorem from distributed systems theory left no room for negotiation.

The checkpoint boundary and what crossing it actually means

Ethereum's beacon chain divides time into epochs of 32 slots, each slot 12 seconds long. At the boundary of every epoch sits a checkpoint: a specific block that validators vote on as the canonical head of that epoch. Validators don't vote on every block. They vote on these epoch boundaries, attesting that a source checkpoint (the last justified one) should lead to a target checkpoint (the current one).

When more than two-thirds of total active stake attests to the same source-to-target link, that target checkpoint becomes justified. When the next checkpoint is then also justified using the just-justified one as its source, the earlier checkpoint becomes finalized. Finality means it cannot be reverted without an attacker burning at least one-third of all staked ETH, a condition called a slashing event.

Work through the numbers. Say the active validator set controls 32 million ETH in aggregate. Checkpoint A is the justified source. For Checkpoint B to become justified, validators whose combined stake exceeds 21.33 million ETH must cast matching attestations pointing from A to B. If only 60% of stake attests, B stays unjustified. The chain keeps growing on top of B, but nothing behind it is yet safe.

Two epochs later, suppose attestations finally cross two-thirds. B gets justified, and if C (the next checkpoint) also clears two-thirds pointing back to B, then B finalizes. Under normal conditions that whole window, justification through finalization, runs about 12.8 minutes. Slow by payment-processor standards. Irreversible in a way that payment processors can only dream about.

Why two-thirds and not some other number

This is where Byzantine Fault Tolerance enters. The classical result, proved by Lamport, Shostak, and Pease in 1982, says a distributed system can tolerate up to one-third of its participants behaving arbitrarily (lying, going offline, equivocating) as long as the honest majority holds at two-thirds plus one. Casper FFG is essentially that theorem applied to money.

The 51% alternative fails badly. Two separate groups could each hit 51% by overlapping on the same validators, producing two conflicting checkpoints that both appear justified. Two finalized histories. The two-thirds rule makes this impossible: two sets of validators cannot each represent two-thirds of stake without sharing more than one-third in common, and that overlapping third would have to double-vote, exposing themselves to slashing.

The threshold isn't arbitrary. It is the minimum fraction that makes conflicting finality mathematically impossible, assuming fewer than one-third of validators are malicious or faulty. That's not a design preference. It's a proof.

Consider two validators, Priya and Marco, who staked at the same time on identical hardware. Priya's node stays online, attests correctly every epoch, and her stake contributes cleanly to checkpoint justification. Marco's ISP goes down for three consecutive epochs. His missing attestations don't break the network because the remaining validators still clear two-thirds, but Marco earns inactivity penalties, a slow bleed on his principal. Now scale that up: if enough validators vanished simultaneously and participation dropped below two-thirds, Ethereum's inactivity leak would gradually drain the offline validators' stakes until the active remainder once again represented a two-thirds supermajority. The mechanism is self-healing, and that is not an accident.

So what do people consistently get wrong about this? The assumption that two-thirds of validators by count is the rule. It isn't. The rule is two-thirds of effective stake by ETH weight. A solo validator with 32 ETH and a large staking pool running the equivalent of 10,000 validators are not equal voices. The vote is economic, not democratic. Think of it less like a town hall and more like a shareholder resolution, where one institutional block can outweigh a thousand retail holders in the same room.

That distinction matters more than the math does, honestly. A small number of large staking entities can, in principle, represent a disproportionate share of the supermajority. The theoretical safety guarantee is airtight. Whether it survives the practical reality of how staking has consolidated is a separate question entirely, and anyone who waves it away with "the cryptoeconomics are sound" is answering a question nobody asked.

The two-thirds figure is correct, clean, and well-founded. The more useful thing to understand is who, concretely, holds that stake right now.