CoinYQ Dossier

A fork forced Stellar to replace consensus—and divide trust among validators, anchors and issuers

Stellar began with a 100-billion-unit payment ledger and a nonprofit distribution promise, then replaced its Ripple-derived consensus after an early fork. SCP, anchors and Soroban now share one network but not one authority: validators choose trust and upgrades, issuers control issued assets, and XLM balances do not select validators or exercise those separate controls.

A nonprofit starts with a distribution promise

In July 2014 Jed McCaleb and Joyce Kim introduced Stellar through a nonprofit foundation. David Mazières led the consensus work, Stripe supplied initial funding, and the ledger began with 100 billion units: 95% for distribution and 5% for operations.

That allocation made SDF a central distributor even though it was not a mining operator. XLM entered circulation through foundation programs and users, not block rewards.

A fork makes replacement urgent

Mazières had already been testing the inherited Ripple-style algorithm and working toward a provably safe replacement. The early network then split: nodes disagreed, the chain switched, and hours of transactions were rolled back or replayed.

The incident did not invent SCP. It turned an existing research problem into an operational deadline. In 2015 Stellar moved to Mazières's federated Byzantine agreement design instead of preserving the old engine.

SCP lets every validator draw its own map of trust

SCP has no miner race and no XLM-weighted election. Each validator sets a quorum threshold and names organizations it trusts; agreement depends on the resulting quorum slices overlapping.

Open node entry therefore does not mean equal influence. SDF's later analysis found many configurations converging on the same tier-one organizations, so an open network can still share a narrow liveness dependency.

Anchors connect the ledger to money—and restore institutional risk

An anchor accepts deposits through banks or cash points, issues or honors a Stellar asset, and handles redemption at the edge. This makes a ledger balance useful in a local economy but places custody, licensing and compliance outside SCP.

Issued assets also carry their own control settings. An issuer may require authorization, revoke it to freeze a trustline, or enable clawback. Native XLM has no issuer or trustline, so it is a different legal and technical object from a dollar token issued on Stellar.

A 67-minute halt reveals the liveness bargain

On May 15, 2019, maintenance and failures among trusted validators left the configured quorum unable to agree. The public network produced no ledgers for 67 minutes.

SCP preserved safety by stopping instead of finalizing rival histories. Recovery also revealed the practical weight of a small group of trusted operators and the quorum files that other nodes had chosen.

Inflation and the burn pass through different powers

The original protocol created 1% more XLM each year and let accounts nominate destinations. By 2019 SDF argued that pools captured most of the mechanism. Validators adopted Protocol 12 on October 28 and disabled the operation.

SDF then used control over its own allocation in a separate November action, destroying 55.5 billion XLM. About 50 billion remained in existence and just under 30 billion was still administered by SDF at that time. A validator vote changed issuance; a foundation treasury decision removed foundation balances.

Soroban arrives after validators pause and reconsider

Before the planned January 2024 Protocol 20 vote, SDF found a bug, disarmed its own validators and supported a postponement. That was substantial influence, but it was not an XLM-holder vote or a unilateral protocol switch.

Validators later adopted Protocol 20 on February 20. The phased rollout reached full smart-contract functionality on March 19, adding Rust/Wasm programs, resource metering and state archival to a ledger previously centered on classic payments.

XLM utility stops short of institutional control

XLM pays network fees, rent and minimum reserves and can bridge trades. Because it has no issuer, a third-party asset issuer cannot freeze native XLM with trustline flags.

An XLM balance does not select validators, force an anchor to redeem, or override an issued asset’s controls. Those powers sit with different actors, and the ledger does not collapse them into token ownership.

How the project changed

  1. 2014-07
    Stellar is introduced

    The nonprofit network begins with 100 billion units and a broad distribution plan.

  2. 2014-12
    The old network forks

    The incident makes migration to the already-developing SCP urgent.

  3. 2015-09
    SCP replaces the first design

    The public network moves to federated Byzantine agreement.

  4. 2019-05-15
    The network halts for 67 minutes

    Quorum fails; ledger production stops without a fork.

  5. 2019-10-28
    Protocol 12 ends inflation

    Validators disable the annual 1% operation.

  6. 2019-11
    SDF burns 55.5 billion XLM

    A separate treasury action leaves roughly 50 billion existing.

  7. 2024-02-20
    Protocol 20 reaches mainnet

    Validators begin the phased Soroban rollout.

  8. 2024-03-19
    Soroban becomes fully functional

    The final phase opens general smart-contract use.

Evidence and primary sources

Last evidence review: 2026-09-05

What is Stellar?

Stellar is a public ledger for moving value between accounts and currencies. Jed McCaleb and Joyce Kim launched it in 2014 through the nonprofit Stellar Development Foundation (SDF); David Mazières was already developing its replacement consensus when the first network's fork made the work urgent. SCP lets every validator name the organizations it trusts.

XLM is the native asset. It pays fees, rent and account reserves and needs neither an issuer nor a trustline. Other assets are promises issued by identifiable accounts or contracts. Anchors connect them to bank and cash rails, while Soroban adds Rust/Wasm smart contracts. One chain therefore contains separate trust questions about validators, issuers, offchain ramps and application code.

What problem does Stellar solve?

Cross-border money often stops at institutional boundaries: one provider holds the sender's currency, another serves the recipient, and they lack a common settlement book. Stellar proposed a neutral ledger where an anchor issues a digital representation, a path converts it, and an anchor at the other edge redeems it.

Fast ledger settlement does not remove those edge institutions. Anchors still decide onboarding, compliance and redemption; liquidity still sets the conversion price. Stellar's early fork supplies the other warning. When a Ripple-derived design rolled back and replayed hours of transactions, the project replaced its consensus engine instead of treating speed as proof of finality.

How does Stellar work?

Stellar Core validators check transactions and use SCP nomination and ballot phases to agree on a ledger. There is no mining or XLM-weighted staking vote. Each node configures a quorum set; overlapping quorum slices protect safety, while unavailable trusted nodes or poor configuration can stop production. That boundary appeared in the 67-minute halt of May 2019, which ended without a fork.

An issued asset normally needs a trustline. Depending on issuer flags, the issuer may require authorization, revoke it to freeze a balance, or claw a balance back. Anchors receive and return offchain money and issue or honor the token, so their promises sit outside SCP. Native XLM has no issuer key.

Protocol changes arrive through Core releases and validator votes. Protocol 12 ended 1% inflation on 2019-10-28. SDF separately burned 55.5 billion XLM the next month, leaving roughly 50 billion and retaining administration of just under 30 billion then. Validators phased in Soroban with Protocol 20 in 2024 after an earlier bug-driven postponement.

Key facts

  • McCaleb and Kim co-founded Stellar in 2014; Mazières designed SCP and Stripe supplied initial funding.
  • The nonprofit began with 100 billion units, a 95% distribution plan and 5% operating allocation.
  • A fork in the Ripple-derived network accelerated the already-underway move to SCP and the 2015 migration.
  • Validators choose quorum sets; XLM neither elects them nor weights their votes.
  • Open node entry coexists with practical dependence on a small tier-one group.
  • The network halted for 67 minutes on 2019-05-15 without finalizing a fork.
  • Protocol 12 ended annual 1% inflation on 2019-10-28.
  • SDF's 55.5B burn was separate from the validator decision that ended inflation.
  • Anchors are offchain businesses; issued assets can carry authorization, freeze and clawback powers.
  • XLM alone has no issuer or trustline and pays fees, rent and reserves.
  • Protocol 20 brought Soroban in phases from 2024-02-20; full functionality followed on 2024-03-19.
  • XLM balances do not select validators and cannot exercise the separate controls held by anchors or issued-asset issuers.

Official links

Categories

Related coins

Frequently asked questions

Who created Stellar?

Jed McCaleb and Joyce Kim launched it through SDF in 2014. David Mazières was already developing a provably safe replacement consensus; the fork made migration urgent.

Is Stellar proof of stake?

No. SCP uses validator-selected quorum sets. XLM balances do not elect validators or weight upgrade votes.

Why was consensus replaced?

The early network forked and rolled back or replayed transactions. Mazières was already developing the replacement; the incident made the 2015 move to SCP urgent.

Can Stellar stop?

Yes. SCP favors safety when quorum fails. The public network halted for 67 minutes in May 2019 and resumed without two finalized histories.

Did the 2019 burn end inflation?

No. Validators ended inflation with Protocol 12 in October. SDF burned 55.5 billion XLM in November through a separate treasury action.

Can an issuer freeze a Stellar asset?

If its flags allow, an issuer can require authorization, revoke a trustline to freeze it, or claw balances back. Those powers do not apply to native XLM.

What is an anchor?

A financial institution or fintech connecting Stellar assets to bank or cash rails. Its custody, compliance and redemption duties are institutional promises outside consensus.

Does XLM ownership govern Stellar?

No. XLM pays network costs and moves value, but balances do not select validators, force an anchor to redeem, or override an issued asset’s controls.

External trackers

Choose a tracking site for Stellar: