At USENIX Safety on Aug. 12, researchers offered a Solana Proof-of-Historical past clock assault they’d disclosed privately to Solana builders in December 2025. Anza’s 50,000 SOL Alpenglow competitors closed seven days later, and its guidelines seem to position the assault outdoors the scope.
The paper describes a protocol-valid approach for a scheduled chief to stretch its efficient block window and suppress sincere leaders’ proposals in a fork-assisted model. The trail depends on Proof-of-Historical past and TowerBFT, the equipment Alpenglow is meant to exchange however had not but displaced on mainnet in Agave 4.2.
The discovering creates each a contest-scope story and a transition-risk query.
The competitors guidelines excluded habits reachable solely when Alpenglow was inactive. Public design paperwork point out that the paper’s actual legacy path ought to grow to be unreachable after activation, however Anza and the Solana Basis haven’t revealed a paper-specific adjudication or implementation evaluation.
How a frontrunner can stretch Solana’s clock
Proof-of-Historical past (PoH) makes use of a sequential hash chain to offer Solana a logical clock. Validators proceed advancing their native view of that clock when a scheduled chief doesn’t instantly publish a block.
The researchers say a malicious scheduled chief can withhold a protocol-valid block whereas sincere validators transfer forward, then launch the block anchored to an earlier level in logical time. If validators undertake that department, they align their PoH state to the block’s earlier level. The researchers name the reset “re-anchoring.”
Time Inflation (TI) repeats that maneuver to offer the attacker extra bodily time to decide on transactions whereas logical time advances extra slowly, and Fork-Assisted Time Inflation (FTI) combines the reset with TowerBFT fork alternative.
Underneath the modeled situations, the attacker’s department can orphan an sincere chief’s block, and Solana’s one-block-per-slot rule prevents that chief from merely producing one other block for a similar slot.
The menace mannequin provides the adversary lower than 33% of stake and no management over the community scheduler. It assumes a recognized, stake-weighted chief schedule, partial synchrony, and supply of an sincere block to sincere validators inside one nominal slot after the community stabilizes.
For an attacker controlling ℓ consecutive four-slot chief rounds, the experiments use a conservative, stake-agnostic most delay of 4ℓ + 1 slot models. One spherical maps to a five-slot-unit delay parameter.
The paper says extra stake might widen a risk-free launch window, however doesn’t current that experimental setting as a common mainnet consequence.
The researchers applied TI and FTI on an area Solana testnet and used simulations for full-epoch attacker configurations. They didn’t determine a selected affected Agave launch, so the paper doesn’t set up that each present shopper model is uncovered in the identical approach.
What public information reveals
The researchers additionally studied public mainnet information and chosen two validators that repeatedly sat within the tail of the timestamp-interval distribution. These validators paired longer intervals with larger transaction inclusion and low skip charges.
The sample is in keeping with TI’s incentive channel as a result of an extended bodily window creates extra alternatives to pick fee-bearing transactions.
The paper says {hardware} variations, native batching or different configuration decisions, community situations, and operational disruptions might create related timing patterns. It additionally discovered no considerably elevated downstream skip charge and mentioned the noticed sample was inconsistent with attribution to FTI.
The analysis establishes a protocol-valid equity and latency concern by way of managed exams and suggestive measurements. It stops wanting exhibiting a reside exploit, theft, demonstrated mainnet manipulation, or a consensus-safety break.
Why the Solana Alpenglow contest in all probability excluded it
Alpenglow competitors submissions closed Aug. 19 at 16:00 UTC. The foundations coated the Alpenglow feature-active consensus floor, integration code whose habits modified as a result of Alpenglow was energetic, and the TowerBFT-to-Alpenglow migration path.
Conduct reachable solely when Alpenglow was inactive belonged to the TowerBFT area and was outdoors the competitors. Beforehand public points had been additionally ineligible.
| Query | Legacy PoH and TowerBFT path | Alpenglow path |
|---|---|---|
| Core consensus | PoH-derived logical time with TowerBFT voting and fork alternative | Votor voting, block manufacturing, and finality with native timeouts |
| Paper’s mechanism | Makes use of PoH re-anchoring and legacy fork-choice habits | Designed to make that actual path unreachable, and not using a public paper-specific adjudication |
| Competitors remedy | Excluded when reachable solely with Alpenglow inactive | Characteristic-active habits and migration code had been in scope |
| Mainnet transition | Related whereas legacy consensus stays energetic | Code was current in Agave 4.2 however not activated on mainnet |
The competitors coated faults brought on by Alpenglow or its migration, and the paper targets the legacy time and fork-choice mannequin Alpenglow is supposed to exchange.
What Alpenglow adjustments
Anza’s Alpenglow overview says the improve replaces TowerBFT and PoH as core consensus elements with Votor. The official SIMD-0326 proposal describes native timeouts that carry out a timing function with out synchronized time and calls the change backward-incompatible.
These designs take away the PoH re-anchoring and TowerBFT fork-choice conditions TI and FTI use. The general public file lacks an Anza or Solana Basis evaluation mapping every assault step onto transport Alpenglow code or ruling out a similar concern in migration logic.
Based on the researchers, the Solana improvement group responded inside sooner or later of the December 2025 disclosure. The paper says the group thought of the habits recognized internally, anticipated a future protocol improve corresponding to Alpenglow to deal with it, monitored for it, and regarded essentially the most extreme situations as unlikely underneath present situations.
The authors additionally mentioned they’d not absolutely deployed mitigation by publication.
A Solana Basis overview of Agave 4.2 mentioned the shopper included Alpenglow code for group take a look at clusters however didn’t activate the brand new consensus on mainnet, with activation anticipated in Agave 4.3.
The paper’s legacy PoH assault seems to have fallen outdoors the 50,000 SOL contest, and Alpenglow is designed to take away its actual conditions. Till activation and a public implementation-level response, the transition stays the unresolved a part of the story.




