Solana’s 50,000 SOL Security Contest Did Not Cover Disclosed Proof-of-History Clock Attack

2 hour ago 2 sources negative

Key takeaways:

  • Solana's PoH clock attack highlights migration risks until Alpenglow fully activates on mainnet.
  • Excluding known attack vectors from the Alpenglow contest raises transparency concerns for external researchers.
  • Watch Agave 4.3 activation closely as legacy consensus may remain susceptible in interim.

A research paper presented at USENIX Security on Aug. 12 described a proof-of-history (PoH) clock attack against Solana that had been privately disclosed to Solana developers in December 2025. The vector allows a malicious scheduled leader to withhold a protocol-valid block while honest validators advance their logical clock, then release the block anchored to an earlier point — a process the researchers call “re-anchoring.” Through Time Inflation (TI) and Fork-Assisted Time Inflation (FTI), an attacker with less than 33% of stake and no scheduler control could in modeled conditions stretch the block window and suppress honest leaders’ proposals.

According to the paper, the attack relies on legacy PoH and TowerBFT fork-choice behavior — the exact consensus machinery that Anza’s Alpenglow upgrade is designed to replace. The 50,000 SOL Alpenglow security competition closed on Aug. 19, seven days after the presentation. Its scope covered the Alpenglow feature-active consensus surface and migration path, while excluding behavior reachable only when Alpenglow was inactive. That exclusion appears to place the PoH clock attack outside the contest’s boundaries.

Researchers implemented TI and FTI on a local Solana testnet and ran simulations for full-epoch attacker configurations. They also examined public mainnet data and identified two validators repeatedly sitting in the tail of the timestamp-interval distribution, pairing longer intervals with higher transaction inclusion and low skip rates. The paper said the pattern was consistent with TI’s incentive channel, but could also be explained by hardware differences, batching, network conditions, or operational disruptions. It found no significantly elevated downstream skip rate and said observations were inconsistent with attribution to FTI. The work stops short of proving a live exploit, theft, mainnet manipulation, or a consensus-safety break.

Solana’s development team responded within one day of the private disclosure. The researchers said the team considered the behavior known internally, expected upgrades such as Alpenglow to address it, monitored for it, and viewed the most severe scenarios as unlikely under current conditions. Alpenglow’s design and SIMD-0326 propose replacing TowerBFT and PoH with Votor and local timeouts, removing the re-anchoring and fork-choice prerequisites. The code was present in Agave 4.2 for test clusters but not activated on mainnet, with activation expected in Agave 4.3.

The episode has drawn scrutiny because a previously disclosed clock attack was omitted from a high-profile, richly funded security contest. The 50,000 SOL reward pool raised expectations of completeness, and the omission created a transparency and transition-risk question: until Alpenglow activates and Anza or the Solana Foundation publishes an implementation-level response, the legacy path and any comparable migration issue remain difficult for outside researchers to assess.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.