Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

NewsThu, 20 Aug 2026 21:00:37 UTC12 hours ago
Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

At USENIX Security on Aug. 12, researchers presented a Solana Proof-of-History clock attack they had disclosed privately to Solana developers in December 2025. Anza's 50,000 SOL Alpenglow competition closed seven days later, and its rules appear to place the attack outside the scope.

The paper describes a protocol-valid way for a scheduled leader to stretch its effective block window and suppress honest leaders' proposals in a fork-assisted version. The path relies on Proof-of-History and TowerBFT, the machinery Alpenglow is intended to replace but had not yet displaced on mainnet in Agave 4.2.

The finding creates both a contest-scope story and a transition-risk question.

The competition rules excluded behavior reachable only when Alpenglow was inactive. Public design documents indicate that the paper's exact legacy path should become unreachable after activation, but Anza and the Solana Foundation have not published a paper-specific adjudication or implementation analysis.

How a leader can stretch Solana's clock

Proof-of-History (PoH) uses a sequential hash chain to give Solana a logical clock. Validators continue advancing their local view of that clock when a scheduled leader does not immediately publish a block.

… Continue reading the full article at the original source below.

Read from Source · cryptoslate.com ↗
This content is automatically aggregated. Full credit goes to the original publisher (cryptoslate.com).

Related