Solana PoH clock attack could isolate blocks with under 33% stake

Researchers from USENIX Security disclosed a clock attack targeting Solana’s Proof of History (PoH) mechanism, which had been privately reported to Solana developers in December 2025. A malicious leader could repeatedly “re-anchor” PoH’s logical clock, slowing the advance of logical time and extending its transaction-selection window in physical time. Using TowerBFT’s fork-choice mechanism, the attacker could isolate blocks produced by honest leaders with a stake share below 33%. Anza’s Alpenglow security competition, which offered 50,000 SOL, closed on Aug. 19, but its rules excluded behavior that could be triggered only while Alpenglow was inactive, so the vulnerability was not reviewed. Solana developers said they were aware of the behavior, considered the most severe scenario unlikely under current conditions, and expected the Alpenglow upgrade to remove the attack prerequisite. Alpenglow code is included in the Agave 4.2 client but has not been activated on mainnet and is expected to launch with Agave 4.3. Until then, the vulnerability’s transition-period risk has not received a public implementation-level analysis or response.

本网站上的信息是使用AI生成的,我们无法保证其准确性。 请仅作为参考信息使用。