Solana’s 50,000 SOL security contest did not cover a clock attack disclosed months earlier

22 hours ago 1



At USENIX Security on Aug. 12, researchers presented a Solana Proof-of-History clock attack they had disclosed privately to Solana developers in December 2025. Anza's 50,000 SOL Alpenglow competition closed seven days later, and its rules appear to place the attack outside the scope.The paper describes a protocol-valid way for a scheduled leader to stretch its effective block window and suppress honest leaders' proposals in a fork-assisted version. The path relies on Proof-of-History and TowerBFT, the machinery Alpenglow is intended to replace but had not yet displaced on mainnet in Agave 4.2.The finding creates both a contest-scope story and a transition-risk question.The competition rules excluded behavior reachable only when Alpenglow was inactive. Public design documents indicate that the paper's exact legacy path should become unreachable after activation, but Anza and the Solana Foundation have not published a paper-specific adjudication or implementation analysis.How a leader can stretch Solana's clockProof-of-History (PoH) uses a sequential hash chain to give Solana a logical clock. Validators continue advancing their local view of that clock when a scheduled leader does no...

Read Entire Article