Researchers disclose Solana PoH clock attack ahead of Alpenglow mainnet activation

Researchers disclose Solana PoH clock attack ahead of Alpenglow mainnet activation

N
News Editor
2026-08-21 00:39:47
Researchers from USENIX Security have publicly disclosed a clock attack against Solana’s Proof of History, according to CryptoSlate, saying the issue had already been privately reported to the Solana development team in December 2025. The paper describes how a malicious scheduled leader could use a “re-anchoring” technique to slow the advance of PoH logical time, giving itself a longer transaction selection window within the same span of physical time. The researchers also said the attack could use TowerBFT’s fork-choice mechanism to isolate blocks produced by honest leaders, while requiring less than 33% stake. The issue was not reviewed in Anza’s 50,000 SOL Alpenglow security competition, which closed on Aug. 19, because the rules excluded behavior that can only be triggered before Alpenglow is activated. Solana developers said they are aware of the behavior, consider the most severe scenario unlikely under current conditions, and expect the Alpenglow upgrade to remove the core preconditions for the attack. Alpenglow code is already included in the Agave 4.2 client but has not yet been activated on mainnet, with activation expected alongside Agave 4.3.

Researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana’s Proof of History, or PoH, according to CryptoSlate. The issue had already been privately reported to the Solana development team in December 2025.

The research says a malicious scheduled leader can manipulate the PoH logical clock through a “re-anchoring” method, slowing the advance of logical time and gaining a longer transaction selection window within physical time. It also says the attacker can use TowerBFT’s fork-choice mechanism to isolate blocks produced by honest leaders, with the required stake coming in below 33%.

The flaw was outside the Alpenglow contest scope

Anza’s Alpenglow security competition, which carried a 50,000 SOL reward, closed on Aug. 19. The vulnerability was not included in the review because the contest rules excluded behavior that can only be triggered when Alpenglow is not activated.

Developer response and rollout status

The Solana development team said it is aware of the behavior and believes the most severe scenario is unlikely under current conditions. The team also expects the Alpenglow upgrade to eliminate the underlying preconditions for the attack.

At present, Alpenglow code has already been included in the Agave 4.2 client, but it has not been activated on mainnet. Activation is expected with the formal rollout of Agave 4.3. Before that happens, the transitional risk tied to the flaw has not yet received a public implementation-level analysis or response.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
50

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.