Researchers disclosed a Solana Proof of History "clock attack" enabling a malicious leader to slow logical time and exploit TowerBFT to isolate honest blocks with under 33% stake, raising near-term protocol risk. While Solana developers view worst-case outcomes as unlikely and expect the upcoming Alpenglow upgrade (bundled in Agave 4.2/4.3) to remove prerequisites, mainnet has not activated it, leaving transitional uncertainty.
Impact level
● Medium
Affected assets
SOL/USDT+5.38%
AI Insight · SOL/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Mars Finance, citing CryptoSlate, reports that researchers affiliated with USENIX Security have publicly detailed a clock-attack vulnerability affecting Solana's Proof of History (PoH) system. The issue was reportedly shared privately with Solana's development team as early as December 2025.
According to the research, a maliciously scheduled leader could use a technique described as "reanchoring" to manipulate PoH's logical clock, slowing logical time to expand the transaction-selection window in real time. The attacker could then leverage the TowerBFT fork-choice mechanism to keep blocks produced by honest leaders isolated. The paper states the attack can be carried out with less than 33% stake.
The Alpenglow Security Competition, backed by Anza with a 50,000 SOL prize pool, ended on Aug. 19. The report notes that the vulnerability was not eligible for evaluation because contest rules excluded behaviors that only occur when Alpenglow is inactive.
Solana's development team has acknowledged the behavior and said the most severe outcome appears unlikely under current conditions. The team expects the Alpenglow upgrade to remove the underlying prerequisites for the attack.
Alpenglow code has already been incorporated into the Agave 4.2 client but remains inactive on mainnet. Official activation is planned alongside Agave 4.3. Until then, the report says there has been no public analysis or response addressing potential transitional implementation-level risk.