Researchers Disclose Solana PoH Clock Attack Flaw; Pre-Alpenglow Transition Risk Remains

AI مارکیٹ کا خلاصہ
Researchers disclosed a Solana Proof of History clock-manipulation vector that could let a malicious leader slow logical time, widen transaction selection, and leverage TowerBFT to isolate honest blocks with less than 33% stake. While Solana developers argue worst-case conditions are unlikely and expect Alpenglow to remove prerequisites, Alpenglow is not yet active on mainnet, leaving transitional implementation risk and potentially increasing near-term security and reliability concerns for SOL.
اثر کی سطح
● ہائی
متاثرہ اثاثے
SOL/USDT+5.49%
AI تجزیاتی سمجھ · SOL/USDTAI تجزیاتی سمجھ
▼ Bearish
ابھی ٹریڈ کریں
⚠️ AI سے تیار کردہ تجزیاتی سمجھ خبروں کے مواد پر مبنی ہے اور صرف معلوماتی مقاصد کے لیے فراہم کی گئی ہے۔ یہ سرمایہ کاری کا مشورہ نہیں ہے اور نہ ہی BingX کے خیالات کی نمائندگی کرتی ہے۔ سرمایہ کاری میں رسک شامل ہے۔ براہ کرم ذمہ داری سے ٹریڈ کریں۔
CryptoSlate reports that USENIX Security researchers publicly disclosed on Aug. 12 a clock attack vulnerability affecting Solana's Proof of History (PoH), which they say had already been privately reported to Solana's development team as early as December 2025. The researchers describe a scenario in which a malicious scheduler leader uses a technique dubbed "reanchoring" to manipulate the PoH logical clock. By slowing logical time relative to physical time, the leader can widen the transaction-selection window and then leverage Solana's TowerBFT fork-choice mechanism to isolate blocks produced by honest leaders. The report says the attack can be carried out with less than 33% stake. The Alpenglow Security Competition, funded by Anza with a 50,000 SOL prize, ended on Aug. 19. The researchers said the issue was not eligible for review under the contest rules because it involves behavior that can only be triggered when Alpenglow is inactive. Solana's development team acknowledged the behavior, saying the worst-case outcome is unlikely under current conditions and that the Alpenglow upgrade is expected to remove the underlying prerequisites for the attack. Alpenglow code has already been incorporated into the Agave 4.2 client but has not been activated on mainnet. Official rollout is planned alongside Agave 4.3. Until then, no public implementation-level analysis or response has addressed the vulnerability's transitional risk.