Crypto insigtX

Researchers Disclose Solana PoH Clock Attack Vulnerability; Transition Risk Lingers Ahead of Alpenglow Upgrade

Researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana's Proof of History (PoH) mechanism, which was privately reported to the Solana development team in…

Published
Market
Crypto
Source
insigtX

Researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana's Proof of History (PoH) mechanism, which was privately reported to the Solana development team in December 2025. The research shows that a malicious scheduling leader can manipulate the PoH logical clock through "re-anchoring," slowing logical time progression to gain a longer transaction selection window in physical time, and can isolate honest leaders' blocks via the TowerBFT fork selection mechanism, with the attacker requiring a staking ratio below 33%.

Anza's Alpenglow security competition, with a 50,000 SOL prize, closed on August 19, but the vulnerability was excluded from review scope due to competition rules that exclude "behaviors triggerable only when Alpenglow is not active." The Solana development team acknowledged awareness of the behavior, assessing that the most severe scenario has a low probability of occurrence under current conditions, and expects the Alpenglow upgrade to fundamentally eliminate the attack's prerequisites. Currently, Alpenglow code is included in the Agave 4.2 client but has not yet been activated on the mainnet, with an expected official release alongside Agave 4.3. Until then, the transitional risk from this vulnerability remains without public implementation-level analysis or response.

[ChainCatcher]

Original: https://www.chaincatcher.com/article/2284267

insigtX content is informational and educational, not investment advice.