BTC $77,390.39 +6.55%
ETH $2,424.71 +4.18%
BNB $679.30 +4.53%
XRP $1.39 +10.59%
SOL $91.89 +5.41%
TRX $0.3402 +0.38%
DOGE $0.0850 +5.29%
ADA $0.2202 +11.17%
BCH $295.23 +32.35%
LINK $11.65 +8.97%
HYPE $75.08 +4.47%
AAVE $111.46 +15.19%
SUI $0.8177 +11.66%
XLM $0.1938 +5.99%
ZEC $669.90 +18.36%
BTC $77,390.39 +6.55%
ETH $2,424.71 +4.18%
BNB $679.30 +4.53%
XRP $1.39 +10.59%
SOL $91.89 +5.41%
TRX $0.3402 +0.38%
DOGE $0.0850 +5.29%
ADA $0.2202 +11.17%
BCH $295.23 +32.35%
LINK $11.65 +8.97%
HYPE $75.08 +4.47%
AAVE $111.46 +15.19%
SUI $0.8177 +11.66%
XLM $0.1938 +5.99%
ZEC $669.90 +18.36%

Researchers disclose Solana PoH clock attack vulnerability: Transition risks remain unresolved before Alpenglow upgrade

2026-08-21 08:39:47

According to CryptoSlate, researchers from USENIX Security have publicly disclosed a clock attack vulnerability targeting Solana's Proof of History (PoH) mechanism, which was privately reported to the Solana development team back in December 2025. The research shows that a malicious scheduler leader can manipulate the PoH logical clock by "re-anchoring," slowing down the advancement of logical time, thus gaining a longer transaction selection window in physical time, and isolating honest leader blocks using the TowerBFT fork choice mechanism, with the required staking ratio for the attacker being less than 33%.

The Alpenglow security competition with a reward of 50,000 SOL under Anza concluded on August 19, but the vulnerability was excluded from the review scope due to the competition rules that state "actions that can only be triggered when Alpenglow is not activated." The Solana development team stated that they are aware of the related behavior, believe that the probability of the most severe scenario occurring under current conditions is low, and expect that the Alpenglow upgrade will fundamentally eliminate the prerequisites for the attack. Currently, the Alpenglow code has been included in the Agave 4.2 client but has not yet been activated on the mainnet, and is expected to go live with Agave 4.3. Until then, the transitional risk of this vulnerability has not been publicly analyzed or addressed at the implementation level.

app_icon
ChainCatcher Building the Web3 world with innovations.