A real data center aisle used to illustrate Solana validator infrastructure security

Solana Put 50,000 SOL Up for Security—But One Threat Fell Outside the Hunt

August 20, 2026 7:20 pm Comments

Solana just finished one of the largest public security hunts in crypto. The more interesting story is the attack that was never really eligible to enter.

Anza offered a prize pool of up to 50,000 SOL for researchers who found serious flaws in Alpenglow, the new consensus system being prepared for Solana. At current market prices, that pool represented more than $4 million worth of SOL.

Seven days before the contest closed, researchers presented a different Solana weakness at USENIX Security: a clock attack that can give a malicious block producer more real-world time than the protocol appears to allow.

CryptoSlate reported that the researchers had privately disclosed the issue to Solana developers in December 2025, months before presenting it publicly on August 12.

The finding matters, but the details matter even more. This was not a report of stolen funds, a demonstrated mainnet exploit, or proof that an attacker had broken Solana’s consensus in the wild.

It was a controlled attack model aimed at Solana’s legacy Proof-of-History and TowerBFT machinery—the same machinery Alpenglow is designed to replace.

CryptoSlate also drew a firm boundary around what the public evidence does and does not show. The researchers reproduced the mechanism on a local test network and modeled broader conditions, but they did not name a universally affected Agave release or demonstrate that an attacker had used the technique against mainnet.

That restraint is essential: the paper identifies a plausible fairness and latency problem without turning suggestive timing data into an accusation.

The USENIX Security research describes how a scheduled leader can withhold a protocol-valid block while honest validators continue advancing their local view of Solana’s clock. The malicious leader can then release a block anchored to an earlier point in logical time.

If validators adopt that branch, their Proof-of-History state moves back to the block’s earlier point. The researchers call that process “re-anchoring.”

Repeated carefully, the maneuver can stretch the attacker’s effective block window. A fork-assisted version can also suppress an honest leader’s proposal under the paper’s modeled conditions.

The experiments used a conservative delay model tied to consecutive four-slot leader rounds. The authors said additional stake could widen an attacker’s release window, but they did not present that condition as a universal mainnet result.

They also noted that Solana’s one-block-per-slot rule can prevent an honest leader from simply replacing a proposal orphaned by the attacker’s branch.

Solana Developers linked a technical ecosystem update immediately before the competition window, as the network was preparing the code and validator changes surrounding Alpenglow.

The paper’s threat model assumed an adversary with less than one-third of stake and no control over the network scheduler. It tested the attack on a local Solana network and used simulations for larger attacker configurations.

The researchers also examined public mainnet timing data and found patterns that were consistent with the incentive behind the attack. But they were careful not to overstate that evidence.

Hardware differences, batching choices, network conditions, and ordinary operational disruptions could produce similar timing patterns. The researchers did not show that the suspicious timing represented a live attack.

That distinction is the line between a serious protocol warning and an unsupported claim that Solana has already been exploited.

So why was this not a 50,000 SOL contest entry?

The official Anza rules limited the competition to Alpenglow’s feature-active consensus surface, behavior changed by Alpenglow, and the migration path from TowerBFT. Behavior reachable only while Alpenglow was inactive remained in the legacy TowerBFT domain and was out of scope.

The rules also excluded findings that were already public. By the time the clock research was presented at USENIX, it could not qualify as a fresh private contest disclosure.

The contest opened on August 5 and closed on August 19 at 16:00 UTC. Reports had to target code still live on Alpenglow’s moving master branch, demonstrate the finding on a local fork, and arrive through a private GitHub Security Advisory.

Those terms were built to reward new faults in the incoming consensus stack, not to reopen every known issue in the system it is replacing.

Solana Developers shared another technical update during the opening days of the bounty period, giving the developer community a direct view into the work being tested around the upgrade.

Anza’s Alpenglow overview explains that the upgrade replaces Proof-of-History and TowerBFT as core consensus components with Votor. Local timeouts take over the timing role without relying on the same synchronized logical-clock structure.

That design should remove the exact Proof-of-History re-anchoring and TowerBFT fork-choice conditions used by the paper’s attack.

Alpenglow’s Votor system changes how validators vote and finalize blocks, while local timeout rules replace the timing function that Proof-of-History supplied to the legacy consensus path. The upgrade is backward-incompatible by design.

That architectural break is why the old clock attack and the new bounty can be connected in one story without pretending they tested the same code. It also makes migration review—not a simple bounty score—the decisive security test for users and validators.

“Should” is doing important work there. CryptoSlate noted that neither Anza nor the Solana Foundation has published a paper-specific, implementation-level analysis showing how every attack step maps—or fails to map—onto the Alpenglow code and migration process.

A Solana Foundation overview of Agave 4.2 said the release included Alpenglow code for community test clusters without activating the new consensus on mainnet. That leaves a transition period in which the old path still deserves attention even if the replacement architecture is designed to eliminate it.

Solana remains the seventh-largest cryptocurrency by market value. CoinGecko data showed SOL near $87.70 with a market capitalization above $51 billion on Thursday evening.

For a network carrying that much value, the correct response is neither panic nor dismissal.

The contest did what it was built to do: concentrate scrutiny on Alpenglow before activation. The USENIX paper did something different: expose a carefully bounded weakness in the system Solana is still leaving behind.

The next proof will come from implementation-level review, a clear public response, and a clean migration—not from the size of the bounty alone.

Join the conversation!

We have no tolerance for comments containing violence, racism, profanity, vulgarity, doxing, or discourteous behavior. If a comment is spam, instead of replying to it please click the icon below and to the right of that comment. Thank you for partnering with us to maintain fruitful conversation.