Solana's Clock Attack Exposed, But Did Security Contest Miss the Mark?
A recent study presented at USENIX Security on August 12 revealed a potential vulnerability in Solana's Proof-of-History (PoH) clock attack. The researchers disclosed this issue privately to Solana developers in December 2025, but it appears the 50,000 SOL security contest did not cover this specific threat.
The study describes a protocol-valid way for a scheduled leader to stretch its effective block window and suppress honest leaders' proposals in a fork-assisted version of PoH. This attack relies on Proof-of-History and TowerBFT, the machinery that Alpenglow is intended to replace but had not yet displaced on mainnet in Agave 4.2.
The researchers implemented Time Inflation (TI) and Fork-Assisted Time Inflation (FTI) on a local Solana testnet and used simulations for full-epoch attacker configurations. They found that the attacker's branch can orphan an honest leader's block, and Solana's one-block-per-slot rule prevents that leader from producing another block for the same slot.
The study also analyzed public mainnet data and selected two validators that repeatedly sat in the tail of the timestamp-interval distribution. The researchers found a consistent pattern with TI's incentive channel, where longer physical windows create more opportunities to select fee-bearing transactions.