Coverage
- 8.0
Solana's 50,000 SOL contest missed pre-disclosed PoH clock attack
At USENIX Security on Aug. 12, researchers presented a Proof-of-History clock attack that had been disclosed privately to Solana developers in December 2025. Anza's 50,000 SOL Alpenglow competition closed seven days later, and its rules appear to place the attack outside the contest's scope. The finding exposes a coverage gap in a major security contest and raises a transition-risk question: the attack exploits legacy TowerBFT behavior, which Alpenglow is intended to replace but has not yet displaced on mainnet. A consensus-level vulnerability threatens network integrity, so this affects validators, developers, and the broader Solana ecosystem during the upgrade window. The attack lets a scheduled leader stretch its effective block window by withholding a protocol-valid block and releasing it anchored to an earlier logical time point ("re-anchoring"), combined with TowerBFT fork choice (Fork-Assisted Time Inflation). The threat model assumes less than 33% stake, partial synchrony, and a known leader schedule; the paper does not identify a specific affected Agave release.
- 7.5
Solana's Alpenglow bug hunt charges researchers 0.5 SOL per report
Anza has launched a two-week bug bounty for the upcoming Alpenglow consensus upgrade, requiring researchers to burn a non-refundable 0.5 SOL fee through its portal for each submission before eligibility or severity is assessed. The competition closes at 16:00 UTC on Aug. 19, with a 50,000 SOL reward pool allocated by severity. Alpenglow is a backwards-incompatible replacement for Solana's Proof-of-History and TowerBFT consensus, making this one of Solana's most consequential protocol changes since mainnet launch. The fee-based submission policy shifts filing risk onto researchers and could affect how many serious vulnerabilities are found before the upgrade goes live, influencing Solana's security posture. The 50,000 SOL pool unlocks in tiers: 10,000 SOL for DoS, 20,000 for liveness failures, 30,000 for consensus or safety violations, and 50,000 for loss of funds; individual awards cap at 25,000 SOL. Findings must be submitted through Anza's portal (which creates a confidential GitHub Security Advisory), identify the vulnerable commit, reproduce on a local fork or simulation, and arrive before a fix lands on Agave master.
- 8.5
Solana Nears Finality Halt as 28.83% of Staked SOL Goes Delinquent
On August 12, 2026, a routing failure at infrastructure provider Teraswitch caused 28.83% of staked SOL to go delinquent, bringing Solana 86% of the way to the threshold at which block finality halts. Marinade reported that 94% of the 118.89 million SOL on its autonomous system went offline. The event highlights systemic concentration risk in Solana's validator infrastructure, because a single provider's routing problem nearly threatened network-wide finality. It also directly affected Marinade, Solana's largest liquid staking protocol, and could shake confidence in staking reliability across the ecosystem. Teraswitch confirmed the outage was caused by a routing software failure triggered during a routine configuration change, affecting 12 sites. Solana's finality stops only when more than 33.34% of staked SOL is delinquent, and roughly 90 validators were affected, losing staking rewards.