Timeline
- 8.0
Solana's 50,000 SOL contest missed pre-disclosed PoH clock attack
At USENIX Security on Aug. 12, researchers presented a Proof-of-History clock attack that had been disclosed privately to Solana developers in December 2025. Anza's 50,000 SOL Alpenglow competition closed seven days later, and its rules appear to place the attack outside the contest's scope. The finding exposes a coverage gap in a major security contest and raises a transition-risk question: the attack exploits legacy TowerBFT behavior, which Alpenglow is intended to replace but has not yet displaced on mainnet. A consensus-level vulnerability threatens network integrity, so this affects validators, developers, and the broader Solana ecosystem during the upgrade window. The attack lets a scheduled leader stretch its effective block window by withholding a protocol-valid block and releasing it anchored to an earlier logical time point ("re-anchoring"), combined with TowerBFT fork choice (Fork-Assisted Time Inflation). The threat model assumes less than 33% stake, partial synchrony, and a known leader schedule; the paper does not identify a specific affected Agave release.
- 7.5
Solana's Alpenglow bug hunt charges researchers 0.5 SOL per report
Anza has launched a two-week bug bounty for the upcoming Alpenglow consensus upgrade, requiring researchers to burn a non-refundable 0.5 SOL fee through its portal for each submission before eligibility or severity is assessed. The competition closes at 16:00 UTC on Aug. 19, with a 50,000 SOL reward pool allocated by severity. Alpenglow is a backwards-incompatible replacement for Solana's Proof-of-History and TowerBFT consensus, making this one of Solana's most consequential protocol changes since mainnet launch. The fee-based submission policy shifts filing risk onto researchers and could affect how many serious vulnerabilities are found before the upgrade goes live, influencing Solana's security posture. The 50,000 SOL pool unlocks in tiers: 10,000 SOL for DoS, 20,000 for liveness failures, 30,000 for consensus or safety violations, and 50,000 for loss of funds; individual awards cap at 25,000 SOL. Findings must be submitted through Anza's portal (which creates a confidential GitHub Security Advisory), identify the vulnerable commit, reproduce on a local fork or simulation, and arrive before a fix lands on Agave master.