USENIX Security2026Top-tier venue
Exploiting PoH Time Semantics in Solana via Re-Anchoring and Forking
Quanbi Feng, Pinshen Xu, Jianyu Niu, Cong Wang, Yinqian Zhang
Abstract
Proof of History (PoH) is a core component of Solana that realizes a publicly verifiable notion of logical time via a sequential hash chain. It allows Solana to run a slot-based leader schedule, where a designated leader is expected to propose a block in each slot. Yet, the security implications of PoH-driven logical time remain insufficiently understood. In this paper, we identify a new protocol-valid attack surface in Solana's PoH time semantics: by withholding and later releasing protocol-valid blocks that commit to an earlier PoH-derived logical time than a validator's current local view, a scheduled malicious leader can trigger PoH re-anchoring at honest validators. Building on this primitive, we develop two attacks. First, Time Inflation Attack (TI) extends the malicious leader's effective block-production time budget by multiple slot intervals, enabling it to include more transactions without necessarily invalidating honest blocks. Second, Fork-Assisted Time Inflation Attack (FTI) extends the former by leveraging fork choice to further increase the time budget while suppressing honest leaders' proposals. We present a formal analysis that characterizes the conditions under which PoH re-anchoring occurs and bounds the adversary's impact under realistic network and stake assumptions. We implemented the attacks in a testbed and reported our findings to the Solana development team. We also analyze on-chain data and report timing and inclusion patterns that are compatible with the incentive channel exploited by TI. Finally, we discuss defenses that harden PoH time semantics and reduce incentives to exploit PoH re-anchoring.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on7
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li et al.S&P 2020 · 607 citations
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 336 citations
- Ouroboros Genesis: Composable Proof-of-Stake Blockchains with Dynamic AvailabilityChristian Badertscher, Peter Gazi, Aggelos Kiayias, Alexander Russell et al.CCS 2018 · 306 citations
- On the Performance of Pipelined HotStuffJianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Chen FengINFOCOM 2021 · 27 citations
- Max Attestation Matters: Making Honest Parties Lose Their Incentives in Ethereum PoSMingfei Zhang, Rujia Li, Sisi DuanUSENIX Security 2024 · 20 citations
Related papers
- Multi-Certificate Attacks against Proof-of-Elapsed-Time and Their CountermeasuresHuibo Wang, Guoxing Chen, Yinqian Zhang, Zhiqiang LinNDSS 2022
- VRust: Automated Vulnerability Detection for Solana Smart ContractsSiwei Cui, Gang Zhao, Yifei Gao, Tien Tavu et al.CCS 2022 · 31 citations
- Forking the RANDAO: Manipulating Ethereum's Distributed Randomness BeaconÁbel Nagy, János Tapolcai, István András Seres, Bence LadóczkiCCS 2025 · 2 citations
- Time-manipulation Attack: Breaking Fairness against Proof of Authority AuraXinrui Zhang, Rujia Li, Qin Wang, Qi Wang et al.WWW 2023 · 9 citations
- Available Attestation: Towards a Reorg-Resilient Solution for Ethereum Proof-of-StakeMingfei Zhang, Rujia Li, Xueqian Lu, Sisi DuanUSENIX Security 2025
