Exploiting PoH Time Semantics in Solana via Re-Anchoring and Forking
Quanbi Feng, Pinshen Xu, Jianyu Niu, Cong Wang, Yinqian Zhang
摘要
Proof of History (PoH) is a core component of Solana that realizes a publicly verifiable notion of logical time via a sequential hash chain. It allows Solana to run a slot-based leader schedule, where a designated leader is expected to propose a block in each slot. Yet, the security implications of PoH-driven logical time remain insufficiently understood. In this paper, we identify a new protocol-valid attack surface in Solana's PoH time semantics: by withholding and later releasing protocol-valid blocks that commit to an earlier PoH-derived logical time than a validator's current local view, a scheduled malicious leader can trigger PoH re-anchoring at honest validators. Building on this primitive, we develop two attacks. First, Time Inflation Attack (TI) extends the malicious leader's effective block-production time budget by multiple slot intervals, enabling it to include more transactions without necessarily invalidating honest blocks. Second, Fork-Assisted Time Inflation Attack (FTI) extends the former by leveraging fork choice to further increase the time budget while suppressing honest leaders' proposals. We present a formal analysis that characterizes the conditions under which PoH re-anchoring occurs and bounds the adversary's impact under realistic network and stake assumptions. We implemented the attacks in a testbed and reported our findings to the Solana development team. We also analyze on-chain data and report timing and inclusion patterns that are compatible with the incentive channel exploited by TI. Finally, we discuss defenses that harden PoH time semantics and reduce incentives to exploit PoH re-anchoring.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper7
- Flash Boys 2.0: Frontrunning in Decentralized Exchanges, Miner Extractable Value, and Consensus InstabilityPhilip Daian, Steven Goldfeder, Tyler Kell, Yunqi Li 等S&P 2020 · 被引用 607 次
- Quantifying Blockchain Extractable Value: How dark is the forest?Kaihua Qin, Liyi Zhou, Arthur GervaisS&P 2022 · 被引用 336 次
- Ouroboros Genesis: Composable Proof-of-Stake Blockchains with Dynamic AvailabilityChristian Badertscher, Peter Gazi, Aggelos Kiayias, Alexander Russell 等CCS 2018 · 被引用 306 次
- On the Performance of Pipelined HotStuffJianyu Niu, Fangyu Gai, Mohammad M. Jalalzai, Chen FengINFOCOM 2021 · 被引用 27 次
- Max Attestation Matters: Making Honest Parties Lose Their Incentives in Ethereum PoSMingfei Zhang, Rujia Li, Sisi DuanUSENIX Security 2024 · 被引用 20 次
相关 Paper
- Multi-Certificate Attacks against Proof-of-Elapsed-Time and Their CountermeasuresHuibo Wang, Guoxing Chen, Yinqian Zhang, Zhiqiang LinNDSS 2022
- VRust: Automated Vulnerability Detection for Solana Smart ContractsSiwei Cui, Gang Zhao, Yifei Gao, Tien Tavu 等CCS 2022 · 被引用 31 次
- Forking the RANDAO: Manipulating Ethereum's Distributed Randomness BeaconÁbel Nagy, János Tapolcai, István András Seres, Bence LadóczkiCCS 2025 · 被引用 2 次
- Time-manipulation Attack: Breaking Fairness against Proof of Authority AuraXinrui Zhang, Rujia Li, Qin Wang, Qi Wang 等WWW 2023 · 被引用 9 次
- Available Attestation: Towards a Reorg-Resilient Solution for Ethereum Proof-of-StakeMingfei Zhang, Rujia Li, Xueqian Lu, Sisi DuanUSENIX Security 2025
