Lune

USENIX Security2026顶会

Exploiting PoH Time Semantics in Solana via Re-Anchoring and Forking

Quanbi Feng, Pinshen Xu, Jianyu Niu, Cong Wang, Yinqian Zhang

出版方
2026年份

摘要

Proof of History (PoH) is a core component of Solana that realizes a publicly verifiable notion of logical time via a sequential hash chain. It allows Solana to run a slot-based leader schedule, where a designated leader is expected to propose a block in each slot. Yet, the security implications of PoH-driven logical time remain insufficiently understood. In this paper, we identify a new protocol-valid attack surface in Solana's PoH time semantics: by withholding and later releasing protocol-valid blocks that commit to an earlier PoH-derived logical time than a validator's current local view, a scheduled malicious leader can trigger PoH re-anchoring at honest validators. Building on this primitive, we develop two attacks. First, Time Inflation Attack (TI) extends the malicious leader's effective block-production time budget by multiple slot intervals, enabling it to include more transactions without necessarily invalidating honest blocks. Second, Fork-Assisted Time Inflation Attack (FTI) extends the former by leveraging fork choice to further increase the time budget while suppressing honest leaders' proposals. We present a formal analysis that characterizes the conditions under which PoH re-anchoring occurs and bounds the adversary's impact under realistic network and stake assumptions. We implemented the attacks in a testbed and reported our findings to the Solana development team. We also analyze on-chain data and report timing and inclusion patterns that are compatible with the incentive channel exploited by TI. Finally, we discuss defenses that harden PoH time semantics and reduce incentives to exploit PoH re-anchoring.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper7

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖