Friday, Apr 26 2024 | Time 10:22 Hrs(IST)
image
Business Economy


Solana snag exposes ‘critical vulnerabilities' in open-source projects: Telos

Mumbai, Sep 21 (UNI) Solana blockchain’s 17-hour outage, which resulted in the network having problems validating transactions, exposes critical vulnerabilities in the way Solana counts and handles transactions, Douglas Horn, chief architect of Telos Blockchain, said on Tuesday.
Solana, on its official website, has stated that while the network was offline for 17 hours, no funds were lost, and the network return ed to full functionality in under 24 hours and that Solana is designed for adversarial conditions.
“The cause of the network stall was, in effect, a denial of service attack. At 1200 UTC, Grape Protocol launched their IDO on Raydium, and bots generated transactions that flooded the network. These transactions created a memory overflow, which caused many validators to crash forcing the network to slow down and eventually stall. The network went offline when the validator network could not come to an agreement on the current state of the blockchain, which prevented the network from confirming new blocks,” Solana stated.
It further said that at 1211 UTC, the validator community noticed the transaction spike and network slowdown and the community took steps to help the network recover but were unsuccessful.
“These transactions flooded a system known as the forwarder queue, causing the memory used by this queue to grow
without limits. The transactions that were encoded into blocks were resource-heavy to process. The combination of the unbounded growth of the forwarder queues and resource-heavy blocks caused block producers to automatically propose a number of forks. The validator processes started to run out of memory and crash, and upon restart, the validators were unable to process all the proposed forks in time to catch back up with the rest of the network,” Solana stated.
Reacting to Solana’s statement, Mr Horn said blockchains should never stall if designed well and that a look at Solana’s purported transactions per second illuminates the key flaws in Solana's blockchain.
“A great portion of Solana transactions is not the user or smart contract transactions that networks like Ethereum (15 TPS) and Telos (10,000 TPS) process but instead include Solana’s thousands of critical consensus messages required by the chain. These processes are typically handled separately from on-chain transactions via a distinct communications channel -- for good reason. This differing design results in seemingly amazing scalability claims, which are entirely misleading. It is this design that forms a large part of why the Solana chain was locked up for over 12 hrs,” he explained.
He also said that mixing critical consensus messaging with regular transactions not only results in inflated TPS numbers but more critically exposes a large surface area of attacks on the blockchain.
“Also, the chain's lack of prioritization capabilities means when the Solana transaction queue becomes flooded, critical consensus message processing is displaced causing a lack of synching between nodes and eventually the forking that resulted in a stalled network. The best avoidance of this and other potential issues would not be to have these transactions mixed together. Nonetheless, prioritization of transactions was a factor yesterday that could have helped avoid Solana stalling from this specific exploit,” he said.
Mr Horn further said that the Solana fee model appears to be “immature in design” making it possible for someone to affordably flood the chain with too many transactions and blocking the critical consensus messaging from occurring in time.
“Again, separation of concerns is the most secure way to avoid this but allowing so many transactions to pass through without significant cost was a huge contributor,” he added.
UNI AAA SS 2019
More News

USD, Yen down ;Pound, Euro up

26 Apr 2024 | 10:02 AM

Mumbai, Apr 26 (UNI) Following were the indicative currency rates and travellers' cheques
buying and selling rates.

see more..

After RBI’s action, Kotak Mahindra Bank assures customers of uninterrupted services

25 Apr 2024 | 9:46 PM

New Delhi, April 25 (UNI) A day after the Reserve Bank of India (RBI) barred Kotak Mahindra Bank to cease and desist from onboarding of new customers due to IT related deficiencies in its network, the MD and CEO of the Bank on Thursday said they are actively working to address concerns raised and are in constant communication with the regulator to resolve issues promptly.

see more..

Arun Alagappan appointed as Executive Chairman of Coromandel International

25 Apr 2024 | 7:41 PM

Hyderabad, April 25 (UNI) Arun Alagappan has been appointed as Executive Chairman of Coromandel International Limited (CIL).

see more..

Tech Mahindra net at Rs 661 crore in Q4; Company gives dividend of Rs 28 per share

25 Apr 2024 | 7:28 PM

New Delhi, April 25 (UNI) Mahindra Group company Tech Mahindra, a technology consulting and digital solutions provider, on Thursday reported about 41 per cent decline in net profit at Rs 661 crore year-on-year basis for the fourth quarter ended March 31, 2024.

see more..

Kottayam-Kochi Rubber Market Rates

25 Apr 2024 | 7:26 PM

Kottayam, April 25 (UNI) Following were the Rubber Market rates announced by the Rubber Board here today per quintal.

see more..
image