Solana's core development firm Anza retired TowerBFT on the network's testnet at slot 444625255 on September 24, 2026, and on devnet at slot 504148999 on September 25, replacing it with Votor, the consensus engine of the Alpenglow protocol. The upgrade targets deterministic finality of 100–150 mi...
"A median latency of 150 ms does not just mean that Solana is fast — it means Solana can compete with Web2 infrastructure." — Quentin Kniep, Kobi Sliwinski, and Roger Wattenhofer, Alpenglow Whitepaper Authors
Solana's core development firm Anza retired TowerBFT on the network's testnet at slot 444625255 on September 24, 2026, and on devnet at slot 504148999 on September 25, replacing it with Votor, the consensus engine of the Alpenglow protocol. The upgrade targets deterministic finality of 100–150 milliseconds, down from the current 12.8 seconds — an approximately 85x reduction. No mainnet activation date has been announced; Anza's release schedule permits feature activations to resume on mainnet-beta on September 28, but the firm has not identified that date as Alpenglow's deployment.
Alpenglow is the largest protocol-level change since Solana's 2020 launch. It eliminates Proof of History, replaces TowerBFT consensus, moves all validator vote transactions off-chain, and introduces BLS signature aggregation. The economic implications are significant: vote transactions currently represent approximately 59% of all Solana network transactions. Their removal reshapes validator economics, reduces the minimum profitable stake threshold from roughly 4,850 SOL (~$800,000) to approximately 450 SOL (~$75,000), and eliminates an estimated 1 SOL per day in voting costs per validator.
Solana's current consensus stack rests on two mechanisms introduced at launch: Proof of History (PoH) and TowerBFT.
Proof of History functions as a cryptographic clock — validators continuously hash a SHA-256 chain to establish ordering without waiting for network-wide agreement on time. PoH allowed Solana to achieve high throughput, but introduced hash-stalling attack vectors and forced validators to grind hashes continuously, consuming compute resources regardless of transaction demand.
TowerBFT is a Byzantine Fault Tolerant consensus protocol that records validator votes on-chain and requires votes to accumulate across 32 incremental slots before finality is reached. This design produces deterministic finality in approximately 12.8 seconds and generates a large volume of vote transactions — roughly 59% of all network transactions by seven-day average, according to Solana Compass analytics.
Alpenglow replaces both entirely. PoH's hash-based clock is replaced by local timeout timers where validators independently set deadlines per leader window at intervals of approximately 400 milliseconds. TowerBFT's on-chain voting is replaced by Votor, which transmits votes as lightweight UDP packets directly between validators, with only certificate headers anchored on-chain.
Votor operates two finalization paths concurrently:
Fast Path. If validators representing at least 80% of total stake vote to accept a block in round one, a Fast-Finalization Certificate is produced immediately. Target latency: approximately 100 milliseconds.
Slow Path. If round one achieves at least 60% but less than 80% stake approval, a second voting round begins. Upon reaching 60% in round two, a Finalized Certificate is produced. Target latency: approximately 150 milliseconds.
The system finalizes as soon as either path completes. According to the Alpenglow whitepaper, consensus overhead adds approximately a 2x multiplier on raw network latency. With the longest one-way latency at roughly 70 milliseconds (based on simulations with a Zurich-based leader), fast-path finality lands in the 120–150 millisecond range. Approximately 65% of Solana's stake operates within 50 milliseconds of network latency from the modeled Zurich location.
Resilience model. Votor uses a "20+20" fault tolerance structure: safety is maintained with up to 20% adversarial stake, and liveness is maintained even if an additional 20% of stake is offline or unresponsive. This represents a higher fault tolerance ceiling than TowerBFT's one-third threshold.
Vote handling. Validators sign vote certificates using BLS signature aggregation and distribute them off-chain via direct validator-to-validator messaging rather than publishing individual vote transactions on the ledger. The Pool data structure — maintained by every node — memoizes received votes per slot and node, then aggregates signatures into certificates once quorum is reached. According to the Anza blog, "only the certificate header is anchored on-chain," replacing thousands of individual vote transactions with one compact certificate per block.
Fork selection. Brennan Watt, an engineer at Anza, stated in a Lightspeed podcast appearance: "You don't really see forking in Alpenglow. It drastically simplifies the fork selection because it's really just, 'Hey, is this block good or not?'" Blocks are either certified and final, or they are not — there is no extended period of ambiguity.
Rotor is the second component of Alpenglow, designed to replace Turbine, Solana's current block propagation mechanism. While Votor is included in the initial activation, Rotor will follow in a later phase.
Turbine currently uses a multi-layer tree with a fanout of 200 nodes to propagate block data. Rotor replaces this with a single-hop relay model:
According to the whitepaper, "with a bandwidth of 1 Gb/s, transmitting n = 1,500 shreds takes 18 ms," well below the average network delay of approximately 80 milliseconds. Reaching 80% of total stake requires only roughly 150 nodes in approximately 2 milliseconds.
Blokstor, a new storage module, manages slice storage, accepting shreds with valid leader signatures and Merkle tree paths. Finalized blocks are stored exclusively; non-finalized data is discarded.
Alpenglow's target finality repositions Solana relative to competing Layer 1 networks. Comparative data as of September 2026:
| Network | Consensus | Deterministic Finality | Block Time | |---------|-----------|----------------------|------------| | Solana (current) | TowerBFT + PoH | ~12.8 seconds | 400 ms | | Solana (Alpenglow) | Votor | 100–150 ms (target) | 400 ms | | Ethereum | Gasper (LMD-GHOST + Casper FFG) | ~12.8 minutes | 12 seconds | | Avalanche C-Chain | Snowman++ | ~2 seconds | ~2 seconds | | Aptos | AptosBFT | ~900 ms | ~900 ms | | Sui | Mysticeti | ~400 ms (owned objects) | 79 ms |
If Alpenglow delivers on its target, Solana would move from the slowest deterministic finality among high-throughput Layer 1s to the fastest among major public blockchains, undercutting Sui's current ~400 millisecond finality by roughly 60–75%.
Ethereum's roadmap targets 8-second finality through its Minimint consensus mechanism, but that upgrade is part of a multi-year, seven-fork roadmap extending through 2029, according to the Ethereum Foundation. The gap between Ethereum and Solana on finality would widen from roughly 60x to approximately 5,000x if both hit their targets.
The economic impact on Solana's validator set is substantial. Current validator economics are under pressure: the active validator count ended Q4 2025 at 791, a 17.9% quarterly decline and roughly a 68% drop from the March 2023 peak of over 2,500, according to The Block.
Current costs. Validators pay approximately 1.1 SOL per day (roughly $130 at $117/SOL) in vote transaction fees. At approximately 401 SOL per year ($47,000), this represents a significant fixed cost before accounting for hardware expenses of approximately $60,000 annually.
Post-Alpenglow costs. Anza's proposed validator admission ticket mechanism reduces daily costs to approximately 0.8 SOL per validator — a roughly 20% reduction. More significantly, the elimination of vote transactions from the ledger removes the per-vote fee structure entirely for consensus participation.
Minimum profitable stake. According to Helius, the elimination of on-chain voting costs theoretically reduces the minimum profitable stake from approximately 4,850 SOL (~$800,000) to approximately 450 SOL (~$75,000) — a roughly 90% reduction. This could reverse the validator consolidation trend by making smaller operations economically viable again.
Transaction count impact. With vote transactions comprising roughly 59% of all network transactions, their removal will cause a significant decline in headline transaction counts. This is a cosmetic change — user-facing transaction throughput and capacity are unaffected — but it will alter commonly cited metrics.
As of early September, only 0.39% of active stake (six validators) was running the Agave v4.3 client required for Alpenglow, according to Solana Compass. General adoption of v4.3 was reported on September 21.
| Date | Event | Status | |------|-------|--------| | September 24, 2026 | Testnet handoff at slot 444625255 | Completed | | September 25, 2026 | Devnet handoff at slot 504148999 | Completed | | September 21, 2026 | General adoption milestone for Agave v4.3 | Completed | | September 28, 2026 | Mainnet-beta feature activation window resumes | Scheduled | | TBD | Mainnet Alpenglow activation | Not announced | | TBD | Rotor deployment (phase 2) | Not announced |
Anza's stated process is testnet, then devnet, then mainnet-beta after an observation period. The firm has provided no specific mainnet date. Brennan Watt indicated in a public interview that Anza would "love to be standing on the stage in Abu Dhabi at Breakpoint and talking about how it's doing on mainnet," suggesting a potential late 2026 or early 2027 target, though this is aspirational rather than committed.
The upgrade affects only the consensus layer. The Solana Virtual Machine, transaction formats, programs, and fee structures remain unchanged. According to Solana Compass, "users, wallets, and smart contracts require no changes." However, breaking changes do affect certain low-level features including SHA-512 syscalls, big-integer operations, and CPI depth increases.
Several material uncertainties remain unresolved in the Alpenglow specification:
Reward mechanisms. The whitepaper does not define exact validator reward distribution under Votor. Watt acknowledged: "We need some way of observing it, some way of incentivizing it and doing some payouts. But I'm not sure exactly what that's going to look like in the end."
Rotor relay compensation. How relay nodes are paid for data propagation services is undefined.
Equivocation penalties. Slashing or penalty procedures for validators that produce conflicting votes have not been specified.
MEV implications. A 150-millisecond finality window compresses the time available for maximal extractable value strategies. The impact on Solana's MEV ecosystem — including Jito's infrastructure — has not been publicly analyzed.
Validator adoption pace. With only 0.39% of stake on v4.3 as of early September, mass migration to the required client version is a prerequisite. Historical Solana client upgrades have sometimes been contentious.
Testnet-to-mainnet performance gap. Testnet conditions differ materially from mainnet. The network currently handles approximately 9.5 million new addresses per day and $5.09 million in daily application revenue. Maintaining Alpenglow's finality targets under mainnet load is unproven.
Alpenglow represents the most structurally significant protocol change in Solana's history, touching consensus, data propagation, timing, and validator economics simultaneously. The 150-millisecond finality target, if achieved on mainnet, would place Solana ahead of every major public blockchain on deterministic settlement speed.
The economic argument is equally material. Removing 59% of network transactions (votes) from the ledger and reducing the minimum profitable stake threshold by approximately 90% addresses the validator consolidation trend directly. Whether this translates into actual validator growth depends on undefined reward mechanisms and the broader staking economics environment.
The protocol risk is concentrated in the transition period. Anza has completed testnet and devnet handoffs in consecutive days but has offered no mainnet timeline commitment. The gap between lab conditions and the roughly $229 million in monthly real-world asset flows currently running through Solana will be the definitive test. The data from devnet observation will determine whether the 150-millisecond target holds or requires adjustment before mainnet deployment.