Solana retired its TowerBFT consensus mechanism on testnet and devnet during the week of September 22-25, 2026, replacing it with Votor, a formally proven protocol developed by Anza's research division in collaboration with ETH Zurich. The upgrade, branded Alpenglow, targets transaction finality ...
"No Alpenrush." — Roger Wattenhofer, Head of Research, Anza (ETH Zurich Professor)
Solana retired its TowerBFT consensus mechanism on testnet and devnet during the week of September 22-25, 2026, replacing it with Votor, a formally proven protocol developed by Anza's research division in collaboration with ETH Zurich. The upgrade, branded Alpenglow, targets transaction finality of 100-150 milliseconds, down from approximately 12.8 seconds under TowerBFT — an 85x reduction.
The testnet handoff completed at slot 444,625,255 on September 24, followed by devnet activation at slot 504,148,999 on September 25. Mainnet-beta activation remains unscheduled. Anza CEO Brennan Watt confirmed Agave v4.3.0 is cleared for mainnet, but the Alpenglow feature gate has not been opened. The next mainnet feature activation window opens November 9, 2026, under the Agave v4.4 release schedule.
Alpenglow eliminates on-chain vote transactions, which constituted 54-59% of all Solana mainnet transactions during the week of September 18-24 (217.1 million vote transactions vs. 168.8 million non-vote transactions on September 24 alone). This frees block capacity currently consumed by validator coordination overhead and compresses vote data from approximately 500 KB per slot to roughly 1,000 bytes via BLS12-381 signature aggregation.
TowerBFT has governed Solana's consensus since the network launched in March 2020. Validators under TowerBFT cast votes as regular on-chain transactions, with blocks reaching finality after accumulating 32 slots of consecutive vote confirmations — a process taking approximately 12.8 seconds.
Votor replaces this architecture entirely. Validators no longer submit votes as transactions. Instead, they exchange lightweight vote messages directly with one another. These messages are aggregated into BLS12-381 certificates of approximately 1,000 bytes that touch the chain; individual votes never do.
The shift has a second consequence: Proof of History (PoH), which previously paced block production, is removed from the consensus layer. A fixed block time of approximately 400 milliseconds plus local timeout timers on each validator now governs slot cadence. PoH ticks no longer appear in the shred stream.
Alpenglow ships with formal safety proofs, according to Anza's research team. TowerBFT's correctness was established through simulation, game-theoretic reasoning, and operational history. Votor's safety properties are mathematically derived — a distinction the team attributes to the involvement of Professor Roger Wattenhofer and former PhD students Kobi Sliwinski and Quentin Kniep from ETH Zurich's distributed systems group. Wattenhofer's team previously co-authored a 2024 paper, "Halting the Solana Blockchain with Epsilon Stake," which identified liveness vulnerabilities in TowerBFT.
Votor runs two concurrent finalization paths:
Fast Path: A block finalizes in a single round when at least 80% of stake votes to notarize it. Under normal network conditions, this path delivers finality in approximately 150 milliseconds.
Slow Path: When the 80% threshold is not met, finalization proceeds through two rounds. A notarization certificate at 60% stake is followed by a finalization certificate, also at 60% stake. Whichever path crosses its threshold first finalizes the block.
The Byzantine fault tolerance model changes materially. TowerBFT tolerated up to 33% adversarial stake. Votor tightens this to 20% adversarial stake while simultaneously tolerating up to 20% offline or crashed stake — yielding 40% total non-responsive tolerance.
Alpenglow introduces several structural modifications:
Agave 4.3 introduces a bank_id field on all Geyser events (transactions, accounts, slots, entries, block metadata). The identifier is node-local and meaningless across connections.
| Date | Event | Detail | |------|-------|--------| | July 8, 2026 | BLS Pubkey Management (SIMD-0387) | Activated on mainnet | | July 22, 2026 | Validator Admission Ticket (SIMD-0357) | Activated on mainnet | | August 12, 2026 | Agave v4.3 schedule published | Anza publishes release timeline | | September 18, 2026 | Agave v4.3.0 reaches mainnet | Alpenglow code deployed in inert state; 250ms slot time activated at epoch 1037 | | September 21, 2026 | Anza recommends v4.3 for all validators | Brennan Watt: "v4.3.0 is a go for mainnet" | | September 22, 2026 | Alpenglow feature gate opens on testnet | 5,000-slot countdown (~17 min) before handoff | | September 24, 2026 | Testnet handoff complete | Slot 444,625,255 at 18:12 UTC | | September 25, 2026 | Devnet handoff complete | Slot 504,148,999 at 20:01 UTC | | September 28, 2026 | Mainnet feature activation window opens | Alpenglow gate NOT activated; mainnet "resumes" feature activation | | November 9, 2026 | Agave v4.4 mainnet activation window | Next scheduled window for feature gates |
Solana co-founder Anatoly Yakovenko responded to premature mainnet launch reports with a single word: "decel." No mainnet-beta activation date has been announced. Anza stated the protocol will undergo an "observation period" on testnet and devnet before any mainnet migration.
Tim Garcia of Jump Crypto confirmed that Alpenglow activation on testnet "marks the end of an era" for Frankendancer. Neither Firedancer nor Frankendancer supports the Alpenglow migration. Validators running either client must migrate to Agave v4.3.0 before the feature gate activates, or their stake will be excluded from activation voting.
This is a material development. The Firedancer client, developed by Jump Crypto, was positioned as Solana's path to client diversity — a property considered important for network resilience. Its incompatibility with Alpenglow means Solana's validator set will temporarily consolidate around a single client implementation until Jump ships an Alpenglow-compatible version.
Under Alpenglow, the top 2,000 validators by stake weight per epoch require a Validator Admission Ticket. Ticket funding must be in place before the gate opens. The mechanism replaces the current vote transaction cost structure: validators transition from approximately 1 SOL per day in vote transaction fees to a Validator Admission Ticket burn of approximately 0.8 SOL per day.
Validators were already operating on a 250ms slot time since September 18 (epoch 1037). Early measurements from September 20 showed average slot times of approximately 266ms with a skip rate of approximately 0.05%.
The economic implications extend beyond infrastructure savings. At current SOL prices (~$118 as of September 29, 2026), the shift from ~1 SOL to ~0.8 SOL daily in validator costs represents a modest reduction in operational expenses. However, the primary economic impact is structural: removing vote transactions from blocks frees capacity for revenue-generating user transactions.
During the week of September 18-24, vote transactions accounted for 54-59% of daily mainnet activity. Eliminating them from blocks does not reduce "real" network throughput — it increases the effective capacity available for DeFi trades, NFT mints, token transfers, and other fee-generating activity.
Solana's average daily spot DEX volume reached $2.84 billion in Q1 2026, with spot DEX market share climbing from 29% to 33% during that period. Additional block capacity could support higher throughput during demand spikes without the congestion-driven fee increases that have periodically affected the network.
| Network | Finality Time | Mechanism | |---------|--------------|-----------| | Solana (TowerBFT) | ~12.8 seconds | Vote transaction accumulation | | Solana (Votor target) | 100-150 ms | BLS certificate aggregation | | Ethereum (post-Merge) | ~12.8 minutes | Two-epoch attestation | | Ethereum (single-slot finality, proposed) | ~12 seconds | Under research | | Avalanche | ~1-2 seconds | Snowball sampling | | Cosmos/Tendermint | ~6-7 seconds | Two-round BFT |
If Votor performs as designed in production, Solana would achieve finality faster than any major Layer 1 network currently in operation. The 100-150ms target approaches the latency floor imposed by physical network propagation delays across geographically distributed validators.
Anza has emphasized backward compatibility for application developers. The following remain unchanged:
Clock.slot and Clock.epoch sysvarsThe upgrade is consensus-layer only. Smart contracts, wallets, and applications built on Solana do not require modification, though infrastructure providers processing the shred stream or relying on vote transaction data will need to adapt.
One notable change for infrastructure: Clock.unix_timestamp is now set by the block leader within a bounded range (parent timestamp to parent timestamp + 2x elapsed slot duration). On 200ms slots, a direct successor block's timestamp is bounded to parent + 400ms.
Alpenglow represents the most significant architectural change to Solana since the network's launch. The replacement of TowerBFT with a formally proven consensus mechanism developed in collaboration with ETH Zurich addresses longstanding criticisms about Solana's consensus design, which was never formally verified.
The economic value proposition is straightforward: faster finality enables use cases that require near-instant settlement, while eliminating vote transactions from blocks increases effective throughput without hardware upgrades. Whether validators, infrastructure providers, and the Firedancer team can execute the migration smoothly remains the primary risk factor. The observation period on testnet and devnet will determine when — and whether — Alpenglow reaches mainnet.