Alpenglow Finality Mechanics: How Solana Plans to Make a Block Irreversible in One or Two Vote Rounds
DividendChase LTD | Technical Note
As of 29 September 2026
Alpenglow is Anza’s rewrite of Solana consensus, not of the SVM. Execution, programs, and fee markets stay. What changes is how validators agree a block cannot be undone. The approved slice is SIMD-0326 (Votor). Rotor (Turbine’s successor) is a later SIMD. First activation is Agave 4.3; Firedancer/Frankendancer are not in that first wave. Community-cluster data exists. Full public mainnet finality at 150 ms is still a target, not a live SLA.Docs.chainstack
What “finality” means today vs after Votor
Slot time stays ~400 ms. You still get a block every 400 ms. You stop waiting 32 more slots to trust it.Solana
The two concurrent paths
Votor does not pick speed or resilience in advance. Both paths run at once. Whichever certificate completes first wins.
Fast path (one round)
- Validators that have the block cast a notarize vote.
- If ≥ 80% of stake notarizes in that first round → fast-finalization certificate.
- Target: ~100 ms after dissemination (simulation / cluster; not a physics law).
Fallback path (two rounds)
- If turnout is only ≥ 60% (not 80%), a notarization certificate forms at 60%.
- A second round runs. Another ≥ 60% produces a finalization certificate.
- Target: ~150 ms.
White paper timing is written as
min(δ80%,2δ60%)
after the block has been distributed — one 80% delay, or two 60% delays. Community-cluster dashboards have printed ~96% of blocks on the fast path. That is the operating hope: most slots look like a healthy network, not a partition.Solanacompass
If neither path works, the slot can be skipped. Skip also has certificates (60% skip / skip-fallback votes). Leaders do not get to stall the chain by going dark.
Votes are no longer transactions
Under TowerBFT every validator embeds a vote tx in later blocks. That is why vote traffic dominates Solana’s explorer and why small validators burn ~1 SOL/day in fees.
Under Votor:
- Validator checks the block.
- Signs a vote message (notarize, skip, etc.).
- Broadcasts it peer-to-peer (lightweight, often described as UDP-class), not as an on-chain tx.
- Any node that collects enough stake-weighted signatures aggregates them with BLS12-381.
- The aggregate — about 1,000 bytes — is the certificate that is written on-chain.
No lockouts in the old Tower sense. No “wait to vote later for a better fork reward.” SIMD-0326 explicitly wants those incentives gone. Validator economics shift from per-slot vote fees to an epoch admission ticket (figures in commentary cluster around ~1.6 SOL/epoch, burned — treat as design, confirm in the live client). Smaller operators are the intended beneficiaries if the ticket is cheaper than today’s vote burn.Helius
Certificate types (the actual state machine)
SIMD-0326 / the v1.1 paper define several certificates, not one magic “final” blob. The ones that matter for finality mechanics:
- Notarization — 60% notarize votes (opens the two-round path).
- Fast-finalization — 80% notarize in round one (one-round done).
- Finalization — second-round 60% after a notarization cert.
- Skip / skip-fallback — 60% agreeing the slot should be empty.
A node that sees a valid finalization or fast-finalization certificate treats that block as irreversible. Exchanges and bridges that today wait for finalized (~12.8 s) can, in principle, credit on the certificate. That is the whole product.
Why the Byzantine threshold fell from 33% to 20%
One-round finality at 80% cannot also tolerate 33% malicious stake. If 33% can lie, 80% honest is not guaranteed. Anza’s trade is explicit: tighter adversary budget, extra crash budget.
- Up to 20% of stake may be Byzantine.
- An additional 20% may be offline.
- Consensus should still complete on the remaining 60% via the two-round path.
That is why 60% appears twice. It is not an arbitrary “supermajority”; it is the residual after 20+20. Fast path (80%) is the “everyone is awake” bonus. Slow path is the “20% asleep” design point. A 21% coordinated equivocation is the new theoretical break, versus ~33% under Tower. Institutions should price that as a safety-model change, not as a free 100× speedup.Chainstack
What does not change in phase one
- Turbine still fans shreds out in a tree. Rotor’s single-hop / erasure-coded relay is not in SIMD-0326.
- Slot duration remains ~400 ms. Alpenglow does not make blocks arrive faster; it makes them stick faster.
- Execution is still the SVM. A heavy program still costs CU.
- Firedancer does not vote this protocol on day one. Until Jump implements Votor, a large stake slice is a laggard or a non-voter during the cutover — the same class of risk dual-clients were meant to remove.
Rotor, when it ships, is about dissemination time δ in that min(δ80%,2δ60%) formula. Faster shreds shrink both paths. Votor without Rotor still assumes Turbine can get the block to 80% of stake in tens of milliseconds. That is an empirical bet on today’s relay tree plus things like DoubleZero — not a proof.
Developer and market consequences of the mechanics
Confirmation levels collapse. Code that treated processed / confirmed / finalized as a risk ladder loses the middle rung. After a certificate, “confirmed” and “final” are meant to be the same object.
Vote spam leaves the chain. Blockspace that was votes becomes user txs. That is a silent TPS and fee-market change even if advertised TPS barely moves.
CEX deposit timers. A 12.8 s root is why many venues wait 30+ seconds. A 150 ms certificate is why payments and perps venues care. They should not cut timers until Firedancer votes and the certificate has survived a non-trivial mainnet partition.
MEV / leader timing. Removing “wait to vote for a better fork” changes leader and voter games. Jito-class schedulers have to live with certificates, not Tower lockouts.
Status check (do not trade 150 ms as live)
- SIMD-0326 passed validator vote (~98% of votes, ~52% of stake participating) in 2025.
- Dedicated community cluster running; fast-path rates in the mid-90s% on that cluster.
- Public testnet / Agave 4.3 feature flags through H2 2026; mainnet still the second-half-2026 plan, not a switched-on SLA.
- 1,000-byte certificate + 80/60 thresholds + 20+20 are the mechanics. 100–150 ms is Anza’s simulated delay given current geography and stake. Geography can miss the number even if the protocol is correct.
DividendChase takeaway
Alpenglow finality is quorum certificates instead of a 32-slot vote tower. One round if 80% of stake answers; two rounds if only 60% does; both races start together; BLS makes the proof small enough to put on-chain once. PoH leaves consensus. Safety is restated as 20% malice plus 20% silence. Phase one does not replace Turbine and does not include Firedancer. Until those two are true on mainnet, treat 150 ms as the spec, 12.8 s as the production clock, and the cutover as a client-diversity event as much as a latency event.
Intelligence for the Discerning Investor
DividendChase LTD

