Solana’s Geographic Speed Plan Relies on Unverifiable Validator Locations

3

Roger Wattenhofer and Quentin Kniep propose accelerating Solana’s block production by scheduling validators with nearby locations consecutively. This plan introduces an unverifiable physical input into the block producer order by relying on self-reported locations. Each scheduled turn for block production is referred to as a leader window.

The objective is to reduce the dependency of fast handovers on proximity to Solana’s major stake centers. According to the authors’ simulations, this approach reduces the mean handover delay between honest validators from 36.2 milliseconds to 17.0 milliseconds without increasing the number of leader windows for any validator. Reordering also alters control continuity, allowing three-window groups to merge into longer consecutive sequences.

Wattenhofer, Anza’s head of research and a professor at ETH Zurich, co-authored the geographic schedule with Kniep, who identifies as a researcher at Anza and ETH Zurich. Their SIMD-0675 draft highlights a specific tension, recording six adversarial windows in succession under the proposed three-window setting.

Both the scheduling proposal and its companion location-registration proposal were submitted as pull requests on September 29. As of October 7, they remain open. These represent proposed rules and modeled outcomes rather than results from a deployed geographic schedule.

Geographic order for identical allocations

Under the proposed design, Solana would first calculate its stake-weighted random leader schedule as usual. A second pass would then rearrange those leader windows into small groups, known as bins, based on reported geographic proximity.

A leader is the validator assigned to build blocks during a specific window. Every validator would retain exactly the number of windows allocated in the original schedule; the change affects only the timing of those opportunities and which leader precedes them.

The preceding leader is significant under Alpenglow’s fast leader handover mechanism, where the previous leader sends its block directly to the next one. The authors argue that a random schedule favors validators located near large concentrations of stake, as they are more likely to be close to the leader they follow, whereas remote validators often face longer transmission hops.

Grouping nearby leaders aims to provide validators outside major hubs with more local handovers. The intended decentralization benefit is an incentive to operate away from existing hubs, rather than a redistribution of stake or an increase in leader allocations. The simulations measure scheduling and latency, leaving actual operator relocation and stake concentration outside their scope.

The draft pairs a three-window bin size with a 10% stake floor. This floor defines how widely a validator’s neighborhood must extend to accumulate sufficient stake. A densely populated location requires a smaller radius, while a sparse area needs a larger one. The floor covers active stake with valid reported locations. A completed bin may contain less than 10% of stake and include repeated windows from the same operator.

The run-length simulation utilizes the mainnet stake distribution from epoch 1038, involving 661 validators whose locations were corrected using Globalping measurements. Each simulated epoch contains 108,000 leader windows, and the results are averaged across five random seeds.

Geographic distance determines bin membership. To evaluate handover speed, the model maps validators to the nearest RIPE Atlas metropolitan area and estimates one-way latency as half the median round-trip time between those areas. Handovers within a single metro area are assigned zero latency.

With a random schedule, the mean delay between honest validators is 36.2 milliseconds. With three-window bins, this drops to 17.0 milliseconds. The median across all handovers, representing a different population, falls from 23.4 milliseconds to 4.5 milliseconds.

These results support a substantial modeled reduction in transfer delay. However, slot duration and transaction finality measure different intervals from the modeled transfer delay. The zero-delay assumption within metros also simplifies the network conditions that validators actually experience.

There is a broader reason to treat geography as a useful but imperfect shortcut. An August study published by the Solana Foundation associated greater distance with handoff penalties but warned that it had not identified distance as the direct cause. Routing, peering, and validator infrastructure remained unobserved.

Why Solana’s new 250ms speed boost could actually trigger network instability

Consecutive control and location incentives

The security trade-off is evident in the same simulation. An adversary holding 5% of total stake and located in Sydney, with no other validator in Oceania, serves as an example. The authors describe this isolated placement as close to a worst-case scenario because the attacker can fill bins independently.

This example is significant alongside the 10% stake floor. While the floor governs neighborhood construction, the isolated 5% attacker illustrates how actual control of a bin can differ from that radius threshold.

An attacker leading the next bin can extend its control across the boundary. At the proposed setting, the longest adversarial sequence observed was six windows, consisting of two consecutive bins. The design allows adjacent bins to extend consecutive control beyond the configured bin size.

Solana's geographic speed plan trusts validator locations the network cannot verify

The draft acknowledges that regional power, network, or jurisdictional disruptions could now affect consecutive leaders, potentially producing longer skipped-slot sequences than a fully random schedule. It also identifies the possibility of more effective regional censorship during a run.

Using the draft’s assumptions of four slots per leader window and 200-millisecond slots, a three-window bin ideally spans 2.4 seconds. This figure describes one bin under the stated timing assumptions, though regional exposure can cross bin boundaries.

Solana nearly froze as a single routing error took 29% of the network stake offline

The authors recognize an additional speed-versus-security choice. An alternative added on October 2 would arrange leaders along the shortest geographic path within each bin. The draft does not adopt this approach, explaining that it would weaken randomized schedule symmetry and make adjacent slots more predictable for co-located adversarial validators.

The companion SIMD-0674 specification would place self-reported coordinates in validators’ vote accounts. Signed updates establish who authorized a registration, and a geometric check ensures the reported point lies near Earth’s surface. The machine’s actual location remains outside these checks.

SIMD-0675 relies on an economic argument: reporting a distant location will often place a validator behind leaders that are farther from its real machine, making its own handovers slower.

The authors tested this argument by taking the largest validator in each of ten cities, leaving them physically in place, and changing their registered city. The modeled Ashburn validator reduced its mean handover delay from 23.7 milliseconds to 21.0 milliseconds by claiming São Paulo, a reported improvement of 2.7 ± 0.2 milliseconds.

The authors reported no other non-equivalent lie gaining more than 0.3 milliseconds.

The experiment also formed neighborhoods and bins using RIPE Atlas latency, whereas the proposed schedule uses geographic distance. The individual-validator incentive results leave coordinated malicious location reporting and its effects on consecutive control unresolved.

False reporting often hurts the sampled validator’s speed, but the Ashburn exception limits the case for trusting physical location through economic incentives alone.

Timing compensation and the review ahead

Another figure in the proposal can obscure the speed claim. SIMD-0675 would raise HANDOVER_COMPENSATION from 25 milliseconds to 50 milliseconds, even as transfer delays fall.

The separate compensation proposal accounts for optimistic block production already performed before ParentReady, the protocol event that starts the counted production timer. Compensation subtracts time from the first slot’s production budget after that event and shifts leader-window timeouts earlier. It is a timing adjustment rather than a change in validator pay.

The geographic simulation increases the interval from receiving the previous leader’s block to ParentReady from 23.2 milliseconds to 46.2 milliseconds. This separate interval accounts for the larger compensation value even as transfer delay decreases.

The scheduling pull request currently shows no reviews. The location-registration pull request received approval from buffalojoec on October 5, with a caveat about potentially separating vote-account layout changes, but remains open. The Foundation’s October 1 changelog likewise lists both changes as proposed while listing Alpenglow under Devnet feature gates.

Solana moves Alpenglow into testnet as SOL nears January highs

The schedule itself is consensus-critical and would require a feature gate; the draft still leaves its feature key and tracking issues unfilled. Its proposed transition would use the new algorithm from two epochs after activation.

The key review question is whether the modeled reduction in delay and co-location advantage justifies the changed continuity of block production.

The post Solana’s geographic speed plan trusts validator locations the network cannot verify appeared first on CryptoSlate.