Cardano In Crisis Mode: Hoskinson Breaks Down The Poison Piggy Attack

bitcoinist发布于2025-11-25更新于2025-11-25

文章摘要

Cardano has just come through one of the most severe technical incidents in its history – a 14-hour chain split...

Trusted Editorial content, reviewed by leading industry experts and seasoned editors. Ad Disclosure

Cardano has just come through one of the most severe technical incidents in its history – a 14-hour chain split that founder Charles Hoskinson insists was “serious, but not existential.” In a late-November livestream, he walked viewers through Pi Lanningham’s “Poison Piggy – After Action Report,” a detailed post-mortem on what happened on November 21, 2025, and what it means for Cardano’s long-held “no downtime” narrative.

Inside Cardano’s 14-Hour Pig-Chain Meltdown

According to Lanningham, a serialization bug in Cardano’s node implementation created the conditions for a unidirectional soft fork. The issue first surfaced on November 20 on the preview testnet, when a malformed delegation certificate was accepted by some nodes and rejected by others. Older nodes correctly rejected the over-long hash; newer nodes, due to a November 2024 code change, truncated it and treated it as valid. That version skew created two incompatible views of the chain.

“The whole reason the testnet exists is to be a safe space” to find these failures, Hoskinson noted. Under normal circumstances, the bug would have been patched and quietly rolled out. Instead, after the fix was identified and was in the process of being communicated to stake pool operators, a near-identical malformed delegation was submitted to mainnet, this time delegating to RATSRATS – conceptually doubling the ticker of RATS, Hoskinson’s own stake pool.

That transaction split Cardano mainnet into two forks. The stricter fork, running older code that rejected the malformed hash, became the “chicken chain.” The permissive fork that accepted it was christened the “pig chain” or “poison piggy.” From that point, the network entered a race: would the poisoned transaction on the pig chain become immutable before the chicken chain could overtake it?

On impact, Lanningham’s numbers are blunt. Cardano remained live but degraded. Transaction inclusion via robust infrastructure slowed dramatically, with delays of up to roughly 400 seconds and block times on the now-dominant chain stretching to around 16 minutes at their worst. Over the incident window, 846 blocks were produced on the pig chain and around 13,900 on the chicken chain. Out of 14,383 observed transactions, 479 – roughly 3.3 percent – were included only on the discarded pig chain and never appeared on the final canonical history. Most of those, when resubmitted, turned out to be invalid due to expired validity intervals or conflicting inputs.

“This constitutes a serious degradation of service for users, but within expected bounds for a high-nines availability of service,” Lanningham wrote. His bottom-line checklist is terse: “Did the chain continue to make progress? Yes. Was service degraded? Yes. Were funds at risk? Potentially. Did the Cardano network recover under essentially worst case conditions? Yes. Would I have confidence to build my business on top of infrastructure that exhibited this level of robustness? Yes.”

The recovery itself is being held up by Hoskinson as proof of both decentralization and design. A patched node was already available thanks to the testnet incident; overnight, IOG, the Cardano Foundation, Emurgo, Intersect, exchanges and many SPOs coordinated via war-room calls and chat channels to upgrade to the fixed version and to follow the more restrictive chicken chain. There was no protocol-level rollback and no centralized “restart.” As stake migrated, block production on the pig chain slowed, the chicken chain accelerated, and Ouroboros’ probabilistic finality properties ensured that once the healthy fork overtook the poisoned one, nodes on the pig chain automatically switched to the longer, denser chain.

“This is the concrete evidence of when the Nakamoto consensus worked as intended and converged the network to a single canonical history,” Lanningham argued. Hoskinson went further, saying, “This could have killed other chains,” but here “time works differently in a distributed system” and effectively stretched the rollback window in Cardano’s favor.

Lessons Learned

Both, however, are clear about the downside. “The fact the bug appeared at all is a failure of our testing rigor,” Lanningham conceded. The reliance of almost all explorers on cardano-db-sync left the ecosystem “flying blind” when that component crashed on the malformed transaction. Many SPOs likely upgraded “blind,” trusting recommendations from founding entities rather than reasoning independently about fork choice. And certain off-chain systems – especially exchanges and bridges – were exposed to replay and double-spend risk, even if early evidence suggests real losses are unlikely.

The post-mortem thus doubles as a roadmap. Lanningham calls for stronger fuzzing and spec-driven testing, richer node-to-client protocols so wallets and exchanges can implement circuit breakers based on real consensus health, more diversity in monitoring stacks, and better education for SPOs on how Ouroboros behaves under stress. Hoskinson, for his part, floated the idea of an AI “upgrade sentinel” for operators and revived demands for a built-in pub/sub channel for emergency alerts.

For the broader narrative war, Lanningham’s position is deliberately dispassionate: “If, after that, you decide for yourself that Cardano ‘went down’, I won’t begrudge you your opinion. I’m not precious about that label… What matters is impact.” Hoskinson is less diplomatic, dismissing most social-media commentary as noise. What he wants the industry to take away is simpler: on November 24, 2025, after Poison Piggy, Cardano is back to one chain – and its next iteration of hardening has already begun.

At press time, ADA traded at $0.4141.

Cardano price
ADA remains at critical level, 1-week chart | Source: ADAUSDT on TradingView.com
Featured image created with DALL.E, chart from TradingView.com
Editorial Process for bitcoinist is centered on delivering thoroughly researched, accurate, and unbiased content. We uphold strict sourcing standards, and each page undergoes diligent review by our team of top technology experts and seasoned editors. This process ensures the integrity, relevance, and value of our content for our readers.

Jake Simmons has been a Bitcoin enthusiast since 2016. Ever since he heard about Bitcoin, he has been studying the topic every day and trying to share his knowledge with others. His goal is to contribute to Bitcoin's financial revolution, which will replace the fiat money system. Besides BTC and crypto, Jake studied Business Informatics at a university. After graduation in 2017, he has been working in the blockchain and crypto sector. You can follow Jake on Twitter at @realJakeSimmons.

热门币种推荐

你可能也喜欢

2万亿美元,AI史上最大IPO进入倒计时

AI公司Anthropic预计将于今年十月进行IPO,估值可能突破2万亿美元,这将是史上最大规模的AI公司上市。其估值由六位投资人根据模型推算得出,其中有人甚至预估超过3万亿美元。公司内部对此并未设定明确目标。 Anthropic在短短五年内实现了惊人增长,从初创公司迅速跻身巨头行列。2025年底年化收入约90亿美元,到2026年5月已飙升至470亿美元,第二季度营收达115亿美元,同比激增14倍。内部预测,到2028年营收可能达到1900亿至2000亿美元。 公司收入主要依靠API和企业合同,按调用量计费,其中编程辅助工具Claude Code是增长核心,贡献近两成收入,在企业和开发者中广泛使用。 然而,公司内部正面临文化撕裂。CEO达里奥·阿莫代伊及其核心团队带有强烈的“拯救人类”使命感,被部分员工形容为“祭司阶层”,其管理风格引发基层员工不满,甚至出现了秘密的吐槽网络。员工在即将到来的财富自由与压抑的工作环境之间陷入挣扎。 Anthropic目前处境微妙:追求最安全的AI需要巨额算力投入,而这又依赖于资本市场支持,迫使公司在理想与商业现实间寻找平衡。其IPO前景虽被看好,但SpaceX上市后股价大跌的前例,以及监管、成本和内部治理等挑战,都为其未来增添了不确定性。

marsbit刚刚

2万亿美元,AI史上最大IPO进入倒计时

marsbit刚刚

降本增效的AI,让VC越来越烧钱

《降本增效的AI,让VC越来越烧钱》一文指出,尽管AI技术降低了创业公司的部分运营和开发成本,却推高了风险投资(VC)获取优质AI公司股权的价格。AI领域融资呈现“杠铃型”结构:一方面,普通初创企业融资规模趋于小额化;另一方面,顶尖团队(如来自OpenAI、Google DeepMind的核心人员)的早期项目估值急剧膨胀,数亿甚至上百亿美元的融资与估值在成立初期便已出现。 这种趋势导致VC持股成本显著上升。早期估值飙升的同时,创始人让渡的股权比例并未同步增加,使得VC为维持相同持股比例所需投入的资金大幅增加。为此,大型风投机构(如Accel、a16z)纷纷募集更大规模的基金,以覆盖从早期进入到后期跟投的全周期,确保在头部项目竞争中不落下风。 资金进一步向少数头部AI项目集中。2026年上半年,全球超70%的创业融资流向AI公司,其中OpenAI和Anthropic两家就占据了全球创业融资总额的43%。这种集中化加剧了VC行业的马太效应,大型基金凭借资金优势持续加码潜在赢家,而小型基金参与热门项目的能力受到削弱。 然而,高估值已提前计入了未来增长预期。若企业最终无法实现与估值匹配的商业化规模,投资回报将面临压缩。目前,许多基金的账面收益仍依赖后续融资的估值重估,而非实际退出。对大型VC而言,当下的核心策略已转变为:在技术“超级周期”中尽早押注潜在龙头,并为伴随估值飙升的持续跟投储备充足弹药。AI降低了创业门槛,却让投资优质AI公司的成本变得愈发昂贵。

marsbit26分钟前

降本增效的AI,让VC越来越烧钱

marsbit26分钟前

八年投入急转弯,以太坊为何突然放弃Poseidon?

以太坊基金会研究员Justin Drake近日宣布,以太坊将在Layer 1层放弃已研发八年的SNARK友好型哈希算法Poseidon,转而采用SHA2或BLAKE2等传统哈希函数。这一重大转向源于后量子密码学研究的突破性进展。 Poseidon自2019年起因其在零知识证明电路中的高效性,被广泛用于zkRollup等应用。但其算法历史较短,密码学分析时间不足。而随着后量子安全成为硬性要求,其局限性显现。最新的SNARK设计,特别是基于“二进制域”的证明系统(如Binius和Flock),已能高效处理传统哈希函数的布尔运算,使得SHA2等成熟算法在证明性能上可媲美甚至超越Poseidon,消除了采用后者的主要优势。 另一关键因素是应对量子计算威胁的时间表正在加速。报告预测“量子破译日”可能在本世纪30年代初到来,将对区块链资产构成巨大风险。以太坊因此需要尽快采用经过长期密码分析验证的、抗量子攻击能力更强的哈希方案。其后续量子路线图计划于2027年推出核心构件leanVM,并在2028年完成共识层、执行层和数据层的部署。 与此同时,其他公链如Solana已选定后量子签名方案Falcon,而StarkNet也计划采用BLAKE2等算法。以太坊此次转向,标志着技术重点从“设计SNARK友好型哈希”转变为“设计哈希友好型SNARK”,是在后量子时代选择更成熟、更稳健的密码学基元的战略调整。

marsbit1小时前

八年投入急转弯,以太坊为何突然放弃Poseidon?

marsbit1小时前

全球程序员都在给Anthropic白送钱!官方终于看不下去了

Anthropic官方发布博客,针对开发者使用Claude Code时可能产生的不必要高额费用,总结了六条核心省钱建议: 1. 任务完成后及时使用 `/clear` 清理对话,避免无关历史占用上下文。 2. 对话开始时固定好模型和推理强度,中途切换会导致提示缓存失效,需全价重新计算历史。 3. 使用 `@` 引用文件,而非手动输入路径,可避免Claude进行工具调用和试探性读取,减少上下文累积。 4. 为输出冗长的命令(如运行测试)添加静默参数,减少输出内容对上下文的占用。 5. 在会话缓存仍有效时(如休息前)进行 `/compact` 压缩对话,成本仅为十分之一。 6. 将产生大量输出的任务交由子Agent处理,其独立上下文不会污染主对话。 文章解释了费用产生的机制:输入token(预填充)成本较低,输出token(解码)成本约为其5倍。模型(Opus/Sonnet/Haiku)和推理强度直接影响单价和token数量。 **提示缓存是关键的省钱杠杆**:若请求前缀与之前完全相同,服务器可加载缓存结果,读取成本仅为正常输入价的10%。但切换模型、改变推理强度、执行压缩、缓存过期等操作都会导致缓存失效。 此外,对话历史会因不断追加文件内容和命令输出而“变胖”,导致后续每轮对话成本呈接近平方级(O(n²))增长。除了上述建议,还可使用 `/rewind` 回退无效轮次以保住前面缓存。 文章指出,管理token开销正成为AI时代开发者的新技能,关系到使用效率和成本控制。Anthropic自身大量使用AI编写代码,精细的成本管理至关重要。

marsbit3小时前

全球程序员都在给Anthropic白送钱!官方终于看不下去了

marsbit3小时前

交易

现货

热门文章

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对ADA(ADA)币价的意见。

活动图片