How Solana Shrugged Off a 6 Tbps DDoS
Solana reportedly absorbed a sustained ~6 Tbps volumetric DDoS attack with no downtime. That's real progress. It's also not the same thing as being protected.
Independent network scans with methods, timelines, and raw artifacts. Findings are reproducible; data and scripts are in GitHub.
Questions about methodology or findings? Check out our GitHub to discuss or contribute.
Solana reportedly absorbed a sustained ~6 Tbps volumetric DDoS attack with no downtime. That's real progress. It's also not the same thing as being protected.
I assumed Cloudflare would protect me from all denial-of-service attacks. It doesn’t. A reality check on origin IP bypasses, non-HTTP floods, and why the gap between the edge and your kernel matters.
Demonstrating the complete XDP detection pipeline with MQTT eventing. Shows kernel-level SYN-flood detection, userspace processing, and real-time remote alerting - all in milliseconds.
Validator nodes face constant exposure. This deep dive explains how NullRabbit Guard uses eBPF and XDP to enforce security directly inside the NIC driver, dropping scans and abnormal traffic at line rate before they reach the kernel or your node.
NullRabbit's September 2025 benchmark provides a consolidated security snapshot of all Sui validators. Scores ranged from 15 to 93, with a median of 45, and 18.5% meeting our good practice threshold. This dataset and heatmap give validators tools to improve, while offering delegators transparency when choosing staking providers.
Recent Ethereum validator slashings showed how fragile infra can be. Our scan of Sui uncovered something worse: nearly 40% of validator voting power exposed.
NullRabbit's August 2025 scan of the Sui validator set revealed nearly 40% of voting power exposed to SSH, CVEs, and misconfigurations - leaving the network one step away from consensus failure.
Introducing our new research hub where we share insights on DePIN security, blockchain infrastructure, and decentralized network protection.