Incident ·
The interconnect failed. Solana didn’t.
On Wednesday, August 12, Solana mainnet kept producing blocks and it kept finalizing them. No client bug. No halt. No status-page incident on the cluster. Jacob Creech’s figure: 597 of 699 staked identities stayed in the vote. The protocol did what thirty months of no halt said it would do.
What failed sat under a subset of the validator set, not inside it. Terraswitch’s private interconnect dropped a default route across twelve European and Asia-Pacific sites. The public internet in front of those machines was still there. Transit did not withdraw. Peering did not flap. Boxes stayed powered. Processes stayed up. The path off that fabric was gone, so those nodes could not receive shreds or land votes until the IGP came back.
That is an operator problem with a clean ending. The cluster did not need a patch. The operators on those sites needed a second path that was not the hosting interconnect. A few already had one and came back clean. SolanaCDN is how the rest of the set gets that path — on a normal Tuesday for faster shreds, and on a night like this so they never leave the cluster in the first place.
597 / 699
staked identities stayed in the vote
12 sites
partitioned on Terraswitch’s interconnect
3 operators
came back on their own second path
What actually broke
This was not a Solana outage and it was not an internet outage.
Terraswitch’s regions are stitched together by a private backbone. Inside each site, the data-center fabric forwards to a local edge when that edge announces an internal default (0.0.0.0/0): the signal that this site can reach the internet. That default is supposed to stay local, distinguished by metric and communities.
In the early hours of August 12 UTC (late evening August 11, PT), a default associated with MIA1 in Miami was propagated with those attributes stripped. Terraswitch’s working statement is that the route never existed as a valid route on MIA1’s routers. A route reflector at AMS2 pushed the altered advertisement into EU and APAC. That is the interconnect: the control plane that binds the regions, not a public transit link.
Edge routers at the far sites read it as locally originated and preferred it over their real local default. They advertised it into the core. The core rejected it. With no acceptable default left, the site fabrics stopped forwarding to their own edge routers.
Hosts lost two things at once:
- The private backbone between Terraswitch sites.
- The path through that fabric to the edge that still had the public internet.
Twelve sites: LON1, AMS1–3, DUB1–2, FRA2, SGP1–2, TYO1–3. North American Terraswitch sites were outside that IGP domain and stayed up. Engineers pulled MIA1 off the private backbone within about ten minutes. Traffic restored 04:16:15 UTC. Nodes took a bit longer to look healthy — Marinade’s window is about 33 minutes, the Foundation said recovery within 40 — because restoring an IGP default is not the same as catching a Solana validator back up to a live slot.
The tell is MIA1 after mitigation. Off the interconnect, it stayed reachable over the public internet. The internet path worked. The cluster worked. The interconnect did not.
Why that takes a validator off the cluster — and why it doesn’t have to
A Solana validator is a real-time participant, not a web server that can sit through a routing event and come back. Inbound it lives on TVU: leaders shred, Turbine fans the tree, Reed-Solomon recovers loss. First-shred latency is replay, vote timing, and leader readiness. Outbound, votes and leader shreds leave through gossip, TPU, and stake-weighted QoS. Miss the window and you miss the credit. Miss a leader slot and you skip. Repair cannot put you back in a slot you already missed.
On a typical single-homed host, all of that shares the site fabric’s default. When the interconnect dropped it, those sockets failed as one. Not because Solana stopped. Not because the IX went away. Because the box could not leave the fabric.
Marinade later counted on the order of 90 validators in that set, and 333 SOL in missed rewards, covered by validator bonds. Helius was in the window. Fifty-nine validators holding 80.2 million SOL in Amsterdam, Frankfurt, and Tokyo came back in the same narrow band — they waited for Terraswitch’s IGP. Of 74 operators Marinade could score, three came back clean on their own redundancy: Laine, Cogent Crypto, and Lion3d.
Read that as a product brief. The cluster had more than enough stake still voting. Three operators proved a second path works. Everyone else proved that a second process, a second VM, or a second identity on the same prefix is not one. A hot-spare that still exits through the same interconnect is not one either.
One other overlay in this ecosystem is worth naming once, so nobody confuses it for that path. DoubleZero’s useful work is getting the block to traders and searchers. Validators publish; the feed faces the other way. It does not write Turbine back onto a validator’s TVU, and Terraswitch is a contributor to that fabric, with devices in the same metros that went dark. Different job. Different customer. Not a spare ingest for a node behind a dead IGP.
The path that stays on the cluster
Keep the box where it is. Same rack, same Terraswitch site, same overnight window. Give the node a shred path that does not traverse AS20326’s IGP.
Native Turbine over the site default still dies. Gossip that was riding the interconnect still dies. Shreds are still being produced — by Creech’s 597, by North America, by every other ASN. The public internet is still moving them. A feed that collects that Turbine stream off the partitioned interconnect and writes it into the local TVU socket is how a node behind a dead fabric default keeps replaying the chain. That is the whole counterfactual. Terraswitch partitioned its interconnect. It did not have to partition the validators on it from mainnet.
SolanaCDN is that path.
It is not a consensus client. It does not replace Agave or Firedancer. It does not touch leader schedule, Tower, or voting rules. It is an out-of-band shred acceleration and relay layer on Pipe’s overlay. A Point of Presence collects the live mainnet Turbine feed on a network that is not AS20326’s IGP and writes raw shreds at your validator’s UDP TVU port — stock Agave ingest, no fork, no sidecar — or delivers the same feed over an authenticated QUIC session. Native Turbine, gossip, and repair keep running. Extra datagrams on the same TVU socket. Whichever source arrives first wins the gap.
You run it on a normal Tuesday because first-shred latency is replay latency, and replay latency is vote timing and leader readiness. A second ingest path that is not your position in the Turbine tree cuts the variance geography and tree depth put on a well-run node. You land votes tighter. You are current when your leader window opens.
You run it on a night like August 12 because you are not waiting on Repair and a snapshot to learn what the last 80 slots were. The listed POPs include London, Frankfurt, Amsterdam, Tokyo, and Singapore — the same metros, not the same fabric — plus North American and Sydney sites. Same cities. Different network. The shreds arriving on TVU did not have to traverse Terraswitch’s default, Terraswitch’s route reflector, or Terraswitch’s private backbone.
Most CDN language is written the other way: if the overlay dies, native Turbine continues. That is how SolanaCDN is built — non-blocking, best-effort, fail-safe. August 12 is the reverse case, and it is the one single-homed hosts are under-provisioned for. The public internet was still there. The cluster was still there. The hosting IGP was not. The redundancy layer is a path that writes shreds back onto the box, on a network that is not that interconnect.
Restore time is not current time
A status-page restore at 04:16 UTC is not the same as being current at 04:16 UTC. Staying on the feed is how those two times collapse back into one.
What to run before the next interconnect event
The next ticket will not say “Terraswitch.” It will look like this one: a preferred route with the wrong attributes, a reflector that did its job, a fabric with nothing valid to install. It will get written up as “the internet,” or worse, as “Solana.” It will have been neither.
If you are single-homed on one hosting ASN, you are in that set. If your backup is another process or another identity on the same prefix, you are still in that set. If your other overlay does not write shreds back onto the validator, you are still in that set.
Run the second path.
- Keep stock Agave or Firedancer. Do not fork consensus to buy connectivity.
- Put SolanaCDN on the TVU socket you already have. Measure first-shred vs native Turbine on a normal day so you know the overlay is live before you need it.
- Treat diversity as a property of paths, not of logos. The test is simple: do shreds still arrive when the hosting interconnect withdraws its default?
- If you operate RPC, the same partition that takes a validator off the vote 522s the endpoints in front of it. A shred feed that does not share that interconnect is how the node stays current.
Solana’s client software earned August 12. The cluster produced and finalized through a twelve-site hosting fault with most of the validator set still voting. That is the story. The operators who only had one path through that interconnect do not have to share its fate next time. Three of them already don’t.
SolanaCDN is the second path. Same machine. Same site. Different network. Still on the cluster.
Public UDP
Put SolanaCDN on TVU
Register the node’s UDP TVU. Stock Agave treats the datagrams like Turbine. Same rack. Different network.
Prepaid
Start a subscription
Wallet sign-in, then the prepaid invoice. Delivery is best-effort. No SLA.
Sources
- Terraswitch incident write-up (status page, Aug 12, 2026)
- Marinade Finance analysis, Aug 12, 2026
- Solana Foundation changelog, Aug 13, 2026
- Jacob Creech comments as reported Aug 12–13
- SolanaCDN public architecture (solanacdn.com)