In the wake of a devastating $270 million exploit of the Drift Protocol, the Solana Foundation has unveiled a multifaceted security overhaul, just five days after the decentralized finance (DeFi) platform fell victim to a sophisticated attack by a North Korean state-affiliated group. The assault, which followed a six-month social engineering campaign, has prompted the foundation to introduce a suite of security measures designed to bolster the network's defenses.
Central to this effort is Stride, a rigorous evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings. Additionally, the Solana Incident Response Network (SIRN) has been established as a membership-based collective of security firms and researchers focused on providing real-time crisis response. While these initiatives address some of the vulnerabilities exposed by the Drift hack, they do not directly address the human element that was exploited in the attack.
The attackers had spent six months building relationships with Drift contributors, ultimately compromising their devices through a malicious code repository and a fake TestFlight app. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with coverage tailored to each protocol's risk profile.
For protocols with over $100 million in TVL, the foundation will also fund formal verification, a mathematical method that checks every possible execution path in a smart contract to guarantee correctness. The SIRN is available to all Solana protocols, with priority given to those with the largest TVL.
Founding members of the network include OtterSec, Neodyme, Squads, and ZeroShadow. Although Stride's formal verification would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals, the SIRN could have potentially accelerated the response to the incident. The attack highlighted the gap between on-chain correctness and off-chain human trust, a vulnerability that existing smart contract audits and monitoring tools are not designed to address. The Solana Foundation has emphasized that these programs do not absolve protocols of their underlying responsibility for security, a point underscored by the Drift postmortem, which revealed that individual contributor devices were the entry point for the nation-state attack.
The foundation already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.