In response to the recent $270 million Drift Protocol exploit, the Solana Foundation has launched a series of security measures. The centerpiece of this initiative is Stride, a rigorous evaluation program led by Asymmetric Research that will assess Solana DeFi protocols against eight key security pillars and publicly disclose the findings. Additionally, the Solana Incident Response Network (SIRN) has been established, comprising a group of security firms and researchers focused on providing real-time crisis response.
While these measures address some of the vulnerabilities exposed by the Drift hack, they do not directly address the human factor that led to the breach. The attackers had spent six months building relationships with Drift contributors and compromised their devices through malicious means. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants. Protocols with over $100 million in TVL will also receive funding for formal verification, a mathematical method that ensures the correctness of smart contracts.
The SIRN network is available to all Solana protocols, with priority given to those with higher TVL. Founding members of the network include OtterSec, Neodyme, Squads, and ZeroShadow. Although the formal verification process would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals, the SIRN network could have potentially shortened the response time.
The foundation emphasized that these programs do not shift the responsibility for security away from the protocols themselves. Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.