In the wake of a $270 million exploit on the Drift Protocol, the Solana Foundation has introduced a robust security program, unveiled just five days after the hack, which was perpetrated by a North Korean state-affiliated group using a six-month social engineering campaign. The program's centerpiece is Stride, a comprehensive evaluation framework led by Asymmetric Research, assessing Solana DeFi protocols against eight key security pillars, with findings to be made public. Additionally, the Solana Incident Response Network (SIRN) has been established, comprising a membership-based group of security firms and researchers focused on real-time crisis management. While these initiatives address some of the vulnerabilities exposed by the Drift hack, they do not directly tackle the root cause of the loss, which was the result of human error.
The attackers had spent six months building relationships with Drift contributors, ultimately compromising their devices through a malicious code repository and a fake TestFlight app. Under Stride, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with coverage tailored to each protocol's risk profile. For protocols with over $100 million in TVL, the foundation will also fund formal verification, a rigorous mathematical method that checks every possible execution path in a smart contract to guarantee correctness.
The network includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, and is available to all Solana protocols, prioritized by TVL. However, it is noted that Stride's formal verification would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals that were then locked into durable nonce transactions and executed weeks later. Similarly, 24/7 monitoring of on-chain activity would not have detected the attack, as the transactions were valid by design and indistinguishable from legitimate administrative actions until they were used to drain the vaults.
The attack highlighted the gap between on-chain correctness and off-chain human trust, a gap that no smart contract audit or monitoring tool is designed to cover. The SIRN, however, could have potentially aided in the response to the attack.
On-chain security expert ZachXBT criticized stablecoin issuer Circle Internet (CRCL) for failing to freeze over $230 million of its stolen dollar-pegged USDC during a six-hour window after the attack began. A dedicated incident response network with established relationships to bridge operators, exchanges, and stablecoin issuers might have shortened the response time, although it is uncertain whether it would have been fast enough to prevent the Wormhole bridging and obfuscation through Tornado Cash.
The foundation emphasized that these programs do not transfer the underlying responsibility away from the protocols themselves, a statement that takes on a different meaning in light of the Drift postmortem, which revealed that individual contributor devices were the entry point for a nation-state attack. Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.