In response to the recent $270 million exploit of DeFi platform Drift Protocol, the Solana Foundation has announced a multifaceted security overhaul. Unveiled just five days after the attack, which was carried out by a North Korean state-affiliated group, the suite of initiatives aims to bolster the security of Solana's DeFi ecosystem. A key component is Stride, a thorough evaluation program led by Asymmetric Research, designed to assess Solana DeFi protocols against eight critical security pillars, with findings to be made publicly available.

Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based collective of security firms and researchers focused on providing real-time crisis response. Protocols with over $10 million in total value locked (TVL) that pass the Stride evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with the level of coverage tailored to each protocol's specific risk profile.

For larger protocols with over $100 million in TVL, the foundation will also provide funding for formal verification, a rigorous mathematical method that verifies the correctness of every possible execution path in a smart contract. The SIRN network, which includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, will be available to all Solana protocols, with priority given to those with higher TVL.

While these initiatives address certain vulnerabilities, they do not cover the human element that was exploited in the Drift attack, where attackers spent six months building relationships with Drift contributors and compromised their devices through malicious means. The Solana Foundation has emphasized that these programs do not shift the fundamental responsibility for security away from the protocols themselves, highlighting the importance of individual protocol security measures. The foundation already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.