In response to the recent $270 million exploit of DeFi platform Drift Protocol, the Solana Foundation has announced a range of security measures. The centerpiece of this initiative is Stride, a structured evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings.
Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based group of security firms and researchers focused on providing real-time crisis response. While these measures address some of the vulnerabilities exposed by the Drift exploit, they do not directly address the human element that was compromised, as the attackers spent six months building relationships with Drift contributors and compromising their devices through malicious means. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with coverage tailored to each protocol's risk profile.
For protocols with over $100 million in TVL, the foundation will also fund formal verification, a method that mathematically checks every possible execution path in a smart contract to guarantee correctness. The network is available to all Solana protocols but prioritizes those with higher TVL.
Founding members of SIRN include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow. Although Stride's formal verification would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals, a dedicated incident response network like SIRN could have potentially shortened the response time. The foundation emphasizes that these programs do not shift the underlying responsibility away from the protocols themselves, highlighting the importance of individual contributor device security in preventing such attacks. Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.