In response to the recent $270 million exploit of Drift Protocol, the Solana Foundation has announced a range of security initiatives aimed at bolstering the network's defenses. The cornerstone of this effort is Stride, a rigorous evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings. Additionally, the foundation has established the Solana Incident Response Network (SIRN), a membership-based group of security experts and firms focused on providing real-time crisis response. While these initiatives address some of the vulnerabilities exposed by the Drift hack, they do not directly address the root cause of the exploit, which was a result of human error rather than a flaw in the protocol's smart contracts.
The attackers had spent six months building relationships with Drift contributors, ultimately compromising their devices through a malicious code repository and a fake TestFlight app. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants.
Protocols with over $100 million in TVL will also be eligible for formal verification, a mathematical method that checks every possible execution path in a smart contract to ensure correctness. The SIRN network, which includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, will be available to all Solana protocols, with priority given to those with higher TVL. However, it is worth noting that even with these enhanced security measures in place, the North Korean attack that exploited Drift Protocol may not have been preventable, as it relied on compromised devices to obtain multisig approvals that were then locked into durable nonce transactions. Nevertheless, the SIRN network could have potentially facilitated a more rapid response to the attack, highlighting the importance of incident response and collaboration between security experts, bridge operators, exchanges, and stablecoin issuers.
The Solana Foundation has emphasized that these new programs do not shift the underlying responsibility for security away from the protocols themselves, a point that takes on added significance in light of the Drift postmortem, which revealed that individual contributor devices were the entry point for the nation-state attack. Solana already offers a range of free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.