In the wake of a $270 million exploit on the Drift Protocol, the Solana Foundation has unveiled a robust suite of security measures. Central to this initiative is Stride, a thorough evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings.
Additionally, the Solana Incident Response Network (SIRN) has been established, comprising a group of security firms and researchers focused on providing real-time crisis response. While these measures address some of the vulnerabilities exposed by the Drift hack, they do not directly tackle the human element that led to the breach. The attackers had spent six months establishing relationships with Drift contributors, ultimately compromising their devices through malicious means.
Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants. Protocols with over $100 million in TVL will also receive funding for formal verification, a process that mathematically verifies the correctness of smart contracts. The SIRN is available to all Solana protocols, with priority given to those with higher TVL.
Founding members include OtterSec, Neodyme, Squads, and ZeroShadow. Although Stride's formal verification would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals, the SIRN could have potentially improved the response time. The foundation emphasized that these programs do not shift the responsibility for security away from the protocols themselves, highlighting the importance of individual contributor device security.
Solana already offers several free security tools for builders, including Hypernative, Range Security, and Neodyme's Riverguard.