In response to the recent $270 million exploit of the Drift Protocol, the Solana Foundation has announced a series of security measures aimed at bolstering the network's defenses. The centerpiece of this effort is Stride, a comprehensive evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings.

Additionally, the foundation has introduced the Solana Incident Response Network (SIRN), a collaborative effort between security firms and researchers focused on providing real-time crisis response. While these initiatives address certain vulnerabilities, they do not directly address the human element that led to the Drift exploit, in which attackers spent six months building relationships with Drift contributors and compromised their devices through malicious means. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants.

Protocols with over $100 million in TVL will also receive funding for formal verification, a rigorous mathematical method that verifies the correctness of smart contracts. The SIRN network, which includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, will prioritize protocols based on their TVL. Although the Stride program's formal verification would not have prevented the North Korean attack, which exploited compromised devices to obtain multisig approvals, the SIRN network could have potentially facilitated a more rapid response to the incident. The Solana Foundation has emphasized that these programs do not absolve protocols of their underlying responsibility for security, a point underscored by the Drift postmortem, which revealed that individual contributor devices were the entry point for the nation-state attack.

Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.