In response to the recent $270 million Drift Protocol exploit, the Solana Foundation has launched a series of security initiatives. The centerpiece of this effort is Stride, a comprehensive evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings. Additionally, the foundation has established the Solana Incident Response Network (SIRN), a membership-based group of security experts and researchers focused on providing real-time crisis response.

These initiatives aim to address the vulnerabilities exposed by the Drift hack, although they do not directly address the human element that was exploited in the attack. The Drift Protocol's smart contracts were not compromised, and the code had passed audits; however, the attackers had spent six months building relationships with Drift contributors and compromised their devices through malicious means.

Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants. For protocols with over $100 million in TVL, the foundation will also fund formal verification, a mathematical method that checks every possible execution path in a smart contract to ensure correctness. The SIRN is available to all Solana protocols, with priority given to those with higher TVL. While these initiatives are a step towards enhancing security, they may not have prevented the North Korean attack, which exploited the gap between on-chain correctness and off-chain human trust.

However, a dedicated incident response network like SIRN could have potentially shortened the response time to the attack. The foundation emphasizes that these programs do not shift the underlying responsibility away from the protocols themselves. Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.