In the wake of a $270 million exploit on the Drift Protocol, a decentralized finance platform, the Solana Foundation has unveiled a comprehensive suite of security initiatives. This move comes just five days after the hack, which was carried out by a North Korean state-affiliated group following a six-month social engineering campaign. The cornerstone of this effort is Stride, a structured evaluation program led by Asymmetric Research, designed to assess Solana DeFi protocols against eight security pillars, with the findings to be made public.

Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based group of security firms and researchers focused on providing real-time crisis response. While these initiatives address part of the issue exposed by the Drift hack, they do not directly tackle the underlying mechanics that led to the loss. The Drift hack was facilitated by the attackers building relationships with Drift contributors over six months, compromising their devices through a malicious code repository and a fake TestFlight app, rather than exploiting the smart contracts themselves. Under the Stride program, protocols with more than $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with the level of coverage tailored to each protocol's risk profile.

For protocols with over $100 million in TVL, the foundation will also fund formal verification, a mathematical method that checks every possible execution path in a smart contract to ensure correctness. The founding members of SIRN include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow, with the network available to all Solana protocols, prioritized by TVL. However, it is noted that Stride's formal verification would not have detected the North Korean attack, which utilized compromised devices to obtain multisig approvals that were then locked into durable nonce transactions and executed weeks later. Similarly, 24/7 monitoring of on-chain activity would not have identified the transactions as they were valid by design and indistinguishable from legitimate administrative actions until they were used to drain the vaults.

The attack exploited the gap between on-chain correctness and off-chain human trust, a gap that no smart contract audit or monitoring tool is designed to cover. Nevertheless, SIRN could have potentially aided in the response to the attack.

An on-chain security expert, ZachXBT, criticized stablecoin issuer Circle Internet (CRCL) for not freezing over $230 million of its stolen dollar-pegged USDC during the six-hour window following the start of the attack. A dedicated incident response network with established relationships to bridge operators, exchanges, and stablecoin issuers might have shortened the response time, although it is uncertain whether it would have been sufficient to prevent the Wormhole bridging and obfuscation through Tornado Cash. The foundation emphasized that these programs do not transfer the underlying responsibility away from the protocols themselves, a statement that takes on a different meaning in light of the Drift postmortem, which revealed that individual contributor devices were the entry point for the nation-state attack.

Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.