The Solana Foundation has launched a series of security measures, just days after the decentralized finance platform Drift Protocol suffered a $270 million hack orchestrated by a North Korean state-affiliated group, which exploited the platform's vulnerabilities through a six-month social engineering campaign. At the forefront of this initiative is Stride, a structured evaluation program led by Asymmetric Research, designed to assess Solana DeFi protocols against eight key security pillars, with the findings to be made publicly available. Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based group of security firms and researchers focused on providing real-time crisis response. Although these initiatives address some of the issues exposed by the Drift hack, they do not directly address the root cause of the loss.
The Drift smart contracts were not compromised, and the code had passed audits. The vulnerability lay in human error: the attackers spent six months building relationships with Drift contributors and compromised their devices through a malicious code repository and a fake TestFlight app.
Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with the level of coverage tailored to each protocol's risk profile. For protocols with over $100 million in TVL, the foundation will also fund formal verification, a mathematical method that checks every possible execution path in a smart contract to guarantee correctness.
The founding members of the network include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow. The network is available to all Solana protocols, with priority given to those with higher TVL.
Read more: How North Korea's 6-month secret espionage program has the crypto community reevaluating security. However, Stride's formal verification would not have detected the North Korean attack, which used compromised devices to obtain multisig approvals that were then locked into durable nonce transactions and executed weeks later. Neither would 24/7 monitoring of on-chain activity, as the transactions were valid by design and indistinguishable from legitimate administrative actions until they were used to drain the vaults. The attack exploited the gap between on-chain correctness and off-chain human trust, a gap that no smart contract audit or monitoring tool is designed to cover.
On the other hand, SIRN could have potentially aided in the response. ZachXBT, an on-chain security expert, criticized stablecoin issuer Circle Internet (CRCL) for failing to freeze over $230 million of its stolen dollar-pegged USDC during a six-hour window after the attack began. A dedicated incident response network with established relationships to bridge operators, exchanges, and stablecoin issuers might have shortened the response time.
However, it is uncertain whether it would have been fast enough to prevent the Wormhole bridging and obfuscation through Tornado Cash. The foundation emphasized that the programs 'do not transfer the underlying responsibility away from the protocols themselves,' a statement that takes on a different meaning after Drift's postmortem revealed that individual contributor devices were the entry point for a nation-state attack. Solana already offers several free security tools for builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.