In response to the recent $270 million exploit of the Drift Protocol, the Solana Foundation has announced a range of security measures aimed at bolstering the network's defenses. The new initiatives, unveiled just five days after the attack, include Stride, a comprehensive evaluation program led by Asymmetric Research that will assess Solana's DeFi protocols against eight key security pillars and make the findings publicly available. Additionally, the Solana Incident Response Network (SIRN) has been established, comprising a group of security firms and researchers focused on providing real-time crisis response. While these measures address some of the vulnerabilities exposed by the Drift hack, they do not directly address the human element that was exploited by the attackers.

The hackers, who were affiliated with a North Korean state-backed group, spent six months building relationships with Drift contributors before compromising their devices through a malicious code repository and a fake TestFlight app. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants.

Protocols with over $100 million in TVL will also be eligible for formal verification, a mathematical method that checks every possible execution path in a smart contract to ensure correctness. The SIRN network, which includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, will be available to all Solana protocols, with priority given to those with higher TVL. However, it is noted that even with these new measures in place, the North Korean attack may not have been prevented, as it exploited the gap between on-chain correctness and off-chain human trust.

The attack used compromised devices to obtain multisig approvals, which were then locked into durable nonce transactions and executed weeks later. The Solana Foundation has emphasized that these new programs do not transfer the underlying responsibility for security away from the protocols themselves, highlighting the importance of individual contributor device security in preventing such attacks.