In response to the recent $270 million Drift Protocol exploit, the Solana Foundation has launched a series of security measures. The centerpiece of this initiative is Stride, a program that evaluates Solana DeFi protocols based on eight security pillars, with the results being made public.
Additionally, the foundation has introduced the Solana Incident Response Network (SIRN), a group of security firms and researchers that provides real-time crisis response. Protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants.
For protocols with over $100 million in TVL, the foundation will also fund formal verification to ensure the correctness of smart contracts. The network is available to all Solana protocols, prioritized by TVL, and founding members include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow. While these measures address some of the security concerns, they may not have prevented the Drift exploit, which was caused by a six-month social engineering campaign that compromised contributor devices. The attack highlighted the gap between on-chain correctness and off-chain human trust, which existing smart contract audits and monitoring tools are not designed to cover.
However, the SIRN could have potentially shortened the response time to the attack. The Solana Foundation emphasized that these programs do not shift the responsibility for security away from the protocols themselves. Solana already offers several free security tools for builders, including Hypernative, Range Security, and Neodyme's Riverguard.