In response to the recent $270 million exploit of Drift Protocol, the Solana Foundation has unveiled a range of security measures. The core component is Stride, a systematic evaluation program led by Asymmetric Research, which will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings.

Additionally, the Solana Incident Response Network (SIRN) has been established, comprising a group of security firms and researchers focused on providing real-time crisis response. While these initiatives address some of the vulnerabilities exposed by the Drift hack, they do not directly address the root cause of the exploit, which was a result of human error. The attackers had spent six months building relationships with Drift contributors, eventually compromising their devices through a malicious code repository and a fake TestFlight app.

Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants. Protocols with over $100 million in TVL will also be eligible for formal verification, a mathematical method that verifies the correctness of smart contracts by checking every possible execution path. The founding members of SIRN include OtterSec, Neodyme, Squads, and ZeroShadow, and the network is available to all Solana protocols, prioritized by TVL. However, it is worth noting that Stride's formal verification would not have prevented the North Korean attack, which exploited the gap between on-chain correctness and off-chain human trust.

The attack used compromised devices to obtain multisig approvals, which were then locked into durable nonce transactions and executed weeks later. In contrast, the SIRN could have potentially helped with the response to the attack, by establishing relationships with bridge operators, exchanges, and stablecoin issuers to facilitate a faster response time.