The Solana Foundation has announced a wide range of security measures, just days after a $270 million exploit on the Drift Protocol, a decentralized finance platform, which was carried out by a North Korean state-affiliated group after a six-month social engineering campaign. At the forefront of this effort is Stride, a structured evaluation program led by Asymmetric Research, designed to assess Solana DeFi protocols against eight key security pillars, with the findings to be made publicly available. Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based group comprising security firms and researchers focused on providing real-time crisis response.
While these initiatives address part of the issue exposed by the Drift exploit, they do not directly address the human element that led to the loss. The attackers had spent six months building relationships with Drift contributors and compromised their devices through a malicious code repository and a fake TestFlight app, highlighting the vulnerability of human factors in security breaches. Under the Stride program, protocols with more than $10 million in total value locked (TVL) that pass the evaluation will receive ongoing operational security and active threat monitoring, funded by Solana Foundation grants, with the level of coverage tailored to each protocol's risk profile.
For larger protocols with over $100 million in TVL, the foundation will also fund formal verification, a rigorous mathematical method that checks every possible execution path in a smart contract to guarantee its correctness. The founding members of SIRN include Asymmetric Research, OtterSec, Neodyme, Squads, and ZeroShadow, with the network available to all Solana protocols, prioritized by TVL. However, it's noted that even with these measures, the North Korean attack, which exploited the gap between on-chain correctness and off-chain human trust, might not have been prevented. The attack used compromised devices to obtain multi-signature approvals that were then locked into durable nonce transactions and executed weeks later, demonstrating a gap that current smart contract audits and monitoring tools are not designed to cover.
Nonetheless, a dedicated incident response network like SIRN could have potentially aided in the response efforts, by establishing relationships that could bridge operators, exchanges, and stablecoin issuers, thereby shortening response times in the event of an attack.