In response to the recent $270 million exploit of DeFi platform Drift Protocol, the Solana Foundation has announced a range of security measures aimed at bolstering the security of its ecosystem. The new initiatives, unveiled just five days after the Drift hack, include Stride, a structured evaluation program led by Asymmetric Research that will assess Solana DeFi protocols against eight key security pillars and publicly disclose its findings. Additionally, the Solana Incident Response Network (SIRN) has been introduced, a membership-based group of security firms and researchers focused on providing real-time crisis response.
While these measures address some of the vulnerabilities exposed by the Drift hack, they do not directly address the human element that was exploited in the attack, in which attackers spent six months building relationships with Drift contributors before compromising their devices. Under the Stride program, protocols with over $10 million in total value locked (TVL) that pass the evaluation will be eligible for ongoing operational security and active threat monitoring, funded by Solana Foundation grants. Protocols with over $100 million in TVL will also be eligible for formal verification, a mathematical method that checks every possible execution path in a smart contract to guarantee correctness.
The SIRN network, which includes founding members such as OtterSec, Neodyme, Squads, and ZeroShadow, will be available to all Solana protocols, with priority given to those with the largest TVL. The Solana Foundation has emphasized that these programs do not shift the underlying responsibility for security away from the protocols themselves, a point that takes on added significance in light of the Drift hack, in which individual contributor devices were the entry point for a nation-state attack.
The foundation has also highlighted the range of free security tools already available to Solana builders, including Hypernative for threat detection, Range Security for real-time monitoring, and Neodyme's Riverguard for attack simulation.