Solana Foundation Launches STRIDE After $270M Drift Hack

Solana Foundation STRIDE security program launch following Drift Protocol hack


The Solana Foundation and Asymmetric Research launched STRIDE on April 6 — a tiered, ongoing security program that replaces single-audit cycles with continuous monitoring scaled to protocol size. The announcement came five days after Drift Protocol lost roughly $270 million to a North Korean state-linked operation, the largest DeFi exploit of 2026 so far.

A DeFi protocol is a software application running on a public blockchain that enables financial transactions — lending, trading, borrowing — without banks or intermediaries.

Key Takeaways

  • Solana Foundation and Asymmetric Research launched STRIDE on April 6, a tiered security framework covering eight operational pillars for Solana DeFi protocols.
  • Protocols with more than $10 million in total value locked qualify for foundation-funded 24/7 threat monitoring; those above $100 million get formal verification using mathematical proofs.
  • SIRN, the Solana Incident Response Network, launched simultaneously with five founding security firms — Asymmetric Research, OtterSec, Neodyme, Squads, and Zeroshadow — to coordinate real-time crisis response.
  • STRIDE follows the $270 million Drift Protocol hack attributed to UNC4736, a North Korean state-linked threat actor, which exploited a six-month infiltration and Solana’s durable nonce feature to bypass multisig controls.

Published: April 7, 2026

What the Drift hack actually exposed

The Drift exploit unfolded over April 1 and 2. A group attributed to UNC4736 — also known as Citrine Sleet, a North Korea-affiliated threat actor — spent six months posing as a quantitative trading firm. They deposited more than $1 million to build credibility, met Drift contributors at conferences, and eventually compromised developer devices through a malicious TestFlight app and a vulnerability in VS Code and Cursor.

Once inside, the attackers abused Solana’s durable nonce feature — a legitimate mechanism that lets transactions be pre-signed and submitted later without expiring — to bypass Drift’s multisig approval process. Within hours, $270.9 million had been swapped to USDC, bridged to Ethereum via CCTP TokenMessengerMinterV2, and distributed across wallets holding roughly 129,000 ETH.

The technical root cause was not a smart contract bug. It was operational: compromised private keys, inadequate access controls, and governance gaps that standard code audits don’t examine.

What STRIDE changes for Solana DeFi

STRIDE stands for Solana Trust, Resilience and Infrastructure for DeFi Enterprises. It replaces the industry’s default approach — commission an audit before launch, ship it, and hope — with continuous, foundation-funded security coverage calibrated to each protocol’s size and risk exposure.

Protocols that complete a STRIDE evaluation and hold more than $10 million in TVL qualify for 24/7 active threat monitoring and operational security support. For protocols above $100 million TVL, the Solana Foundation funds formal verification: a method that uses mathematical proofs to check every possible execution path in a smart contract, eliminating entire vulnerability classes that audits can miss. Evaluation results are published publicly, giving users and institutional allocators a live security reference.

The eight STRIDE pillars cover operational security, access controls, multisig configurations, governance vulnerabilities, smart contract integrity, key management, economic design, and incident preparedness — precisely the categories the Drift attack exploited.

“Solana was built for security. As the ecosystem scales, so does our investment in the tools, standards, and support,” the Solana Foundation said in its announcement.

The incident response network standing behind it

Alongside STRIDE, the Foundation launched SIRN — the Solana Incident Response Network. It is a membership-based coalition of security firms built to coordinate real-time crisis response when protocols come under attack. Founding participants include Asymmetric Research, OtterSec, Neodyme, Squads, and Zeroshadow. SIRN access is prioritized by TVL and potential ecosystem impact.

The Foundation described both STRIDE and SIRN as expansions of security resources already available to ecosystem builders at no cost, not new programs built from scratch in reaction to the Drift incident.

As of April 7, no funds from the Drift exploit have been recovered. On-chain outreach to the attacker’s Ethereum wallets has been attempted by affected parties. Law enforcement agencies in multiple jurisdictions are tracking the stolen assets, which remain split across wallets. Follow W3BN’s News Bites for updates as the recovery effort develops.

The Drift exploit represents roughly 18% of Solana’s DeFi total value locked erased in a single event. Whether STRIDE would have caught the specific operational failures that enabled it — compromised developer devices, not the protocol code — is a question the Solana security community has not yet answered directly.

Frequently asked questions

What is the Solana Foundation’s STRIDE program?

STRIDE (Solana Trust, Resilience and Infrastructure for DeFi Enterprises) is a tiered security program launched April 6, 2026 by the Solana Foundation and Asymmetric Research. It provides ongoing security evaluations, 24/7 threat monitoring for protocols above $10 million TVL, and formal verification for those above $100 million TVL — replacing one-time pre-launch audits with continuous coverage.

How did the $270 million Drift Protocol hack happen?

Attackers attributed to UNC4736, a North Korean state-linked group, spent six months posing as a trading firm to gain trust, then compromised developer devices using a malicious app and a code editor vulnerability. They exploited Solana’s durable nonce feature — which lets transactions be pre-signed and executed later — to bypass multisig security and drain $270.9 million, converted to ETH and split across wallets.

What is SIRN and who are its founding members?

SIRN is the Solana Incident Response Network, a membership-based coalition of security firms built to coordinate real-time crisis response when Solana protocols come under attack. The five founding members are Asymmetric Research, OtterSec, Neodyme, Squads, and Zeroshadow. Access is prioritized based on a protocol’s TVL and potential ecosystem impact.


Staff Correspondent New York, NY

Alex Mitchell is a staff correspondent at Web3BusinessNews covering breaking news and daily developments across the cryptocurrency and blockchain landscape. With over five years of experience in financial journalism and digital asset reporting, Alex delivers fast, accurate coverage of market movements, protocol updates, and emerging trends shaping the Web3 ecosystem.

  • Cryptocurrency
  • Blockchain News
  • Digital Assets
  • Market Analysis
Share it :

Leave a Reply

Your email address will not be published. Required fields are marked *