← solana-toolbox.com Section G · 07 of 8 Issue 14 · 05.2026
G
4 entries · curated May 2026

Security & Auditing

Static analysis, formal verification, and audit firms.

Use Anchor constraints by default. Audit with OtterSec or Neodyme before mainnet.

Security in Solana programs centers on account validation — ensuring that the accounts passed into an instruction are what the program expects. Anchor's built-in constraints (has_one, constraint, owner, signer) handle the most common validation patterns declaratively and eliminate a large class of vulnerabilities by construction.

For automated scanning, Sec3 (formerly Soteria) provides static analysis against known Solana vulnerability patterns. For formal audits before mainnet deployment, OtterSec and Neodyme are two of the most respected firms in the ecosystem — both have audited Jupiter, Marinade, Drift, and other major protocols.

The Solana Security Workshop (sealevel-attacks) is the best starting point for developers learning about Solana-specific exploits. It contains deliberately vulnerable programs covering the full taxonomy of common attacks.

Filter
4 of 4 entries
G.02
OtterSec DEV

Leading Solana security auditing firm. Audited Jupiter, Marinade, Drift, and many top protocols.

Tags
audit-firmsecurity-research
G.03
Neodyme DEV

Security research firm specializing in Solana. Known for discovering critical vulnerabilities in core programs.

Tags
audit-firmsecurity-research