Solana program audits
Audits of Solana programs written in Rust, with Anchor or without. $999 per audit. If we find no High or Critical issues, it costs $499.
Rust, Anchor, Native programs, SPL Token and Token-2022
We already audit on
- Sherlock
- Cantina
- Immunefi
What we check in Solana code
Account validation
Missing owner or signer checks, one account type passed as another, unchecked remaining_accounts, the same mutable account passed twice.
PDAs and seeds
Non-canonical bumps, colliding seeds, and PDAs shared between users that should be separate.
Cross-program invocation
CPI to a program ID the caller chooses, PDA signer authority passed to the wrong program, and account data not reloaded after a CPI.
Arithmetic
Overflow in release builds, unchecked casts, and rounding in share and fee calculations.
Token-2022 extensions
Transfer hooks, transfer fees, permanent delegates and mint close authority, each of which breaks assumptions made by SPL Token code.
Account lifecycle
Closed accounts that can be revived, rent exemption, re-initialization, and stale data after realloc.
Solana chains
Questions
Do you audit native programs as well as Anchor?
Yes. With Anchor we check how the constraints are used. With native programs we check the hand-written account validation.
Do you check Token-2022 integrations?
Yes. Extensions like transfer hooks and transfer fees change how token transfers behave, so we check each place your program moves tokens.
How much does an audit cost?
$999 per audit. If we find no High or Critical issues, the price drops to $499. You pay a $10 deposit when you submit, and we subtract it from the invoice.
Why is it cheaper when there are no High or Critical findings?
If your code only has Medium or Low issues, the audit was less useful to you, so you pay $499, about half.
Who does the audits?
AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.