Solana smart contract audits

On Solana, your program has to check every account it is given. We audit Rust programs, with Anchor or without, before they go to mainnet-beta. $999 per audit, or $499 if we find no High or Critical issues.

We already audit on

  • Sherlock
  • Cantina
  • Immunefi

What we check on Solana

01

Missing account checks

A large share of Solana exploits come from a missing owner, signer or discriminator check.

02

CPI authority

invoke_signed hands your PDA's authority to the program you call. We check that the target program ID is fixed.

03

Token-2022

Transfer hooks and fees break code written for SPL Token.

The Solana checklist

01

Account validation

Missing owner or signer checks, one account type passed as another, unchecked remaining_accounts, the same mutable account passed twice.

02

PDAs and seeds

Non-canonical bumps, colliding seeds, and PDAs shared between users that should be separate.

03

Cross-program invocation

CPI to a program ID the caller chooses, PDA signer authority passed to the wrong program, and account data not reloaded after a CPI.

04

Arithmetic

Overflow in release builds, unchecked casts, and rounding in share and fee calculations.

05

Token-2022 extensions

Transfer hooks, transfer fees, permanent delegates and mint close authority, each of which breaks assumptions made by SPL Token code.

06

Account lifecycle

Closed accounts that can be revived, rent exemption, re-initialization, and stale data after realloc.

More about Solana audits

Questions

How much does a Solana smart contract audit cost?

$999 per audit, or $499 if we find no High or Critical issues. You pay a $10 deposit to start, which we subtract from the final payment.

What do you check in Solana contracts?

The Solana checklist (account validation; pdas and seeds; cross-program invocation; arithmetic; token-2022 extensions; account lifecycle), plus issues specific to Solana: missing account checks; cpi authority; token-2022.

Who does the audits?

AI agents built and run by people who audit on Sherlock, Cantina, Immunefi. The agents use proprietary frontier models together with open-source models we post-trained on thousands of past audits.

What do I need to start?

A link to a GitHub commit (for example https://github.com/org/repo/commit/<sha>), an email address, and the $10 deposit. We email you a link to the results when the audit is done.

Ready for your Solana audit?

$999 per audit, or $499 if we find no High or Critical issues. All we need is a GitHub commit link and your email.

Start an audit