
Protecting Solana-based DeFi protocols by reviewing critical program logic, upgrade paths, and external integrations that impact security and protocol integrity.






Check your finished Solana program code and design materials. This will help you figure out the audit scope. Provide a tailored cost estimate based on program complexity and review depth. We can arrange an NDA if needed.




Define Scope and Estimate Effort
Check your finished Solana program code and design materials. This will help you figure out the audit scope. Provide a tailored cost estimate based on program complexity and review depth. We can arrange an NDA if needed.

Confirm Engagement and Timeline
Complete audit terms, payment details, and the project schedule. Set clear start and delivery milestones to ensure a smooth Solana audit process.

Perform Audit and Confirm Fixes
Conduct a thorough Solana audit using in-house analysis tools and manual review. Share findings with your team and review remediation changes. Teams may apply multiple review rounds for complex programs.

Deliver Report and Security Guidance
Issue a signed audit report covering all findings, severity levels, and mitigation advice. Provide clear guidance to help strengthen program security and reduce future risk.

We conduct Solana audits using expert knowledge and specialized tools. This ensures thorough and reliable security coverage.
We don't just skim the surface; we dive deep into every single line of your code to find hidden bugs that others miss.
We use our own special security tools, such as advanced fuzzers and static analyzers, which no other audit firm has.
We audit your entire project stack, from smart contracts and blockchain code to wallets and off-chain websites.
We go beyond audits by offering tools (like Phalcon) that can actively stop a hack when it happens to save your funds.

~$39.5M Lost: Allbridge, Wanchain & More | BlockSec Weekly
During the week of July 20-26, 2026, 8 notable security incidents resulted in approximately $39.5M in total losses across Solana, Ethereum, BNB Chain, Arbitrum, Zilliqa, and Cardano. The highlighted Allbridge Core incident (~$1.65M) exposed a Solana input validation flaw where the same Pool account was accepted in both swap roles, with analysis reconstructed entirely from the deployed program binary. Other analyzed incidents include Wanchain (~$500K, flawed message encoding in a Cardano bridge validator), Zilliqa (~$400K, flawed nonce generation in a Ledger app since 2019), and Lien Finance (~$542K, flawed validation logic in bond exchange).

Top 10 "Awesome" Security Incidents in 2025
To help the community learn from what happened, BlockSec selected ten incidents that stood out most this year. These cases were chosen not only for the scale of loss, but also for the distinct techniques involved, the unexpected twists in execution, and the new or underexplored attack surfaces they revealed.
Newsletter - December 2025
In December 2025, the DeFi sector encountered three significant security incidents, resulting in total losses of approximately $19.7 million. Yearn Finance faced nearly $10 million in losses due to vulnerabilities in its yETH pool and legacy contracts. Trust Wallet suffered a malicious backdoor attack on its Chrome extension, leading to losses of about $7 million. Ribbon Finance experienced a loss of $2.7 million due to improper access controls.