Solana Security Hub · Powered by Certora

Build on Solana.
Ship Securely.

Your central resource for security best practices, tooling, and audit preparation when building programs on Solana.

Resources

Security Resources for Solana Builders

Practical materials to help you identify risks early and apply proven security patterns.

Certora Solana Prover Docs

Official documentation: setup, CVLR language, and Solana program verification end-to-end.

Docs

Securing Kamino Lending

How formal verification identified future risks in Kamino's lending protocol before deployment.

Case Study
Solana Smart Contract Formal Verification

Solana Verification Part 1: Introduction to FV

The foundational blog post introducing formal verification for Solana smart contracts.

Article
Solana Verification Part 2: Formal Verification of SPL Token 2022

Solana Verification Part 2: Formal Verification of SPL Token 2022

Verifying the correctness of the Mint operation in SPL Token 2022, with practical harness and spec examples.

Article
Solana Verification Part 3: Formal Verification of the Confidentiality Extension of SPL

Solana Verification Part 3: Formal Verification of the Confidentiality Extension of SPL

How the Certora Prover detected a critical bug in SPL Token 2022's confidential transfer extension.

Article
Reviewing Token Extensions with Formal Verification

Reviewing Token Extensions with Formal Verification

Applying formal verification to Solana SPL token extensions to surface hidden edge cases.

Article
How Certora Secures Billions on Solana

How Certora Secures Billions on Solana

Mooly Sagiv on Certora's security approach, common misconceptions, and emerging risks in 2026.

Video
Security Block: Certora at Breakpoint 2025

Security Block: Certora at Breakpoint 2025

Pamina Georgiou presents formal verification to the Solana ecosystem at Breakpoint 2025.

VideoConference
SOLANA Start-Up Village – Toronto

Formal Verification Live Demo — Superteam Canada Toronto

Live demonstration of Solana program verification techniques from first principles to production.

DemoVideo
Securing Solana Protocols With Formal Verification

Securing Solana Protocols With Formal Verification

Arie Gurfinkel on the academic and engineering perspective behind applying FV to Solana.

Video

CVLR Library for Solana

Rust library for writing formal verification specs directly on Solana programs.

ToolLibrary

Solana Spec Template

A ready-to-use starting point for new Solana formal verification projects.

Template

CVLR by Example

Practical verification patterns from Certora's Solana examples repository.

Example

Security Subsidy Program

$1M Solana Security Subsidy Program

Designed and launched by Areta, this $1M initiative removes the financial barrier to audits - so Solana builders can ship with confidence, not compromise.

About Areta

Areta is the ecosystem development arm behind the program's design and launch. They built the Solana Builder Services Marketplace and continue to drive targeted support and resource allocation across the Solana ecosystem.

  • Apply for a subsidy
    Submit your project for review by the assessment board.
  • Work with Certora
    Certora is one of the top security firms in the Solana ecosystem, trusted by top protocols such as Squads, Kamino, Jupiter Lend, Jito, Manifest, and many more. Through the subsidy program, qualifying teams can access Certora security services at no cost.
Explore on Areta Marketplace →

Office Hours

Talk Directly to a Security Expert

1-1 Free Sessions with Certora

Direct, no-pitch access to researchers who specialize in Solana programs. Whether you're at idea stage or post-launch, you'll get actionable feedback.

  • Threat modeling (DEXs, lending, vaults, staking)
  • Account architecture & design patterns
  • Audit readiness assessment
  • Formal verification & fuzzing strategies
Genuinely free - no obligation to pursue an audit
What these sessions are not
  • A full security audit
  • A written audit report
  • A sales engagement
Ready to book?
Slots are limited. Reserve your session with the Certora Solana team.
Book a Session →

Track Record

Certora x Solana

Security work completed across the Solana ecosystem, from design reviews to formal verification.

Light
Light — Extension | Mar 2026 | Audit only
Zero-knowledge compression extension security audit
AuditMar 2026
Kamino
Kamino — LIMO | Jul 2025 | FV + Audit
Limit order protocol formal verification and audit
FVAuditJul 2025
Fragmetric
Fragmetric — Restaking v0.6.3 | Jul 2025 | Audit only
Liquid restaking protocol security audit
AuditJul 2025
Kamino
Kamino — Vault | Jul 2025 | FV + Audit
Yield vault formal verification and audit
FVAuditJul 2025
Kamino
Kamino — Lending | Feb 2025 | FV + Audit
Lending protocol formal verification and audit
FVAuditFeb 2025
Squads
Squads — Smart Account | Feb 2025 | FV + Audit
Smart account infrastructure formal verification and audit
FVAuditFeb 2025
Lulo
Lulo — Protocol | Feb 2025 | Audit only
Lending aggregator protocol security audit
AuditFeb 2025
Veda
Veda — Boring Bridge | Jan 2025 | Audit only
Cross-chain bridge infrastructure security audit
AuditJan 2025
Jito
Jito — Tip Router | Jan 2025 | Audit only
MEV tip routing protocol security audit
AuditJan 2025
Manifest
Manifest — Protocol | Dec 2024 | FV + Audit
On-chain order book formal verification and audit
FVAuditDec 2024
Glow
Glow — V1 | Dec 2024 | Audit only
Climate rewards protocol security audit
AuditDec 2024
Squads
Squads — V4 | Dec 2024 | FV + Audit
Multisig wallet formal verification and audit
FVAuditDec 2024
Jito
Jito — Interceptor | Dec 2024 | FV + Audit
Transaction interceptor formal verification and audit
FVAuditDec 2024
Fragmetric
Fragmetric — Protocol | Nov 2024 | FV + Audit
Liquid restaking protocol formal verification and audit
FVAuditNov 2024
Jito
Jito — Restaking V2 | Nov 2024 | FV + Audit
Restaking protocol formal verification and audit
FVAuditNov 2024
Jito
Jito — Restaking V1 | Sep 2024 | FV + Audit
Restaking protocol formal verification and audit
FVAuditSep 2024
Solana Foundation
Solana Foundation — Token-2022 | May 2024 | FV only
SPL Token 2022 standard formal verification
FVMay 2024

Start Building Securely on Solana

Access resources, book office hours, or apply for a security subsidy through the Areta-led $1M program - all from one place.