EVMbench for Solana: Trident Arena, a multi-agent AI security scanning solution.
21 out of 30 critical/high-severity vulnerabilities found across 6 open source Solana code bases in benchmarks.
70%+ true positive rate.
See it in action: During a manual audit, TridentArena helped us find a critical-severity issue (later fixed), making @MetaDAOProject even more secure.
Built by the School of Solana senior auditors, securing leading protocols.
Time to IBRL of Solana security audits!
Launch blog post: https://t.co/KgnWZWA6nz
Request access → https://t.co/bs5oEOUyvd
Follow @TridentSolana for product updates and insights.
On February 2, an attacker forged a cross-chain message to drain $2.8M from CrossCurve.
It worked because the protocol's receiver contract exposed a privileged execution path without access control.
How to prevent these types of exploits? ↓
On January 8th, @Truebitprotocol lost 8,535 ETH ($26.4M) to an integer overflow.
The vulnerable contract was deployed in 2021, never audited, and held millions in ETH.
Here's what happened ↓
Security is only as strong as the weakest link.
You can have great fuzzing and still lose funds to:
• weak access control
• unsafe dependencies
• missing monitoring/response
• social engineering in ops
Treat security as a system: code quality + testing + fuzzing + audits.
Learn how to set up our fuzzing framework @TridentSolana, write a test to catch a real program vulnerability, and monitor the results.
Thank you @mikehale & @Quicknode@QuicknodeSolana for collaborating with us on this deep dive. ↓
https://t.co/VT1eti6GZ5
Solana Developers should know: one missing account constraint can drain your program's funds.
This tool✨found the bug instantly✨.
New guide with @AckeeBlockchain: how to fuzz test your Solana programs with @TridentSolana
Get started with @WakeFramework for Solidity development and testing to prevent protocol-breaking vulnerabilities in your EVM project: https://t.co/qNztt458AS
Our auditors have already discovered dozens of vulnerabilities in major Solana protocols.
Don't miss the opportunity to work with Solana OGs and get in touch at the link below.
The jump from Wake Arena 3.0 to 3.1 is a +21 percentage point increase in detection rate.
3.0 at 46% → 3.1 at 67%
Frontier LLMs plateau around 44%.
That ceiling is real: more compute, better prompts, same result.
The staircase:
Opus 4.5 (22%)
GPT-5 (26%)
GPT-5.2 xhigh (44%) = Zellic v12 (44%)
Wake Arena 3.0 (46%)
Wake Arena 3.1 (67%).
Breaking through that ceiling required a different architecture.
Not a different prompt.
Learn more ↓
Learn how to set up our fuzzing framework @TridentSolana, write a test to catch a real program vulnerability, and monitor the results.
Thank you @mikehale & @Quicknode@QuicknodeSolana for collaborating with us on this deep dive. ↓
Solana Developers should know: one missing account constraint can drain your program's funds.
This tool✨found the bug instantly✨.
New guide with @AckeeBlockchain: how to fuzz test your Solana programs with @TridentSolana
Ackee is coming to @EthCC – let's talk security, fuzzing, and AI solutions for smart contract auditing.
Reach out to schedule a meeting:
@jgattermayer@0xTomass@jaczkal@tldrteo
See you in Cannes!
Ackee is coming to @EthCC – let's talk security, fuzzing, and AI solutions for smart contract auditing.
Reach out to schedule a meeting:
@jgattermayer@0xTomass@jaczkal@tldrteo
See you in Cannes!
Security is only as strong as the weakest link.
You can have great fuzzing and still lose funds to:
• weak access control
• unsafe dependencies
• missing monitoring/response
• social engineering in ops
Treat security as a system: code quality + testing + fuzzing + audits.
What builders get:
• One CLI command to deploy the staking product-related contracts
• White-label embeddable widget for websites or apps
DeFi Wrapper and connector contracts are audited by @MixBytes and @AckeeBlockchain:
https://t.co/KXpPE7h95o
You can prompt Claude or GPT to review your Solana code.
Or you can ask Trident Arena.
One catches ~33% of critical/high vulnerabilities.
The other 70%.
Same code. Same task. Very different outcomes.
Thread ↓