Solana is a high-throughput blockchain designed for low latency and parallel transaction execution. Its smart contracts, called programs, follow a model very different from the EVM, so Ethereum experience does not transfer directly. For a project, choosing Solana means working with Rust specialists and budgeting for a review focused on how accounts are passed and validated.
Building on Solana
Programs are stateless: data lives in separate accounts that each transaction must list explicitly, and the program is responsible for checking that every account it receives is the one it expects. Programs can call each other through cross-program invocations and control accounts derived from their own address (program derived addresses). Programs are upgradeable by default through an upgrade authority, which can be kept, transferred or removed.
Language: Rust, compiled for the Solana runtime
Framework: Anchor, which generates much of the account validation code
Tokens: the SPL token programs, including the newer token program with extensions
Not EVM-compatible
What auditors look at
Account validation: owner checks, signer checks, type confusion between accounts, and substitution of a legitimate account by an attacker's account
Program derived addresses: seed design, bump handling and collisions between different account types
Cross-program invocations: calling the expected program ID and the privileges passed along
Arithmetic and precision in token amounts, and rounding in favor of the protocol
Upgrade authority, account closing and reinitialization, and compute limits on large operations
Before requesting quotes
Specify whether the program uses Anchor or native Rust, and the Anchor version
Provide a description of every instruction with the accounts it expects and their constraints
Share tests that exercise failure cases, not only successful flows
State who holds the upgrade authority and whether the program will be made immutable
Solana smart contract auditors Wrocław software house for blockchain development, on-chain analytics and crypto compliance
Ethereum · Arbitrum · Base · Polygon · BNB Chain · +4 more
A Public informationSingapore Singapore-based security firm auditing Solana programs built with Anchor, Pinocchio or native Rust
AB Public informationCzechia Prague firm auditing Solana and EVM smart contracts, maker of the Wake and Trident fuzzers
AL Public informationUnited States Blockchain security firm offering audits, fuzzing, formal verification and penetration testing
Solana · Ethereum · Sui · Aptos · BNB Chain
B Public informationUkraine Ukrainian blockchain development company with a dedicated security audit practice
Ethereum · Polygon · Arbitrum · Solana · Sui · +4 more
Smart contract audits combining manual review with formal verification by Certora Prover
C Public informationSwitzerland Zurich smart contract audit firm reviewing DeFi, stablecoin, bridge and L1/L2 code
Ethereum · Solana · Starknet · Sui · Aptos
C Public informationArgentina Argentine blockchain security and development company auditing Solidity, Rust, Clarity and Soroban
Ethereum · Solana · Polkadot
C Public informationSingapore Security firm offering manual smart contract audits, pentesting and the SolidityScan scanner
Smart contract audits, penetration testing and security education, maker of Aderyn and Solodit
Ethereum · ZKsync · Arbitrum · Avalanche · BNB Chain · +8 more
EL Public informationUnited Kingdom London onchain development studio building smart contracts, dApps, token and NFT launches
Ethereum · Base · Solana · Polygon · Avalanche
French offensive security company auditing blockchains and smart contracts with fuzzing
Solana · Ethereum · NEAR · Starknet · Sui · +3 more
Smart contract audits with invariant fuzzing, plus off-chain pentests and SDK audits
H Public informationEstonia Estonian blockchain security and compliance firm: audits, pentests and MiCA, DORA readiness
Blockchain security firm: smart contract assessments, L1 reviews, penetration testing, advisory
Ethereum · Solana · Cosmos
KS Public informationSwitzerland Swiss cybersecurity company with a blockchain security assessment practice and public report archive
LA Public informationGermany Berlin security consultancy auditing smart contracts, cryptographic protocols and ZK systems
Ethereum · Polygon · Cosmos · Solana · Avalanche
Boutique firm auditing smart contracts and Solana programs, with protocol development
Ethereum · Solana · Optimism · Arbitrum · Base
Spanish blockchain-only development company focused on RWA tokenization and smart contracts
Ethereum · Polygon · BNB Chain · Arbitrum · Solana
M Public informationCayman Islands DeFi-focused audit firm: design reviews, smart contract audits and ongoing security support
N Public informationGermany German security firm auditing Solana programs and core blockchains, with pentests and trainings
N Public informationUnited Kingdom London blockchain engineering and research firm; its Nethermind Security arm audits smart contracts
Ethereum · Starknet · ZKsync · Solana
OS Public informationGermany Munich-based Web3 security firm auditing EVM, Solana, Cosmos, Substrate and Starknet code
Ethereum · Solana · Cosmos · Polkadot · Starknet · +2 more
Blockchain security firm auditing layer 1s, wallets, DeFi and bridges, with pentesting and fuzzing
Solana · Ethereum · Sui · Aptos · Cosmos · +1 more
Remote team of security researchers auditing EVM, Solana and Move smart contracts
Ethereum · Solana · Arbitrum · Optimism · Base · +3 more
Blockchain engineering firm building and auditing smart contracts on EVM chains, Solana and Cardano
Ethereum · Solana · Cardano
Web3 security firm offering smart contract audits, economic analysis and infrastructure tests
Ethereum · Solana · Polygon · TON · Avalanche · +3 more
Smart contract audit firm also offering dApp penetration testing, wallet audits and monitoring
Ethereum · NEAR · BNB Chain · Polygon · Optimism · +8 more
RL Public informationUnited States Web3 and AI engineering firm with a Buenos Aires team, building and auditing smart contracts
Ethereum · Arbitrum · Base · Optimism · Polygon · +5 more
Formal methods firm offering security audits, fuzzing and formal verification
Web3 security team auditing smart contracts, dApps and blockchains, with a Bitcoin layer 2 focus
Ethereum · Arbitrum · BNB Chain · Solana · Polygon · +3 more
Solana security firm offering audits, formal verification and post-deployment monitoring
SR Public informationGermany Berlin security research firm reviewing smart contracts, chain runtimes and bridges
Ethereum · Cosmos · Solana · Polkadot
S Public informationBulgaria Bulgarian Web3 security company offering smart contract audits by review or by subscription
Audit Penetration testing Development Ethereum · Solana · ZKsync · Avalanche · BNB Chain · +1 more
S Public informationGermany Flensburg Web3 company offering smart contract audits, pentests, development and compliance
Development Audit Penetration testing Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more
Code security audits and economic audits for Web3 protocols, in Solidity, Rust and Move
Ethereum · Arbitrum · Polygon · Base · Optimism · +4 more
TO Public informationUnited States Security firm reviewing smart contracts, nodes and bridges, maker of Slither and Echidna
Ethereum · Arbitrum · Optimism · Solana · Sui · +4 more
V Public informationVietnam Security firm auditing smart contracts, protocols and cryptography, with penetration testing
Ethereum · BNB Chain · Solana · Avalanche · Polygon · +1 more
Polish security firm offering smart contract audits, dApp pentesting and AI security reviews
Audit Penetration testing Development Ethereum · Arbitrum · Polygon · BNB Chain · Base · +4 more
Security assessments of smart contracts, ZK circuits, L1s and web applications
Ethereum · Solana · Aptos · Sui · Cosmos
Z Public informationUnited Arab Emirates Smart contract and protocol audits, pentesting, compliance and product development, Dubai
Audit Penetration testing Development Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more
Solana smart contract developers Wrocław software house for blockchain development, on-chain analytics and crypto compliance
Ethereum · Arbitrum · Base · Polygon · BNB Chain · +4 more
B Public informationUkraine Ukrainian blockchain development company with a dedicated security audit practice
Ethereum · Polygon · Arbitrum · Solana · Sui · +4 more
Warsaw software studio building Web3 products, with smart contracts in Solidity and ink!
C Public informationArgentina Argentine blockchain security and development company auditing Solidity, Rust, Clarity and Soroban
Ethereum · Solana · Polkadot
EL Public informationUnited Kingdom London onchain development studio building smart contracts, dApps, token and NFT launches
Ethereum · Base · Solana · Polygon · Avalanche
L Public informationAustralia Brisbane product studio building smart contracts, DeFi protocols and full Web3 products
Ethereum · Base · Arbitrum · Optimism · Polygon · +1 more
L Public informationBulgaria Bulgarian blockchain engineering firm building smart contracts, protocols and onchain products
Ethereum · Polygon · Base · Solana · NEAR · +1 more
LL Public informationSwitzerland Swiss blockchain software studio building Web3 and fintech products on EVM, HyperEVM and Solana
Boutique firm auditing smart contracts and Solana programs, with protocol development
Ethereum · Solana · Optimism · Arbitrum · Base
Spanish blockchain-only development company focused on RWA tokenization and smart contracts
Ethereum · Polygon · BNB Chain · Arbitrum · Solana
ML Public informationUnited States Blockchain engineering firm for institutional protocols, tokenization and payment infrastructure
Ethereum · ZKsync · Solana · Polkadot
N Public informationUnited Kingdom London blockchain engineering and research firm; its Nethermind Security arm audits smart contracts
Ethereum · Starknet · ZKsync · Solana
Blockchain engineering firm building and auditing smart contracts on EVM chains, Solana and Cardano
Ethereum · Solana · Cardano
RL Public informationUnited States Web3 and AI engineering firm with a Buenos Aires team, building and auditing smart contracts
Ethereum · Arbitrum · Base · Optimism · Polygon · +5 more
R Public informationUkraine Web3 engineering partner writing audit-ready smart contracts on EVM chains, Solana and Bitcoin
Ethereum · Polygon · BNB Chain · Arbitrum · Base · +6 more
Kraków software house with a blockchain practice: smart contracts, DeFi, dApps, bridges
Ethereum · Solana · Polygon · BNB Chain · Avalanche
S Public informationBulgaria Bulgarian Web3 security company offering smart contract audits by review or by subscription
Audit Penetration testing Development Ethereum · Solana · ZKsync · Avalanche · BNB Chain · +1 more
S Public informationGermany Flensburg Web3 company offering smart contract audits, pentests, development and compliance
Development Audit Penetration testing Ethereum · Arbitrum · Optimism · Base · Polygon · +8 more
Polish security firm offering smart contract audits, dApp pentesting and AI security reviews
Audit Penetration testing Development Ethereum · Arbitrum · Polygon · BNB Chain · Base · +4 more
Z Public informationUnited Arab Emirates Smart contract and protocol audits, pentesting, compliance and product development, Dubai
Audit Penetration testing Development Ethereum · Solana · Polygon · Arbitrum · Optimism · +9 more
Z Public informationEstonia Senior crypto engineering team for L1 consensus, zero-knowledge, DeFi mechanisms and stablecoins
Ethereum · Solana · NEAR · Arbitrum · Base · +1 more