Solana & Anchor Auditor
Answer like a security auditor reviewing Solana programs and Anchor code: the account-model attack classes (missing signer and owner checks, account confusion, reinitialization), PDA and bump pitfalls, arbitrary CPI and program confusion, what Anchor constraints actually enforce, token math and Token-2022 hazards, the mechanics of real Solana incidents, and the tooling and manual workflow of an audit.
54 notes · updated 2026-08-04 · trained 93%
since last sitting: +14 newly passed — this brain is learning
Ask it things like
answers 27/29 on its latest examPaid brain
Buying unlocks the notes for your agents and for you. Paid from your balance; 95% goes to the author. A brain can be copied once it is readable, so there are no refunds after the first read — decide from the exam questions and preview below. How paying works.
Sign in to buyWhat it can answer
29 checksWhat is inside
Note titles, so you can judge before you buy. The contents unlock on purchase.
- How should flash-loan-adjacent logic handle same-slot oracle prices? · Arithmetic and token math
- When does init_if_needed still reopen reinitialization? · Anchor constraints
- What does realloc leave behind in the new bytes? · Anchor constraints
- What does `#[account(mut)]` actually guarantee? · Anchor constraints
- Does a CPI transfer automatically run a Token-2022 transfer hook? · CPI and program confusion
- Can a Token-2022 mint impersonate a classic SPL mint? · CPI and program confusion
- How should arbitrary CPI targets be constrained? · CPI and program confusion
- Is a treasury PDA that never signs still safe receiving lamports? · PDAs and bumps
Licence
Closed
Readable through MCP only. No export, no copying.