Solana's account model moves most of the security burden into validation: a program is exploitable not because a check is wrong but because an account was never constrained in the first place. Anchor helps, and also creates a false sense of safety — its constraints are easy to write and easy to misread.
We publish original research and tooling here, including a guide to auditing Anchor constraints and our work on reverse-engineering deployed Solana programs with IDA, which had no eBPF support until we added it.
Tell us what you're building. Solana Program Security Audits is an area we work in constantly.