Assisted Audit of Solana Programs
Yuru Shao, Emanuele Cesena · Team GLAM
Submitted to Defensive Acceleration Hackathon. Sprint projects are early-stage work by participants, not Apart Research publications.
Multi-agent solution that assists in auditing Solana programs, allows to consolidate audit findings into a knowledge base, and can integrate into CI/CD pipelines to prevent security regressions.

Reviews
Strengths: This is a rare example of AI and blockchain that truly makes sense together. Scaling security audits for high-value smart contracts is a present problem, and the multi-agent architecture is well-designed for it. The Librarian Agent for cross-program dependency tracking is the highlight. Solana programs constantly interact with external protocols, and vulnerabilities often live in those interaction layers. Building infrastructure that maintains versioned external references and flags upstream changes is genuinely useful. Finding 3 additional vulnerabilities beyond the original audit scope validates the approach.
Suggestions: Coverage is the obvious next step. Six agents based on six audit findings is a (definitely solid) proof of concept. From here, a production system needs broader vulnerability class coverage. The framework is strong; now it needs scale.
Bottom line from a Halcyon Ventures investor: Rather than crypto for crypto's sake, or AI for AI's sake, I really liked this team’s sound usage of intelligent systems for auditing high-financial value smart contracts. The real-world application of securing against financial losses in an increasingly decentralized world came across sharp, sound, and necessary. There was clear first-principles thinking in what the team needed to orchestrate / bring to life in its multi-agent system. The team’s attention to posture management software limitations was honest and accurate: that it historically only focuses on a moment in time/is not dynamic. We need more defensive AI security that understands the unique needs of financial markets (and their future) - well done for pioneering this!
Read full reviewShow less
Cite this project
@misc{shao2025assisted,
title = {{Assisted Audit of Solana Programs}},
author = {Yuru Shao and Emanuele Cesena},
year = {2025},
month = nov,
note = {Submitted to Defensive Acceleration Hackathon, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/assisted-audit-of-solana-programs-iexy}},
url = {https://apartresearch.com/sprints/projects/assisted-audit-of-solana-programs-iexy}
}More from Defensive Acceleration Hackathon
- View project: Neops - DevSecOps for the AI era
Neops - DevSecOps for the AI era
Broad Bros
NEOps is a CLI-based tool that embeds AI safety into your product lifecycle from day one. While development teams routinely build cybersecurity checks, AI-safety often comes later—or not at all. NEOps fills that gap by …
- View project: Mechanistic Watchdog
Mechanistic Watchdog
SL5
Mechanistic Watchdog is a mechanistic-interpretability-based “cognitive kill switch” for language models. Instead of only filtering final text, we monitor a model’s internal activations in real time and learn linear …
- View project: GUARDIAN: Guarded Universal Architecture for Defensive Interpretation And traNslation
GUARDIAN: Guarded Universal Architecture for Defensive Interpretation And traNslation
Guardian team
GUARDIAN is a multi-stage, LLM-driven system to automate the translation of C codebases to memory-safe Rust. GUARDIAN promotes defense acceleration at-scale by guiding an LLM transpiler with dependency graph …