Solana Projects › OtterSec

OtterSec

Security audits and open-source tools that protect Solana and beyond

Programs · 24h on-chain

On-chain activity

All programs →

OtterSec Security Audit

OtterSec Security Audit is a blockchain security service examining code vulnerabilities, exploitation vectors, and security architecture across multiple chains. The assessment includes detailed reports with risk ratings and remediation recommendations.

Visit
Project content

OtterSec news, features & analysis

Matched from published articles, podcasts, and talks using the project name, token name, or token symbol.

  1. Tokenomics & Incentive Design Article

    Solana Validators Push SOL Burn and Disinflation Proposals to the Edge of the Vote Threshold

    SGP-0003's 14x SOL burn and disinflation rewrite has 14.4% stake support. One percent point separates it from a formal vote; the deadline is August 18, 2026.

  2. DeFi Article

    Asymmetric Research Publishes First STRIDE Findings After 12 Weeks Auditing Solana Protocols

    STRIDE audited 40 Solana DeFi protocols: 17% have full logging, 13% mature key management, 9% advanced program defenses. First findings by Asymmetric Research.

  3. Accelerate 25 Conference Talk 7 min read

    Scale or Die at Accelerate 2025: Decompiling Solana Programs

    In a groundbreaking presentation at Accelerate 2025, Robert Chen from Ottersec unveiled revolutionary tools for decompiling Solana programs, potentially transforming the landscape of blockchain security and transparency. ... Robert Chen, representing Ottersec, introduced a suite of tools designed to decompile Solana programs, addressing a critical need in the ecosystem where 96.9% of programs (by compute) are closed-source.

  4. Breakpoint 24 Conference Talk 7 min read

    Breakpoint 2024: Product Keynote: Safe Solana Stack Smashing by OtterSec (Robert Chen)

    In a revealing presentation at Breakpoint 2024, Robert Chen of OtterSec exposes a critical bug in the Solana compiler that's been causing headaches for developers over the past year.

About

OtterSec

OtterSec is a blockchain security audit firm founded in February 2022 by Robert Chen, who studied computer science at Carnegie Mellon University and previously worked as a mobile vulnerability researcher. The company launched in Wyoming and grew quickly, reporting over 1 million dollars in revenue within its first two months. Today it is one of the most recognizable audit brands in the Solana ecosystem, combining a professional audit practice with open-source infrastructure contributions and active security research.

Core Services

OtterSec primary business is security auditing: comprehensive assessments of smart contracts, on-chain programs, wallets, bridges, and blockchain infrastructure. Rather than focusing on a single chain, the firm operates across more than a dozen ecosystems including Solana, Ethereum, Aptos, Sui, Cosmos, Polkadot, Near, Movement, Fuel, Stellar, and TON, allowing the team to apply cross-chain pattern recognition when evaluating novel designs. OtterSec emphasizes close, ongoing client relationships rather than transactional engagements, providing post-audit support and long-term security partnerships.

Every member of OtterSec team brings a web2 security background. As founder Robert Chen has stated, 100 percent of the team has a background in web2 security and those skills transpose directly to web3. This means OtterSec approaches blockchain code with the same adversarial rigor applied in traditional software security including developing threat scenarios, stress-testing protocols, simulating denial-of-service conditions, and systematically analyzing business logic. Sixty-six percent of their audit findings are classified as core-severity, reflecting a focus on substantive vulnerabilities rather than surface-level issues.

Track Record

Since 2022, OtterSec has audited more than 120 projects, secured more than 36.8 billion dollars in total value locked on-chain, and identified vulnerabilities representing more than 1 billion dollars in potential exposure. Their client list spans the industry highest-profile names: Solana Foundation, Sui Foundation, Circle, Tether, Aptos Labs, MetaMask, Wormhole, LayerZero, PancakeSwap, Phantom, Raydium, Jupiter, Kamino Finance, and Pyth Network, among many others. Audit reports are publicly available on the OtterSec website, with recent work including Doppler on Solana in March 2026, a Fogo Validator security assessment in October 2025, and a broad set of Sui ecosystem projects.

Solana-Specific Contributions

OtterSec involvement in Solana extends well beyond paid auditing. The firm maintains Anchor, the dominant smart contract framework for Solana development. With more than 5,100 GitHub stars and active development through mid-2026, Anchor defines how most Solana programs are structured and provides security-by-default guardrails that reduce common vulnerability classes. OtterSec stewardship of this framework makes it a foundational actor in Solana developer ecosystem.

The firm has also tackled one of Solana most significant transparency challenges: the fact that 96.9 percent of Solana programs by compute usage are closed-source. At Accelerate 2025, Robert Chen presented OtterSec Binary Ninja decompiler tooling, which enables security researchers to reverse-engineer closed-source sBPF programs and produce human-readable representations of on-chain code. This work is open-sourced as the bn-ebpf-solana plugin with 248 GitHub stars and materially expands the community capacity to audit programs that have never published their source code. At Breakpoint 2025, Chen presented Anchor: Today and Tomorrow alongside Solana Foundation Jacob Creech, outlining the framework development roadmap.

OtterSec also maintains the solana-verified-programs-api, an HTTP server for verifying on-chain Solana programs against their published source, and the sol-ctf-framework, a Rust library for building Solana capture-the-flag security challenges used in competitive events.

Security Research

OtterSec publishes an active research blog covering issues well beyond on-chain code. Recent posts include an analysis of more than 20 mobile web3 wallets where insecure WebView integrations allowed unauthorized permission escalation by malicious applications in June 2026; a critical flaw in Dusk Network PLONK implementation where a validator skipped essential cryptographic verification checks affecting approximately 60 million dollars in assets in April 2026; a discovery of ordering bugs that allowed attackers to bypass cryptographic validation in six separate zero-knowledge virtual machines in March 2026; exploitation of a heap overflow in QEMU enabling guest-to-host hypervisor escape in March 2026; and a Samsung Internet zero-day exploiting an outdated V8 engine on Galaxy S25 devices in April 2026. A June 2026 post reverse-engineered Hyperliquid risk engine using agentic tooling, demonstrating the firm move toward automated security analysis for complex financial systems. The breadth of this research spanning mobile, browser, hypervisor, zero-knowledge, and blockchain domains signals a team doing foundational security work rather than checklist audits.

CTF Community

OtterSec has deep roots in competitive hacking. The firm participates in and supports capture-the-flag competitions, and has built infrastructure for the community. Their rCTF platform is an open-source CTF hosting system with 104 GitHub stars. In July 2026, OtterSec released rCTF v2 and simultaneously committed 100,000 dollars to the Save CTFs Fund, responding to concerns that AI assistance was changing the competitive landscape. The fund aims to adapt CTF formats and scoring to preserve their educational and competitive value in an era when language models can assist with challenge solutions.

Legal Context

OtterSec early history includes a co-founder dispute. Robert Chen and David Chen, who are unrelated, co-founded the firm in early 2022, but David Chen was 16 at the time of founding and had his ownership stake held under his father Sam Chen name. In November 2024, Robert Chen and OtterSec filed an amended complaint in US District Court alleging David Chen misappropriated proprietary trading code and approximately 24,000 dollars in company cryptocurrency. The case transferred to Maryland federal court and remains active as of early 2026 with no trial date set. The dispute does not appear to have materially disrupted OtterSec audit operations or client relationships.

Positioning

OtterSec sits at the intersection of Solana core infrastructure through Anchor maintenance and decompiler tooling, professional security services through its multi-chain audit practice, and grassroots security culture through CTF infrastructure and open-source research. For protocols building on Solana, OtterSec functions both as a direct security partner and as a persistent contributor to the ecosystem overall security posture through the frameworks, tools, and publicly disclosed research that benefit the entire developer community.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →