On-chain activity
Sec3 news, features & analysis
Matched from published articles, podcasts, and talks using the project name, token name, or token symbol.
Sec3
Sec3 is a Solana-specialist blockchain security firm that combines PhD-led formal verification, manual audit expertise, automated scanning, and live on-chain monitoring to cover the full development lifecycle of smart contract protocols.
What Sec3 Does
Founded in 2021 and headquartered in the Solana ecosystem, Sec3 positions itself as the only audit firm offering security coverage before, during, and after a protocol launches on Solana. Its tagline — "Protection at every step of the development cycle" — reflects a product suite designed to address distinct phases: pre-launch design review, pre-deployment code audit, automated scanning during development, and post-launch runtime monitoring.
The firm has secured 200+ protocols and published more than 40 research articles. Its team is notable for including both PhD-level researchers and an 8x DEF CON CTF finalist, combining academic formal methods with adversarial red-team thinking.
Products and Services
Security Audits
Sec3's core manual audit service covers program logic, authority structures, external system integrations, and protocol state invariants as an interconnected system rather than isolated functions. Engagements include severity-rated findings, remediation recommendations, and re-audit support. The firm frames audits as protocol assurance engagements rather than compliance checkboxes, and audited clients span the major Solana protocols: Solana Foundation, Solana Labs, Jupiter, Wormhole, Raydium, Orca, and Metaplex, among others. More recent audit clients include Huma Finance, DeFi Tuna, Keel, LFJ, Lulo, and Symphony.
Formal Verification
Sec3 offers mathematical proof of protocol invariants through formal verification, a service the firm targets at high-TVL protocols requiring the highest assurance. This work is led by researchers with formal methods backgrounds and is designed to prove that a program behaves correctly under all possible inputs, not merely the inputs covered by testing.
X-Ray — Automated Static Analysis Scanner
X-Ray is Sec3's proprietary automated scanner purpose-built for Solana smart contracts. It detects more than 50 types of security vulnerabilities classified under Sec3's own taxonomy, the Sec3 Vulnerabilities and Exposures (SVE) system, covering both Rust-native and Anchor-framework programs. Key capabilities include GitHub integration for CI/CD workflows, GitHub code scanning alert compatibility, SARIF export for downstream tooling, and an interactive vulnerability dashboard. Complex programs receive full reports within minutes. Sec3 offers a free tier with limited detection and paid Build and Scale tiers that unlock the full 50+ SVE vulnerability set. Programs passing all checks receive a Sec3 security certificate.
WatchTower — Real-Time Threat Monitoring
WatchTower is Sec3's in-situ threat monitoring service for deployed Solana programs. It uses the Solana programming model to run continuously-learned, auto-tuned invariants against live transaction streams, flagging deviations that match known attack patterns. Built-in monitors cover abnormal token transfers, rug pulls, flash loan exploits, fake input accounts, round-trip trades, and cross-chain bridge attacks. The platform demonstrated detection of the Wormhole attack scenario in its announcement, identifying both suspicious token transfers and counterfeit system variable accounts in real time. Protocols integrate by adding their contract addresses to WatchTower projects and configuring monitoring bots with customized security policies; alerts surface through a dashboard.
CircuitBreaker
CircuitBreaker works alongside WatchTower to move from detection to automated response, blocking suspicious transactions in real time rather than merely alerting on them.
SecLaunch
SecLaunch is an end-to-end managed service for institutional protocol teams, covering design, development, deployment, and ongoing operational security under Sec3 oversight. It is positioned for teams that want embedded security expertise rather than point-in-time audits.
Open-Source Tools
Sec3 maintains several open-source tools. IDL Guesser recovers instruction layouts from closed-source Solana programs. OwLLM v1 is an open-source language model fine-tuned for web3 security contexts. Sec3 also offers a free nonce and multisig monitoring service to any Solana team.
Security Research and Findings
Sec3 publishes substantive technical research, including a multi-part audit methodology series, detailed post-mortems of Solana hacks (Wormhole, CashioApp, CremaFinance), and deep dives into Solana internals (the TPU pipeline, bank module, native programs). Notable disclosed pre-exploitation findings include a $20 million bug identified in Jet Protocol before it could be exploited, and a semantic inconsistency in the Solana Stake Pool program. The team has also placed in CTF competitions including MetaTrust 2023 and Aptos 2022.
2025 Solana Security Ecosystem Report
Sec3 released a data-driven analysis of the Solana security landscape covering 163 audits and 1,669 recorded vulnerabilities. Key findings: on-chain Solana smart contract exploits dropped to $8 million in 2025 from a peak of $550 million in 2022. The average audit uncovered 10.3 issues; 51% of audits contained at least one high or critical vulnerability. The top three vulnerability categories — business logic errors (36.9% of high/critical findings), input validation failures (27.9%), and access control weaknesses (20.7%) — accounted for 85.5% of all severe findings. This concentration suggests that fundamental design and permission flaws pose greater systemic risk than arithmetic errors or liveness bugs.
Team and Funding
Chris Wang is co-founder and president of Sec3. In January 2023, Sec3 raised a $10 million seed round led by Multicoin Capital, which holds a board observer seat. Sanctor Capital and Essence VC also participated. Angel investors included Santiago Santos (former ParaFi Capital partner) and Anatoly Yakovenko, co-founder of Solana, reflecting significant institutional confidence in Sec3's positioning within the Solana ecosystem.
Tokens and On-Chain Assets
Sec3 has not issued a token. Its products are accessed through its web platform (pro.sec3.dev) under tiered subscriptions; audit engagements are contracted directly. There are no associated on-chain programs reported.
Ecosystem Role
Sec3 occupies the security infrastructure layer of the Solana ecosystem. As Solana's DeFi and institutional adoption have grown, the audit bottleneck and post-launch vulnerability window have become recognized risks; Sec3 addresses both with tooling that scales beyond manual review alone. Its research also functions as a public good for the Solana developer community, providing vulnerability taxonomies, exploit analyses, and formal methodology guides that raise baseline security practices across the ecosystem.
Contents
- What Sec3 Does
- Products and Services
- Security Research and Findings
- Team and Funding
- Tokens and On-Chain Assets
- Ecosystem Role
Solana Token Markets