Sec3

Solana security audits, formal verification, and open-source analysis tooling

Programs · 24h on-chain

On-chain activity

All programs →

X-ray Security Scanner

A security scanner designed for Solana smart contracts, detecting over 50 types of vulnerabilities.

Visit

WatchTower

Automated post-deployment security for smart contracts, alerting on suspicious activities before they occur.

Visit
Project content

Sec3 news, features & analysis

Matched from published articles, podcasts, and talks using the project name, token name, or token symbol.

  1. Accelerate 25 Conference Talk 7 min read

    Scale or Die at Accelerate 2025: IDL Guesser (Chris Wang | Sec3)

    In a groundbreaking presentation at Accelerate 2025, Chris Wang of Sec3 unveils a revolutionary tool set to transform the Solana ecosystem. ... Chris Wang, co-founder of Sec3, introduces the IDL Guesser, an open-source tool designed to decipher Interface Description Language (IDL) from closed-source Solana programs.

About

Sec3

Sec3 is a blockchain security firm that specialises in Solana, offering manual smart contract audits, formal verification, and open-source tools that help developers find vulnerabilities before and after their programs go live.

The company began in 2021 under the name Soteria and later rebranded as Sec3. It has concentrated on Solana from the start. According to its website, Sec3 has audited more than 200 protocols and published over 40 research articles. It lists the Solana Foundation, Solana Labs, Jupiter, Wormhole, Kamino, Raydium, Orca and Metaplex among the organisations it has worked with.

What Sec3 does

Sec3's work falls into three areas: paid security engagements, free and open-source developer tools, and public research.

Security audits

Sec3's audit service is a researcher-led review that pairs manual analysis with the firm's own tooling. The company says an engagement covers:

  • Program logic: smart contract logic, state transitions and edge cases.
  • Dependency risk: external dependencies, cross-program invocations (CPIs) and shared state.
  • Operational security: deployment procedures, upgrade authorities and administrative key management.
  • Reporting: findings ranked by severity, with recommended fixes.
  • Post-deployment support: monitoring guidance and help integrating security tools.

Sec3 publishes its audit reports on GitHub. Recent public reports cover Huma Finance, DeFi Tuna, Keel, LFJ, Symphony, Lulo and Defenders. The firm now reviews Solidity code as well as Solana programs.

Formal verification and SecLaunch

For protocols with large amounts of value locked, Sec3 offers PhD-led formal verification, which mathematically checks that a protocol's key invariants hold. Its SecLaunch package is an end-to-end engagement that runs from design review through audits to security operations after launch.

X-ray static analyzer

X-ray is Sec3's best-known product. It launched in October 2021 as a commercial "auto auditor" under the Soteria name. According to the X-ray documentation, it detects more than 50 types of common vulnerabilities in both native Rust and Anchor-based Solana programs. Those vulnerability types are catalogued in Sec3's own taxonomy, the Sec3 Vulnerabilities and Exposures (SVE) list. X-ray plugs into GitHub CI and code-scanning alerts, exports SARIF reports for other tools, and issues a certificate when a scan finds nothing. The hosted service has a free tier plus paid Build and Scale plans that unlock the full set of SVE checks.

At Breakpoint 2024, Sec3 co-founder Chris Wang announced that X-ray was going open source. The X-ray repository is licensed under AGPL-3.0. It describes a pipeline that parses Rust programs into an abstract syntax tree, converts that into LLVM intermediate representation and then runs static analysis over it. The open-source checks cover issues including integer overflow and underflow, unverified account data, type confusion, unsafe program derived address (PDA) usage and arbitrary CPI calls. It ships as container images, prebuilt Linux binaries or source.

IDL Guesser and monitoring

In April 2025 Sec3 released IDL Guesser, a prototype tool that recovers instruction definitions from closed-source Solana program binaries. That includes the required accounts, their signer and writable flags, and parameter information. The company also offers free nonce and multisig monitoring. Earlier products described in its 2023 funding announcement included WatchTower, a real-time threat monitoring service for Solana smart contracts announced in September 2022, and CircuitBreaker, which was designed to detect and block suspicious activity. Neither appears in the current product line on Sec3's homepage.

Research

Sec3's biggest recent research project is the Solana Security Ecosystem Review 2025, also posted as a paper on SSRN by Jack Tsai, Chris Wang and Nick Zheng. It pools 163 Solana security reviews from eight audit firms: Sec3, Neodyme, OtterSec, Zellic, Pashov, Offside Labs, Zenith and Accretion. Together those reviews contain 1,669 vulnerability-level findings. The report found:

  • 99.4% of audits found at least one vulnerability.
  • Business logic, input validation and access control accounted for 82.5% of all findings and 85.5% of high and critical ones.
  • On-chain exploit losses on Solana fell from a peak of about $550 million in 2022 to about $8 million in 2025, even though audits kept finding vulnerabilities.

The report also compares vulnerability patterns across the native Rust SDK, Anchor and Pinocchio. It flags newer risk areas too: stacked protocols, yield-bearing stablecoins, AI-generated code and agent-driven execution.

Sec3's blog also covers developer topics such as Anchor account sizing, as well as validator client work. In July 2026 it published a post on Firedancer conformance testing, which explained how Firedancer's execution is checked against Agave using differential fixtures and fuzzing. In May 2023 the team released Owl LM (OwLLM v1), which it described as an open-source large language model for Web3.

Team, funding and background

Chris Wang is Sec3's co-founder and president. The firm says its team combines PhD-level research with competitive hacking experience and includes an eight-time DEF CON CTF finalist. Sec3 placed first in the Aptos CTF MOVEment 2022 and in the Sui CTF of the 2023 MetaTrust CTF.

In December 2021 Sec3 received a Solana Foundation grant to keep building security tools for the ecosystem. The Block reported in January 2023 that Sec3 had raised a $10 million seed round, which closed in April 2022. Multicoin Capital led the round, with Sanctor Capital and Essence VC joining. Angel investors included Solana co-founder Anatoly Yakovenko and Santiago Santos. At the time the company had about 15 staff and named Helium, Metaplex and Tulip as clients. It also said it planned to expand to other chains and to launch a governance token. We found no evidence that Sec3 has launched a token.

Place in the Solana ecosystem

Sec3 is one of a small group of audit firms that specialise in Solana programs. It has built both a paid audit business and free, open-source tools that any team can run. Open-sourcing X-ray and IDL Guesser, together with the multi-firm vulnerability dataset in its 2025 report, puts Sec3 in the tooling and research layer that Solana developers use before and after deployment, not just among firms selling audits.

Contents

Note: inclusion in Solana Compass directory does not indicate a recommendation or endorsement of this project, its token(s) or its products. Data sourced with thanks from The Grid to aid in building these pages.

Reviews

0.0
0 reviews
Please login to write a review.
Solana tokens

Solana Token Markets

Explore all tokens →