This is an example of how to do incident response right.
* have proper monitoring in place
* work quickly to identify and patch the issue
* utilize Solana’s SIRN program for assistance
* publicly acknowledge and address the impact as soon as possible
* make affected users whole
Great example to set for the ecosystem and a case study we’ll use to improve the Solana ecosystem’s security posture even more in the future.
Earlier today, Rain’s monitoring systems discovered a vulnerability impacting a small number of programs using an outdated version of our Solana contracts. Other programs were not impacted. Rain immediately launched an investigation to determine the full scope of the situation.
Our team has successfully upgraded all programs that were using the outdated version of the Solana contracts, which has resolved the situation. Rain is continuing to monitor the issue, has engaged third-party forensics experts to investigate, and will work with law enforcement and relevant regulatory authorities.
All affected users will be made whole. We’ve already begun the remediation process and are focused on delivering a swift and responsible resolution.