Adrena security assessment, April 2026: 42 findings on a Solana perpetuals DEX

Autonom engaged Fidesium to assess the Adrena program, a perpetual futures protocol on Solana. The assessment covered 33,747 lines of Rust across 168 source files and 125 public instructions, ran from 10 February to 18 March 2026, and was followed by a review of the remediation work between 31 March and 8 April. Forty-two findings were raised: 1 Critical, 3 High, 8 Medium, 12 Low and 18 Informational. The report was delivered on 11 April 2026 and the protocol’s risk score moved from 43 out of 100 at first delivery to 11 out of 100 at the close of the review.

What was reviewed

ProtocolAdrena, perpetual futures
ChainSolana
Engaged byAutonom
Repositorygithub.com/AdrenaFoundation/adrena, as stated in the report
Audited commit, initialb7ab492090a66f096b593bafec00bfc197542570
Audited commit, review94265a322a681a168d634da03c2e9b79dba1b4a3
Source files 168
Source lines of code33,747
Public instructions125
State structs63
Assessment period 10 February to 18 March 2026 Review period 31 March to 8 April 2026 Delivered 11 April 2026 Report version 2.0

The code splits into four areas. Instruction handlers account for 24,027 lines, on-chain state accounts for 10,912, shared maths, error and event code for 1,716, and external program adapters for 577. A perpetuals venue on Solana carries most of its risk in two of those places: the oracle path that prices every position, and the accounting that decides what a liquidity provider’s share is worth. Both are reflected in where the findings landed.

The assessment produced three documents. The main report carries the findings, the risk scoring and the remediation roadmap. A second covers the v38 to v39 migration, its behavioural differences and its freeze window. A third is the test matrix, holding the proof-of-concept inventory, the characterisation tests, the fuzzing architecture and the invariant catalogue.

The findings

Forty-two findings were raised in total.

Critial

1

High

3

Medium

8

Low

12

Info

18

The single Critical finding is recorded as resolved. Two of the three High findings are recorded as resolved, and their fixes are described below. The remaining findings carry their own status in the signed report, which is linked in full at the end of this page.

Findings whose fixes are recorded and verified:

IDFindingSeverityStatus
C1Missing timelock on admin operations, with single-step authority transferCriticalResolved
H1Virtual funding rate obligations invisible to assets under managementHighResolved
H3Switchboard oracle staleness launderingHighResolved
M1Governance vote weight inflated by re-counting resolved locked stakesMediumResolved
M3Profit and loss priced at the oracle midpoint rather than a protective confidence bandMediumResolved
M4Closed position accounts revivable because the discriminator was not zeroedMediumResolved
M6Oracle consensus threshold silently underweightedMediumResolved
M7Incorrect exponent handling in fixed-point divisionMediumResolved

 

What was fixed, and how it was verified

The admin key could take over the protocol in a single signature

Every privileged operation on the program executed immediately, atomically and under one signature, with no delay between intent and effect. A compromised admin key would therefore have granted immediate control, and there was no window in which anyone could react.

Adrena replaced the single-step transfer with a two-step process carrying a fixed 48 hour delay. The old single-step path is no longer usable, and the current admin can cancel a transfer that is pending. Fidesium records the finding as resolved, and notes that the change removes the immediate takeover risk identified in the original write-up.

Funding obligations were missing from the assets-under-management figure

The protocol’s assets-under-management calculation ignored accrued virtual funding rate obligations, because the function assembling a collective position zeroed the funding fields through a struct default. Liquidity provider tokens were therefore redeemed against a figure that did not carry the pool’s funding liabilities.

Two aggregate fields were added to the positions accounting struct, reusing existing padding bytes, and the collective position function now populates the unrealised funding figures from those aggregates instead of zeroing them. A residual issue in the same area, where individual instructions updated position-level funding directly and bypassed the aggregate, was closed at the same time: a single settlement method now updates the position and the custody-level aggregates atomically, and the report confirms that all ten instruction paths that touch funding call it. Fidesium records the finding as resolved in full.

Oracle timestamps could be laundered into a window of stale prices

The program overwrote the stored timestamp on an oracle price at the moment it was stored, which meant a price that was already old could be presented downstream as fresh. Combined with a caller-supplied freshness parameter that had no on-chain cap, that opened a window of roughly 20 seconds in which stale data would pass the staleness check.

The fix clamps the timestamp at storage time to the current time, so a stored price can never claim to be newer than it is, and rejects any quote whose age exceeds the parameter. Fidesium records the finding as resolved across three commits, the first introducing the clamp and two further commits refining it.

The four remaining fixes

Four Medium findings in governance, accounting and maths were closed in the same round: governance voting power that could be re-inflated by re-counting stakes already resolved, profit and loss priced at an oracle midpoint rather than a protective confidence band, closed position accounts that could be revived because their discriminator was not zeroed on close, and an exponent sign error that inflated the result of a fixed-point division. Each is described in the signed report.

How the assessment was run

Nine methods were applied: manual source code review, system design analysis, fuzzing, on-chain analysis, red-team exploit simulation, economic modelling, formal verification, supply chain and dependency audit, and compound attack chain analysis.

The work was carried out by named engineers rather than subcontracted. Abraham Polishchuk led, Chadi Sebbar ran the red team, and Gregory Bockenstette was the third researcher on the engagement.

The dates are the honest answer to how long an audit of this size takes. Five weeks of assessment for 33,747 lines of Rust and 125 public instructions, then a delivery, then a separate remediation review the following month once the team had made its changes. The risk score is the record of what that second pass bought: 43 out of 100 at first delivery on 18 March, 17 out of 100 on 5 April, and 11 out of 100 on 11 April.

The methodology behind the engagement, including the four-pass framework and the three-layer test suite built for it, is written up separately in the Fidesium and Adrena case study.

Audit summary
Fidesium Audits

The signed report

The complete report is the artefact of record and it is unchanged: Adrena v3, 11 April 2026 (PDF). It carries every finding at every severity, the remediation roadmap, and eleven appendices covering the architecture, token flows, on-chain state, the permissionless attack surface and the dependency analysis.

The report is governed by Fidesium’s terms and conditions. It is an assessment of code quality and risk at two specific commits. It is not an endorsement of Adrena or of Autonom, it is not investment advice, and it does not guarantee the absence of bugs. An audit describes a codebase on the day it was read, which is why the engagement included a second pass against the changed code.

Other Solana protocols in the public portfolio include BlockAsset, a real world asset protocol audited in January 2025, and Banana Zone, audited in December 2025. All 23 public reports are listed at audits.

Request a quote

An audit of this depth starts with scope, and scope starts with a conversation about which parts of the codebase carry the risk. Fidesium’s manual smart contract audits are line-by-line reviews by the engineers who built the tooling, with two rounds of fix verification included, priced from $5,000 depending on the codebase.

Tell us what you are shipping and when, and we will scope it.

Tell us your security needs