Adrena security assessment, April 2026: 42 findings on a Solana perpetuals DEX
Autonom engaged Fidesium to assess the Adrena program, a perpetual futures protocol on Solana. The assessment covered 33,747 lines of Rust across 168 source files and 125 public instructions, ran from 10 February to 18 March 2026, and was followed by a review of the remediation work between 31 March and 8 April. Forty-two findings were raised: 1 Critical, 3 High, 8 Medium, 12 Low and 18 Informational. The report was delivered on 11 April 2026 and the protocol’s risk score moved from 43 out of 100 at first delivery to 11 out of 100 at the close of the review.
What was reviewed
| Protocol | Adrena, perpetual futures |
| Chain | Solana |
| Engaged by | Autonom |
| Repository | github.com/AdrenaFoundation/adrena, as stated in the report |
| Audited commit, initial | b7ab492090a66f096b593bafec00bfc197542570 |
| Audited commit, review | 94265a322a681a168d634da03c2e9b79dba1b4a3 |
| Source files | 168 |
| Source lines of code | 33,747 |
| Public instructions | 125 |
| State structs | 63 |
| Assessment period 10 February to 18 March 2026 | Review period 31 March to 8 April 2026 | Delivered 11 April 2026 | Report version 2.0 |
The code splits into four areas. Instruction handlers account for 24,027 lines, on-chain state accounts for 10,912, shared maths, error and event code for 1,716, and external program adapters for 577. A perpetuals venue on Solana carries most of its risk in two of those places: the oracle path that prices every position, and the accounting that decides what a liquidity provider’s share is worth. Both are reflected in where the findings landed.
The assessment produced three documents. The main report carries the findings, the risk scoring and the remediation roadmap. A second covers the v38 to v39 migration, its behavioural differences and its freeze window. A third is the test matrix, holding the proof-of-concept inventory, the characterisation tests, the fuzzing architecture and the invariant catalogue.
The findings
Forty-two findings were raised in total.
Critial
1
High
3
Medium
8
Low
12
Info
18
The single Critical finding is recorded as resolved. Two of the three High findings are recorded as resolved, and their fixes are described below. The remaining findings carry their own status in the signed report, which is linked in full at the end of this page.
Findings whose fixes are recorded and verified:
| ID | Finding | Severity | Status |
|---|---|---|---|
| C1 | Missing timelock on admin operations, with single-step authority transfer | Critical | Resolved |
| H1 | Virtual funding rate obligations invisible to assets under management | High | Resolved |
| H3 | Switchboard oracle staleness laundering | High | Resolved |
| M1 | Governance vote weight inflated by re-counting resolved locked stakes | Medium | Resolved |
| M3 | Profit and loss priced at the oracle midpoint rather than a protective confidence band | Medium | Resolved |
| M4 | Closed position accounts revivable because the discriminator was not zeroed | Medium | Resolved |
| M6 | Oracle consensus threshold silently underweighted | Medium | Resolved |
| M7 | Incorrect exponent handling in fixed-point division | Medium | Resolved |
What was fixed, and how it was verified
The admin key could take over the protocol in a single signature
Every privileged operation on the program executed immediately, atomically and under one signature, with no delay between intent and effect. A compromised admin key would therefore have granted immediate control, and there was no window in which anyone could react.
Adrena replaced the single-step transfer with a two-step process carrying a fixed 48 hour delay. The old single-step path is no longer usable, and the current admin can cancel a transfer that is pending. Fidesium records the finding as resolved, and notes that the change removes the immediate takeover risk identified in the original write-up.
Funding obligations were missing from the assets-under-management figure
The protocol’s assets-under-management calculation ignored accrued virtual funding rate obligations, because the function assembling a collective position zeroed the funding fields through a struct default. Liquidity provider tokens were therefore redeemed against a figure that did not carry the pool’s funding liabilities.
Two aggregate fields were added to the positions accounting struct, reusing existing padding bytes, and the collective position function now populates the unrealised funding figures from those aggregates instead of zeroing them. A residual issue in the same area, where individual instructions updated position-level funding directly and bypassed the aggregate, was closed at the same time: a single settlement method now updates the position and the custody-level aggregates atomically, and the report confirms that all ten instruction paths that touch funding call it. Fidesium records the finding as resolved in full.
Oracle timestamps could be laundered into a window of stale prices
The program overwrote the stored timestamp on an oracle price at the moment it was stored, which meant a price that was already old could be presented downstream as fresh. Combined with a caller-supplied freshness parameter that had no on-chain cap, that opened a window of roughly 20 seconds in which stale data would pass the staleness check.
The fix clamps the timestamp at storage time to the current time, so a stored price can never claim to be newer than it is, and rejects any quote whose age exceeds the parameter. Fidesium records the finding as resolved across three commits, the first introducing the clamp and two further commits refining it.
The four remaining fixes
Four Medium findings in governance, accounting and maths were closed in the same round: governance voting power that could be re-inflated by re-counting stakes already resolved, profit and loss priced at an oracle midpoint rather than a protective confidence band, closed position accounts that could be revived because their discriminator was not zeroed on close, and an exponent sign error that inflated the result of a fixed-point division. Each is described in the signed report.
How the assessment was run
Nine methods were applied: manual source code review, system design analysis, fuzzing, on-chain analysis, red-team exploit simulation, economic modelling, formal verification, supply chain and dependency audit, and compound attack chain analysis.
The work was carried out by named engineers rather than subcontracted. Abraham Polishchuk led, Chadi Sebbar ran the red team, and Gregory Bockenstette was the third researcher on the engagement.
The dates are the honest answer to how long an audit of this size takes. Five weeks of assessment for 33,747 lines of Rust and 125 public instructions, then a delivery, then a separate remediation review the following month once the team had made its changes. The risk score is the record of what that second pass bought: 43 out of 100 at first delivery on 18 March, 17 out of 100 on 5 April, and 11 out of 100 on 11 April.
The methodology behind the engagement, including the four-pass framework and the three-layer test suite built for it, is written up separately in the Fidesium and Adrena case study.
The signed report
The complete report is the artefact of record and it is unchanged: Adrena v3, 11 April 2026 (PDF). It carries every finding at every severity, the remediation roadmap, and eleven appendices covering the architecture, token flows, on-chain state, the permissionless attack surface and the dependency analysis.
The report is governed by Fidesium’s terms and conditions. It is an assessment of code quality and risk at two specific commits. It is not an endorsement of Adrena or of Autonom, it is not investment advice, and it does not guarantee the absence of bugs. An audit describes a codebase on the day it was read, which is why the engagement included a second pass against the changed code.
Other Solana protocols in the public portfolio include BlockAsset, a real world asset protocol audited in January 2025, and Banana Zone, audited in December 2025. All 23 public reports are listed at audits.
Request a quote
An audit of this depth starts with scope, and scope starts with a conversation about which parts of the codebase carry the risk. Fidesium’s manual smart contract audits are line-by-line reviews by the engineers who built the tooling, with two rounds of fix verification included, priced from $5,000 depending on the codebase.
Tell us what you are shipping and when, and we will scope it.