Frank Castle Audits (FCA) is a specialist security firm for the Solana and Rust ecosystems. We find the critical vulnerabilities that drain protocols across Solana before attackers do
Work directly with the senior review team from day one
We merge top-firm manual auditing rigor with native Solana/Rust specialization, giving teams high-security assurance without standard corporate overhead.
Real, documented security results on named protocols. Detected major design vulnerabilities on ORO (11 Criticals, 1 High), STIX (3 Criticals, 4 Highs), cNGN (2 Criticals, 2 Highs), and BTRFI (5 Criticals, 2 Highs).
Proven excellence in public security contests. Ranked 2nd on HydraDX Omnipool (Code4rena, $21,555 reward) and 4th on Centrifuge (Cantina, $5,300 reward).
Deep expertise in Anchor v2, account-validation vectors (duplicate-mutable, type cosplay, reinitialization), CPI safety, and stablecoin precision/rounding math. We are dedicated Solana specialists, not generalists who dabble.
Work directly with the security researchers writing the code audits. No account managers, junior bait-and-switches, or administrative delays.
FCA active security research shapes open-source tools to assist developers in building and deploying secure smart contracts in Anchor and native Rust.
A template engine for compiling production-grade, secure Solana smart contracts in Anchor and native Rust. Encodes secure-by-default logic patterns and automated validator structures.
GitHub Repository →A weekly competitive challenges platform designed for security researchers to audit Solana smart contracts and claim verifiable, on-chain cryptographic credentials.
GitHub Repository →A structured 6-month developer journey path mapping fundamentals from basic Rust primitives up to advanced Solana smart contract security analysis.
GitHub Repository →Capture-the-flag exercises and target nodes designed for developer testing and practicing manual Solana exploit-finding mechanisms.
GitHub Repository →A list of verified private smart contract security audits completed by Frank Castle Audits. Our full historical ledger is hosted publicly on GitHub.
| ID | Protocol | Ecosystem | Vulnerabilities Found | Scope Partner | Report Ledger |
|---|---|---|---|---|---|
| #38 | Wick-2 by Lantern Validator | Rust · Solana | 5M 1L | FCA Direct | PDF Report ↗ |
| #37 | Wick by Lantern Validator | Rust · Solana | 4M 2L 8I | FCA Direct | PDF Report ↗ |
| #36 | GoldSand StableCoin | Rust · Solana | 1H 9M 14L | FCA Direct | NDA (Secure) |
| #35 | cNGN Stablecoin | Rust · Solana | 2C 2H 2M 13L | FCA Direct | NDA (Secure) |
| #34 | pAMM by Quantum Labs | Rust · Solana (pinocchio) | 1C 1H 2M 5L | FCA Direct | Announcement ↗ |
| #33 | Coalesce Finance | Rust · Solana | 3H 14M 15L | Pashov Audit Group | PDF Report ↗ |
| #32 | Meteora | Rust · Solana | 1M 5L | Pashov Audit Group | PDF Report ↗ |
| #31 | Weed Addicted | Rust · Solana | 3C | Pashov Audit Group | Upcoming |
| #30 | BitCorn × LayerZero | Rust · Solana | OFT Token | Spearbit · Cantina | — |
| #29 | Pump | Rust · Solana | NDA | Pashov Audit Group | NDA (Secure) |
| #28 | Pump (Token Incentive) | Rust · Solana | NDA | Pashov Audit Group | NDA (Secure) |
| #27 | Layer N | Rust · Solana | 1C 1M 4L | Cantina · Spearbit | PDF Report ↗ |
| #26 | BTRFI | Rust · Solana | 5C 2H 5M 13L | Pashov Audit Group | PDF Report ↗ |
We benchmark our manual review speed and severity detection rate in competitive arenas, proving audit credibility against top researchers globally.
Deep technical breakdowns of smart contract vulnerabilities, Anchor layouts, and stablecoin precision errors from our security research team.
Anchor V2 collapsed every account into one type, Slab, and replaced its duplicate-account checks with a single bitmask test. A teardown of both, ending on a bug shipping today.
Read Full Article →
A teardown of the decimal, precision, and validation bugs that drain Solana stablecoin programs, from a real Cantina review.
Read Full Article →Input your protocol details below. Our security team will review and reply within 24 hours.