CCWork
CC
Email me

Work

Sorare security review

Via Lazer I led the internal pre-audit security review of four Anchor programs for Sorare's move to Solana, and built the devnet tooling.

Role
Led the internal pre-audit security review and built the devnet tooling
When
Sep–Oct 2025
Client
Sorare, via Lazer Technologies
Stack
Rust, Anchor, Solana, Metaplex Bubblegum V2, MPL Core, Umi, and 4 more
Sorare blog post announcing Sorare's migration to Solana, with Sorare and Solana logos on the hero art
Sorare's public migration announcement, Oct 8, 2025.

Context

In October 2025 Sorare announced it was moving its officially licensed sports cards from StarkEx, an Ethereum scaling layer, to Solana. The new on-chain system was a set of Anchor programs covering minting, scarcity limits, secondary-market transfers and custody of user funds.

The external audit date was fixed, and my job was the internal review before it.

What I did

Via Lazer Technologies, I led the internal pre-audit review of four Anchor programs in an 11-day sprint. I found three critical issues, each verified in the code and delivered with a proposed fix, before the external audit. I also built the devnet tooling around the review.

  • I read each program line by line against Solana and Anchor practice, and delivered each finding with a severity, a confidence label, a proposed fix and an estimate.
  • I wrote TypeScript and bash scripts that stand up the whole test environment in dependency order: funded keypairs, MPL Core collections, Bubblegum V2 Merkle trees, address lookup tables and IPFS metadata. Tree and collection authority sit with program-derived addresses, so minting never needs a raw private key. The scripts are idempotent, so a half-finished run can just be run again.
  • I proposed a pooled-vault custody design, and a test strategy with a CI pipeline (lint, a parallel test matrix, a security scan and a devnet preview deploy) and regression tests for every issue I found.

Key decisions

I tagged every finding as certain, high confidence, educated guess or uncertain. A review read under deadline pressure gets acted on literally, and the tags meant nobody spent a day "fixing" a guess or skipped something I'd verified in the code.

I also kept private keys out of the minting path. Minting could only go through the minting program, and there was no key on a laptop to leak.

Result

The findings reached the team before the external audit, and the devnet tooling gave them a repeatable environment to test against. I can't share the findings themselves.

My part

Other engineers on the Lazer team wrote the on-chain programs. I reviewed them, and I wrote the devnet scripts and the test runner. The vault redesign, the test strategy and the CI pipeline were proposals, and I can't say how much of them shipped. A separate firm did the external audit.

Numbers

FigureWhat it measures
4Anchor programs reviewed
11 dayspre-audit sprint, before the external audit
3critical, code-verified issues, each delivered with a proposed fix
Questions