Sorare security review
Via Lazer I led the internal pre-audit security review of four Anchor programs for Sorare's move to Solana, and built the devnet tooling.
- Role
- Led the internal pre-audit security review and built the devnet tooling
- When
- Sep–Oct 2025
- Client
- Sorare, via Lazer Technologies
- Stack
- Rust, Anchor, Solana, Metaplex Bubblegum V2, MPL Core, Umi, and 4 more
Context
In October 2025 Sorare announced it was moving its officially licensed sports cards from StarkEx, an Ethereum scaling layer, to Solana. The new on-chain system was a set of Anchor programs covering minting, scarcity limits, secondary-market transfers and custody of user funds.
The external audit date was fixed, and my job was the internal review before it.
What I did
Via Lazer Technologies, I led the internal pre-audit review of four Anchor programs in an 11-day sprint. I found three critical issues, each verified in the code and delivered with a proposed fix, before the external audit. I also built the devnet tooling around the review.
- I read each program line by line against Solana and Anchor practice, and delivered each finding with a severity, a confidence label, a proposed fix and an estimate.
- I wrote TypeScript and bash scripts that stand up the whole test environment in dependency order: funded keypairs, MPL Core collections, Bubblegum V2 Merkle trees, address lookup tables and IPFS metadata. Tree and collection authority sit with program-derived addresses, so minting never needs a raw private key. The scripts are idempotent, so a half-finished run can just be run again.
- I proposed a pooled-vault custody design, and a test strategy with a CI pipeline (lint, a parallel test matrix, a security scan and a devnet preview deploy) and regression tests for every issue I found.
Key decisions
I tagged every finding as certain, high confidence, educated guess or uncertain. A review read under deadline pressure gets acted on literally, and the tags meant nobody spent a day "fixing" a guess or skipped something I'd verified in the code.
I also kept private keys out of the minting path. Minting could only go through the minting program, and there was no key on a laptop to leak.
Result
The findings reached the team before the external audit, and the devnet tooling gave them a repeatable environment to test against. I can't share the findings themselves.
My part
Other engineers on the Lazer team wrote the on-chain programs. I reviewed them, and I wrote the devnet scripts and the test runner. The vault redesign, the test strategy and the CI pipeline were proposals, and I can't say how much of them shipped. A separate firm did the external audit.
Numbers
| Figure | What it measures |
|---|---|
| 4 | Anchor programs reviewed |
| 11 days | pre-audit sprint, before the external audit |
| 3 | critical, code-verified issues, each delivered with a proposed fix |
Links
Stack: Rust, Anchor, Solana, Metaplex Bubblegum V2, MPL Core, Umi, TypeScript, Bash, Helius, GitHub Actions
