FIELD MANUAL
[ LABS · LEARN BY HUNTING ]
A Solana security curriculum: foundations first (the account model every bug exploits), then eleven vulnerability classes — each lab shows the vulnerable code, the fix, the real-world exploit it caused, and lets you unleash the pack on it. No slides.
TIER 0 · FOUNDATIONS
read these first — the mental model every vuln class exploits
TIER 1 · THE ACCOUNT MODEL
where Solana bugs live: who signed, who owns, what the bytes mean
TIER 2 · CPI & PDAs
cross-program trust, derived addresses, and the edges between them
Reinitialization
reinitialization · 4-initialization
Arbitrary CPIPACK-PROVEN
arbitrary-cpi · 5-arbitrary-cpi
Duplicate Mutable Accounts
duplicate-mutable-accounts · 6-duplicate-mutable-accounts
Bump Seed Canonicalization
bump-seed-canonicalization · 7-bump-seed-canonicalization
PDA Sharing
pda-sharing · 8-pda-sharing
TIER 3 · LIFECYCLE & SYSVARS
account death, revival, and forged runtime inputs
lab programs from coral-xyz/sealevel-attacks (Apache-2.0) — insecure / secure / recommended variants