◂ labs
TIER 1 · THE ACCOUNT MODEL · 0-signer-authorization

MISSING SIGNER CHECK

In Solana, nothing stops anyone from passing any account as "authority". If the handler never calls `is_signer`, a stranger can invoke privileged actions as someone else — no signature required. The single most common root cause in Solana exploits.

seen in the wild
Class behind countless drains; the pack proved it on our own vault corpus — 5 SOL gone in one tx.
rust · anchor
use anchor_lang::prelude::*;

declare_id!("Fg6PaFpoGXkYsidMpWTK6W2BeZ7FEfcYkg476zPFsLnS");
#[program]
pub mod signer_authorization_insecure {
    use super::*;

    pub fn log_message(ctx: Context<LogMessage>) -> ProgramResult {
        msg!("GM {}", ctx.accounts.authority.key().to_string());
        Ok(())
    }
}

#[derive(Accounts)]
pub struct LogMessage<'info> {
    authority: AccountInfo<'info>,
}
▸ the pack already hunted this class — watch the live feed of run_1789557416_ab10c0