◂ labs
TIER 0 · FOUNDATIONS

OWNERSHIP = TRUST

A program can only write to accounts it owns — the runtime enforces that. What it does NOT enforce: that an account you READ was created by who you think. Any program can craft an account whose bytes deserialize perfectly into your struct. Checking account.owner == expected_program is what turns "bytes that look right" into "data I can trust".

seen in the wild
Fake-account attacks powered the early Solana exploit wave. Anchor's Account<'info, T> validates owner + discriminator automatically; raw AccountInfo validates nothing.