◂ labs
TIER 0 · FOUNDATIONS

THE ACCOUNT MODEL

Ethereum contracts own their storage. Solana programs are stateless — they hold no data. Everything lives in accounts: lamports (balance), data (raw bytes), owner (the program allowed to write it), and flags. A "wallet" is an account owned by the System Program. A "token account" is an account owned by the Token Program whose data encodes mint+owner+amount. Every instruction receives the accounts it may touch as arguments — the runtime enforces nothing about what they mean. That single design choice is why Solana security exists as a discipline.

seen in the wild
Almost every Solana exploit is an account-model misunderstanding weaponized: wrong owner, wrong data, wrong signer, wrong program. Learn the model and the bugs read themselves.