Solana Foundation switches to 24/7 monitoring. For Lazarus, that's table stakes.
The Foundation closed the off-hours gap state-funded attackers exploit. Whether $10M buys you real coverage is a different question.

CryptoVibe Desk · solana · security · infrastructure

- →Solana Foundation launched 24/7 threat monitoring and a dedicated incident-response network for protocols carrying more than $10M in user deposits, announced April 7 and ramping through the rest of the month.
- →State-sponsored groups like Lazarus Group run continuous, multi-week operations and time exploits for low-staffing windows; best-effort monitoring was never adequate against that adversary class.
- →The first live exploit against a Solana protocol above the $10M threshold post-rollout, and whether the response network activates automated mitigation within the first 60 minutes rather than filing an after-action report after the fact, will arrive before year-end 2026.
- Lazarus Group → A North Korean state-sponsored hacking collective known for targeting crypto protocols with multi-week reconnaissance campaigns and off-hours execution.
- circuit breaker → An automated mechanism in a smart contract that pauses protocol functions if suspicious activity exceeds a threshold, limiting how much can be drained during an active exploit.
The problem with on-call security programs is that attackers don't respect working hours. Solana Foundation's April 7 security overhaul addresses this directly: 24/7 threat monitoring across the validator network, and a dedicated incident-response capability for any Solana-deployed protocol carrying more than $10M in user deposits.
The $10M threshold defines who is inside the coverage perimeter. Protocols below it are still on their own, and that's not a knock on the Foundation: you can't monitor everything. But any team near that line should understand the boundary explicitly.
The reason this matters is the adversary type. State-sponsored groups like Lazarus Group don't run standard business-hours operations. They run reconnaissance over weeks, probe infrastructure during low-staffing windows, and trigger exploits when human response time is slowest.
Lazarus's documented playbook across prior DeFi exploits includes multi-week pre-attack reconnaissance and off-hours execution. A monitoring posture where someone checks alerts during the day and catches a Slack ping at 2 a.m. is not a real deterrent against that threat model. Continuous coverage is.
The tradeoff is staffing cost for coverage depth. A 24/7 incident-response program requires alert infrastructure, runbooks, and clear escalation paths. The Foundation hasn't published specifics on what its dedicated incident-response network means operationally: whether it includes automated circuit breakers, coordinated validator-set response, or human escalation chains. That distinction matters. An automated pause mechanism and a human pager are not the same tool against a coordinated, multi-vector attack.
What actually ships is what counts. The April 7 announcement set the policy; the rest of April has been ramping the infrastructure. The bar the Foundation set is the correct bar for the adversary class Solana protocols are actually facing. It is also the minimum bar, not the ceiling.
The Foundation's choice to ship coverage without a published runbook is the wrong call. Protocol teams inside the $10M perimeter are anchoring their security posture to a program they cannot read, verify, or integrate with at the contract level. Opaque incident response is not incident response.
The first live exploit against a Solana protocol above the $10M threshold post-rollout will be the real test. Watch whether the incident-response network activates automated mitigation within 60 minutes or files an after-action report after the fact. That answer arrives before year-end 2026.
Primary links and supporting reads used by the desk for this story.
Forward this.











