On-chain program upgrade analysis
SolDiff
Understand what changed.
Reconstruct historical Solana program versions from upgrade buffer writes, then compare the binaries with evidence-backed diffs — not marketing claims.
Illustrative reconstruction flow — live reports use real on-chain signatures and hashes.
Run a real mainnet upgrade diff.
Five verified on-chain upgrade pairs (Token-2022 → Kamino stress → reused buffer). Open Analyze with the exact program ID and upgrade signatures — reports come from the live pipeline, not hand-written fixtures.
Token-2022
Lightest real pair (~1.35 MB). Distinct buffers: GcAbnM4D… (542 writes) → BsRtj52F… (629 writes). Both cycles verified clean. Non-Anchor — exercises historical IDL unavailable (never silently unchanged).
- Program ID
- TokenzQdBNbLqP5VEhdkAS6EPFLC1PHnBqCXEpPxuEb
- Version A · slot 346,170,941
- 39CiabTipsmCxWLVsY9ciVBuY5FNHUr2FpF5x6shs42w6KFjx1J2nogMtJezwgNfyAxDgTexZwc3P1SEUMd2vhPP
- Version B · slot 427,147,035
- 2cM3S25AJnHyy4shW7zsoqz5W8JPXPvXiUxk545n5ANf6BET9VvBRfsnSNYi9MqogjVWNBxNfaZpE9QBJX4XCbfn
From upgrade signatures to
evidence-backed bytecode diffs.
Built around trustworthy historical reconstruction first. Advanced semantic claims stay out of scope until they can be proven.
Parse upgrade transactions
SolDiff reads two BPF Upgradeable Loader Upgrade transactions, extracts buffer / Program / ProgramData addresses, and validates Version A is older than Version B.
parseUpgradeTransaction(sigA|sigB)Reconstruct historical ELFs
Buffer Write instructions are collected, ordered deterministically, isolated to a deployment cycle, coverage-checked, and assembled into validated ELF64 artifacts with full SHA-256 identity.
Write replay → coverage map → validateElf()Raw byte + SBF instruction diff
`.text` and `.rodata` are compared at the byte-chunk layer. An SBF instruction-level decoder adds sequence-aligned instruction evidence. This is not a semantic decompiler.
raw-byte diff + soldiff-ebpf-isa / optional sbpf|llvm-objdumpOptional Anchor IDL diff
When an IDL can be historically matched, instruction/account/discriminator changes are reported with evidence. Otherwise historical IDL is marked unavailable — never silently unchanged.
normalizeIdl → compareNormalizedIdlsEvidence-backed findings
Heuristic findings attach analyzer, confidence, and evidence. Overstated claims (e.g. treating sampled pubkeys as CPI targets) are avoided.
Finding{ analyzer, code, severity, confidence, evidence }Reproducible case study
CLI/scripts emit manifest.json + report.md with hashes and provenance. Reports are ephemeral in the UI today — persistence/shareable URLs are not shipped yet.
bun run case-study --program … --from … --to …Ten rules that catch
real exploits.
Every rule is derived from a real Solana incident. The engine targets a zero false-negative rate on CRITICAL findings — if it fires, treat the upgrade as dangerous until proven otherwise.
Fits into your existing workflow.
Web UI, CLI, TypeScript SDK, or GitHub Actions. One engine, every entry point.