30 Common Mistakes Solana Developers Make (And How to Avoid Them)
Solana's account model and Rust-based development create unique pitfalls that catch even experienced developers. Here are the most common mistakes and how to avoid them.
Account Validation Failures
Missing account ownership check
Not verifying that accounts are owned by expected programs allows attackers to pass fake accounts.
Not validating account discriminators
Without discriminator checks, wrong account types can be passed to instructions.
Missing signer validation
Not checking that required accounts have actually signed the transaction.
Trusting account data without validation
Assuming account data is correctly formatted without deserializing and validating.
Not checking account mutability
Attempting to write to accounts not marked as writable.
PDA Problems
Inconsistent PDA seeds
Using different seeds for derivation and validation causes lookup failures.
Not storing bump in account
Recalculating bump wastes compute units and can fail.
Using find_program_address in instruction handlers
find_program_address is expensive. Calling it repeatedly wastes compute.
Wrong program ID in PDA derivation
Using wrong program ID creates PDAs that can't sign for your program.
Seeds too long
PDA seeds have a maximum total length of 32 bytes.
Token Handling Errors
Not checking token mint
Token accounts can hold any SPL token. Not validating mint allows wrong tokens.
Ignoring token decimals
Calculating amounts without considering decimals leads to wrong values.
Not closing empty accounts
Empty token accounts still cost rent. Not closing them leaks SOL.
Wrong token program ID
Token-2022 uses different program ID than SPL Token.
Not handling frozen accounts
Transfers to/from frozen accounts fail silently or with confusing errors.
Arithmetic Issues
Integer overflow/underflow
Rust's release mode doesn't check for overflow by default.
Precision loss in division
Integer division truncates. Order of operations matters for precision.
Rounding in wrong direction
Rounding errors can be exploited over many transactions.
Using u64 for timestamps
Solana Clock uses i64 for timestamps. Type mismatch causes issues.
CPI Vulnerabilities
CPI to arbitrary programs
Not validating target program allows attackers to redirect CPIs.
Missing signer seeds in CPI
PDA-signed CPIs without seeds fail authorization.
Reentrancy through CPI
CPIs can call back into your program with unexpected state.
Not checking CPI return values
Ignoring CPI results can mask failures.
Common Development Mistakes
Not handling compute budget
Complex operations can exceed compute limit.
Forgetting to update IDL
Changed program without updating IDL breaks clients.
Testing only on localnet
Localnet doesn't have same constraints as mainnet.
Not initializing accounts properly
Uninitialized accounts contain garbage data.
Ignoring rent requirements
Accounts below rent-exempt threshold get garbage collected.
Clockwork misuse
Using Solana's clock sysvar for critical timing without considering validator manipulation.
Hardcoded cluster-specific addresses
Using mainnet program IDs in devnet code or vice versa.
Ignoring transaction size limits
Solana transactions have a 1232 byte limit, causing unexpected failures.
Key Recommendations
Read the source code of programs you interact with via CPI. Documentation may be outdated.
Test with realistic transaction volumes. Solana programs behave differently under load.
Keep your Anchor version pinned. Breaking changes between versions are common.
