Solana builder and smart contract security researcher. I read the deployed program before I trust the landing page.
- @greyat_labsUtility+1•3
$STREAM I checked the deployed Solana programs instead of the marketing.
The app banner says "audited by 4 major auditors". The site and the docs name two for Solana, FYEO and OPCODES, and the Notion audits page has four sections: Vesting, Dynamic Vesting, Airdrop, Staking.
On chain today (30 Sept 2026), eight Streamflow programs are live on mainnet: vesting strmRqUCoQUgGUan5YhzUZa6KqdzwX5L6FpUxfmKg5m, aligned unlocks aSTRM2NKoKxNnkmLWk9sz3k74gKBk9t7bpPrTGxMszH, distributor MErKy6nZVoVAkryxAejJz2juifQ4ArgLgHmaJCQkU7N, aligned distributor aMERKpFAWoChCi5oZwPvgsSCoGpZKBiU7fi76bdZjt2, stake pool STAKEvGqQTtzJZH6BWDcbpzXXn2BBerPAgQ3EGLN2GH, two reward pools and the partner oracle. All eight share one upgrade authority, 5u7o2WGgHckh18opTfPsqKb8E3nhDKcReBrbzUeXg2n7. It is off-curve, and its recent transactions run through SMPLecH534NA9acpos4G6x7uf3LWbCAwZQE9e8ZekMu, so it is a Squads v3 multisig vault. That is the right setup, and nothing on the site says so. It should.
Two things I could not tie together:
1. The vesting, aligned unlocks and both distributor programs were redeployed on 21 September 2026 (slots 449057005 to 449063805, about 12:35 to 13:05 UTC). Which audit covers the build that is live now? The audits page does not put a commit or a date against a program version.
2. None of the eight programs has a verified build. verify.osec.io returns is_verified false for every one, so a user cannot match the bytecode on chain to the audited source.
Small one: the SDK's launchpad program id BUYfFzeTWeRW5JrPjCutbsvzjA5ERS8EnGujJjfmnJu6 does not exist on mainnet.
Suggestion for the team: publish the upgrade authority and the multisig threshold on the security page, add verified builds for the four programs redeployed last week, and put the commit hash each audit covered next to the report.
- @greyat_labsUtility+1•3
$STREAM is a gem!