FlashTrade Hack

Reported loss $98K
Solana
Missing Input Validation

What happened

An attacker withdrew approximately $98,000 from FlashTrade's MagicBlock-powered ephemeral instance. FlashTrade paused operations, reconciled the affected state, and restored trading after deploying a mitigation.

Technical root cause

MagicBlock's ephemeral-rollup undelegation callback did not validate that the supplied buffer account was derived from the expected program-derived address.

How it happened

During undelegation, a forged buffer account was accepted as the canonical program-derived address. The invalid account allowed an unauthorized withdrawal from the affected ephemeral instance.

Protocol details

Classification Input Validation
Protocol Type Derivatives
Implementation language Rust
Protocol links Website @FlashTrade

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.