FlashTrade Hack
What happened
An attacker withdrew approximately $98,000 from FlashTrade's MagicBlock-powered ephemeral instance. FlashTrade paused operations, reconciled the affected state, and restored trading after deploying a mitigation.
MagicBlock's ephemeral-rollup undelegation callback did not validate that the supplied buffer account was derived from the expected program-derived address.
How it happened
During undelegation, a forged buffer account was accepted as the canonical program-derived address. The invalid account allowed an unauthorized withdrawal from the affected ephemeral instance.
Protocol details
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.