Solana’s Flash Trade Hit by $98,000 USDC Exploit, Says Users Won’t Lose Funds
Hacked

Solana’s Flash Trade Hit by $98,000 USDC Exploit, Says Users Won’t Lose Funds

By Samuel

Flash Trade suffered a $98,000 USDC exploit tied to a MagicBlock SDK bug, but the team confirms all user funds stay fully covered.

Flash Trade’s Solana-based perpetuals exchange suffered an unauthorized withdrawal of $98,000 in USDC on July 22 at 00:21 SGT. The exploit stemmed from a validation flaw in MagicBlock’s SDK, which let an attacker slip a fake account past the platform’s undelegation checks. 

Moreover, Flash Trade’s recently deployed batching and monitoring systems flagged the activity within minutes. The team paused all deposits, withdrawals, and trading as a precaution. 

Both Flash Trade and MagicBlock confirmed the full amount would be reimbursed, with zero impact on user balances.

MagicBlock SDK Flaw Behind the Flash Trade Exploit

The root cause traced back to an incomplete validation path inside the #[ephemeral] Anchor macro built into MagicBlock’s SDK. This macro handles callbacks that integrator smart contracts use to process undelegation requests from Ephemeral Rollup instances. 

The attacker deployed a program that delegated a manufactured account meant to mimic a real user deposit. 

Within the same transaction, that account got passed off as the buffer for a sibling undelegation instruction. The macro checked that the buffer was a signer owned by the delegation program, but it never confirmed the buffer matched the correct PDA seeds. 

That gap let the attacker’s account pass as legitimate, triggering an invalid receipt and clearing the way for the withdrawal.

MagicBlock said it reviewed every other program using the same macro and contacted affected teams directly. 

A patched SDK version, 0.16.2, now enforces the missing validation by default. The company urged all integrators running earlier versions to upgrade immediately.

Read also: 

Wanchain Cardano Bridge Exploited, 515M NIGHT Drained From Treasury

Flash Trade’s Response and Fund Recovery Timeline

Flash Trade said its withdrawal batching and monitoring system, rolled out recently, caught the suspicious activity almost instantly. 

Trading, deposits, and withdrawals were paused while the team investigated alongside MagicBlock. Within hours, trading resumed, though deposits and withdrawals stayed offline for roughly 24 hours during reconciliation. 

The team said this sequencing was deliberate, prioritizing accurate fund reconciliation before reopening withdrawals. 

Flash Trade and MagicBlock jointly contributed to a fund covering 100% of the affected deposits. The platform stated no user would be out of pocket. 

Industry Reaction to the Solana Perpetuals Exchange Hack

Backpack CEO Armani Ferrante weighed in publicly, describing the incident as another example of a margin system exploit. He proposed a structural fix involving an isolated, formally verified custody contract paired with a 24-hour withdrawal timelock. 

Ferrante argued that such a design would let platforms halt withdrawals quickly during an attack. This would limit damage across oracle failures, wallet compromises, and margin manipulation. 

He also acknowledged Flash Trade’s fast response, placing the team among others that have handled similar incidents well. 

MagicBlock, for its part, said it would continue working with integrators, auditors, and independent researchers to strengthen SDK-level security going forward.

Samuel

About the Author

Samuel

Leave a Reply