Incident case file
Sign in to watchFlashTrade — MagicBlock SDK undelegation validation flaw
1 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — not publicly disclosed. Incident fully reimbursed; zero user impact.
Timeline: On July 21, 2026 at approximately 00:21 SGT (16:21 UTC), FlashTrade — a Solana-based perpetuals exchange using MagicBlock's ephemeral rollup technology — detected an unauthorized $98,000 USDC withdrawal from its ephemeral rollup instance. The attack exploited an incomplete validation path in the #[ephemeral] Anchor macro within MagicBlock's SDK: the macro's undelegation callback failed to reject a crafted fake account, allowing the withdrawal to bypass normal authorization checks. FlashTrade's newly deployed withdrawal-batching and monitoring system flagged the anomaly within minutes. The team immediately paused trading, deposits and withdrawals. MagicBlock confirmed the root cause, audited all programs using the same macro, notified affected teams, and released patched SDK v0.16.2 enforcing the missing validation. Trading resumed within hours; full deposit/withdrawal functionality was restored approximately 24 hours after the incident. FlashTrade and MagicBlock jointly funded 100% reimbursement — no user lost funds.
Sources and coverage
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)