Flash Trade, a decentralized perpetual trading platform operating on the Solana network, experienced an exploit resulting in the unauthorized withdrawal of $98,000 in USDC. The incident took place on July 22 at 00:21 SGT and was linked to a validation flaw in the MagicBlock software development kit (SDK) used by the platform.
MagicBlock SDK flaw triggers unauthorized withdrawal
The exploit was traced to a vulnerability within the #[ephemeral] Anchor macro in the MagicBlock SDK, which handles callback processes for integrator smart contracts during undelegation requests. The flaw allowed an attacker to bypass undelegation checks by submitting a fabricated account designed to mimic a genuine user deposit.
Within a single transaction, the attacker’s account was used as the buffer for a sibling undelegation instruction. While the system correctly verified that the buffer was a signer owned by the delegation program, it failed to check that the buffer’s seeds matched the correct program-derived address. This oversight provided an opening for the exploit and resulted in the unauthorized withdrawal.
MagicBlock responded by reviewing other integrations that used the affected macro and notifying impacted projects. A patched version of the SDK, 0.16.2, now addresses the missing validation and is being recommended for immediate adoption by all integrators.
Mini dictionary: MagicBlock is a blockchain infrastructure company specializing in software tools and SDKs that enable fast and secure smart contract integration on Solana and other networks.
On July 22 at 00:21 SGT, Flash experienced an attack that resulted in a 98,000 USDC withdrawal from the platform. Flash’s batching and monitoring systems surfaced the activity immediately, and the team paused deposits and withdrawals within minutes.
According to statements from MagicBlock, the company has already worked with affected ecosystem participants to prevent similar incidents and is encouraging early upgrades to the patched SDK version.
Immediate response from Flash Trade and user fund protection
Flash Trade reported that its new monitoring and batching systems flagged the unauthorized withdrawal within minutes, allowing the team to react quickly. All trading, deposits, and withdrawals were immediately paused as a precaution while the incident was investigated in coordination with MagicBlock.
Normal trading functions resumed within a few hours, but deposits and withdrawals remained offline for approximately 24 hours during a reconciliation process aimed at confirming all platform balances and ensuring user fund integrity. The team emphasized that this suspension was intentional to guarantee a full and accurate reconciliation.
Flash Trade and MagicBlock have jointly contributed to a reimbursement fund covering the entire affected amount, ensuring that users bear no losses resulting from the exploit.
Both Flash Trade and MagicBlock affirmed that they would fully cover the unauthorized withdrawals, guaranteeing that no user funds would be lost. The prompt response and full reimbursement have drawn praise from the broader Solana community.
Industry reaction and security recommendations
Armani Ferrante, CEO of Backpack, an established digital asset wallet provider, commented publicly on the incident. Ferrante identified the exploit as an example of system design weaknesses in margin trading platforms, suggesting the need for a structural overhaul. He recommended implementing an isolated, formally verified custody contract combined with a 24-hour withdrawal timelock to provide platforms with more time to halt suspicious transactions in the event of a compromise.
Such mechanisms, Ferrante argued, would help contain damage from attacks affecting oracle systems, wallet compromises, and margin manipulation. He recognized Flash Trade’s rapid response, noting the importance of proactive security measures in reducing potential losses.
MagicBlock, following the incident, has pledged ongoing collaboration with blockchain integrators, auditors, and independent security researchers to improve the resilience of their SDK offerings and support the wider ecosystem in mitigating such vulnerabilities moving forward.
| Platform | Exploit Date | Asset Affected | Amount Lost | User Funds Covered? |
|---|---|---|---|---|
| Flash Trade | July 22, 2026 | USDC | $98,000 | Yes (fully covered) |
| Wanchain Cardano Bridge | Previous months | NIGHT | 515 million | N/A |




