Pirates Parley

Pirates Parley

Every week, Steve (aka Happy Pirate) sits down with the builders, founders, and OGs shaping the Solana ecosystem. From DeFi protocols and DEX aggregators to wallets, oracles, and infrastructure — Pirates Parley dives deep into what it takes to build on-chain solutions on Solana.

Subscribe & Listen

New episodes weekly

Latest Episode

Who's Selling Your Swaps? Benjamin Boulin on Order Flow, MEV, and Getting Paid Back

0:000:00

All Episodes(12+)

Who's Selling Your Swaps? Benjamin Boulin on Order Flow, MEV, and Getting Paid Back
1:03:58
October 8, 2026

Who's Selling Your Swaps? Benjamin Boulin on Order Flow, MEV, and Getting Paid Back

Benjamin Boulin was running Minecraft servers at 11 and paying developers in Bitcoin by 2015. Today he's the founder of Circular, built after his arb team hit 30 million transactions a day and no tool on Solana could keep up. We get into how a simple swap leaks value to whoever controls the order flow, why platforms selling your swaps are earning double on you, and how Circular's monetization layer sends 65% of recovered arb profit straight back to the trader's wallet. Ben breaks down where a landing tip actually goes (Jito, Harmonic, SWQoS, direct to the leader), why every launchpad ends up building its own AMM, and why "we don't do MEV" is not the user protection it sounds like. Also: Counter-Strike skins lost to casinos, Valve's total control over your inventory, and what happens the day GTA 6 puts its cars on-chain. Fast transaction landing: landfast.io Circular: circular.fi 0:00 Welcome — one of my best friends in the ecosystem 1:40 Entrepreneur at 11: Minecraft servers, PayPal bans, and a broken financial system 7:07 A dev demanded Bitcoin in 2015 — and Ben didn't get it until Ethereum 12:00 Nifting: Steam meets Twitter for NFT skins 15:08 Who owns your skins? Valve's power and the GTA 6 on-chain test 21:45 Stablecoin arb on four chains — and the no-approval swap that sold him on Solana 27:30 Selling your swaps: why Triton won't, and the extortion nobody talks about 29:45 30M transactions a day: building Circular to track themselves 33:24 How your swap leaks value: AMMs, order flow, and the arb you never see 36:45 The monetization layer: what you're losing and how much comes back 44:28 Why every launchpad builds its own AMM 46:23 Integrating Fast: 1-cent tips, where they go, and 65% cashback 52:16 Colosseum builders: casino cranks, traders, and where to get RPC 56:33 Hidden fees and ignored priority fees: why validators should be angry 1:00:31 Counter-Strike, Trackmania, Risk — and next up: Ellie on Breakpoint

$250K in Hidden Fees: How Imperial Built a 1bp Perp DEX on Solana
1:04:04
October 7, 2026

$250K in Hidden Fees: How Imperial Built a 1bp Perp DEX on Solana

Imperial started as a Jupiter Perps wrapper that just told you what you were actually paying. Jordan Prince built it after finding he'd paid a quarter of a million dollars in fees, part of it in swap charges the front end never reported. Now he and Hunter run Armada: a prop-AMM perp venue native to Solana with 1 basis point taker fees and books up to 20x deeper than the competition. We get into Jordan and Bartosz's early Solana Labs days (Metaplex, Candy Machine, the first hacker house in a Lisbon horse stable), Hunter's road from a DC lobbyist family to Teleport, the four perp ideas that flopped first, and why a failed MagicBlock L2 experiment pushed them to hedged, delta-neutral liquidity. Plus why traders stay loyal to more expensive venues: perp DEXs behave more like NFT collections than markets. Also: closing a $1.5M round from Foundation Capital a week before bankruptcy, and the no-paperwork $25K wire from Brian Long that bought them two more weeks. Trade at imperial.space. Armada needs an access code, so start in their Discord. Follow-ups and codes: t.me/piratesparley 0:00 Welcome — Imperial isn't just an aggregator anymore 2:11 Citadel hell to Solana Labs: Jordan, Bartosz and the first DeFi commits 4:00 The first hacker house, built overnight in a billionaire's horse stable 9:41 Hunter: lobbyist's kid, Ritz-Carlton basement, $15M for Teleport 17:13 Four failed perp ideas: BTC volatility perps and memes too dangerous to trade 20:14 $330K in trading profits and "Jupiter lies about fees" 24:54 People don't want choice, they want the perception of choice: routing explained 29:24 The MagicBlock L2 experiment that got their pool farmed 31:02 Armada: 1 basis point fees, and why 10x leverage turns 5 bps into 1% 34:06 Perp DEXs are NFT collections: why traders don't switch to cheaper venues 41:18 20x deeper books, hedged and delta neutral: how the prop AMM works 46:12 $1.5M from Foundation Capital, a week from bankruptcy, and Brian's $25K wire 54:25 "We are a premium RPC company": Helius vs Triton 57:39 How to get an Armada code, pre-IPO Anthropic perps, and gacha perp packs 1:02:01 Closers — Breakpoint, Telegram codes, and the Circular tease

"Go Hack That Bank": Asymmetric Research's CEO on Wormhole, Drift, and Bad OPSEC
1:02:17
October 1, 2026

"Go Hack That Bank": Asymmetric Research's CEO on Wormhole, Drift, and Bad OPSEC

Jonathan Claudius, CEO and co-founder of Asymmetric Research, started his first real pen-test after guys in suits picked him up at the airport, dropped him at a bank, and told him to go hack it. Twenty years later he's the person Solana calls when something blows up. We get into his path from breaking into banks to running offensive security at Mozilla, and why his second day at Jump Crypto was the day Wormhole got hacked. He explains why AR doesn't call itself an audit firm, and why AI knocked out the bottom of the audit market without touching the top: "when execution is free, you end up with a huge human attention bottleneck." He also walks through STRIDE and SIRN, the proactive and reactive programs AR runs with the Solana Foundation. By his count, about 60% of Solana TVL has gone through STRIDE, and SIRN has saved north of $5M so far. Also: wrench attacks and why AR now runs protective services with an ex-Secret Service agent, Lazarus versus the 14-year-old with $200M, and the boring afternoon of policy work that would have prevented this year's biggest hacks. 0:00 Welcome — Jonathan from Asymmetric Research ("we're not an audit company") 1:34 From breaking into banks to Mozilla: what offensive security actually is 5:05 Day two at Jump Crypto: Wormhole gets hacked, and the 2.5-year recovery 8:37 Founding AR at Block Zero Amsterdam: "the first rule of BD is we don't sell anything" 13:18 Audit firm vs. security firm: being the inside guys, and "Be Boring" 16:53 AI ate the bottom of the audit market, and judgment is the new bottleneck 21:24 Can AI replace your auditor? Agreeable models and waves of AI psychosis 25:21 Re-audit every commit? Threat models, Mozilla's RRA, and where to start 32:10 STRIDE and SIRN: the Solana Foundation's proactive and reactive security programs 37:05 Is it always North Korea? Attribution, AI-enabled attackers, the 14-year-old with $200M 40:56 From leaky code to bad OPSEC: why 2026's big hacks were human failures 47:07 Wrench attacks, Tom's mustache, and AR's protective services 51:50 Eden's question: the bank bathroom trick and the "running man" 57:45 The question you should've asked: boring policy wins, hardware keys, branch protection 1:01:02 Pirates Parley Telegram + see you in London

Percolator: Toly's Risk Engine, Two Vibe-Coders, and the "Pump.fun for Perps
59:23
September 17, 2026

Percolator: Toly's Risk Engine, Two Vibe-Coders, and the "Pump.fun for Perps

Squid and Dark are the two-person team behind Percolator — Solana's permissionless perps DEX built on Anatoly Yakovenko's open-sourced risk engine. Any token with a DEX pool gets a perp market, no gatekeeping. We get into how they CTO'd a rugged pump.fun token into an 8,500-person waitlist, why they've spent eight months and roughly $1,000 in Claude subscriptions instead of hiring, and what "formal verification" actually buys you when every market is isolated and no one steps in during a flash crash. Squid and Dark walk through the creator-stake model that filters out imbalanced markets, why they're deliberately targeting the pump.fun crowd first, and how OPSEC changes when your entire codebase is public in the AI era. Also: the name comes from a bad house track called "It's Time for the Percolator" — Toly picked it while listening to it — and apparently Squid drinks half as much coffee as I do. DevNet V2 lands end of September, then a raise, then an audit. Percolator is quoted at $300k+ to audit properly. Waitlist: percolator.trade/waitlist. Next week I'm off; the week after, Asymmetric Research on why audits cost what they cost. 0:00 Welcome — meet Squid and Dark from Percolator 1:00 Castle DAO recap and how tall Dark actually is (spoiler: not 6'7") 2:35 How Percolator came to be: CTOing a rugged pump.fun token 5:00 What Percolator is: permissionless perps for any DEX pool 8:20 Toly's role — he'll do the risk engine, nothing else 10:00 "Is Toly really that much of a dev?" — the AI-assisted question 11:10 Vibe-coding with 11 OpenClaw agents, then slowing back down 12:35 DevNet V2 end of month, then audit, then mainnet 19:25 Why the risk engine is different: formal verification and isolated markets 24:00 OPSEC in the AI era, spoofed emails, and never merging PRs 32:05 The case for open source: copiers fail, contributors help 38:30 Devil's advocate — is Percolator "pump.fun for perps"? 42:20 Closed beta, VCs, and the road to permissionless by end of 2027 50:00 Agentic trading and adopting Toly's risk engine changes 54:20 Where the name came from, 20 cups of coffee, and next week's tease

Harmonic Launches Preconfs on Triton One: Sabs on Validator Choice, MREV, and the New Client Stack
44:56
September 15, 2026

Harmonic Launches Preconfs on Triton One: Sabs on Validator Choice, MREV, and the New Client Stack

Sabs from the Harmonic team joins to launch preconfs (pre-confirmations) as a Triton One exclusive — a 15-20ms early view into what's about to hit the network, and the first time Harmonic has shipped a product through a single partner.We get into what Harmonic actually is (block production split off from the validator client, so validators plug in and get the rewards without giving up control), where the long-tail alpha comes from, and how Harmonic differs from Jito BAM — no opinions, just FIFO, 50ms FBA, or MREV, and validators pick. Sabs explains why preconfs aren't front-running bait, why they matter for market makers and prop AMMs, and why Triton got the exclusive — the short version being: don't repeat the shreds market collapse.Also: Sabs's hot take that the best way to buy SOL is Coinbase → USDC → Solana, why Grinder equity did more volume on-chain than on NASDAQ on day one, and why Solana feels like a mechanic shop full of cracked engineers next to Ethereum's white-paper crowd.Preconfs are live today, Triton One exclusive. KYC/KYB required — sign up at triton.one and open a ticket through the customer portal to get on the queue.Follow Sabs: @S4BS94 on X.0:00 Welcome — Harmonic launches preconfs as a Triton One exclusive0:35 Meet Sabs — Coinbase alum, 5 years across Solana, joined Harmonic ~7 months ago2:00 What Harmonic actually is — block production split off from the validator client4:16 Where the extra rewards come from — no rate limits, wide funnel, long-tail transactions6:38 Harmonic vs Jito BAM — FIFO, 50ms FBA, MREV, and the "no opinions" thesis10:00 Should validators run MREV? Network-aligned vs revenue-max, and what it means for retail12:51 Preconfs launch — what pre-confirmations are and the 15-20ms early view15:04 Why Triton got the exclusive — don't repeat the shreds market collapse16:56 Are preconfs front-running bait? And what if the slot gets forked?20:00 Is Solana getting too complex? Sabs: it's just TradFi with better tech23:37 Grinder beats NASDAQ day one — and the best way to buy SOL is via Coinbase27:13 Why Solana over Ethereum — "a mechanic shop with a cool car everyone's building"31:27 Vibes, dumping, and why the Solana community bulls harder when the chart bleeds32:46 Who actually needs preconfs — prop AMMs, market makers, traders, Jupiter upstream37:52 Pitch to validators + audience Q&A on multi-hop and account filters

Inder Preet Singh, Doma: 1,600 New TLDs, $70M AI.com Deals, and What Happens to Your .sol
1:02:13
September 10, 2026

Inder Preet Singh, Doma: 1,600 New TLDs, $70M AI.com Deals, and What Happens to Your .sol

Inder runs product and tech at D3 — the team building the DOMA protocol, which brings domains on-chain as tradable, fractionalizable assets. We get into the $70M cash sale of AI dot com (no escrow, both founders just trusted each other), the 1,600 new TLDs applied for in 2026 (BTC, crypto, agent, human, and more), and how fractional ownership means you'll soon be able to buy $10 of AI dot com instead of the whole thing. Inder walks through what actually happens to your .sol domains under the new model, why he wouldn't recommend registering new ones right now, and what the program for existing .sol holders will look like. Also: why a credibly neutral internet matters more than any digital asset, why 40-60% of web traffic is now AI bots (up from 20-30%), and Steve's petty-genius story of buying borissucks dot sol just to knock a guy off second place on a leaderboard. 0:00 Welcome — the domain space is about to change 1:26 Inder's background and why DNS is bulletproof but everything on top is archaic 4:48 AI dot com sold for $70M cash — and how you'll be able to buy $10 of it 9:04 The 2026 TLD land rush: 1,600 new extensions (BTC, crypto, agent, human) 15:40 D3's origin: Fred, Paul, and the guy who bought 300 TLDs in 2012 18:51 Building DOMA: custody, Namecheap, Paradigm, and why RWAs need checks 23:07 What happens to your .sol — SRS, snapshots, and don't buy new .sol right now 27:23 Pricing: why .sol won't play the $1 first year / $30 renewal game 32:33 Steve's petty-genius: buying borissucks dot sol to knock a guy off a leaderboard 35:20 Domains as your passport on the internet — mTLS, agents, and identity 40:02 Hot take: a neutral internet matters more than crypto itself 41:18 AI traffic is 40-60% of web traffic and Cloudflare can't be the arbiter 46:09 Privacy on DOMA: shielded registration, anonymous domains 54:22 What Solana still needs: the consumer packaging layer 58:57 October timeline, where to follow, and next week

0% Interest Loans on Tokenized Stocks: The Two Pauls Behind Spout Finance
56:43
September 3, 2026

0% Interest Loans on Tokenized Stocks: The Two Pauls Behind Spout Finance

Two Pauls from Spout Finance join Pirates Parley — Dutch co-founders and childhood friends going on 24 years, building a lending protocol where you borrow at 0% interest against your tokenized equities. The trick: sell covered calls on the collateral to generate the yield lenders want, so borrowers get stock-backed liquidity without paying rate.We get into how the covered-call mechanic actually works, why they abandoned EVM's global fee market after building on Starknet and Aptos, what three months in the Solana Foundation Incubator was actually like (weekly sessions with Eman, a one-on-one with Nigel Eccles who exited FanDuel for $440M, Nick Ducoff as a repeat helper), and the multi-jurisdiction setup — US corp, BVI for RWA issuance, Panama for the lending piece — that's currently the price of doing this legally. We also cover DTCC-land vs on-chain market structure, transfer agent licenses, which kinds of MEV are actually load-bearing, DoubleZero and validator geography for a real global order book, and why building a company with your kindergarten friend works if you can fight and go get tacos afterwards.Also: why Rust is better than Solidity, and where NYSE-on-chain actually lands.Mainnet in ~1 month, larger go-to-market push ~2 months out. Test net access by pinging them on X or Telegram. Hiring BDs when go-to-market kicks off. 0:00 Welcome — Two Pauls from Spout Finance, 24 years of friendship1:22 Paul on Starknet privacy, Aptos in NYC, and finding co-founder Mark4:16 Why EVM's global fee market was a dealbreaker6:53 Paul's Bitcoin origin: a Call of Duty payout, then a smart-contract thesis8:50 Pivoting from corporate bonds to tokenized equities12:14 The pitch: 0% loans against tokenized stocks, funded by covered calls16:01 How lenders still earn when nobody's borrowing (T-bill backstop)19:11 Three months at the Solana Incubator: Iman weekly, Nigel Eccles from FanDuel24:24 Coming from Ethereum: how much hands-on help Solana gives DeFi teams27:22 Building with your kindergarten friend: fights, trust, and tacos after31:55 Chicken-and-egg: launching a lending protocol that needs both sides34:49 US corp, BVI, Panama — one protocol, three jurisdictions39:44 Transfer agents, NYSE-on-chain, and direct ownership vs the DTCC43:04 MEV on-chain vs Nasdaq, DoubleZero, and a global order book49:12 Audits, mainnet in a month, biggest fumbles, and why Rust beats Solidity

Velocity: Inside the Drift Rebuild, North Korea's Hack, and What "Good OPSEC" Actually Means
1:18:54
August 20, 2026

Velocity: Inside the Drift Rebuild, North Korea's Hack, and What "Good OPSEC" Actually Means

Noah Prince is back on Pirates Parley — this time as the protocol engineer rebuilding what was Drift into Velocity, after North Korea drained ~$290M through a socially-engineered admin multisig.We get into how the hack actually worked (durable nonces, compromised laptops, and a circuit-breaker bypass that shouldn't have existed), what real OPSEC looks like when Ledgers can't clear-sign, why "seven years to pay users back" is a failure state, and the new tech Velocity is shipping post-launch: prop AMMs on perps and dynamic on-chain routing.Also: Tether's rescue deal, how Cindy negotiated it, the DFX claim mechanism, why Noah stays bullish on Solana ("Bitcoin and Ethereum are so shitty"), and — for the traders — how to actually model your loss exposure before depositing anywhere.Velocity is in closed beta. Talk to Tracy (@TracyBBD) to get on the whitelist. They're also hiring smart-contract engineers.0:00 Welcome — Noah's back after the Helium turducken2:05 How Drift got hacked: North Korea, ~$290M, the multisig4:30 How Noah got the call from Jacob Creech6:05 Tether's rescue and the DFX claim mechanism11:15 Why relaunch — winning Solana's perp war15:40 OPSEC deep dive: durable nonces and the anatomy of the exploit19:35 Hot take: Ledgers are worthless doorstops22:25 The fixes: circuit breakers, tiered admins, time locks26:25 Auditing culture and why you diversify across protocols33:55 Noah's Solana origin story — $8 in Ethereum fees40:35 Seven years or bust: what "success" actually means48:25 Justin Sun, team security, and modeling your real DeFi risk57:10 Leverage, launch timeline, and what's coming (prop AMMs, routing)1:09:45 Beta access, hiring, and Drift's governance risks1:16:15 Brother Jordan's Imperial + what's next on the pod

Sunsetting the mempool: Lucas Bruder on Jito, BAM, and betting long-term on Solana
1:09:33
August 13, 2026

Sunsetting the mempool: Lucas Bruder on Jito, BAM, and betting long-term on Solana

Lucas Bruder, co-founder and CEO of Jito Labs, joins Pirates Parley to break down why they shut off the public mempool, how BAM works, and what confidential block building on Solana looks like inside a secure enclave.Lucas got here via Tesla body controls on the Model X, an Xbox controller for surgical robots, a 50,000 pound bulldozer at Built Robotics, and lidar firmware at Ouster, before falling down the MEV rabbit hole and starting Jito in 2021.They cover:- Lucas's path from Tesla and Built Robotics to lidar and then Jito- how the Jito block engine works, and why the best analogy is Cloudflare- the peak day the Trump token launched, when Jito generated the network $20m and made up more than 50% of Solana REV- why they sunset the public mempool, and why Steve thinks it's the biggest pivot any blockchain company has made- BAM: transparent, verifiable, confidential block building inside a secure enclave- the maker priority plugin, and BAM running on just under 33% of stake- Jump running Bison as the number one prop amm on Solana- what has to happen for tokenised securities to work: Clarity, an SEC exemption, and users- why Jito Labs built JTX and how they think about execution- restaking, the honest reflection, and where Jito is focusing now- 100m CU blocks activated last week and the road to 200ms slots and Alpenglow- advice for new builders coming into Solana--------------------------------------------------------------00:00 - Welcome and cold open01:14 - Lucas's path: Tesla, hardware consultancy, cadavers05:13 - Built Robotics and the bulldozer06:46 - Ouster, MEV, and falling down the rabbit hole11:12 - What Jito does today: the market layer16:40 - The Jito block engine explained21:11 - The mempool: what it was, where it went wrong24:49 - Sunsetting the mempool: the biggest pivot in blockchain28:05 - BAM: block assembly marketplace31:10 - Maker priority, 33% stake, and consistent execution36:41 - Tokenised securities, Clarity, and what has to happen46:34 - Why Jito built JTX48:52 - Team size, focus, and letting restaking run54:11 - 100m CU blocks, Alpenglow, and shipping at Anza speed1:04:47 - Advice for new builders

Streamflow: solution first, problem later, and the alpha on equity-backed tokens
57:55
August 6, 2026

Streamflow: solution first, problem later, and the alpha on equity-backed tokens

Malisha Stanojevic, founder and CEO of Streamflow, joins Pirates Parley to walk through five years of building the token distribution platform on Solana, and to drop the news on what they are turning it into next.Malisha joined Solana in May 2021 via a hackathon, built a Sablier-inspired token streaming protocol before he knew what problem it solved, and raised his first check at the Breakpoint 2021 closing party by typing a note on his phone because it was too loud to talk. Streamflow has since had over 40,000 tokens go through its programs and peaked at two billion dollars worth of tokens in escrow.They cover:Building the solution before finding the problem, and why he does not recommend itThe first check raised on a phone screen at Breakpoint 2021A 15-person VC call that turned into an interrogationSolana Ventures backing Streamflow and two of its competitors at the same timeWhy ETH, Aptos and Sui conferences felt like a different planetThe $1-a-day customer stream that got topped up with $15,000What it feels like to sit on two billion in customer escrowStride, Asymmetric Research, and how AI is now inside their CI/CD and code reviewWhy mental health is a founder virtue, not a weaknessThe alpha: equity-backed tokens, a Cayman Islands legal framework, and Streamflow becoming an onchain capital formation platformThe STREAM token transition and the Solana Summit Belgrade rollout00:00 - welcome and intro00:30 - how Malisha found Solana via a hackathon in 202103:40 - solution first, problem later: the Streamflow origin story08:50 - raising the first check on a phone screen at Breakpoint 202113:55 - the 15-person VC call about stolen open-source code18:20 - bias for action and why perfect is not that important21:20 - ETH vs Solana culture, and Solana Ventures backing three competitors26:20 - what Streamflow actually does: vesting, locks, airdrops, staking29:20 - the $1-a-day topup that extended a stream by 11 years33:20 - two billion in escrow and the top two fears in life37:40 - Stride, Asymmetric Research, and AI in the security stack42:40 - mental health as a founder virtue48:00 - the numbers: 20 people, $2.5M in 2025, still profitable50:20 - the alpha: equity-backed tokens and onchain capital formation56:00 - Cayman Islands framework and the STREAM transition58:00 - Solana Summit Belgrade, and next week on Pirates Parley

Sharded order books, and a $150K raise that filled in 5 seconds | Pirates Parley E26
55:03
July 30, 2026

Sharded order books, and a $150K raise that filled in 5 seconds | Pirates Parley E26

Avhi and Arjun from Ordr join Pirates Parley the day after their futarchy raise on Futardio closed at 50x oversubscribed. We get into how the four of them met in a Solana Twitter space, why they think open market making beats prop AMMs, and what happens when you give every market maker their own book. They cover: Why Ordr gives each market maker a private book instead of one shared state Write-lock contention on Solana and how sharded books route around it ACE via Jito's BAM plugin, live in production today Repricing near-free via hot paths hand-written in sBPF assembly Colosseum honorable mention in the DeFi track and what it taught them The Futardio raise: $150K target, filled in under 5 seconds, 50x oversubscribed at the time of recording Their thesis on OpenMM: proprietary AMMs are closed black boxes, Ordr opens the same performance tier to anyone Mobile-native market making on Seeker, no infra required Codebase in Pinocchio, "developers who have lost their training wheels" Roadmap: audit first, public mainnet in four to five months Avhi finishing his four-year degree the day before the raise closed 0:00 Welcome and the day after Ordr's raise 1:45 Meet Avhi and Arjun, four founders from India 4:50 Meeting in a Solana Twitter space and shipping to Colosseum 10:35 Why Solana needs another order book: write-lock contention 12:00 How order books work and where aggregators fit 15:45 Sharded books: every maker gets their own account 21:00 Archer, price updates, and CU-level efficiency 22:00 Toxic order flow and ACE via Jito BAM 25:35 Fully onchain matching engine 26:30 Solana's read layer, Alpenglow, and finality 29:55 Triton infra and where Ordr sits on the read layer 31:30 The $150K raise, filled in five seconds 34:05 Avhi graduating the day before, and the team's ages 35:25 Why futarchy: betting on the belief 37:35 Token distribution and the ICO close on 31 July 40:10 Audit-first roadmap, public mainnet in four to five months 42:30 Pinocchio, sBPF assembly, and lost training wheels 43:45 Building in public and the audit proposal 45:10 OpenMM thesis and mobile-native market making on Seeker 50:55 Relentless teams and hard problems 51:55 Website walkthrough and Yellowstone Shield

The $100k exploit, the attacker who tuned in, and six hours to recovery
1:04:12
July 23, 2026

The $100k exploit, the attacker who tuned in, and six hours to recovery

Anas Khader, co-founder of Flash Trade, joins Pirates Parley hours after one of the more instructive exploits Solana DeFi has seen -- a forged buffer account in the Magic Blocks ephemeral rollup SDK that exposed $100k in user deposits. Zoheb Shahzan, co-founder and the engineer who handled the response, joins mid-episode to walk through the root cause, the five-minute noop deployment, and how fund isolation kept the pool TVL untouched. Anas has been in crypto for 11 years, started at BitMEX, and moved to Solana via SBF's Serum threads. Flash Trade was the first DeFi exchange to integrate with Magic Blocks' ephemeral rollup, which drops execution latency to ~50ms by removing consensus overhead. The exploit was a direct consequence of that novel architecture -- and so was the recovery. They cover: What Flash Trade is and why 500x leverage is mostly a stress-test Why Solana was the only chain capable of serving a full order book What scheduler wars and oracle skipping look like from the exchange side (5--10 second pricing delays at peak) How the ephemeral rollup works: finality and trust from Solana, unlimited speed on a dedicated SVM The full exploit RCA: a forged buffer account passed as the canonical PDA on undelegation How fund isolation (no co-mingling, isolated collateral token accounts) limited exposure to user deposits only The noop instruction -- why every upgradeable DeFi programme should have one -- and how it was deployed in five minutes via Triton's RPC and transaction sending service How the attacker attended Flash Trade's own Monday livestream and extracted the exact withdrawal cap Why the team had an alert and a response within a minute of the withdrawal hitting AI as a defensive tool -- the frontier models that built the monitoring bots that caught it Tracking the funds: Monero → ChangeNow → Mayan Finance bridge → Ethereum, address flagged across all CEXes Percolator (Armani Ferrante) and CERN (Asymmetric Research) as recommended reading on risk engine design The $1.3M NFT raise, how all revenue was returned to holders, and the FAF token's 50% rev share flywheel What's next: 24/7 markets and a UX where users don't know they're onchain 00:00 - Anas Khader and Flash Trade00:53 - What is Flash Trade? The 500x leverage question03:04 - From BitMEX to Solana: how Serum and SBF threads changed everything08:29 - Why perpetuals exist (futures were invented for farmers)10:35 - Solana was the only blockchain that could serve a full order book12:35 - The move to Magic Blocks: what the ephemeral rollup actually does16:26 - Scheduler wars and oracle delays: 5--10 seconds of pricing lag at peak21:03 - Triton dedicated channel and building rapport in a trustless world22:07 - The elephant in the room: what happened yesterday?22:37 - Xoheb joins to explain the technical root cause25:43 - The buffer account PDA vulnerability: how the exploit worked32:07 - $100k withdrawn, PagerDuty fires, team on desks in under a minute33:21 - Noop deployed in five minutes via Triton RPC; Triton transaction sending lands it in seconds35:20 - Malicious state reconciled; limited trading reopens36:01 - Trading fully live again within six to seven hours36:50 - The attacker attended Flash Trade's Monday livestream and knew the exact cap38:13 - Comms were spontaneous; AI-built bots caught it in under a minute39:21 - AI levels the field: it's not just for hackers43:05 - Seal Team 911 and tracking the funds: Monero → ChangeNow → Mayan → Ethereum43:56 - Percolator and CERN: the risk engine reading list49:23 - Team size: about 10 people50:32 - Bootstrapped vs funded: why being on your toes drives output53:24 - The $1.3M NFT raise, revenue returned to holders, and the FAF token58:34 - What's next: 24/7 markets and invisible onchain UX1:02:19 - Outro and next week's guest