
The $100k exploit, the attacker who tuned in, and six hours to recovery
Anas Khader, co-founder of Flash Trade, joins Pirates Parley hours after one of the more instructive exploits Solana DeFi has seen -- a forged buffer account in the Magic Blocks ephemeral rollup SDK that exposed $100k in user deposits. Zoheb Shahzan, co-founder and the engineer who handled the response, joins mid-episode to walk through the root cause, the five-minute noop deployment, and how fund isolation kept the pool TVL untouched. Anas has been in crypto for 11 years, started at BitMEX, and moved to Solana via SBF's Serum threads. Flash Trade was the first DeFi exchange to integrate with Magic Blocks' ephemeral rollup, which drops execution latency to ~50ms by removing consensus overhead. The exploit was a direct consequence of that novel architecture -- and so was the recovery. They cover:
What Flash Trade is and why 500x leverage is mostly a stress-test Why Solana was the only chain capable of serving a full order book What scheduler wars and oracle skipping look like from the exchange side (5--10 second pricing delays at peak) How the ephemeral rollup works: finality and trust from Solana, unlimited speed on a dedicated SVM The full exploit RCA: a forged buffer account passed as the canonical PDA on undelegation How fund isolation (no co-mingling, isolated collateral token accounts) limited exposure to user deposits only The noop instruction -- why every upgradeable DeFi programme should have one -- and how it was deployed in five minutes via Triton's RPC and transaction sending service How the attacker attended Flash Trade's own Monday livestream and extracted the exact withdrawal cap Why the team had an alert and a response within a minute of the withdrawal hitting AI as a defensive tool -- the frontier models that built the monitoring bots that caught it Tracking the funds: Monero → ChangeNow → Mayan Finance bridge → Ethereum, address flagged across all CEXes Percolator (Armani Ferrante) and CERN (Asymmetric Research) as recommended reading on risk engine design The $1.3M NFT raise, how all revenue was returned to holders, and the FAF token's 50% rev share flywheel What's next: 24/7 markets and a UX where users don't know they're onchain
00:00 - Anas Khader and Flash Trade00:53 - What is Flash Trade? The 500x leverage question03:04 - From BitMEX to Solana: how Serum and SBF threads changed everything08:29 - Why perpetuals exist (futures were invented for farmers)10:35 - Solana was the only blockchain that could serve a full order book12:35 - The move to Magic Blocks: what the ephemeral rollup actually does16:26 - Scheduler wars and oracle delays: 5--10 seconds of pricing lag at peak21:03 - Triton dedicated channel and building rapport in a trustless world22:07 - The elephant in the room: what happened yesterday?22:37 - Xoheb joins to explain the technical root cause25:43 - The buffer account PDA vulnerability: how the exploit worked32:07 - $100k withdrawn, PagerDuty fires, team on desks in under a minute33:21 - Noop deployed in five minutes via Triton RPC; Triton transaction sending lands it in seconds35:20 - Malicious state reconciled; limited trading reopens36:01 - Trading fully live again within six to seven hours36:50 - The attacker attended Flash Trade's Monday livestream and knew the exact cap38:13 - Comms were spontaneous; AI-built bots caught it in under a minute39:21 - AI levels the field: it's not just for hackers43:05 - Seal Team 911 and tracking the funds: Monero → ChangeNow → Mayan → Ethereum43:56 - Percolator and CERN: the risk engine reading list49:23 - Team size: about 10 people50:32 - Bootstrapped vs funded: why being on your toes drives output53:24 - The $1.3M NFT raise, revenue returned to holders, and the FAF token58:34 - What's next: 24/7 markets and invisible onchain UX1:02:19 - Outro and next week's guest
The $100k exploit, the attacker who tuned in, and six hours to recovery
Coffee on Solana: from a $20 mint to the Miami Heat | Pirates Parley E24
Sharded order books, and a $150K raise that filled in 5 seconds | Pirates Parley E26
More from Pirates Parley

Sharded order books, and a $150K raise that filled in 5 seconds | Pirates Parley E26
Avhi and Arjun from Ordr join Pirates Parley the day after their futarchy raise on Futardio closed at 50x oversubscribed. We get into how the four of them met in a Solana Twitter space, why they think open market making beats prop AMMs, and what happens when you give every market maker their own book. They cover: Why Ordr gives each market maker a private book instead of one shared state Write-lock contention on Solana and how sharded books route around it ACE via Jito's BAM plugin, live in production today Repricing near-free via hot paths hand-written in sBPF assembly Colosseum honorable mention in the DeFi track and what it taught them The Futardio raise: $150K target, filled in under 5 seconds, 50x oversubscribed at the time of recording Their thesis on OpenMM: proprietary AMMs are closed black boxes, Ordr opens the same performance tier to anyone Mobile-native market making on Seeker, no infra required Codebase in Pinocchio, "developers who have lost their training wheels" Roadmap: audit first, public mainnet in four to five months Avhi finishing his four-year degree the day before the raise closed 0:00 Welcome and the day after Ordr's raise 1:45 Meet Avhi and Arjun, four founders from India 4:50 Meeting in a Solana Twitter space and shipping to Colosseum 10:35 Why Solana needs another order book: write-lock contention 12:00 How order books work and where aggregators fit 15:45 Sharded books: every maker gets their own account 21:00 Archer, price updates, and CU-level efficiency 22:00 Toxic order flow and ACE via Jito BAM 25:35 Fully onchain matching engine 26:30 Solana's read layer, Alpenglow, and finality 29:55 Triton infra and where Ordr sits on the read layer 31:30 The $150K raise, filled in five seconds 34:05 Avhi graduating the day before, and the team's ages 35:25 Why futarchy: betting on the belief 37:35 Token distribution and the ICO close on 31 July 40:10 Audit-first roadmap, public mainnet in four to five months 42:30 Pinocchio, sBPF assembly, and lost training wheels 43:45 Building in public and the audit proposal 45:10 OpenMM thesis and mobile-native market making on Seeker 50:55 Relentless teams and hard problems 51:55 Website walkthrough and Yellowstone Shield

Coffee on Solana: from a $20 mint to the Miami Heat | Pirates Parley E24
The Raposa Coffee crew joins Pirates Parley to break down how a $20 NFT mint at the bottom of the bear market turned into the specialty coffee brand of the Solana ecosystem, now pouring at Miami Heat and Marlins games. They cover: Selling out the 10k Kups collection in April 2023 85% of Solana Pay transactions at Breakpoint 2023 from one booth Three years with basically zero marketing spend The unfair advantage of building a brand on Solana Record sales in their first six Marlins games The on-chain loyalty app, badge marketplace and Kups burns Jungles vs cosmics, and Raposa's biggest fumble 00:00 - Welcome and intros 4:49 - Chapter one: from NFT mint to coffee brand 9:04 - Becoming the ecosystem's coffee staple 15:35 - The crypto coffee brand question 17:56 - The unfair advantage 21:25 - Miami Heat and Marlins 27:25 - Why Solana 43:44 - The on-chain loyalty app 53:26 - Jungles vs cosmics 54:56 - Raposa's biggest fumble 59:38 - What's next

Building an Ecosystem Interface: How Solflare has kept it's successful course
Vidor, co-founder of Solflare, joins Pirates Parley to tell about how Solflare started it's successful endeavor, being the Solana Ecosystem interface, and what it means to give people the tools for self-custody.