Pirates Parley
Pirates Parley
July 23, 2026·1:04:12

The $100k exploit, the attacker who tuned in, and six hours to recovery

Anas Khader, co-founder of Flash Trade, joins Pirates Parley hours after one of the more instructive exploits Solana DeFi has seen -- a forged buffer account in the Magic Blocks ephemeral rollup SDK that exposed $100k in user deposits. Zoheb Shahzan, co-founder and the engineer who handled the response, joins mid-episode to walk through the root cause, the five-minute noop deployment, and how fund isolation kept the pool TVL untouched. Anas has been in crypto for 11 years, started at BitMEX, and moved to Solana via SBF's Serum threads. Flash Trade was the first DeFi exchange to integrate with Magic Blocks' ephemeral rollup, which drops execution latency to ~50ms by removing consensus overhead. The exploit was a direct consequence of that novel architecture -- and so was the recovery. They cover:

What Flash Trade is and why 500x leverage is mostly a stress-test Why Solana was the only chain capable of serving a full order book What scheduler wars and oracle skipping look like from the exchange side (5--10 second pricing delays at peak) How the ephemeral rollup works: finality and trust from Solana, unlimited speed on a dedicated SVM The full exploit RCA: a forged buffer account passed as the canonical PDA on undelegation How fund isolation (no co-mingling, isolated collateral token accounts) limited exposure to user deposits only The noop instruction -- why every upgradeable DeFi programme should have one -- and how it was deployed in five minutes via Triton's RPC and transaction sending service How the attacker attended Flash Trade's own Monday livestream and extracted the exact withdrawal cap Why the team had an alert and a response within a minute of the withdrawal hitting AI as a defensive tool -- the frontier models that built the monitoring bots that caught it Tracking the funds: Monero → ChangeNow → Mayan Finance bridge → Ethereum, address flagged across all CEXes Percolator (Armani Ferrante) and CERN (Asymmetric Research) as recommended reading on risk engine design The $1.3M NFT raise, how all revenue was returned to holders, and the FAF token's 50% rev share flywheel What's next: 24/7 markets and a UX where users don't know they're onchain

00:00 - Anas Khader and Flash Trade00:53 - What is Flash Trade? The 500x leverage question03:04 - From BitMEX to Solana: how Serum and SBF threads changed everything08:29 - Why perpetuals exist (futures were invented for farmers)10:35 - Solana was the only blockchain that could serve a full order book12:35 - The move to Magic Blocks: what the ephemeral rollup actually does16:26 - Scheduler wars and oracle delays: 5--10 seconds of pricing lag at peak21:03 - Triton dedicated channel and building rapport in a trustless world22:07 - The elephant in the room: what happened yesterday?22:37 - Xoheb joins to explain the technical root cause25:43 - The buffer account PDA vulnerability: how the exploit worked32:07 - $100k withdrawn, PagerDuty fires, team on desks in under a minute33:21 - Noop deployed in five minutes via Triton RPC; Triton transaction sending lands it in seconds35:20 - Malicious state reconciled; limited trading reopens36:01 - Trading fully live again within six to seven hours36:50 - The attacker attended Flash Trade's Monday livestream and knew the exact cap38:13 - Comms were spontaneous; AI-built bots caught it in under a minute39:21 - AI levels the field: it's not just for hackers43:05 - Seal Team 911 and tracking the funds: Monero → ChangeNow → Mayan → Ethereum43:56 - Percolator and CERN: the risk engine reading list49:23 - Team size: about 10 people50:32 - Bootstrapped vs funded: why being on your toes drives output53:24 - The $1.3M NFT raise, revenue returned to holders, and the FAF token58:34 - What's next: 24/7 markets and invisible onchain UX1:02:19 - Outro and next week's guest

S(
Steve (Happy Pirate)

The $100k exploit, the attacker who tuned in, and six hours to recovery

0:000:00

Share this episode

Subscribe & Listen

More from Pirates Parley

Percolator: Toly's Risk Engine, Two Vibe-Coders, and the "Pump.fun for Perps
59:23
September 17, 2026

Percolator: Toly's Risk Engine, Two Vibe-Coders, and the "Pump.fun for Perps

Squid and Dark are the two-person team behind Percolator — Solana's permissionless perps DEX built on Anatoly Yakovenko's open-sourced risk engine. Any token with a DEX pool gets a perp market, no gatekeeping. We get into how they CTO'd a rugged pump.fun token into an 8,500-person waitlist, why they've spent eight months and roughly $1,000 in Claude subscriptions instead of hiring, and what "formal verification" actually buys you when every market is isolated and no one steps in during a flash crash. Squid and Dark walk through the creator-stake model that filters out imbalanced markets, why they're deliberately targeting the pump.fun crowd first, and how OPSEC changes when your entire codebase is public in the AI era. Also: the name comes from a bad house track called "It's Time for the Percolator" — Toly picked it while listening to it — and apparently Squid drinks half as much coffee as I do. DevNet V2 lands end of September, then a raise, then an audit. Percolator is quoted at $300k+ to audit properly. Waitlist: percolator.trade/waitlist. Next week I'm off; the week after, Asymmetric Research on why audits cost what they cost. 0:00 Welcome — meet Squid and Dark from Percolator 1:00 Castle DAO recap and how tall Dark actually is (spoiler: not 6'7") 2:35 How Percolator came to be: CTOing a rugged pump.fun token 5:00 What Percolator is: permissionless perps for any DEX pool 8:20 Toly's role — he'll do the risk engine, nothing else 10:00 "Is Toly really that much of a dev?" — the AI-assisted question 11:10 Vibe-coding with 11 OpenClaw agents, then slowing back down 12:35 DevNet V2 end of month, then audit, then mainnet 19:25 Why the risk engine is different: formal verification and isolated markets 24:00 OPSEC in the AI era, spoofed emails, and never merging PRs 32:05 The case for open source: copiers fail, contributors help 38:30 Devil's advocate — is Percolator "pump.fun for perps"? 42:20 Closed beta, VCs, and the road to permissionless by end of 2027 50:00 Agentic trading and adopting Toly's risk engine changes 54:20 Where the name came from, 20 cups of coffee, and next week's tease

Harmonic Launches Preconfs on Triton One: Sabs on Validator Choice, MREV, and the New Client Stack
44:56
September 15, 2026

Harmonic Launches Preconfs on Triton One: Sabs on Validator Choice, MREV, and the New Client Stack

Sabs from the Harmonic team joins to launch preconfs (pre-confirmations) as a Triton One exclusive — a 15-20ms early view into what's about to hit the network, and the first time Harmonic has shipped a product through a single partner.We get into what Harmonic actually is (block production split off from the validator client, so validators plug in and get the rewards without giving up control), where the long-tail alpha comes from, and how Harmonic differs from Jito BAM — no opinions, just FIFO, 50ms FBA, or MREV, and validators pick. Sabs explains why preconfs aren't front-running bait, why they matter for market makers and prop AMMs, and why Triton got the exclusive — the short version being: don't repeat the shreds market collapse.Also: Sabs's hot take that the best way to buy SOL is Coinbase → USDC → Solana, why Grinder equity did more volume on-chain than on NASDAQ on day one, and why Solana feels like a mechanic shop full of cracked engineers next to Ethereum's white-paper crowd.Preconfs are live today, Triton One exclusive. KYC/KYB required — sign up at triton.one and open a ticket through the customer portal to get on the queue.Follow Sabs: @S4BS94 on X.0:00 Welcome — Harmonic launches preconfs as a Triton One exclusive0:35 Meet Sabs — Coinbase alum, 5 years across Solana, joined Harmonic ~7 months ago2:00 What Harmonic actually is — block production split off from the validator client4:16 Where the extra rewards come from — no rate limits, wide funnel, long-tail transactions6:38 Harmonic vs Jito BAM — FIFO, 50ms FBA, MREV, and the "no opinions" thesis10:00 Should validators run MREV? Network-aligned vs revenue-max, and what it means for retail12:51 Preconfs launch — what pre-confirmations are and the 15-20ms early view15:04 Why Triton got the exclusive — don't repeat the shreds market collapse16:56 Are preconfs front-running bait? And what if the slot gets forked?20:00 Is Solana getting too complex? Sabs: it's just TradFi with better tech23:37 Grinder beats NASDAQ day one — and the best way to buy SOL is via Coinbase27:13 Why Solana over Ethereum — "a mechanic shop with a cool car everyone's building"31:27 Vibes, dumping, and why the Solana community bulls harder when the chart bleeds32:46 Who actually needs preconfs — prop AMMs, market makers, traders, Jupiter upstream37:52 Pitch to validators + audience Q&A on multi-hop and account filters

Inder Preet Singh, Doma: 1,600 New TLDs, $70M AI.com Deals, and What Happens to Your .sol
1:02:13
September 10, 2026

Inder Preet Singh, Doma: 1,600 New TLDs, $70M AI.com Deals, and What Happens to Your .sol

Inder runs product and tech at D3 — the team building the DOMA protocol, which brings domains on-chain as tradable, fractionalizable assets. We get into the $70M cash sale of AI dot com (no escrow, both founders just trusted each other), the 1,600 new TLDs applied for in 2026 (BTC, crypto, agent, human, and more), and how fractional ownership means you'll soon be able to buy $10 of AI dot com instead of the whole thing. Inder walks through what actually happens to your .sol domains under the new model, why he wouldn't recommend registering new ones right now, and what the program for existing .sol holders will look like. Also: why a credibly neutral internet matters more than any digital asset, why 40-60% of web traffic is now AI bots (up from 20-30%), and Steve's petty-genius story of buying borissucks dot sol just to knock a guy off second place on a leaderboard. 0:00 Welcome — the domain space is about to change 1:26 Inder's background and why DNS is bulletproof but everything on top is archaic 4:48 AI dot com sold for $70M cash — and how you'll be able to buy $10 of it 9:04 The 2026 TLD land rush: 1,600 new extensions (BTC, crypto, agent, human) 15:40 D3's origin: Fred, Paul, and the guy who bought 300 TLDs in 2012 18:51 Building DOMA: custody, Namecheap, Paradigm, and why RWAs need checks 23:07 What happens to your .sol — SRS, snapshots, and don't buy new .sol right now 27:23 Pricing: why .sol won't play the $1 first year / $30 renewal game 32:33 Steve's petty-genius: buying borissucks dot sol to knock a guy off a leaderboard 35:20 Domains as your passport on the internet — mTLS, agents, and identity 40:02 Hot take: a neutral internet matters more than crypto itself 41:18 AI traffic is 40-60% of web traffic and Cloudflare can't be the arbiter 46:09 Privacy on DOMA: shielded registration, anonymous domains 54:22 What Solana still needs: the consumer packaging layer 58:57 October timeline, where to follow, and next week