Close Menu
FintechFetch
    FintechFetch
    • Home
    • Fintech
    • Financial Technology
    • Credit Cards
    • Finance
    • Stock Market
    • More
      • Business Startups
      • Blockchain
      • Bitcoin News
      • Cryptocurrency
    FintechFetch
    Home»Cryptocurrency»Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
    Cryptocurrency

    Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident

    FintechFetchBy FintechFetchFebruary 19, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

    The report clarified that the breach stemmed from vulnerabilities in Cardex’s frontend code rather than an issue with Abstract’s core infrastructure or session key validation contracts.

    Cardex Wallet Compromise

    The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

    While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signer’s private key to Cardex’s frontend code, which ultimately led to the exploit.

    According to Abstract’s root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

    Importantly, only the ETH used within Cardex was affected. Meanwhile, users’ ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

    The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

    Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

    Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

    What’s Ahead

    In response to this breach, Abstract is also integrating Blockaid’s transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

    A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

    SPECIAL OFFER (Sponsored)

    Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

    LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere’s how £10k could set a stock market beginner on the path to riches in 2025!
    Next Article Is a PYTH Crypto ETF Next? Grayscale Just Launched a Pyth Trust
    FintechFetch
    • Website

    Related Posts

    Cryptocurrency

    Is Solana Ready to Hit $260 Again After 33% Pullback?

    October 17, 2025
    Cryptocurrency

    OKX Taps Standard Chartered to Deliver Bank-Level Security for Institutional Investors in Europe

    October 16, 2025
    Cryptocurrency

    Binance-Led Selling Pressures Bitcoin, But ‘Uptober’ May Soon Flip the Script

    October 16, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    America Is Creating a Bitcoin Reserve But Crypto is Crashing: What The F?

    March 11, 2025

    XRP Sees Renewed Trader Activity as Market Absorbs Selling Pressure

    May 14, 2025

    Up 300% in 5 years, the Marks and Spencer share price looks unstoppable to me

    May 22, 2025

    Julia Stewart: Snubbed for Promotion, Later Acquired Company

    August 26, 2025

    Playtech CEO Sees “Landmark Year” as Company Exceeds EBITDA Targets in 2024

    March 31, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    Most Popular

    Stablecoins at $44.7T: Signals You Cannot Ignore: By Nkahiseng Ralepeli

    September 26, 2025

    My favourite growth stock is up 30% in a month – is it about to go gangbusters again?

    May 25, 2025

    Software Engineers Promise $10K If You Help Them Find Work

    April 4, 2025
    Our Picks

    Unlocking G20 Cross-Border Goals in APAC with Project Nexus

    October 17, 2025

    Employee ownership isn’t an exit plan—it’s a legacy

    October 17, 2025

    Will Bitcoin Recover After $5.6Bn Miner Sell-Off? Analysts Weigh In on $110K Support and 2020-Style Bottom

    October 17, 2025
    Categories
    • Bitcoin News
    • Blockchain
    • Business Startups
    • Credit Cards
    • Cryptocurrency
    • Finance
    • Financial Technology
    • Fintech
    • Stock Market
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us
    Copyright © 2024 Fintechfetch.comAll Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.