• CONTACT
  • Privacy Policy
  • Blog
  • Terms & Conditions
  • About Us
Crypto Tag News
  • Home
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
Reading: Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
Share
  • bitcoinBitcoin(BTC)$107,792.00
  • ethereumEthereum(ETH)$2,499.25
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$2.31
  • binancecoinBNB(BNB)$664.75
  • solanaSolana(SOL)$172.29
  • usd-coinUSDC(USDC)$1.00
  • dogecoinDogecoin(DOGE)$0.222171
  • cardanoCardano(ADA)$0.74
  • tronTRON(TRX)$0.269852
Crypto Tag NewsCrypto Tag News
Aa
  • Home
  • Blockchain
  • Crypto
  • Market
Search
  • Home
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
Have an existing account? Sign In
Follow US
© Crypto Tag NEWS. All Rights Reserved.
Crypto Tag News > Blog > Crypto > Ethereum > Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
Ethereum

Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident

snifferius
Last updated: 2025/02/20 at 2:41 AM
snifferius Published February 20, 2025
Share



Contents
Cardex Wallet CompromiseWhat’s Ahead

Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

The report clarified that the breach stemmed from vulnerabilities in Cardex’s frontend code rather than an issue with Abstract’s core infrastructure or session key validation contracts.

Cardex Wallet Compromise

The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signer’s private key to Cardex’s frontend code, which ultimately led to the exploit.

According to Abstract’s root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

Importantly, only the ETH used within Cardex was affected. Meanwhile, users’ ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

What’s Ahead

In response to this breach, Abstract is also integrating Blockaid’s transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

You Might Also Like

CZ Slams WSJ for Claiming He Helped Trump-Linked Crypto Deal

Top Crypto Gainers Today May 23 – Optimism, Injective, Clearpool, Acet

Bitcoin Reverses Gains as President Trump Revives Tariff Scare

Democrats Push to Amend GENIUS Act Due to Trump’s Crypto Ties

FIFA to Launch Custom Avalanche Blockchain for Digital Collectibles

TAGGED: 400K, Abstract, Breach, Cardex, Crypto, Ethereum, incident, Layer, platform, reports

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.

By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share this Article
Facebook Twitter Email Copy Link Print
Previous Article PBOC sets one and five year loan prime rates unchanged
Next Article The Next Decade, Part 3: The Road Blocks(And Roads Around?)
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Socials
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
CZ Slams WSJ for Claiming He Helped Trump-Linked Crypto Deal
Understanding Bitcoin: A Beginner’s Guide to the World of Cryptocurrency
Exploring the Impact of Cryptocurrency Regulations on Global Finance

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Crypto Tag News

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad image

© Crypto Tag NEWS. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?