financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
Feb 19, 2025 3:23 PM

Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

The report clarified that the breach stemmed from vulnerabilities in Cardexs frontend code rather than an issue with Abstracts core infrastructure or session key validation contracts.

Cardex Wallet Compromise

The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signers private key to Cardexs frontend code, which ultimately led to the exploit.

According to Abstracts root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

Importantly, only the ETH used within Cardex was affected. Meanwhile, users ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

Whats Ahead

In response to this breach, Abstract is also integrating Blockaids transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
BNY to Become Custodian of OpenEden’s Tokenized US T
BNY to Become Custodian of OpenEden’s Tokenized US T
Aug 13, 2025
The oldest bank in the United States will become the primary manager of a fund for digitized treasury bills, spearheaded by a prominent RWA tokenization platform. The entity has already achieved several notable milestones and advancements in the DeFi space, and this latest accomplishment is another testament to their commitment. A Modern Twist to Treasury Bills The corporate brand of...
WIF Eyes Breakout From Bullish Wedge After 17% Daily Surge
WIF Eyes Breakout From Bullish Wedge After 17% Daily Surge
Aug 13, 2025
TL;DR WIF challenges $1.02–$1.04 resistance, with analysts targeting $1.3 after bullish wedge breakout confirmation. Active addresses rebound from early August lows, aligning with recent price recovery toward the $1 level. Trading volume up 28% to $1.8B, open interest rises 13% as market participation increases. Price Breakout From Broadening Wedge Dogwifhat (WIF) was trading at $1.04 at press time after gaining...
$76B Fiat Flood into Crypto Sends Strong Market Signal
$76B Fiat Flood into Crypto Sends Strong Market Signal
Aug 13, 2025
The stablecoin market is witnessing a remarkable surge. Billions of fresh capital are potentially setting the stage for increased trading activity and asset appreciation. USDT and USDCs combined growth means investors are positioning for further upside across the crypto market. Billions in Fiat Pour Tethers USDT saw its market cap climb from $120 billion before the US election in November...
Bitcoin Bounces Back This Week, But Glassnode Sees Trouble Ahead
Bitcoin Bounces Back This Week, But Glassnode Sees Trouble Ahead
Aug 13, 2025
The blockchain analytics firm Glassnode shared its weekly report, which features various key metrics and on-chain data related to the leading cryptocurrency. Spot Metrics The spot price rebounded strongly over the past week, after re-testing the sub-$114,000 level and climbing back towards $121,000. This brought momentum back into the spot market, with several sectors showing signs of renewed user activity,...
Copyright 2023-2026 - www.financetom.com All Rights Reserved