financetom
Cryptocurrency
financetom
/
Cryptocurrency
/
Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
Feb 19, 2025 3:23 PM

Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

The report clarified that the breach stemmed from vulnerabilities in Cardexs frontend code rather than an issue with Abstracts core infrastructure or session key validation contracts.

Cardex Wallet Compromise

The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signers private key to Cardexs frontend code, which ultimately led to the exploit.

According to Abstracts root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

Importantly, only the ETH used within Cardex was affected. Meanwhile, users ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

Whats Ahead

In response to this breach, Abstract is also integrating Blockaids transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
MARA: US Must Dominate Bitcoin Hash Rate to Ensure Financial Sovereignty
MARA: US Must Dominate Bitcoin Hash Rate to Ensure Financial Sovereignty
Nov 27, 2024
Following Donald Trumps presidential victory and his promise to establish a strategic Bitcoin reserve, momentum has surged around the idea of integrating Bitcoin into the nations economic and geopolitical strategy. In the latest development, crypto miner MARA Holdings has urged the United States to aggressively pursue leadership in the sector and in Bitcoin mining, positioning the asset as a matter...
Bullish Shiba Inu (SHIB) Price Prediction: 50% Rally Incoming?
Bullish Shiba Inu (SHIB) Price Prediction: 50% Rally Incoming?
Nov 27, 2024
TL;DR Analysts predict SHIB could see significant gains if it breaks key resistance, with reduced exchange supply supporting the bullish forecasts. Shibarium’s progress could also drive the meme coins next rally. SHIB Gearing up for Another Pump? The cryptocurrency market experienced a substantial correction in the past few days, with leading assets like Bitcoin (BTC), Ethereum (ETH), Solana (SOL), and...
CFTC Could Lead Crypto Regulation Revolution as Trump Administration Reshapes Jurisdiction
CFTC Could Lead Crypto Regulation Revolution as Trump Administration Reshapes Jurisdiction
Nov 27, 2024
After years of positioning itself as the dominant regulatory force in the digital asset space, often at odds with crypto advocates, the Securities and Exchange Commission (SEC) faces a significant shift in jurisdictional control. Amidst mounting frustration with the agencys combative approach, the incoming Trump administration is pushing to expand the Commodity Futures Trading Commission (CFTC) s powers, granting it...
Pump Science Key Leak Sparks Token Fraud Concerns
Pump Science Key Leak Sparks Token Fraud Concerns
Nov 27, 2024
Pump Science, a decentralized science (DeSci) launch platform on Solana, has disclosed a severe security breach involving one of its wallet addresses. The wallet’s private key, identified as T5j2UB…jjb8sc, was inadvertently exposed by a developer who embedded it in the platform’s codebase. The error allowed attackers to hijack the wallet, leading to the unauthorized creation of tokens linked to Pump...
Copyright 2023-2025 - www.financetom.com All Rights Reserved