CryptoSpiel.com
No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams
No Result
View All Result
CryptoSpiel.com
No Result
View All Result

Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident

February 19, 2025
in Crypto News
Reading Time: 2 mins read
A A
0
Ethereum’s Vanity Addresses Drained of Over $3M Despite 1inch’s Warning
0
SHARES
5
VIEWS
ShareShareShareShareShare

RELATED POSTS

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

The report clarified that the breach stemmed from vulnerabilities in Cardex’s frontend code rather than an issue with Abstract’s core infrastructure or session key validation contracts.

Cardex Wallet Compromise

The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signer’s private key to Cardex’s frontend code, which ultimately led to the exploit.

According to Abstract’s root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

Importantly, only the ETH used within Cardex was affected. Meanwhile, users’ ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

What’s Ahead

In response to this breach, Abstract is also integrating Blockaid’s transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

Credit: Source link

Buy JNews
ADVERTISEMENT
ShareTweetSendPinShare
Previous Post

5 Cryptocurrencies Making Waves as Bitcoin Nears $100K: BLEM, BTC, LTC, LINK & SHIB

Next Post

Top Crypto Market Maker Wintermute Opens New York Office Amid Trump Optimism: Report

Related Posts

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
Crypto News

Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases

April 14, 2026
Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)
Crypto News

Argentina Reviews Phone Logs in LIBRA Case Linked to Javier Milei (Report)

April 8, 2026
Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link
Crypto News

Stabble Urges Users to Pull Liquidity After Alleged North Korean Hacker Link

April 8, 2026
Next Post
New York Attorney General Says She Will ‘Go After’ Crypto Companies Who Don’t Play by the Rules

Top Crypto Market Maker Wintermute Opens New York Office Amid Trump Optimism: Report

Crypto Market Maker Wintermute Eyes US Growth With New OTC Products

Crypto Market Maker Wintermute Eyes US Growth With New OTC Products

Recommended Stories

Bitcoin Addresses Holding Between 100 and 10,000 BTC Hit a 7-Week High

Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

April 10, 2026
Institutional Investors Sell $414,000,000 in Bitcoin and Crypto Assets in One Week: CoinShares

Institutional Investors Sell $414,000,000 in Bitcoin and Crypto Assets in One Week: CoinShares

March 30, 2026
SEC fight over tokenized stocks could decide whether Wall Street keeps control

SEC fight over tokenized stocks could decide whether Wall Street keeps control

April 7, 2026

Popular Stories

  • One Month Of BTC: Ups And Downs Of El Salvador’s Bitcoin Adoption

    One Month Of BTC: Ups And Downs Of El Salvador’s Bitcoin Adoption

    0 shares
    Share 0 Tweet 0
  • Stripe Buys Stablecoin Platform Bridge in Record-Breaking $1.1B Deal: Report

    0 shares
    Share 0 Tweet 0
  • Will it be possible to earn money with Mana? Updates

    0 shares
    Share 0 Tweet 0
  • $140M Worth Stolen Assets Recovered

    0 shares
    Share 0 Tweet 0
  • HK FinTech Week: Understanding Misconceptions on Cryptocurrency

    0 shares
    Share 0 Tweet 0
CryptoSpiel.com

This is an online news portal that aims to provide the latest crypto news, blockchain, regulations and much more stuff like that around the world. Feel free to get in touch with us!

What’s New Here!

  • Ripple CEO Says CLARITY Act Talks Near Breakthrough as Senate Standoff Eases
  • SEC Opens Proceedings on NYSE Proposal to List Grayscale Crypto ETF Options – Regulation Bitcoin News
  • Anthropic Reveals Claude Code Tool Design Philosophy Behind AI Agent Development

Subscribe Now

Loading
  • Live Crypto Prices
  • Contact Us
  • Privacy Policy
  • Terms of Use
  • DMCA

© 2021 - cryptospiel.com - All rights reserved!

No Result
View All Result
  • Home
  • Live Crypto Prices
  • Live ICO
  • Exchange
  • Crypto News
  • Bitcoin
  • Altcoins
  • Blockchain
  • Regulations
  • Trading
  • Scams

© 2021 - cryptospiel.com - All rights reserved!

Please enter CoinGecko Free Api Key to get this plugin works.