Close Menu
Global News HQ
    What's Hot

    Should You Buy Enphase Stock Before July 22? | The Motley Fool

    July 8, 2025

    Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure

    July 8, 2025

    PepsiCo and Wendy’s exec Kirk Tanner to become Hershey’s next CEO

    July 8, 2025
    Recent Posts
    • Should You Buy Enphase Stock Before July 22? | The Motley Fool
    • Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure
    • PepsiCo and Wendy’s exec Kirk Tanner to become Hershey’s next CEO
    • It’s Time to Refresh Your Bathroom Towels—and Our Walmart Line Has the Softest Sets
    • Wolfe Landau converting former Barneys in Chelsea 
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Should You Buy Enphase Stock Before July 22? | The Motley Fool
    • Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure
    • PepsiCo and Wendy’s exec Kirk Tanner to become Hershey’s next CEO
    • It’s Time to Refresh Your Bathroom Towels—and Our Walmart Line Has the Softest Sets
    • Wolfe Landau converting former Barneys in Chelsea 
    • The 2025 Pro Bono Scorecard: National Report | Law.com
    • Trade war live: Trump says no extension to August tariff deadline
    • Fitness and Wellness Deals Worth Adding to Cart on Amazon Prime Day July 2025
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Cryptocurrency & Blockchain - Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident
    Cryptocurrency & Blockchain

    Ethereum Layer 2 Platform Abstract Reports $400K Crypto Breach in Cardex Incident

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Ethereum Layer 2 Platform Abstract Reports 0K Crypto Breach in Cardex Incident
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Ethereum Layer 2 platform, Abstract, has released an initial post-mortem on a security incident that resulted in the compromise of approximately $400,000 worth of ETH across 9,000 wallets interacting with Cardex, a blockchain-based game on its network.

    The report clarified that the breach stemmed from vulnerabilities in Cardex’s frontend code rather than an issue with Abstract’s core infrastructure or session key validation contracts.

    Cardex Wallet Compromise

    The incident revolved around the misuse of session keys, a mechanism in the Abstract Global Wallet (AGW) that allows for temporary, scoped permissions to improve user experience.

    While session keys themselves are a well-audited security feature, Cardex made a critical error by using a shared session signer wallet for all users, a practice that is not recommended. This flaw was further amplified by the exposure of the session signer’s private key to Cardex’s frontend code, which ultimately led to the exploit.

    According to Abstract’s root cause analysis, attackers identified an open session from a victim, initiated a buyShares transaction on their behalf, and then used the compromised session key to transfer the shares to themselves before selling them on the Cardex bonding curve to extract ETH.

    Importantly, only the ETH used within Cardex was affected. Meanwhile, users’ ERC-20 tokens and NFTs remained secure due to session key permissions limitations.

    The timeline of events indicates that the first signs of suspicious activity were flagged at 6:07 AM EST on February 18th when a developer posted a transaction link showing an address draining funds. In less than 30 minutes, Cardex was suspected as the source of the exploit, and security teams quickly mobilized to investigate.

    Within hours, mitigation steps were taken. This included blocking access to Cardex, deploying a session revocation site, as well as upgrading the affected contract to prevent further transactions.

    Abstract has outlined several measures to prevent future incidents of this nature. Going forward, all applications listed in its portal must undergo a stricter security review, including front-end code audits to prevent the exposure of sensitive keys. Additionally, session key usage across listed apps will be reassessed to ensure proper scoping and storage practices. Documentation on session key implementation will be updated to reinforce best practices.

    What’s Ahead

    In response to this breach, Abstract is also integrating Blockaid’s transaction simulation tools into AGW, which will help users to see what permissions they are granting when creating session keys. Further collaborations with Privy and Blockaid are underway to improve session key security.

    A session key dashboard will also be introduced in The Portal, which is expected to give users a centralized interface to review and revoke their open sessions.

    SPECIAL OFFER (Sponsored)

    Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

    LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!



    Source link

    Hacks
    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleThe Dangers of Action-Faking and Hustle Culture
    Next Article Rocket offering renters up to $5K in closing credits

    Related Posts

    Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure

    July 8, 2025

    Falcon USD stablecoin loses dollar peg amid liquidity, collateral concerns

    July 8, 2025

    DigitalX Taps Animoca’s Yat Siu, Raises $13.5M to Buy Bitcoin – Decrypt

    July 8, 2025

    Shiba Inu Price Could See 180% Explosion As This Indicator Flashes Bullish Divergence

    July 8, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Finance & Investment
    2 Mins Read

    Should You Buy Enphase Stock Before July 22? | The Motley Fool

    In this video, Motley Fool contributor Jason Hall breaks down what has happened with Enphase…

    Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure

    July 8, 2025

    PepsiCo and Wendy’s exec Kirk Tanner to become Hershey’s next CEO

    July 8, 2025

    It’s Time to Refresh Your Bathroom Towels—and Our Walmart Line Has the Softest Sets

    July 8, 2025
    Top
    Finance & Investment
    2 Mins Read

    Should You Buy Enphase Stock Before July 22? | The Motley Fool

    In this video, Motley Fool contributor Jason Hall breaks down what has happened with Enphase…

    Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure

    July 8, 2025

    PepsiCo and Wendy’s exec Kirk Tanner to become Hershey’s next CEO

    July 8, 2025
    Our Picks
    Finance & Investment
    2 Mins Read

    Should You Buy Enphase Stock Before July 22? | The Motley Fool

    In this video, Motley Fool contributor Jason Hall breaks down what has happened with Enphase…

    Cryptocurrency & Blockchain
    2 Mins Read

    Tether holds $8 billion worth of gold in Swiss vault, matching UBS exposure

    Tether CEO Paolo Ardoino revealed that the firm holds roughly $8 billion in gold in…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version