CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data

  • CONTACT
  • MARKETCAP
  • BLOG
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
  • BOOKMARKS
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Reading: ‘Cardex’ Game Exploit Drains Wallets on Ethereum Layer-2 Abstract
Share
You have not selected any currencies to display
CoinRSS: Bitcoin, Ethereum, Crypto News and Price DataCoinRSS: Bitcoin, Ethereum, Crypto News and Price Data
0
Font ResizerAa
  • Blockchain
  • Crypto
  • Market
  • News
Search
  • Blockchain
  • Crypto
    • Bitcoin
    • Ethereum
    • Forex
    • Tether
  • Market
    • Binance
    • Business
    • Investor
    • Money
    • Trading
  • News
    • Coinbase
    • Mining
    • NFT
    • Stocks
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data > Blog > News > ‘Cardex’ Game Exploit Drains Wallets on Ethereum Layer-2 Abstract
News

‘Cardex’ Game Exploit Drains Wallets on Ethereum Layer-2 Abstract

CoinRSS
Last updated: February 20, 2025 2:02 am
CoinRSS Published February 20, 2025
Share

Cardex, a blockchain trading card game on Ethereum layer-2 network Abstract, mishandled its private keys, according to Abstract network core contributors, leading to over $470,000 worth of Ethereum being drained from wallets that interacted with it.

Cardex offered tokenized digital versions of “high-end trading cards,” like a 1st Edition Shining Charizard Pokémon card, which could then be used to compete in online tournaments. Each card has a score that is calculated by its “performance” rating and multiplied by its rarity, with these scores used to determine who would win a tournament.

The game officially launched last week, after a 24-hour card presale for early access users. Early on Tuesday, wallets that had interacted with the Abstract app started to be drained of funds. Pseudonymous Abstract core contributors Cygaar and 0xBeans figured out that the Cardex private key had been mishandled, falling into the hands of a malicious actor, confirming it on X (formerly Twitter).

Full report coming in a bit, but here’s the TLDR of the situation:

– The issue is related to @cardex_space. If you’ve ever interacted with this app, revoke your sessions here: https://t.co/lJfbG3nlZW. This is super important.

– This is not an issue with AGW’s contracts. There…

— cygaar (@0xCygaar) February 18, 2025

With this key, the attacker was able to drain wallets that had an active “session” with the game. It appears that when playing Cardex, users were prompted to sign a transaction, referred to as a session, that would give the app full control over the wallet’s funds for a period of time—allegedly a month in this case, according to one developer who spoke with Decrypt.

“Session basically refers to a temporary authorization that allows a smart contract (or dapp) to execute transactions on behalf of the user without requiring new approvals every time,” CEO of security firm Quill Audits, Preetam Rao, told Decrypt.

Over the course of seven hours, the attacker successfully drained over 180 ETH, worth approximately $484,000, according to a Dune dashboard tracking the attacker’s wallet.

Fortunately, the exploit was isolated to only those that had interacted with Cardex so much of the network remained safe—although some users dispute this. Equally, according to Cygaar, the Cardex was updated which brought an end to the attack. Cygaar confirmed a full report of the situation will be published once all details are ironed out.

“This is a huge blow to the abstract ecosystem,” Rao told Decrypt. “Cardex still hasn’t confirmed the attack from their socials yet, which is a bad move. They should be transparent at a time like this.”

The attack has raised uncomfortable questions around which apps are promoted within the Abstract ecosystem. Some Abstract users are annoyed that they were encouraged to explore apps that have potentially put their funds at risk.

“All app contracts on the portal have been audited (anything spotlighted has a tier-1 firm auditing it),” Cygaar claimed. “The problem in this case was not contract specific, but even then we could’ve done a better job forcing them to have their [operational security] verified.”

Still, some users have pushed back on this explanation, claiming that the exploit shows that session keys on the whole aren’t a safe solution for users. Abstract was built around user-friendliness and attracting a broad consumer base thanks to streamlined features like this.

Rao said that broadly blaming session keys isn’t the answer, however, even if this particular implementation burned users.

“Generally, session keys are good to have,” Rao explained. “It just depends on how they are managed. Think of them like guest passes—you wouldn’t want to give approval to a contract again and again for a swap transaction, right? It just makes it more convenient.”

Edited by Andrew Hayward

GG Newsletter

Get the latest web3 gaming news, hear directly from gaming studios and influencers covering the space, and receive power-ups from our partners.

Source link

You Might Also Like

Ondo Finance Reveals Chain Launch Plans as Trump-Linked Project Buys a Bundle of Tokens

Ethereum Giants Formerly Known as MakerDAO and DAI Now on Solana

Onyxcoin: Up by 68% in 30 hours, altcoin’s next step will be…

Metaplanet Appoints Eric Trump to Newly Formed Strategic Advisory Board

Ethena [ENA] whales lock in losses, but did they exit too soon?

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Copy Link Print
Previous Article If FET bulls defend $0.743 support, a historic rally could follow – How?
Next Article Toncoin TVL falls, but staking activity surges – Is investor behavior shifting?
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Socials
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
Subscribe to our newslettern

Get Newest Articles Instantly!

- Advertisement -
Ad image
Popular News
XRP Leaves Dogecoin Chasing Its Tail, Ethereum in the Ether: Analysis
BTC Price will Hit $100K before Bitcoin Sweeps $30K Lows
Crypto Bahamas: Regulations Enter Critical Stage as Gov’t Shows Interest

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data coin-rss-logo

We influence 20 million users and is the number one business blockchain and crypto news network on the planet.

Subscribe to our newsletter

You can be the first to find out the latest news and tips about trading, markets...

Ad imageAd image
© CoinRSS: Bitcoin, Ethereum, Crypto News and Price Data. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?