AbstractChain has suffered a security breach linked to the third-party app Cardex on Tuesday, with multiple users reporting unauthorized withdrawals from their wallets.
We are aware of some Abstract users being compromised and want to assure everyone it is not a network wide Abstract Global Wallet (AGW) issue.
This issue seems to be isolated to an app (seems to be Cardex, please do not interact for the time being), we are working to get to the…
Despite initial concerns of a broader vulnerability within the Abstract Global Wallet (AGW), AbstractChain’s engineers have confirmed that the issue is isolated to Cardex.
AbstractChain’s Security Incident: What Went Wrong with Cardex?
The breach stemmed from a flaw in session key management within the Cardex smart contract, exposing users to unauthorized transactions.
Poorly implemented session key handling allowed an attacker to access active sessions and execute transactions without requiring direct user confirmation.
The AbstractChain team, including engineers 0xBeans and 0xCygaar, has actively addressed the situation and assured users that the Abstract Global Wallet itself remains secure.
Full report coming in a bit, but here’s the TLDR of the situation:
– The issue is related to @cardex_space. If you’ve ever interacted with this app, revoke your sessions here: https://t.co/lJfbG3nlZW. This is super important.
– This is not an issue with AGW’s contracts. There…
They have urged anyone who interacted with Cardex to immediately revoke existing approvals to prevent further security breaches.
Blockchain security experts have noted that the exploit resulted from improper session key management rather than a vulnerability in AbstractChain’s infrastructure.
Studying comms from amazing builders:@AbstractChain Security Concern.
TLDR: Abstract took the issue very seriously, addressed it immediately, and gave a first-hand report of the situation from trusted gigabrain engineers.
1⃣ Borked session key management leads to extreme…
Attackers leveraged this weakness to drain funds from users who had previously interacted with the compromised app.
Although the full extent of the financial losses is still being assessed, multiple users have reported losing Ethereum from their Abstract-linked wallets.
Two important things about the @cardex_space exploit from this morning
1) This was an isolated event with Cardex, not a larger issue around Abstract or the AGW itself.
2) The team is actively working on additional security measures that will help prevent against similar…
To mitigate risks, security specialists recommend that all Cardex users revoke session keys via the official revocation tool (https://revoke.abs.xyz) and enable two-factor authentication (2FA) for added security.
How the Community Responded to the Cardex Exploit
The AbstractChain team has received widespread support for its transparency and swift response to the breach.
Unlike traditional crisis management approaches led by marketing teams, AbstractChain allowed its engineers to communicate directly with the community.
Immediate public acknowledgment and ongoing technical explanations have reassured some users, though others remain concerned.
The team has pledged to release a full audit report detailing the root cause of the exploit and outlining corrective measures.
This articles is written by : Nermeen Nabil Khear Abdelmalak
All rights reserved to : USAGOLDMIES . www.usagoldmines.com
You can Enjoy surfing our website categories and read more content in many fields you may like .
Why USAGoldMines ?
USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.