{"investigation":{"slug":"cardex","entity_name":"Cardex","trust_score":28,"severity_base":null,"score_modifier":0,"confidence":0.82,"status":"published","content_type":"investigation","summary":"Cardex is an on-chain fantasy trading card game that launched on the Ethereum layer-2 network Abstract in February 2025, offering tokenized digital versions of collectible trading cards for competition in online tournaments. Within one week of launch, a critical operational security failure — the inadvertent exposure of a shared session signer private key on the application's frontend — allowed an attacker to drain approximately $400,000–$470,000 in ETH from roughly 9,000 user wallets over a seven-hour period. The project has been flagged by ZachXBT; user accusations of a rug pull circulated on Telegram, though Abstract core contributors attributed the incident to mishandled credentials rather than intentional fraud. No confirmed restitution fund or formal accountability measure had been publicly disclosed as of the most recent reporting.","sections":[{"content":"On February 18, 2025, suspicious activity on the Abstract layer-2 network was first flagged at approximately 6:07 AM EST when a developer posted a transaction link showing funds being drained. Abstract core contributors identified the source as Cardex within 30 minutes. The exploit continued for approximately seven hours before Cardex's contract was upgraded and access was blocked, halting further losses. Abstract contributors 0xBeans and Cygaar confirmed via X (formerly Twitter) that the issue was isolated to the Cardex application and did not represent a network-wide vulnerability in the Abstract Global Wallet (AGW) infrastructure. Abstract advised all users who had interacted with Cardex to revoke active session approvals via a dedicated tool deployed at revoke.abs.xyz.","heading":"Exploit Overview","sources":[{"url":"https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets","name":"decrypt.co","type":"other","credibility":3},{"url":"https://crypto.news/users-report-six-figure-losses-in-cardex-exploit-on-abstract-chain/","name":"crypto.news","type":"other","credibility":3},{"url":"https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://www.theblock.co/post/341472/abstract-chain-wallet-drains-cardex","name":"theblock.co","type":"other","credibility":3}],"severity":"medium"},{"content":"The exploit stemmed from two compounding operational security failures by the Cardex team. First, Cardex implemented a shared session signer wallet used across all users — a design pattern explicitly advised against by security practitioners. Session keys on Abstract typically grant a third-party application temporary, scoped control over a user's wallet without requiring repeated transaction approvals. Because all user sessions shared a single signer, compromise of that key gave an attacker simultaneous control over every active session. Second, Cardex inadvertently exposed the private key for this shared session signer directly in its frontend code, making it publicly accessible. The attacker exploited the leaked key to execute buyShares transactions on behalf of victim wallets, transferred the resulting shares to a controlled address, and then liquidated those shares via Cardex's bonding curve to extract ETH. The session key permissions were scoped to Cardex's smart contracts, which limited the blast radius: users' ERC-20 tokens and NFTs in their broader wallets were not affected. The vulnerable contract is labeled on the Abstract block explorer at address 0xee580828b426b6cc33817bCE419DaF65a516aA7e and carries an active vulnerability warning. Abstract's own post-mortem confirmed this was an operational security failure, not a flaw in Abstract's core smart contract infrastructure.","heading":"Technical Root Cause","sources":[{"url":"https://bitnewsbot.com/cardex-trading-card-game-loses-470k-in-eth-after-private-key-breach/","name":"bitnewsbot.com","type":"other","credibility":3},{"url":"https://playtoearn.com/news/cardex-exploit-drains-400k-from-abstract-users-heres-what-happened","name":"playtoearn.com","type":"other","credibility":3},{"url":"https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://abscan.org/address/0xee580828b426b6cc33817bce419daf65a516aa7e","name":"abscan.org","type":"other","credibility":3}],"severity":"medium"},{"content":"Abstract's post-mortem confirmed approximately $400,000 in ETH was drained from roughly 9,000 wallets. Some individual users reported losses exceeding $100,000, while others lost smaller amounts. Separate reporting by Bitnewsbot and Decrypt cited figures of approximately $470,000–$484,000 (over 180 ETH), reflecting the total drain across the seven-hour attack window before mitigation. On-chain data showed over 7,000 incoming transactions sent to the attacker's address, corroborating the scale of affected wallets. Cardex had launched only approximately one week prior to the exploit and was actively promoted on Abstract's official Discover page, meaning a significant portion of the affected users were early adopters who had engaged with the platform during its initial promotion window.","heading":"Financial Impact and Affected Users","sources":[{"url":"https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://bitnewsbot.com/cardex-trading-card-game-loses-470k-in-eth-after-private-key-breach/","name":"bitnewsbot.com","type":"other","credibility":3},{"url":"https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets","name":"decrypt.co","type":"other","credibility":3},{"url":"https://cryptorank.io/news/feed/6cc87-ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident","name":"cryptorank.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the exploit, users flooded Cardex's official Telegram channel and Abstract's Discord server with accusations that Cardex had conducted a rug pull. Multiple users demanded refunds and raised concerns about the delayed public response from both the Cardex team and Abstract. Abstract core contributor 0xBeans publicly attributed the breach to Cardex mishandling credentials rather than intentional fraud, and Cygaar acknowledged that while app contracts were audited, \"we could've done a better job forcing them to have their operational security verified.\" Cardex itself confirmed the attack and stated it was \"currently working with the Abstract team to trace the flow of stolen funds and the recovery situation\" but provided limited specifics. As of available reporting, no formal refund mechanism or restitution fund had been established. The distinction between negligent key mismanagement and intentional misconduct remained disputed in community forums. ZachXBT has flagged Cardex as a notable risk entity, though no published ZachXBT investigation specifically attributing deliberate fraud to the Cardex team was identified in available sources.","heading":"Rug Pull Allegations and Community Response","sources":[{"url":"https://crypto.news/users-report-six-figure-losses-in-cardex-exploit-on-abstract-chain/","name":"crypto.news","type":"other","credibility":3},{"url":"https://www.chaincatcher.com/en/article/2168538","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://en.cryptonomist.ch/2025/02/18/ethereum-l2-abstract-under-accusation-wallets-emptied-and-suspected-ties-with-cardex/","name":"en.cryptonomist.ch","type":"other","credibility":3},{"url":"https://www.cryptopolitan.com/abstract-chain-users-compromised/","name":"cryptopolitan.com","type":"other","credibility":3}],"severity":"medium"},{"content":"Following the Cardex incident, Abstract announced a series of security reforms applicable to all applications listed on its Portal. These included mandatory front-end code audits in addition to smart contract audits, reassessment of session key usage across all listed apps to enforce per-user session signers and encrypted key storage, integration of Blockaid's transaction simulation tools for improved real-time threat detection, and publication of updated developer documentation on best practices for session key implementation. Abstract also deployed a new user-facing session key dashboard enabling wallet holders to review and revoke active session approvals at any time. The chain further confirmed that Privy and Blockaid were engaged as partners in the improved security framework. Cygaar acknowledged on X that the portal's prior vetting process was insufficient in that it covered smart contract code but not operational security practices such as frontend key handling.","heading":"Abstract's Post-Exploit Security Reforms","sources":[{"url":"https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","name":"cryptopotato.com","type":"other","credibility":3},{"url":"https://playtoearn.com/news/cardex-exploit-drains-400k-from-abstract-users-heres-what-happened","name":"playtoearn.com","type":"other","credibility":3},{"url":"https://cryptonews.com/news/abstract-releases-post-mortem-on-cardex-security-breach-affecting-9000-wallets/","name":"cryptonews.com","type":"other","credibility":3},{"url":"https://nftinsider.io/abstract-tcg-cardex-suffers-exploit/","name":"nftinsider.io","type":"other","credibility":3}],"severity":"medium"},{"content":"Public information about Cardex's founding team and organizational structure is limited. The project operated under the handle @cardex_space on X and deployed contracts via the address labeled \"Cardex: Deployer\" (0x14d4deaa4aec28a6387a1805ff853f1f06c909f3) on the Abstract block explorer. No named founders or executives were identified in available reporting. Cardex's public communication following the exploit was minimal; the team confirmed the breach and stated cooperation with the Abstract team on tracing stolen funds but did not publish a formal post-mortem or accountability statement. The anonymous or pseudonymous nature of the team, combined with the absence of a disclosed fund-recovery plan, contributed to community skepticism. Abstract, for its part, stated that helping Cardex remediate the situation and refund affected users was its \"top priority,\" but no confirmed disbursement had been reported in available sources.","heading":"Team Transparency and Accountability","sources":[{"url":"https://www.chaincatcher.com/en/article/2168538","name":"chaincatcher.com","type":"other","credibility":3},{"url":"https://abscan.org/address/0xee580828b426b6cc33817bce419daf65a516aa7e","name":"abscan.org","type":"other","credibility":3},{"url":"https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets","name":"decrypt.co","type":"other","credibility":3},{"url":"https://crypto.news/users-report-six-figure-losses-in-cardex-exploit-on-abstract-chain/","name":"crypto.news","type":"other","credibility":3}],"severity":"medium"}],"timeline":[{"date":"2025-02-12","event":"Cardex launches on Abstract layer-2 network, appearing on Abstract's official Discover/Portal page and conducting a 24-hour card presale for early access users.","source":""},{"date":"2025-02-18","event":"At approximately 6:07 AM EST, first suspicious activity is flagged on Abstract as wallet drains are reported. Abstract contributor 0xBeans posts on X identifying Cardex as the likely source and urges users not to interact with the app.","source":""},{"date":"2025-02-18","event":"Within 30 minutes of initial flagging, Cardex is confirmed as the source of the exploit. The attack continues for approximately seven hours, draining over 180 ETH (~$400,000–$470,000) from roughly 9,000 wallets.","source":""},{"date":"2025-02-18","event":"Cardex's vulnerable contract is upgraded to halt further exploit transactions. Abstract deploys revoke.abs.xyz to allow users to cancel active session approvals. Abstract contributor Cygaar confirms the attack vector: a shared session signer private key exposed in Cardex's frontend code.","source":""},{"date":"2025-02-18","event":"Users flood Cardex's Telegram channel and Abstract's Discord with rug pull accusations and refund demands. Cardex confirms the attack and states cooperation with Abstract to trace stolen funds.","source":""},{"date":"2025-02-19","event":"Abstract releases a post-mortem confirming ~$400,000 stolen from ~9,000 wallets and announces new Portal security requirements: mandatory frontend audits, per-user session signers, encrypted key storage, and Blockaid integration.","source":""}],"sources_used":[{"url":"https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets","name":"decrypt.co","type":"other","archive_url":"http://web.archive.org/web/20260516235031/https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets","credibility":3,"archive_timestamp":"2026-05-16T23:50:31+00:00"},{"url":"https://crypto.news/users-report-six-figure-losses-in-cardex-exploit-on-abstract-chain/","name":"crypto.news","type":"other","archive_url":"http://web.archive.org/web/20260608235619/https://crypto.news/users-report-six-figure-losses-in-cardex-exploit-on-abstract-chain/","credibility":3,"archive_timestamp":"2026-06-08T23:56:19+00:00"},{"url":"https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","name":"cryptopotato.com","type":"other","archive_url":"http://web.archive.org/web/20260216074042/https://cryptopotato.com/ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident/","credibility":3,"archive_timestamp":"2026-02-16T07:40:42+00:00"},{"url":"https://www.theblock.co/post/341472/abstract-chain-wallet-drains-cardex","name":"theblock.co","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://bitnewsbot.com/cardex-trading-card-game-loses-470k-in-eth-after-private-key-breach/","name":"bitnewsbot.com","type":"other","archive_url":"http://web.archive.org/web/20260829024614/https://bitnewsbot.com/cardex-trading-card-game-loses-470k-in-eth-after-private-key-breach/","credibility":3,"archive_timestamp":"2026-08-29T02:46:14+00:00"},{"url":"https://playtoearn.com/news/cardex-exploit-drains-400k-from-abstract-users-heres-what-happened","name":"playtoearn.com","type":"other","archive_url":"http://web.archive.org/web/20260116214003/https://playtoearn.com/news/cardex-exploit-drains-400k-from-abstract-users-heres-what-happened","credibility":3,"archive_timestamp":"2026-01-16T21:40:03+00:00"},{"url":"https://abscan.org/address/0xee580828b426b6cc33817bce419daf65a516aa7e","name":"abscan.org","type":"other","archive_url":"http://web.archive.org/web/20260829023212/https://abscan.org/address/0xee580828b426b6cc33817bce419daf65a516aa7e","credibility":3,"archive_timestamp":"2026-08-29T02:32:12+00:00"},{"url":"https://cryptorank.io/news/feed/6cc87-ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident","name":"cryptorank.io","type":"other","archive_url":"https://web.archive.org/web/20260830032608/https://cryptorank.io/news/feed/6cc87-ethereum-layer-2-platform-abstract-reports-400k-crypto-breach-in-cardex-incident","credibility":3,"archive_timestamp":"2026-08-30T03:26:08+00:00"},{"url":"https://www.chaincatcher.com/en/article/2168538","name":"chaincatcher.com","type":"other","archive_url":"https://web.archive.org/web/20260829045119/https://www.chaincatcher.com/en/article/2168538","credibility":3,"archive_timestamp":"2026-08-29T04:51:19+00:00"},{"url":"https://en.cryptonomist.ch/2025/02/18/ethereum-l2-abstract-under-accusation-wallets-emptied-and-suspected-ties-with-cardex/","name":"en.cryptonomist.ch","type":"other","archive_url":"http://web.archive.org/web/20260207171134/https://en.cryptonomist.ch/2025/02/18/ethereum-l2-abstract-under-accusation-wallets-emptied-and-suspected-ties-with-cardex/","credibility":3,"archive_timestamp":"2026-02-07T17:11:34+00:00"},{"url":"https://www.cryptopolitan.com/abstract-chain-users-compromised/","name":"cryptopolitan.com","type":"other","archive_url":"http://web.archive.org/web/20260208233859/https://www.cryptopolitan.com/abstract-chain-users-compromised/","credibility":3,"archive_timestamp":"2026-02-08T23:38:59+00:00"},{"url":"https://cryptonews.com/news/abstract-releases-post-mortem-on-cardex-security-breach-affecting-9000-wallets/","name":"cryptonews.com","type":"other","archive_url":null,"credibility":3,"archive_error":"error:no-request","archive_status":"unarchivable","archive_timestamp":null},{"url":"https://nftinsider.io/abstract-tcg-cardex-suffers-exploit/","name":"nftinsider.io","type":"other","archive_url":"http://web.archive.org/web/20260610152421/https://nftinsider.io/abstract-tcg-cardex-suffers-exploit/","credibility":3,"archive_timestamp":"2026-06-10T15:24:21+00:00"}],"source_tags":["defillama"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet-4-6","created_at":"2026-05-04T02:54:25.424265+00:00","updated_at":"2026-08-30T03:55:00.277905+00:00"}}