Summary
Cardex is an on-chain fantasy trading card game that launched on the Ethereum layer-2 network Abstract in February 2025, offering tokenized digital versions of collectible trading cards for competition in online tournaments. Within one week of launch, a critical operational security failure — the inadvertent exposure of a shared session signer private key on the application's frontend — allowed an attacker to drain approximately $400,000–$470,000 in ETH from roughly 9,000 user wallets over a seven-hour period. The project has been flagged by ZachXBT; user accusations of a rug pull circulated on Telegram, though Abstract core contributors attributed the incident to mishandled credentials rather than intentional fraud. No confirmed restitution fund or formal accountability measure had been publicly disclosed as of the most recent reporting.
Connected Entities
1 entitiesTimeline(6 events)
2025-02-12
Cardex launches on Abstract layer-2 network, appearing on Abstract's official Discover/Portal page and conducting a 24-hour card presale for early access users.
2025-02-18
At approximately 6:07 AM EST, first suspicious activity is flagged on Abstract as wallet drains are reported. Abstract contributor 0xBeans posts on X identifying Cardex as the likely source and urges users not to interact with the app.
2025-02-18
Within 30 minutes of initial flagging, Cardex is confirmed as the source of the exploit. The attack continues for approximately seven hours, draining over 180 ETH (~$400,000–$470,000) from roughly 9,000 wallets.
2025-02-18
Cardex's vulnerable contract is upgraded to halt further exploit transactions. Abstract deploys revoke.abs.xyz to allow users to cancel active session approvals. Abstract contributor Cygaar confirms the attack vector: a shared session signer private key exposed in Cardex's frontend code.
2025-02-18
Users flood Cardex's Telegram channel and Abstract's Discord with rug pull accusations and refund demands. Cardex confirms the attack and states cooperation with Abstract to trace stolen funds.
2025-02-19
Abstract releases a post-mortem confirming ~$400,000 stolen from ~9,000 wallets and announces new Portal security requirements: mandatory frontend audits, per-user session signers, encrypted key storage, and Blockaid integration.
Decision Log
- hash: 5T64jqShZyRYYwsdU7xeVmAXaKAJAfejsGQuKWcQM63w
This investigation is cryptographically anchored to the Solana blockchain and source URLs are archived via the Internet Archive.
model: claude-sonnet-4-6
generated: 5/4/2026, 2:54:25 AM
last updated: 5/30/2026, 4:47:55 AM
avoid.net — verified advice for a post-truth world