Abstract Chain users have been compromised, most likely linked to Cardex app

Source Cryptopolitan

Multiple users have been compromised on Abstract Chain, an EVM-compatible L2 solution, though the issue was limited to specific wallets. Abstract Chain says its platform remains secure, and no network-wide issue has been noticed.

Abstract Chain users with exposure to the Cardex app may be individually affected, as noticed by on-chain investigators. 

The Abstract Chain team confirmed that the network is secure and that no attacks occurred on any wallets. The team tracked the problem to a specific app.

They did not announce the amount of drained funds and aim to keep the vulnerability a secret to prevent further losses.

Cardex went live on the Abstract Chain after February 12 and has already met with the first problem of the partnership. Cardex is a collectible and gaming app, currently running an active tournament, which may have exposed more wallets. Amid the chaos, users have suggested activating 2FA for all Abstract Chain accounts. 

Abstract Chain wallet affects other wallets and accounts

Some Abstract users noted all types of wallets were drained, not only those that engaged with Cardex. Web3 investigators also identified the attack as a ‘first session key hack’. A malicious session that connected the wallet to an app gave the exploiter access to all wallets for a month. 

After the recent hack, on-chain investigators advised users to disconnect from all apps, especially Cardex. Users are urged to move their funds from the wallets, and remove all permissions for Cardex.

An ongoing investigation found the address that is accumulating funds from compromised wallets. Less than two hours after the hack, the amount was relatively minor: $24,520, mostly in Ethereum (ETH), with no other coins or tokens affected. 

Additionally, the malicious wallets may hold up to 50 ETH, with wallets draining still ongoing. When a wallet has been compromised, it checks for sufficient gas. However, because it has given permission to the malicious session contract, it will send the funds to the address of the exploiter.

There are also rumors that even wallets with 2FA activated can be drained, as they have given permission to the contract. 

The final balance in the exploiter’s wallet is unclear, as there are data of up to $81,000 drained. The funds were apparently moved, though no outgoing transaction is found. 

On-chain data showed over 7,000 incoming transactions sent to the hacker’s wallet. This level of activity points to the possible number of affected wallets. Most of the transactions are for minimal amounts of ETH, as the wallets are used for small-scale on-chain usage and fun apps. 

Wallet hacks threaten Web3 adoption

Abstract wallets, which offered a login similar to regular web services, were seen as one of the answers to wider Web3 adoption.

The Abstract Chain wallet hack revealed those tools are not entirely suited for users with no blockchain experience. App connections are still risky, as any contract in the ecosystem can be compromised.

Currently, the only known safeguard is to stop permissions for all apps, and move the funds to a safe wallet if possible. The attack also showed signs of stopping after a total of 17,304 incoming transactions exhausted the pool of vulnerable wallets.

The amount of funds drained reached $31,570. Other estimates saw the funds flow out of the hacker’s wallet and pinned the losses at over $100,000 since the start of the exploit. Estimates vary wildly, with some on-chain explorers noticing up to 300 ETH drained. 

Abstract Chain allows users to create sessions for apps, which may expose their addresses. The chain remained highly popular, as it is linked to the Pudgy Penguins community. However, the user sessions and app permissions may be an ongoing weakness to compromise wallets.

Cryptopolitan Academy: Are You Making These Web3 Resume Mistakes? - Find Out Here

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Dogecoin Eyes Breakout: Bullish Cues Could Push DOGE Towards February HighsDogecoin (DOGE) has been exhibiting potential for a breakout in recent days, fueled by positive market conditions and investor sentiment. Currently trading at $0.25, the meme coin is eyeing a crucial
Author  Beincrypto
8 hours ago
Dogecoin (DOGE) has been exhibiting potential for a breakout in recent days, fueled by positive market conditions and investor sentiment. Currently trading at $0.25, the meme coin is eyeing a crucial
placeholder
Ripple’s XRP surges 7% overnight – XRP ETF filings sentiments take effectXRP was among the top performers in the top ten market cap rankings of cryptocurrencies on Wednesday, surging by more than 7% before Wednesday’s close. The price uptick follows growing optimism over multiple XRP exchange-traded fund (ETF) filings in the United States and Brazil’s regulatory approval of what could become the world’s first spot XRP […]
Author  Cryptopolitan
9 hours ago
XRP was among the top performers in the top ten market cap rankings of cryptocurrencies on Wednesday, surging by more than 7% before Wednesday’s close. The price uptick follows growing optimism over multiple XRP exchange-traded fund (ETF) filings in the United States and Brazil’s regulatory approval of what could become the world’s first spot XRP […]
placeholder
Is Bitcoin Showing Early Signs Of Bullish Divergence? Analyst ExplainsAccording to a recent post on X by crypto analyst Rekt Capital, Bitcoin (BTC) may finally be showing early signs of bullish divergence. If this pattern plays out, BTC could target the $101,000 level
Author  NewsBTC
10 hours ago
According to a recent post on X by crypto analyst Rekt Capital, Bitcoin (BTC) may finally be showing early signs of bullish divergence. If this pattern plays out, BTC could target the $101,000 level
placeholder
Forex Today: Gold hits new record-high, USD struggles to find directionHere is what you need to know on Thursday, February 20: While major currency pairs are having a tough time making a decisive move in either direction, Gold extends its uptrend to a new record-high on Thursday.
Author  FXStreet
10 hours ago
Here is what you need to know on Thursday, February 20: While major currency pairs are having a tough time making a decisive move in either direction, Gold extends its uptrend to a new record-high on Thursday.
placeholder
Trump approves the ‘D.O.G.E dividend’ tax refund for US taxpayersPresident Donald Trump just signed off on a tax refund plan that could send billions back into the pockets of Americans. The ‘D.O.G.E Dividend’, named after Elon Musk’s Department of Government Efficiency (D.O.G.E), will return 20% of the savings from Musk’s cost-cutting initiative directly to taxpayers. Trump confirmed the plan during a Miami Beach event […]
Author  Cryptopolitan
11 hours ago
President Donald Trump just signed off on a tax refund plan that could send billions back into the pockets of Americans. The ‘D.O.G.E Dividend’, named after Elon Musk’s Department of Government Efficiency (D.O.G.E), will return 20% of the savings from Musk’s cost-cutting initiative directly to taxpayers. Trump confirmed the plan during a Miami Beach event […]
goTop
quote