Cardex Session Key Breach Leads to $400K Token Theft
- Abstract’s Cardex app experienced a session key breach, resulting in unauthorized access to nearly $400,000 in user tokens.
- The security flaw was isolated to Cardex and did not affect the Abstract Global Wallet or its network.
- The breach occurred due to the exposure of a session subscriber’s private key during a website approval process.
- No threats were posed to ERC20 token holders or NFT users despite the incident.
- Abstract is working with Seal 911 for emergency security assistance and resolution.
A session key breach in Abstract’s Cardex app led to unauthorized access of nearly $400,000 in user tokens. The issue was confined to Cardex and did not impact other parts of Abstract’s network.
Source (2.6)https://hodl.press/hackers-steal-400k-in-tokens-via-cardex-app-exploit/?rand=24434