<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Cardex_Wallets_Drained_Compromised_Private_Session_Key</id>
	<title>Cardex Wallets Drained Compromised Private Session Key - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?action=history&amp;feed=atom&amp;title=Cardex_Wallets_Drained_Compromised_Private_Session_Key"/>
	<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Cardex_Wallets_Drained_Compromised_Private_Session_Key&amp;action=history"/>
	<updated>2026-08-24T03:53:46Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.1</generator>
	<entry>
		<id>https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Cardex_Wallets_Drained_Compromised_Private_Session_Key&amp;diff=6689&amp;oldid=prev</id>
		<title>Azoundria: Created page with &quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/cardexwalletsdrainedcompromisedprivatesessionkey.php}} {{Unattributed Sources}}  Cardex Logo/Homepage&lt;ref name=&quot;abstractchaintweet-19360&quot; /&gt;&lt;ref name=&quot;cardexspacetweet-19361&quot; /&gt;&lt;ref name=&quot;cardexhomepage-19362&quot; /&gt;&lt;ref name=&quot;brad1867tweet-19363&quot; /&gt;&lt;ref name=&quot;zigoshkatweet-19364&quot; /&gt;&lt;ref name=&quot;cardextweet1-19365&quot; /&gt;&lt;ref name=&quot;cardextweet2-19366&quot; /&gt;&lt;ref name=&quot;...&quot;</title>
		<link rel="alternate" type="text/html" href="https://quadrigainitiative.com/cryptocurrencyhackscamfraudwiki/index.php?title=Cardex_Wallets_Drained_Compromised_Private_Session_Key&amp;diff=6689&amp;oldid=prev"/>
		<updated>2025-05-09T23:06:42Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/cardexwalletsdrainedcompromisedprivatesessionkey.php}} {{Unattributed Sources}}  &lt;a href=&quot;/cryptocurrencyhackscamfraudwiki/index.php?title=File:Cardexspace.jpg&quot; title=&quot;File:Cardexspace.jpg&quot;&gt;thumb|Cardex Logo/Homepage&lt;/a&gt;&amp;lt;ref name=&amp;quot;abstractchaintweet-19360&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardexspacetweet-19361&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardexhomepage-19362&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;brad1867tweet-19363&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zigoshkatweet-19364&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet1-19365&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet2-19366&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;{{Imported Case Study 2 With About|source=https://www.quadrigainitiative.com/casestudy/cardexwalletsdrainedcompromisedprivatesessionkey.php}}&lt;br /&gt;
{{Unattributed Sources}}&lt;br /&gt;
&lt;br /&gt;
[[File:Cardexspace.jpg|thumb|Cardex Logo/Homepage]]&amp;lt;ref name=&amp;quot;abstractchaintweet-19360&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardexspacetweet-19361&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardexhomepage-19362&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;brad1867tweet-19363&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zigoshkatweet-19364&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet1-19365&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet2-19366&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet3-19367&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abscanjarrodwattsdev-19368&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abscancardexlaunch-19369&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abscanfirstshares-19370&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abscanpudgytheft-19371&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abscanfirstetherprofit-19372&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;abstractchaintweet-19373&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardexspacetweet-19374&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;brad1867tweet-19375&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;zigoshkatweet-19376&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet1-19377&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet2-19378&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;cardextweet3-19379&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-19380&amp;quot; /&amp;gt;&amp;lt;ref name=&amp;quot;unnamed-19381&amp;quot; /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== About CardEx ==&lt;br /&gt;
&amp;quot;Cardex offered tokenized digital versions of “high-end trading cards,” like a 1st Edition Shining Charizard Pokémon card, which could then be used to compete in online tournaments. Each card has a score that is calculated by its “performance” rating and multiplied by its rarity, with these scores used to determine who would win a tournament.&lt;br /&gt;
&lt;br /&gt;
The game officially launched last week, after a 24-hour card presale for early access users.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== The Reality ==&lt;br /&gt;
This sections is included if a case involved deception or information that was unknown at the time. Examples include:&lt;br /&gt;
&lt;br /&gt;
* When the service was actually started (if different than the &amp;quot;official story&amp;quot;).&lt;br /&gt;
* Who actually ran a service and their own personal history.&lt;br /&gt;
* How the service was structured behind the scenes. (For example, there was no &amp;quot;trading bot&amp;quot;.)&lt;br /&gt;
* Details of what audits reported and how vulnerabilities were missed during auditing.&lt;br /&gt;
&lt;br /&gt;
== What Happened ==&lt;br /&gt;
$400k worth of Ethereum were reportedly stolen from Cardex users on Abstract chain.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+Key Event Timeline - Cardex Wallets Drained Compromised Private Session Key&lt;br /&gt;
!Date&lt;br /&gt;
!Event&lt;br /&gt;
!Description&lt;br /&gt;
|-&lt;br /&gt;
|February 7th, 2025 10:22:03 PM MST&lt;br /&gt;
|Cardex Contract Created&lt;br /&gt;
|The Cardex smart contract is first launched on the blockchain.&lt;br /&gt;
|-&lt;br /&gt;
|February 7th, 2025 11:55:23 PM MST&lt;br /&gt;
|First Cardex Share Purchase&lt;br /&gt;
|The very first Cardex shares are purchased in a blockchain transaction.&lt;br /&gt;
|-&lt;br /&gt;
|February 11th, 2025 4:53:00 PM MST&lt;br /&gt;
|Cardex Launch Tweet&lt;br /&gt;
|Cardex reports that they are now live on Abstract Chain.&lt;br /&gt;
|-&lt;br /&gt;
|February 17th, 2025 2:27:33 AM MST&lt;br /&gt;
|Ethereum Profit Theft Transaction&lt;br /&gt;
|An early transaction taking profit in Ethereum from exploiting the Cardex smart contract.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:07:00 AM MST&lt;br /&gt;
|Suspicious Address Reporting&lt;br /&gt;
|@jarrodWattsDev posts this abscan link with a suspicious address taking in user’s funds.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:07:00 AM MST&lt;br /&gt;
|First Users Report Drainer&lt;br /&gt;
|The first user tweets and reports a drainer&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:14:00 AM MST&lt;br /&gt;
|StinkyPablo Ping SEAL 911&lt;br /&gt;
|@stinkypablo pings SEAL 911.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:15:00 AM MST&lt;br /&gt;
|Reply From SEAL 911&lt;br /&gt;
|SEAL 911 replies.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:24:00 AM MST&lt;br /&gt;
|Cardex Suspect As Source&lt;br /&gt;
|Cardex suspected as root cause of drains.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 4:50:00 AM MST&lt;br /&gt;
|0xBeans Notifies Twitter&lt;br /&gt;
|@0x_Beans notifies users on Twitter of the issue.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 5:30:00 AM MST&lt;br /&gt;
|NSerec Revoke Source Code&lt;br /&gt;
|@NSerec shares source code for revoke site (revoke-session.vercel.app) so it can be deployed on an abstract domain.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 5:32:00 AM MST&lt;br /&gt;
|Chainlight Confirms Exposed Key&lt;br /&gt;
|Chainlight confirms that session signer key is exposed on the Cardex frontend.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 5:39:00 AM MST&lt;br /&gt;
|Blockaid Flags Draining&lt;br /&gt;
|Blockaid flags the draining activity through their automated dashboard.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 6:28:00 AM MST&lt;br /&gt;
|Privy Blocks Website Access&lt;br /&gt;
|Privy blocked all users from accessing Cardex to prevent new sessions from being created.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 6:56:00 AM MST&lt;br /&gt;
|Revoke Website Deployed&lt;br /&gt;
|https://revoke.abs.xyz deployed to help users revoke their open sessions.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 7:35:00 AM MST&lt;br /&gt;
|Contract Upgrade Completed&lt;br /&gt;
|Contract was upgraded to revert on every transaction, thus preventing any further exploits.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 12:11:00 PM MST&lt;br /&gt;
|AbstractChain Announcement&lt;br /&gt;
|AbstractChain posts an announcement addressing an early-morning exploit involving Cardex, a third-party app in The Portal, clarifying that the Abstract Global Wallet and network were not compromised. The breach, which impacted around $400,000 in token value, was due to Cardex exposing a session signer key in their frontend code—an issue outside the scope of their initial audits. Abstract praised the swift action of its team, Cardex, and Seal 911 in containing the exploit and reaffirmed its commitment to high security standards. Users are urged to revoke unnecessary approvals via a new revocation portal website which was set up.&lt;br /&gt;
|-&lt;br /&gt;
|February 18th, 2025 1:31:00 PM MST&lt;br /&gt;
|Post-Mortem Published&lt;br /&gt;
|Cygaar from AbstractChain posts a detailed post-mortem of the compromise, explaining that although Abstract’s infrastructure and session key contracts were uncompromised, the issue stemmed from Cardex’s frontend exposing a shared session signer key. This exposed key allowed an attacker to drain ~$400k in ETH from ~9,000 wallets by abusing session permissions to buy, transfer, and sell shares on behalf of victims. No ERC20s or NFTs were affected. The breach is attributed to poor session key practices by Cardex, particularly their use of a single session signer for all users. Abstract now mandates stricter audits, improved frontend security, and is rolling out tools like a session key dashboard and Blockaid’s simulation tech to prevent similar incidents.&lt;br /&gt;
|-&lt;br /&gt;
|March 5th, 2025 4:55:00 PM MST&lt;br /&gt;
|Cardex Claims Disbursements&lt;br /&gt;
|Cardex provides an update on the recent hack, expressing gratitude to the Abstract team for their exceptional support in the recovery process. As of today, Cardex has distributed 94.85 ETH directly to affected wallets and is actively collaborating with Abstract and law enforcement to trace and potentially recover additional funds. They thank the community for their patience throughout the ongoing efforts. The vast majority of comments are users who claim to have not received any compensation.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Technical Details ==&lt;br /&gt;
&amp;quot;The Cardex team completed their initial audits to be approved to be listed on the portal, during this process the Cardex team inadvertently exposed the private key to their session signer on the front end of their website which was outside of the scope of the audit and a practice we warn about. This allowed an attacker to initiate transactions to the Cardex contracts for any wallet that had approved a session key with them.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;quot;The problem today was that the session signer wallet was compromised through a leaked key in Cardex’s frontend code. Because the session signer is shared amongst all sessions, all users who had created sessions on Cardex were at risk.&lt;br /&gt;
The actual exploit worked like this:&lt;br /&gt;
The attacker finds an open session belonging to a victim&lt;br /&gt;
Attacker creates a buyShares transaction to purchase shares on behalf of the victim&lt;br /&gt;
Attacker then calls transferShares through the compromised session to transfer shares to the attacker&lt;br /&gt;
The attacker then sells these shares on the Cardex bonding curve to effectively steal ETH from the victim&lt;br /&gt;
It is important to note that users’ ERC20s and NFTs were not at risk here due to the permissioning of the session keys.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Total Amount Lost ==&lt;br /&gt;
Losses have been consistently reported as 400k.&lt;br /&gt;
&lt;br /&gt;
The total amount lost has been estimated at $400,000 USD.&lt;br /&gt;
&lt;br /&gt;
== Immediate Reactions ==&lt;br /&gt;
The incident was rapidly detected and addressed on February 18th, 2025, beginning at 4:07 AM MST when @jarrodWattsDev flagged a suspicious address draining user funds. By 6:07 AM EST, the first public reports of a drainer surfaced, prompting swift action from the community. SEAL 911 was contacted and responded promptly, and by 6:24 AM EST, Cardex was identified as the likely source. Over the following hours, security researchers confirmed an exposed session signer key on the Cardex frontend, while tools like Blockaid flagged ongoing draining activity. Mitigation efforts included Privy blocking access to Cardex, the deployment of a revoke tool at revoke.abs.xyz, and a critical contract upgrade at 9:35 AM EST to halt further exploits.&lt;br /&gt;
&lt;br /&gt;
== Ultimate Outcome ==&lt;br /&gt;
The Abstract Chain was the first to publicly report on the incident, heavily reporting and shifting a narrative that specifically blamed the poor session key handling of Cardex. Cardex ultimately came to publicly acknowledge the exploit. Cardex worked with others to ultimately return a portion of the funds to affected users.&lt;br /&gt;
&lt;br /&gt;
== Total Amount Recovered ==&lt;br /&gt;
It was reported by Cardex that they returned 94.85 ETH to affected users, which appears to have been focused around higher value wallets. Many users reported that they did not receive compensation and it does not appear to have been made public which users were compensated and how that was decided.&lt;br /&gt;
&lt;br /&gt;
There do not appear to have been any funds recovered in this case.&lt;br /&gt;
&lt;br /&gt;
== Ongoing Developments ==&lt;br /&gt;
It appears that Cardex is continuing to pursue the remaining funds here. It does not appear that Cardex is relaunching their service.&lt;br /&gt;
== General Prevention Policies ==&lt;br /&gt;
&amp;quot;The primary issues in this attack were the shared session signer wallet and exposed session signer key on the frontend. This exploit would not have happened had the session signer wallet been scoped to each user or if the private key of the session signer was not exposed. When we work with teams on session key integration, we recommend they create separate session signers per user and to not store these keys in plain text (should be encrypted in local storage) on the frontend.&amp;quot;&lt;br /&gt;
== Individual Prevention Policies ==&lt;br /&gt;
{{Prevention:Individuals:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Individuals:End}}&lt;br /&gt;
&lt;br /&gt;
== Platform Prevention Policies ==&lt;br /&gt;
{{Prevention:Platforms:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Platforms:End}}&lt;br /&gt;
&lt;br /&gt;
== Regulatory Prevention Policies ==&lt;br /&gt;
{{Prevention:Regulators:Placeholder}}&lt;br /&gt;
&lt;br /&gt;
{{Prevention:Regulators:End}}&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
&amp;lt;references&amp;gt;&amp;lt;ref name=&amp;quot;abstractchaintweet-19360&amp;quot;&amp;gt;[https://twitter.com/AbstractChain/status/1891928658341753039 Abstract Chain - &amp;quot;Early this morning, the Abstract security team detected an exploit originating from Cardex, an app within The Portal. This was not a vulnerability in the Abstract Global Wallet (AGW) or the Abstract network itself but an isolated security failure by a third-party app (Cardex).&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardexspacetweet-19361&amp;quot;&amp;gt;[https://twitter.com/cardex_space/status/1888609372655243590 Cardex Space - &amp;quot;Cardex Army Onboarding... FYI, anyone who spam the mechanism to create an AGW with 0.001 ETH then immediatelly transfer out will be nuked and get smoked.&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardexhomepage-19362&amp;quot;&amp;gt;[https://cardex.space/ Cardex Homepage] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;brad1867tweet-19363&amp;quot;&amp;gt;[https://twitter.com/Brad1867/status/1891957729213743408 Brad (Windsor) - &amp;quot;Thank you for the update but it's been a bad day. ETH drained, cant afford to fund again and now I get 253 XP after using for hours a day all week. I was so hyped just a day ago and now I feel gutted. Where do I go from here?&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zigoshkatweet-19364&amp;quot;&amp;gt;[https://twitter.com/zigoshka/status/1892171750210691073 &amp;lt;nowiki&amp;gt;Zigoshi - &amp;quot;ABSTRACT TEAM SENDS THEIR USERS [AWAY], THEY DON'T CARE THAT THEY PUT SCAM ON THEIR SITE AND THEY BAN ALL DISSATISFIED PEOPLE WHO WANT TO GET THEIR MONEY BACK. even if you just put a smiley face on a post you get banned.&amp;quot; - Twitter/X&amp;lt;/nowiki&amp;gt;] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet1-19365&amp;quot;&amp;gt;[https://twitter.com/cardex_space/status/1897435911224496300 Cardex - &amp;quot;We want to start off by thanking the Abstract team for their continuous support in helping us recover funds. The support we've been given has been unmatched and they are going above and beyond. Here are some updates on where we are: 1. We have distributed a total of 94.85 ETH directly to affected wallets today 2. Alongside Abstract, we are currently working with law enforcement to identify any additional funds that may be able to be recovered. We appreciate the community's patience while we worked through recovering funds.&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet2-19366&amp;quot;&amp;gt;[https://twitter.com/cardex_space/status/1892050287705079882 Cardex - &amp;quot;On Feb 18th, Cardex suffered from an attack associated with the compromised session key. We'd like to thank our users and abstract teams for their help. We're working with abstract team to track the flow of funds and recovery. Thanks for your patience.&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet3-19367&amp;quot;&amp;gt;[https://twitter.com/cardex_space/status/1889462911912837501 Cardex - &amp;quot;Cardex is now live @AbstractChain! No code needed. Trade, Compete, Win. Built on top of real TCG cards. First 24 hrs is presale for early access users, then public. Tournament will start later.&amp;quot; - Twitter/X] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abscanjarrodwattsdev-19368&amp;quot;&amp;gt;[https://abscan.org/address/0xee580828b426b6cc33817bce419daf65a516aa7e Malicious Contract Reported By @jarrodWattsDev - Abscan] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abscancardexlaunch-19369&amp;quot;&amp;gt;[https://abscan.org/tx/0x464b53b86f82231a21d6bedb8c57fcdd73ae4412a896cc8f9b4c051b5aa49fe6 Cardex Smart Contract Creation - Abscan] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abscanfirstshares-19370&amp;quot;&amp;gt;[https://abscan.org/tx/0xd3df562e639a3ce2e34ec481442b73093f9a2171349bc19a722ef6541dec9d27 First Purchase of Cardex Shares - Abscan] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abscanpudgytheft-19371&amp;quot;&amp;gt;[https://abscan.org/tx/0x80b8ba0c4dce252a5d7105a8e8e6a33c832f2e1d232e84fd16609eb7dd76ad2f Theft Of Pudgy Penguin NFT - Abscan] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abscanfirstetherprofit-19372&amp;quot;&amp;gt;[https://abscan.org/tx/0x2868e883a03cbba1e00f8cd0e34fd987a67483370df87ff84a0e2333e19f8d68 First Ethereum Profit Transaction - Abscan] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;abstractchaintweet-19373&amp;quot;&amp;gt;[https://x.com/AbstractChain/status/1891928658341753039 https://x.com/AbstractChain/status/1891928658341753039] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardexspacetweet-19374&amp;quot;&amp;gt;[https://x.com/cardex_space/status/1888609372655243590 https://x.com/cardex_space/status/1888609372655243590] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;brad1867tweet-19375&amp;quot;&amp;gt;[https://x.com/Brad1867/status/1891957729213743408 https://x.com/Brad1867/status/1891957729213743408] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;zigoshkatweet-19376&amp;quot;&amp;gt;[https://x.com/zigoshka/status/1892171750210691073 https://x.com/zigoshka/status/1892171750210691073] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet1-19377&amp;quot;&amp;gt;[https://x.com/cardex_space/status/1897435911224496300 https://x.com/cardex_space/status/1897435911224496300] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet2-19378&amp;quot;&amp;gt;[https://x.com/cardex_space/status/1892050287705079882 https://x.com/cardex_space/status/1892050287705079882] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;cardextweet3-19379&amp;quot;&amp;gt;[https://x.com/cardex_space/status/1889462911912837501 https://x.com/cardex_space/status/1889462911912837501] (Accessed Apr 24, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-19380&amp;quot;&amp;gt;[https://dune.com/artemisrsch/abstract-drain https://dune.com/artemisrsch/abstract-drain] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;ref name=&amp;quot;unnamed-19381&amp;quot;&amp;gt;[https://decrypt.co/306608/cardex-game-exploit-drains-abstract-wallets 'Cardex' Game Exploit Drains Wallets on Ethereum Layer-2 Abstract - Decrypt] (Accessed Apr 25, 2025)&amp;lt;/ref&amp;gt;&amp;lt;/references&amp;gt;&lt;/div&gt;</summary>
		<author><name>Azoundria</name></author>
	</entry>
</feed>