Key Compromise Behind Fetch.ai-Linked Bridge Attack Drives Losses To $16.77M
In Brief
A compromised signing key behind the Fetch.ai-linked SingularityNET bridge enabled an exploit draining FET and unauthorizedly minting NTX, AGIX and WMTx, losses now top $16.77M.
On the evening of September 19, 2026, attackers drained the TokenConversionManagerV3 contract, the Ethereum-side component of the official SingularityNET bridge linking Ethereum and Cardano, of its entire FET liquidity, according to on-chain analysis. A single call to the contract’s conversionIn function paid out 8,721,530 FET, roughly $1.55 million, to a wallet under attacker control. The transaction was authorized by a valid cryptographic signature from the bridge’s own conversion authorizer, a nonce-zero offline key that exists solely to sign backend approvals, indicating the compromise occurred in key custody or the signing service rather than in contract code.
The verified contract itself amplified the damage. Two design weaknesses allowed one signed message to cause total loss: conversionIn enforces no per-conversion limit — the 8.72 million FET payout was 8.7 times the configured maximum applied only to conversionOut — and the signed digest binds the caller, amount, and conversion ID but not the recipient, letting any valid signature pay any address. Investigators also flagged the drain’s conversion ID as anomalous raw bytes, unlike the UUID-style identifiers in all 100 prior legitimate conversions.
Twenty-nine minutes after the drain, the same receiving wallet received 408.5 million newly minted NTX, about 42% of NuNet‘s total supply, from a minter key dormant since March 2023, gas-funded moments earlier by a separate wallet. Forensics show both operations were rehearsed in advance: pre-positioned NTX was already being sold through MetaMask’s swap router before the FET drain executed. NuNet’s NTX fell roughly 65% as the attacker dumped more than half the mint; thin on-chain liquidity meant roughly 547.9 ETH, about $1.44 million, was the effectively extractable value.
Operation Expands to AGIX and WMTx as Response Leaves Keys Live
The same exploiter subsequently minted 260 million AGIX and 53.8 million WMTx on Ethereum, according to PeckShield monitoring, expanding total holdings to approximately $16.77 million, including 198.3 million AGIX worth about $14.42 million, 649 ETH, and 33.5 million WMTx. AGIX is a legacy SingularityNET token with extremely thin liquidity following the 2024 ASI Alliance merger that made FET the main token; World Mobile’s WMTx appears to have been affected through shared SingularityNET cross-chain permissions.
Fetch.ai and SingularityNET both confirmed awareness of the incident. Fetch.ai stated its own contracts are unaffected and that the attack targets SingularityNET infrastructure, while SingularityNET noted that treasury and exchange wallets were not impacted and that holders need take no action. Both teams paused AGIX-to-FET conversions and the Ethereum bridge contract as a precaution, deactivated the affected wallets and contracts, and published a preliminary on-chain analysis tracing the attack from the compromised signing key to the attacker’s cash-out wallets.
Critical remediation gaps remain. As of the latest tracking update, the compromised conversion authorizer had not been rotated and the stolen NuNet minter role had not been revoked, meaning both keys can still sign further conversions and mint additional supply. Refilling the drained bridge contract before rotating the authorizer would simply re-arm the same attack against fresh funds, analysts warn.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



