|

Key Compromise Behind Fetch.ai-Linked Bridge Attack Drives Losses To $16.77M

Key Compromise Behind Fetch.ai-Linked Bridge Attack Drives Losses To $16.77M
Key Compromise Behind Fetch.ai-Linked Bridge Attack Drives Losses To $16.77M

On the night of September 19, 2026, attackers drained the TokenConversionManagerV3 contract, the Ethereum-side element of the official SingularityNET bridge linking Ethereum and Cardano, of its whole FET liquidity, based on on-chain evaluation. A single name to the contract’s conversionIn operate paid out 8,721,530 FET, roughly $1.55 million, to a pockets beneath attacker management. The transaction was licensed by a sound cryptographic signature from the bridge’s personal conversion authorizer, a nonce-zero offline key that exists solely to signal backend approvals, indicating the compromise occurred in key custody or the signing service quite than in contract code.

The verified contract itself amplified the injury. Two design weaknesses allowed one signed message to trigger whole loss: conversionIn enforces no per-conversion restrict — the 8.72 million FET payout was 8.7 occasions the configured most utilized solely to conversionOut — and the signed digest binds the caller, quantity, and conversion ID however not the recipient, letting any legitimate signature pay any deal with. Investigators additionally flagged the drain’s conversion ID as anomalous uncooked bytes, in contrast to the UUID-style identifiers in all 100 prior reputable conversions.

Twenty-nine minutes after the drain, the identical receiving pockets obtained 408.5 million newly minted NTX, about 42% of NuNet‘s whole provide, from a minter key dormant since March 2023, gas-funded moments earlier by a separate pockets. Forensics present each operations have been rehearsed prematurely: pre-positioned NTX was already being bought via MetaMask’s swap router earlier than the FET drain executed. NuNet’s NTX fell roughly 65% because the attacker dumped greater than half the mint; skinny on-chain liquidity meant roughly 547.9 ETH, about $1.44 million, was the successfully extractable worth.

Operation Expands to AGIX and WMTx as Response Leaves Keys Live

The similar exploiter subsequently minted 260 million AGIX and 53.8 million WMTx on Ethereum, based on PeckShield monitoring, increasing whole holdings to roughly $16.77 million, together with 198.3 million AGIX price about $14.42 million, 649 ETH, and 33.5 million WMTx. AGIX is a legacy SingularityNET token with extraordinarily skinny liquidity following the 2024 ASI Alliance merger that made FET the principle token; World Mobile’s WMTx seems to have been affected via shared SingularityNET cross-chain permissions.

Fetch.ai and SingularityNET each confirmed consciousness of the incident. Fetch.ai acknowledged its personal contracts are unaffected and that the assault targets SingularityNET infrastructure, whereas SingularityNET famous that treasury and change wallets weren’t impacted and that holders want take no motion. Both groups paused AGIX-to-FET conversions and the Ethereum bridge contract as a precaution, deactivated the affected wallets and contracts, and printed a preliminary on-chain evaluation tracing the assault from the compromised signing key to the attacker’s cash-out wallets.

Critical remediation gaps stay. As of the newest monitoring replace, the compromised conversion authorizer had not been rotated and the stolen NuNet minter position had not been revoked, which means each keys can nonetheless signal additional conversions and mint further provide. Refilling the drained bridge contract earlier than rotating the authorizer would merely re-arm the identical assault towards contemporary funds, analysts warn.

The submit Key Compromise Behind Fetch.ai-Linked Bridge Attack Drives Losses To $16.77M appeared first on Metaverse Post.

Similar Posts