|

One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint

A coordinated assault drained 8.7 million FET and used a compromised NuNet minter key to create 408.5 million NTX.

The Sept. 19 attack emptied the Ethereum-side conversion contract utilized by SingularityNET’s bridge, eradicating 8,721,530 FET value about $1.55 million on the time. Twenty-nine minutes later, a stolen NuNet minter created 408.5 million NTX and despatched the tokens to the identical receiving wallet, in accordance to an on-chain forensic report ready by Athena.

Fetch.ai subsequently paused AGIX-to-FET conversions and its Ethereum-side bridge contract as a precaution. The firm mentioned the affected infrastructure belonged to SingularityNET, primarily its Ethereum-Cardano bridge, whereas Fetch.ai’s personal contracts and regular FET transfers remained operational.

The forensic report recognized the affected contract as TokenConversionManagerV3, the legit Ethereum-side lock-and-release part of SingularityNET’s bridge. Its verified supply matches SingularityNET’s public repository, and the contract is tied to the present Artificial Superintelligence Alliance FET token.

Investigators traced the loss to a compromised backend authorization key, not a flaw that permit an attacker bypass the bridge contract. The transaction carried a legitimate signature from the tackle the contract was configured to belief, permitting its conversionIn operate to launch the complete FET steadiness to an attacker-controlled wallet.

The contract’s design magnified the harm. Its 1 million FET transaction cap utilized to tokens shifting out of Ethereum however was not enforced onconversionIn, permitting the attacker to withdraw 8.72 million FET in a single transaction. The signed message additionally failed to bind the eventual recipient, which means a legitimate authorization might direct the tokens to an tackle chosen by the caller.

Same wallet connects separate compromised keys

The NuNet exercise supplies the strongest proof that the FET drain fashioned a part of a broader coordinated operation.

At 20:50 UTC, 29 minutes after the FET withdrawal, a NuNet minter key dormant since March 2023 created 408,532,878 NTX and despatched the complete quantity to the identical wallet that obtained the stolen FET. The mint was equal to roughly 42% of NuNet’s documented token provide, in accordance to the report.

A later forensic go tightened that connection. At 19:36 UTC, 45 minutes earlier than the FET drain, the NuNet minter despatched 0.3667 ETH instantly to the eventual receiving wallet, whereas one other attacker-linked account moved 24.3 million NTX into it.

NTX gross sales by MetaMask’s swap infrastructure had additionally begun earlier than the FET bridge was emptied, indicating that the operation involving the 2 compromised credentials was already underway forward of the primary withdrawal.

The attacker then started changing the belongings. The stolen FET was routed by MetaMask’s swap infrastructure and exchanged largely for Ethereum, whereas greater than 217 million of the newly minted NTX was offered by decentralized liquidity venues.

By about 1:10 UTC on Sept. 20, the central wallet held 547.89 ETH value roughly $1.44 million and one other 230 million NTX, in accordance to the report.

Liquidity shortly grew to become a constraint on the NTX aspect. Four later gross sales involving 38.55 million NTX elevated the attacker’s ETH steadiness by solely about 0.30 ETH as obtainable swimming pools have been depleted. A separate 10 million NTX transaction routed by Mayan Protocol finally produced about 940 USDT for cross-chain dispatch.

Infographic showing the Sept. 19 and Sept. 20 bridge-incident service changes, documented ASI/FET, WMTX and NTX routes, Fetch.ai services that remained operational, and the unresolved NTX supply question.

The disruption later widened past the 2 belongings examined within the forensic report. Bitvavo suspended WMTX deposits and withdrawals on Sept. 20 after citing an lively safety incident affecting the token, then quickly halted buying and selling. The alternate mentioned buyer balances remained protected.

Historical SingularityNET materials exhibits WMTX, FET and NTX all used infrastructure related to its Ethereum-Cardano bridge ecosystem. The obtainable forensic proof, nevertheless, examined the FET and NTX exercise intimately and doesn’t set up that WMTX was compromised by the identical mechanism.

Related Reading

515M NIGHT bridge exploit rocks Cardano but ADA jumps 8% anyway after landmark hard fork


Fetch.ai mentioned it was working with SingularityNET and paused conversions whereas it investigated the incident.

The report’s first monitoring window discovered that the compromised FET bridge authorizer and NuNet minter credentials had not but been rotated or revoked roughly 5 hours after the assault. By then, the FET bridge was empty and inactive.

That makes credential remediation central to restoring the affected companies. Refilling the FET conversion contract whereas the identical authorizer stays trusted might expose recent liquidity to one other signed withdrawal, whereas NuNet faces a separate threat so long as the affected wallet retains authority to create extra NTX.

Fetch.ai’s AGIX-to-FET conversion service and Ethereum-side bridge are due to this fact among the many clearest operational markers to watch.

For WMTX, Bitvavo has mentioned buying and selling and transfers will stay restricted whereas it assesses the incident, leaving alternate reopenings and credential rotations as the following seen checks of whether or not the affected infrastructure is safe.

The put up One wallet links $1.55 million FetchAI theft to massive 408.5 million NTX mint appeared first on CryptoSlate.

Similar Posts