NewsCryptoKey Compromise Behind SingularityNET Bridge Attack Drives Losses to $16.77M

Key Compromise Behind SingularityNET Bridge Attack Drives Losses to $16.77M

Author: Metaverse Post·

Key Takeaways

  • A compromised off-chain signing key allowed attackers to drain 8.72 million FET, roughly $1.55 million, from SingularityNET's TokenConversionManagerV3 bridge contract in a single call, indicating the breach occurred in key custody or the signing service rather than the contract code.
  • The contract's design amplified the loss because the conversionIn function imposed no per-conversion limit and the signed message did not bind the payout recipient, letting one valid signature direct funds to any address.
  • Twenty-nine minutes after the FET drain, the attacker's wallet received 408.5 million newly minted NTX, about 42% of NuNet's total supply, from a minter key dormant since March 2023, and the resulting dump drove NTX down roughly 65%.
  • The same exploiter minted 260 million AGIX and 53.8 million WMTx on Ethereum, expanding total holdings to approximately $16.77 million, according to PeckShield monitoring.
  • As of the latest tracking update, the compromised conversion authorizer had not been rotated and the stolen NuNet minter role had not been revoked, leaving both keys capable of signing further conversions and minting additional supply.
Key Compromise Behind SingularityNET Bridge Attack Drives Losses to $16.77M

Attackers drained the Ethereum-side component of the official SingularityNET bridge connecting Ethereum and Cardano of its entire FET liquidity on the evening of 19, 2026, after a compromised off-chain signing key authorized the transfer, according to on-chain analysis. Total losses across affected tokens have since reached approximately $16.77 million.

The targeted contract, TokenConversionManagerV3, paid out 8,721,530 FET — roughly $1.55 million — to an attacker-controlled wallet in a single call to its conversionIn function. The transaction was authorized by a valid cryptographic signature from the bridge's own conversion authorizer, a nonce-zero offline key that exists solely to sign backend approvals, indicating the compromise occurred in key custody or the signing service rather than in the contract code.

FET is the main token of the Artificial Superintelligence Alliance (ASI), formed in 2024 through the merger of Fetch.ai, SingularityNET, and Ocean Protocol.

Contract Design Amplified the Damage

The verified contract's own design magnified the loss. Investigators identified two weaknesses that allowed a single signed message to produce a total drain. First, conversionIn enforces no per-conversion limit: the 8.72 million FET payout was 8.7 times the configured maximum, a cap that applies only to the conversionOut direction. Second, the signed digest binds the caller, amount, and conversion ID — but not the recipient — meaning any valid signature can direct the payout to any address.

Investigators also flagged the conversion ID used in the drain as anomalous raw bytes, unlike the UUID-style identifiers attached to all 100 prior legitimate conversions.

NuNet Mint Follows Within Minutes

Twenty-nine minutes after the FET drain, the same receiving wallet received 408.5 million newly minted NTX — approximately 42% of NuNet's total supply — from a minter key that had been dormant since March 2023 and was gas-funded moments earlier by a separate wallet. Forensics show both operations were rehearsed in advance: pre-positioned NTX was already being sold through MetaMask's swap router before the FET drain executed.

NTX fell roughly 65% as the attacker dumped more than half of the mint, and thin on-chain liquidity meant that roughly 547.9 ETH, about $1.44 million, was the effectively extractable value.

Attack Expands to AGIX and WMTx as Response Leaves Keys Live

The same exploiter subsequently minted 260 million AGIX and 53.8 million WMTx on Ethereum, according to PeckShield monitoring, expanding total holdings to approximately $16.77 million — including 198.3 million AGIX worth about $14.42 million, 649 ETH, and 33.5 million WMTx. AGIX is a legacy SingularityNET token with extremely thin liquidity following the 2024 ASI Alliance merger that made FET the main token, while World Mobile's WMTx appears to have been affected through shared SingularityNET cross-chain permissions.

#PeckShieldAlert The same exploiter has exploited @SingularityNET , resulting in the unauthorised minting of 260M $AGIX \u0026 53.838M $WMTx on Ethereum. The exploiter currently holds ~$16.77M worth of crypto, including 198.3M AGIX (worth $14.42M), 649 $ETH (worth ~$1.67M), and… pic.twitter.com/oHBpbWXQMj — PeckShieldAlert (@PeckShieldAlert) September 20, 2026

Teams Confirm Incident and Pause Conversions

Fetch.ai and SingularityNET both confirmed awareness of the incident. Fetch.ai stated that its own contracts are unaffected and that the attack targets SingularityNET infrastructure, while SingularityNET noted that treasury and exchange wallets were not impacted and that holders need take no action.

Both teams paused AGIX-to-FET conversions and the Ethereum bridge contract as a precaution, deactivated the affected wallets and contracts, and published a preliminary on-chain analysis tracing the attack from the compromised signing key to the attacker's cash-out wallets.

We are aware of an exploit involving the FET token migration and bridge architecture, as well as other tokens within this infrastructure. Our team responded immediately and is working with security partners. An unauthorized party withdrew approximately $1.56M in FET from the… — Artificial Superintelligence Alliance (@ASI_Alliance) September 20, 2026

Following reports of an exploit on 19 September, here is where things stand. \u003e contracts are not affected. No contract is under threat at this time, and FET continues to operate normally. \u003e The attack is targeting SingularityNET… — Fetch.ai (@Fetch_ai) September 20, 2026

Critical Remediation Gaps Remain

As of the latest tracking update, the compromised conversion authorizer had not been rotated, and the stolen NuNet minter role had not been revoked — meaning both keys can still sign further conversions and mint additional supply. Analysts warn that refilling the drained bridge contract before rotating the authorizer would simply re-arm the same attack against fresh funds.

Source: Metaverse Post