A coordinated attack drained 8,721,530 FET worth about $1.55 million from SingularityNET’s Ethereum-side conversion contract on Sept. 19. Twenty-nine minutes later, a dormant NuNet minter key created 408,532,878 NTX and sent the tokens to the same receiving wallet.
The Athena forensic report links the two events through shared wallet activity and separate compromised credentials. Investigators found that a valid signature from the trusted bridge authorizer released the FET, pointing to a compromised backend key rather than a direct flaw that bypassed the contract. The conversionIn function also lacked the 1 million FET cap applied to outbound Ethereum transfers, allowing the full 8.72 million FET balance to leave in one transaction.
Why it matters
The incident shows how authorization design can magnify the impact of a stolen key. The signed message did not bind the eventual recipient, allowing the caller to direct funds to an attacker-controlled address. The NuNet key had been dormant since March 2023, yet it was used to mint an amount equal to roughly 42% of NuNet’s documented token supply.
Fetch.ai paused AGIX-to-FET conversions and its Ethereum-side bridge as a precaution, while saying its own contracts and normal FET transfers remained operational. Bitvavo separately restricted WMTX deposits, withdrawals and trading after citing an active security incident, though the available analysis does not establish that WMTX was compromised through the same mechanism.
Market impact
The attacker routed the stolen FET through MetaMask’s swap infrastructure, exchanged much of it for Ethereum and sold more than 217 million NTX through decentralized liquidity venues. By about 1:10 UTC on Sept. 20, the central wallet held 547.89 ETH worth roughly $1.44 million and another 230 million NTX.
Liquidity quickly limited further NTX sales. Four later transactions involving 38.55 million NTX produced only about 0.30 ETH, while a separate 10 million NTX transfer through Mayan Protocol yielded about 940 USDT.
Frequently asked questions
-
How much FET was drained in the attack?
The attacker withdrew 8,721,530 FET, worth about $1.55 million at the time, from SingularityNET’s Ethereum-side conversion contract.
-
How was the NTX mint connected to the FET theft?
A dormant NuNet minter key created 408,532,878 NTX 29 minutes after the FET withdrawal and sent the tokens to the same receiving wallet.
-
Was the FET bridge contract itself bypassed?
Investigators attributed the withdrawal to a compromised backend authorization key and a valid trusted signature, rather than a direct contract bypass.
-
What protections failed during the FET withdrawal?
The conversionIn function did not enforce the 1 million FET cap used for outbound Ethereum transfers. Its signed message also did not bind the eventual recipient.
-
What actions are being taken after the incident?
Fetch.ai paused AGIX-to-FET conversions and its Ethereum-side bridge as a precaution. Credential rotation and revocation, followed by service reopening, are key remediation tests.
CryptoSlate