Attacker uses single wallet to steal $1.55M in FET and mint 408.5M NTX tokens
A single wallet has been tied to both the $1.55 million theft of FET tokens from a SingularityNET-linked bridge and a subsequent mint of 408.5 million NTX tokens, according to an on-chain forensic report. The pairing indicates two separate compromised credentials were exploited in a coordinated operation rather than two unrelated incidents, a distinction that matters for any institution holding exposure to Fetch.ai, SingularityNET or NuNet infrastructure.
- The attacker drained 8,721,530 FET, worth about $1.55 million at the time, from SingularityNET’s Ethereum-side bridge contract on Saturday (September 19).
- Twenty-nine minutes later, a NuNet minter key dormant since March 2023 created 408,532,878 NTX, roughly 42% of NuNet’s documented token supply, and sent it to the same wallet.
- Bitvavo suspended WMTX deposits and withdrawals on Sunday (September 20) and later halted trading, though the forensic evidence does not establish WMTX was compromised through the same mechanism.
- $1.55M value of FET drained from the bridge contract in one transaction
- 408.5M NTX minted, equal to about 42% of NuNet’s supply
- 547.89 ETH attacker’s holdings by 1:10 UTC Sept. 20, worth roughly $1.44 million
The attack emptied TokenConversionManagerV3, the legitimate Ethereum-side lock-and-release component of SingularityNET’s bridge, according to an on-chain forensic report prepared by Athena and first detailed by CryptoSlate. Fetch.ai subsequently paused its AGIX-to-FET conversion service and Ethereum-side bridge contract as a precaution.
Fetch.ai said the affected infrastructure belonged to SingularityNET, primarily its Ethereum-Cardano bridge. The company’s own contracts and standard FET transfers kept operating throughout.
NuNet Minter Sends 408.5 Million NTX to the Same Wallet That Received Stolen FET
Investigators found that the FET loss traced to a compromised backend authorization key rather than a flaw allowing an attacker to bypass the bridge contract itself. The withdrawal transaction carried a valid signature from the address the contract was configured to trust, letting its conversionIn function release the full FET balance to an attacker-controlled wallet.
The NuNet activity supplied the strongest link tying the two thefts to one operation. At 20:50 UTC, 29 minutes after the FET withdrawal, the dormant minter key created 408,532,878 NTX and sent the entire batch to the wallet that had just received the stolen FET.
A later forensic pass pushed the timeline earlier still. At 19:36 UTC, 45 minutes before the FET drain, the NuNet minter sent 0.3667 ETH directly to the eventual receiving wallet, while a separate attacker-linked account moved 24.3 million NTX into it, and NTX sales through MetaMask’s swap infrastructure had already begun.
Uncapped Conversion Function Let Attacker Withdraw 8.72 Million FET in One Transaction
The contract’s own design amplified the damage once the key was compromised. Its 1 million FET transaction cap applied only to tokens moving out of Ethereum and was never enforced on conversionIn, letting the attacker withdraw all 8.72 million FET at once instead of in capped increments.
The signed authorization message also failed to bind a specific recipient, meaning a valid signature could redirect funds to any address the caller chose.
Liquidity constraints then shaped how much value the attacker could extract.
The stolen FET was swapped largely into Ethereum, while more than 217 million of the newly minted NTX was sold through decentralized venues before pools thinned; four later sales of 38.55 million NTX combined added only about 0.30 ETH, and a 10 million NTX transaction routed through Mayan Protocol produced roughly 940 USDT.
Bitvavo Halts WMTX Trading While Credentials Remain Unrotated
Bitvavo suspended WMTX deposits and withdrawals on Sunday (September 20) citing an active security incident, then temporarily halted trading, while telling customers their balances remained safe. Historical SingularityNET material shows WMTX shares infrastructure with FET and NTX through the Ethereum-Cardano bridge ecosystem, but the forensic report examined only the FET and NTX activity in detail.
Roughly five hours after the attack, the report’s first tracking window found the compromised FET bridge authorizer and NuNet minter credentials had still not been rotated or revoked. By then the FET bridge itself was empty and inactive.
That leaves a narrow but consequential window open. Refilling the FET conversion contract while the same authorizer stays trusted risks exposing fresh liquidity to another signed withdrawal, and NuNet faces a parallel risk as long as the compromised wallet retains minting authority.
The CCS read. The real exposure here sits with anyone treating AI-agent token bridges as fungible custody infrastructure rather than distinct trust boundaries. NTX holders absorbed dilution equal to nearly half the prior supply before any exchange froze trading, while WMTX got caught by association rather than evidence. Institutions building positions across the Fetch.ai, SingularityNET and NuNet complex should be pricing each bridge’s key-management practices separately, not as a single ASI Alliance risk.
Fetch.ai has not said when AGIX-to-FET conversions or its Ethereum-side bridge will resume, and Bitvavo has said WMTX trading and transfers stay restricted until it completes its own assessment. Whether either team has rotated the compromised authorizer and minter keys since the report’s five-hour snapshot remains the next verifiable marker for institutions tracking the affected infrastructure.