ASI Alliance SingularityNET Bridge Key Compromise
A compromised bridge signing key let an attacker drain FET and mint AGIX, NTX and WMTx across the ASI Alliance's Ethereum token-conversion contracts, amassing roughly $16.77 million in tokens.
- Date
- Victim
- ASI Alliance
- Chain(s)
- Status
- Funds Stolen
On September 19, 2026, the ASI Alliance — the merged Fetch.ai, SingularityNET and Ocean project — suffered a bridge key compromise that let an attacker drain and mint tokens across its Ethereum conversion contracts, ultimately holding tokens worth approximately $16.77 million.
What happened
The abused component was TokenConversionManagerV3, the Ethereum-side contract of SingularityNET's official bridge. The transaction that started the theft carried a valid cryptographic signature from the bridge's own conversion authorizer — a nonce-zero offline key that exists only to sign backend approvals. Nothing in the contract logic was broken; the compromise sat in key custody or the signing service, giving the attacker the bridge's own minting and release authority.
With that authority the attacker moved in stages:
- Drained 8,721,530 FET (~$1.55 million) from TokenConversionManagerV3 in a single transaction.
- Minted 408.5 million NTX — roughly 42% of NuNet's supply — crashing the token more than 65%.
- On September 20, minted 260 million AGIX and 53.8 million WMTx (World Mobile) using the same compromised signing stack.
By the end, the attacker's cluster held about $16.77 million in tokens — 198.3M AGIX ($14.42M), 649 ETH ($1.67M) and 33.5M WMTx (~$627K). Most of that was newly minted inventory, not realized cash; the only cleanly liquidated leg was the FET drain.
Aftermath
Fetch.ai and SingularityNET paused AGIX-to-FET conversions and the Ethereum bridge contract once anomalous cross-chain flows were detected. Both stressed that treasury, exchange and self-custodied user funds were unaffected and that holders needed to take no action. A worrying gap remained at the time of reporting: neither the compromised authorizer key nor the stolen NuNet minter role had been revoked.
Why it matters
This was a signing-authority failure, not a contract bug — the same class as the KelpDAO rsETH bridge exploit, where a 1-of-1 verifier controlled unbacked minting, and the Liquid Network sidechain breach. When a single offline key can authorize a bridge to mint, its custody is the entire security model. It also shows why the raw "value minted" headline overstates realized damage: unbacked mint inventory collapses in price the moment the attacker tries to sell, so the market, not the exploit, sets the final loss.
Sources & on-chain evidence
- [01]mpost.iohttps://mpost.io/key-compromise-behind-fetch-ai-linked-bridge-attack-drives-losses-to-16-77m/
- [02]kucoin.comhttps://www.kucoin.com/blog/en-fetch-ai-fet-exploit-1-56m-drained-from-token-converter-after-signing-key-compromise
- [03]cryptotimes.iohttps://www.cryptotimes.io/2026/09/21/singularitynet-bridge-hack-widens-260m-agix-53-8m-wmtx-minted-16-77m-held-by-attacker/