On September 19, an Ethereum-side contract used by SingularityNET for asset conversion was manipulated, sending out 8,721,530 FET worth about $1.55 million at the time. Twenty-nine minutes later, a NuNet minting key that had been dormant for years created 408.5 million NTX and sent the entire amount to the same receiving wallet. Blockchain forensics firm Athena said the two operations may have been coordinated, although existing evidence has not established whether WMTX was affected through the same mechanism.
Fetch.ai subsequently suspended its AGIX-to-FET conversion service and the Ethereum-side bridge contract. The company said the affected infrastructure belongs to SingularityNET and primarily involves its Ethereum-Cardano bridge. Fetch.ai's own contracts and ordinary FET transfers remained operational.
SingularityNET's conversion contract was emptied
The forensic analysis identified the affected contract as TokenConversionManagerV3. It is the formal Ethereum-side component of SingularityNET's bridging system that locks and releases assets, and its verified code matches SingularityNET's public code repository. The contract is also linked to the FET token used by the Artificial Superintelligence Alliance.
Investigators believe the loss resulted from the compromise of a backend authorization key rather than from bypassing the bridge contract itself. The attack transaction carried a valid signature from an address already trusted by the contract, allowing the attacker to call the conversionIn function and release all FET held by the contract to a wallet under their control.
The contract's design increased the impact of a single transaction. A 1 million FET transaction cap applied only to tokens leaving Ethereum and was not enforced on the conversionIn route. The attacker was therefore able to withdraw roughly 8.72 million FET in one transaction. The signed message also did not bind the transaction to a final recipient address, meaning any caller with a valid authorization could specify the wallet receiving the tokens.
Dormant NuNet key mints 408.5 million NTX
The on-chain timeline shows that at 20:50 UTC on September 19, roughly 29 minutes after the FET withdrawal, a NuNet minting key inactive since March 2023 created 408,532,878 NTX. All of the newly minted tokens were sent to the wallet that received the stolen FET. The amount represented about 42% of NuNet's disclosed token supply.
Further tracing strengthened the apparent link between the two events. At 19:36 UTC, 45 minutes before the FET withdrawal, a NuNet minting address sent 0.3667 ETH directly to the final receiving wallet. Another account connected to the attacker sent 24.3 million NTX to the same address.
NTX had also begun moving through MetaMask's swap infrastructure before the FET bridge contract was emptied. This indicates that transfers and attempted monetization involving two sets of compromised credentials may have started before the main FET withdrawal.
Liquidity constrained the asset sales
The attacker then began processing both tokens. Most of the stolen FET was exchanged for ETH through MetaMask's swap infrastructure, while more than 217 million of the newly minted NTX was sold through decentralized liquidity venues. By about 01:10 UTC on September 20, the central wallet held 547.89 ETH, worth approximately $1.44 million, and still held about 230 million NTX.
Further NTX sales were quickly constrained by thin liquidity. Four transactions totaling 38.55 million NTX increased the attacker's ETH balance by only about 0.30 ETH as available pool liquidity had fallen sharply. A separate 10 million NTX transaction was routed through Mayan Protocol and ultimately produced about 940 USDT, which was used for a cross-chain transfer.
Market data for the assets also showed sharp moves. NTX was quoted at $0.00053, up 780.38% over 24 hours; ETH stood at $2,747.34, up 4.23%; and AGIX, associated with SingularityNET, traded at $0.08, down 0.47%. These prices describe market conditions after the incident and do not by themselves show that the token supply or losses have been fully resolved.
WMTX trading halted as link remains unproven
The incident later extended to WMTX. On September 20, Bitvavo suspended WMTX deposits and withdrawals, citing an ongoing security incident involving the token, and subsequently paused trading temporarily. The exchange said customer balances remained safe.
Historical SingularityNET materials indicate that WMTX, FET and NTX have all used infrastructure associated with its Ethereum-Cardano bridging ecosystem. The forensic work to date, however, has focused in detail on the FET and NTX activity and has not established that WMTX was affected through the same vulnerability or the same set of credentials. Cardano was trading at $0.24, up 6.75% over 24 hours.
Credential rotation is central to service recovery
Fetch.ai said it was working with SingularityNET on the investigation and had suspended the relevant conversion services while the review continued. The initial tracing window showed that roughly five hours after the attack, the FET bridge's authorization address and NuNet's minting credentials had not yet been rotated or revoked. By then, the FET bridge contract had been emptied and had stopped operating.
The status of those credentials is therefore a key condition for restoring services. If the same authorization address remains trusted by the contract, replenishing liquidity in the FET conversion contract could leave it exposed to another signed withdrawal. NuNet must likewise address the possibility that the affected wallet could continue minting NTX.
The next operational signals will include when Fetch.ai restores AGIX-to-FET conversions and Ethereum-side bridge services, and whether the relevant authorization credentials are rotated. For WMTX, Bitvavo said trading and transfers would remain restricted during its assessment; the exchange's reopening decision and progress on credential security will determine when affected services can resume.