
AI-generated summary
The attack targeted SingularityNET's Ethereum-Cardano bridge, specifically the TokenConversionManagerV3 contract, which Fetch.ai uses for AGIX-to-FET conversions. The infrastructure is part of the Artificial Superintelligence Alliance ecosystem. Fetch.ai paused conversions as a precaution, confirming its own contracts remained unaffected.
A coordinated attack drained 8.7 million FET and used a compromised NuNet minter key to create 408.5 million NTX.
The Sept. 19 attack emptied the Ethereum-side conversion contract used by SingularityNET’s bridge, removing 8,721,530 FET worth about $1.55 million at the time. Twenty-nine minutes later, a stolen NuNet minter created 408.5 million NTX and sent the tokens to the same receiving wallet, according to an on-chain forensic report prepared by Athena.
Fetch.ai subsequently paused AGIX-to-FET conversions and its Ethereum-side bridge contract as a precaution. The company said the affected infrastructure belonged to SingularityNET, primarily its Ethereum-Cardano bridge, while Fetch.ai’s own contracts and normal FET transfers remained operational.
The forensic report identified the affected contract as TokenConversionManagerV3, the legitimate Ethereum-side lock-and-release component of SingularityNET’s bridge. Its verified source matches SingularityNET’s public repository, and the contract is tied to the current Artificial Superintelligence Alliance FET token.
Investigators traced the loss to a compromised backend authorization key, not a flaw that let an attacker bypass the bridge contract. The transaction carried a valid signature from the address the contract was configured to trust, allowing its conversionIn function to release the entire FET balance to an attacker-controlled wallet.
The contract’s design magnified the damage. Its 1 million FET transaction cap applied to tokens moving out of Ethereum but was not enforced onconversionIn, allowing the attacker to withdraw 8.72 million FET in one transaction. The signed message also failed to bind the eventual recipient, meaning a valid authorization could direct the tokens to an address selected by the caller.
Same wallet connects separate compromised keys
The NuNet activity provides the strongest evidence that the FET drain formed part of a broader coordinated operation.
At 20:50 UTC, 29 minutes after the FET withdrawal, a NuNet minter key dormant since March 2023 created 408,532,878 NTX and sent the entire amount to the same wallet that received the stolen FET. The mint was equivalent to roughly 42% of NuNet’s documented token supply, according to the report.
A later forensic pass tightened that connection. At 19:36 UTC, 45 minutes before the FET drain, the NuNet minter sent 0.3667 ETH directly to the eventual receiving wallet, while another attacker-linked account moved 24.3 million NTX into it.
NTX sales through MetaMask’s swap infrastructure had also begun before the FET bridge was emptied, indicating that the operation involving the two compromised credentials was already underway ahead of the main withdrawal.
The attacker then began converting the assets. The stolen FET was routed through MetaMask’s swap infrastructure and exchanged largely for Ethereum, while more than 217 million of the newly minted NTX was sold through decentralized liquidity venues.
By about 1:10 UTC on Sept. 20, the central wallet held 547.89 ETH worth roughly $1.44 million and another 230 million NTX, according to the report.
Liquidity quickly became a constraint on the NTX side. Four later sales involving 38.55 million NTX increased the attacker’s ETH balance by only about 0.30 ETH as available pools were depleted. A separate 10 million NTX transaction routed through Mayan Protocol ultimately produced about 940 USDT for cross-chain dispatch.
The disruption later widened beyond the two assets examined in the forensic report. Bitvavo suspended WMTX deposits and withdrawals on Sept. 20 after citing an active security incident affecting the token, then temporarily halted trading. The exchange said customer balances remained safe.
Historical SingularityNET material shows WMTX, FET and NTX all used infrastructure connected to its Ethereum-Cardano bridge ecosystem. The available forensic evidence, however, examined the FET and NTX activity in detail and does not establish that WMTX was compromised through the same mechanism.
Fetch.ai said it was working with SingularityNET and paused conversions while it investigated the incident.
The report’s first tracking window found that the compromised FET bridge authorizer and NuNet minter credentials had not yet been rotated or revoked roughly five hours after the attack. By then, the FET bridge was empty and inactive.
That makes credential remediation central to restoring the affected services. Refilling the FET conversion contract while the same authorizer remains trusted could expose fresh liquidity to another signed withdrawal, while NuNet faces a separate risk as long as the affected wallet retains authority to create additional NTX.
Fetch.ai’s AGIX-to-FET conversion service and Ethereum-side bridge are therefore among the clearest operational markers to watch.
For WMTX, Bitvavo has said trading and transfers will remain restricted while it assesses the incident, leaving exchange reopenings and credential rotations as the next visible tests of whether the affected infrastructure is secure.
AI outlook — possibilities, not facts
Fetch.ai will resume AGIX-to-FET conversions after completing security audits and confirming key rotation
Likely · Within days
Bitvavo will restore WMTX trading after completing its security assessment
Possible · Within weeks

Blockchain security firm SlowMist discovered malicious code in versions 1.1 and 1.2 of the FomoPeek iPhone app, which was distributed via Apple's App Store and marketed as a cryptocurrency transaction tracker. The app contained hidden modules enabling iOS sandbox escapes to steal private keys and sensitive data, leading to approximately $579,900 in USDT theft traced to attacker address 0x6d37f2C5e8F8546b648D317295565dA95975f4BB. Crypto platforms including Binance and OKX have warned users to remove the app, update iOS, and move assets to new wallets.

The UN Security Council will hear briefings from AI executives including Sam Altman, Dario Amodei, Yoshua Bengio, and Clément Delangue on risks posed by artificial intelligence, such as autonomous cyberattacks, election interference, and weapon design. The session, organized by France, also includes invited statements from Chinese firms DeepSeek and Moonshot. Amodei advocated for slowing AI development and restricting chip exports to China, while Trump dismissed AI risks as a 'hoax'.

White-hat actors have moved 40.71 BTC worth $3.31 million from the Coldcard hardware wallet exploit into a recovery effort labeled 'Crypto Recovery Trust,' according to Galaxy Research. The funds represent 2.8% of the total $130 million theft stemming from a 2021 firmware flaw that generated weak seed phrases on Coinkite devices.

OpenAI released GPT-6 Sol and GPT-6 Luna models on Tuesday, minutes after Anthropic launched Claude Opus 5.5. Sol and Luna are positioned as cheaper, faster alternatives to GPT-6 Astra, with API costs reduced by 50% compared to GPT-5.6 promotional rates. OpenAI claims Sol outperforms Claude Opus 5 on AutomationBench and Agents' Last Exam at significantly lower cost per task, and both models are now available in ChatGPT Work and Codex for paid tiers, with Luna also reaching free users via desktop app.

Anthropic released Claude Opus 5.5, stating it performs at the level of its priciest flagship model Fable 5.1 on most tasks while costing 20% less to run than Opus 5 and 60% less than Fable 5.1. The model leads in agentic coding benchmarks like Terminal-Bench 4.0 and FrontierCode, and is now live across AWS, Google Cloud, and Azure, with Sonnet 5.5 and Haiku 5.5 to follow.

White hats transferred 52.37 Bitcoin rescued from wallets exposed by a Coldcard vulnerability to the Wyoming-based Crypto Recovery Trust to return funds to victims.