ANNONSE
ANNONSE
EGW-NewsTre på rad: én angriper, ett sett med stjålne nøkler og en veldig dårlig helg for ASI-alliansen
Tre på rad: én angriper, ett sett med stjålne nøkler og en veldig dårlig helg for ASI-alliansen
251
Add as a Preferred Source
0
0

Tre på rad: én angriper, ett sett med stjålne nøkler og en veldig dårlig helg for ASI-alliansen

Denne artikkelen er tilgjengelig på følgende språk

Over the weekend of September 19 and 20, a single attacker walked through three AI-focused crypto projects one after another. Fetch.ai, NuNet and SingularityNET all got hit, and PeckShield flagged that the same exploiter was behind every one of them. The wallet now holds about $16.77 million on paper. The money that actually left is much smaller, and that gap is the interesting part of this story.

Saturday: the FET drain

The first move came at 20:21 UTC on September 19, when roughly 8.7 million FET left Fetch.ai's Ethereum token converter. Fetch.ai's own on-chain analysis, relayed by KuCoin, puts the figure at 8,721,530 FET, about $1.55 million, and traces it to a compromised backend key on SingularityNET's cross-chain bridge. Nobody cracked the contract. The attacker showed up with a valid signature and the converter said yes.

Startup Fortune reports that the function involved never called the limit check Fetch.ai had already built into its sister function. So even a legitimate-looking signature could empty the pot in one go.

Within a minute, a stolen NuNet minting key printed 408.5 million NTX, around 42% of the total supply. NTX fell 65 to 70 percent in the first reports, and Startup Fortune says the drop reached 95% at the worst point. FET slipped about 10%. The attacker sold the real FET for roughly 523 ETH, according to Crypto Economy.

Fetch.ai said on X it was working with SingularityNET to deactivate the affected wallets and contracts, and that its own preliminary read pointed to a compromised signing key, not a bug in the contract logic.

Sunday: SingularityNET

A few hours later the same address moved on to the SingularityNET bridge. According to PANews, PeckShield reported 260 million AGIX and 53.838 million WMTx minted on Ethereum, and World Mobile Chain confirmed its side of the bridge had been exploited too. Other tallies are bigger. Coin Bureau, as summarized by Hokanews, counts 896 million AGIX, 500.5 million WMTx and 492.4 million CGV across the whole incident. I'd treat the per-token mint numbers as provisional until someone publishes a full reconciliation.

The ASI Alliance's own account said Fetch.ai's core contracts were unaffected and AGIX-to-FET conversions were paused as a precaution. As of September 21, Crypto Times noted that SingularityNET had not put out a standalone incident statement of its own.

The $17 million problem

PeckShield's number is real, but read it carefully. The wallet holds 198.3 million AGIX valued at $14.42 million, plus 649 ETH and a slice of WMTx. Most of that value is freshly minted AGIX, a legacy token with very thin liquidity since the 2024 merger made FET the main asset, according to Metaverse Post. Try selling 198 million of it and the price you were counting on isn't there anymore.

The cash-out side looks like this: about $1.55 million in FET, around 547.9 ETH (roughly $1.44 million) worth of extractable NTX value, and $289,575 in USDC taken from a payroll contract, per Protos. Protos puts the realized theft near $2 million.

That also matters for the theory floating around that the size of the wallet means these three hacks were far from the first. Maybe. The reporting I found doesn't tie this address to earlier thefts, and most of the $17 million balance is explained by this exact incident. It's a fair question. It just isn't answered yet.

Keys, not code

The detail that bothers me most is Bitquery's. Before any token moved, the attacker swept ETH and BNB from 16 wallets, and four of them had previously been labelled as SingularityNET or NuNet staff wallets. That looks less like a clever contract exploit and more like someone getting inside the house. Bitquery also warned that most of the signing keys had not been changed, and as of September 21 the compromised converter authorizer and the stolen NuNet minter role were both reported as still live.

I keep coming back to that. This is an alliance that sells decentralized AI infrastructure, and it got undone by the oldest question in the industry: who holds the keys, and how many things do those keys touch? One authorizer key reached a converter, a minter and a bridge across projects that share history but, on paper, are separate companies.

September has been crowded with exploits, so this one could easily blur into the pile. The open items are concrete: whether the keys are finally rotated, what NuNet does about the 230 million NTX still sitting in one wallet, and whether AGIX-to-FET conversions come back at all.

Ikke gå glipp av nyheter og oppdateringer om esport! Registrer deg og motta ukentlig artikkeloversikt!
Registrer deg

Airdrops and retrodrops were supposed to be the money story of 2026. So far the only retrodrop that paid out in this corner of the market went to whoever held the minting key.

ANNONSE
Legge igjen en kommentar
Likte du artikkelen?
0
0

Kommentarer

ANNONSE
FREE SUBSCRIPTION ON EXCLUSIVE CONTENT
Receive a selection of the most important and up-to-date news in the industry.
*
*Only important news, no spam.
SUBSCRIBE
LATER